Re: [OAUTH-WG] Small bug in DPoP 12

2023-01-09 Thread Justin Richer
I agree with Brian’s proposed fix — that is a “target URI” as defined by “HTTP”. The fact that it’s :also: required to be HTTPS is separate. — Justin On Jan 9, 2023, at 7:58 AM, Brian Campbell mailto:bcampbell=40pingidentity@dmarc.ietf.org>> wrote: Thanks Dominick, I believe they

Re: [OAUTH-WG] Small bug in DPoP 12

2023-01-09 Thread Brian Campbell
Thanks Dominick, I believe they should both use HTTP because that claim and check is about something from HTTP semantics. And the general requirement to use HTTPS is stated elsewhere. I'll update that accordingly as part of IETF last call