I also support adoption.

We should further discuss the contentious points in the WG, but I do believe it 
would be worthwhile to work on this in the WG and
for an HTTP Message Signature based mechanism to be defined that co-exists with 
DPoP. DPoP solves specific problems and
solves them well, but we see DPoP being thrown at problems that it wasn’t 
designed for and it’s starting to cause problems right now imho.

Best Regards,
Christian

> On 21. Sep 2026, at 21:16, Rifaat Shekh-Yusef <[email protected]> wrote:
> 
> All,
> 
> This is an official call for adoption for the OAuth Proof of Possession 
> Tokens with HTTP Message Signatures draft:
> https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html
> 
> Please, reply on the mailing list, on whether you support or oppose the 
> adoption of this draft as a WG document by October 5th.
> 
> Regards,
>  Rifaat & Hannes
> _______________________________________________
> OAuth mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to