[OAUTH-WG] IETF117 OAuth WG Agenda Change

2023-07-21 Thread Rifaat Shekh-Yusef
All, The agenda for the OAuth WG has changed. Our 3 sessions are now on *Tuesday*, *Wednesday* and *Friday* all at *9:30am*. Here is a link to the updated agenda: https://datatracker.ietf.org/meeting/117/materials/agenda-117-oauth-08 Regards, Rifaat & Hannes

Re: [OAUTH-WG] OAuth 2.0 Attestation-Based Client Authentication

2023-07-21 Thread Orie Steele
It would be excellent to see more information on "attested_security_context" and "key_type" which appear in the example https://datatracker.ietf.org/doc/html/draft-looker-oauth-attestation-based-client-auth-00#name-wallet-instance-attestation I gather from searching that this is relevant: https://

Re: [OAUTH-WG] OAuth 2.0 Attestation-Based Client Authentication

2023-07-21 Thread torsten=40lodderstedt . net
Those claims are asserted by the issuer of the assertion, which could be a trusted third party. Trust management happens on top of the draft. This could mean x5c, could also be a trust list with the issuer URLs. In the OID4VC High Assurance Profile, which utilizes this draft, we will facilitate

[OAUTH-WG] [Editorial Errata Reported] RFC6749 (7569)

2023-07-21 Thread RFC Errata System
The following errata report has been submitted for RFC6749, "The OAuth 2.0 Authorization Framework". -- You may review the report below and at: https://www.rfc-editor.org/errata/eid7569 -- Type: Editorial Reported by: BRUNO L