Re: [OAUTH-WG] [UNVERIFIED SENDER] OAuth Topics for Vancouver

2020-01-20 Thread Rob Cordes
Hi Annabelle, Sure TLS is not th one size fits all but if you swap out Client Y signs / authenticates message A to recipient X by: Client Y uses TLS for authentication of the source (itself), integrity of data / communications and even confidentiality (not really needed in our HTTP

Re: [OAUTH-WG] OAuth Topics for Vancouver

2020-01-20 Thread Rob Cordes
? Best regards, Rob Cordes Feature Engineer / InfoSec specialist @ ING bank > On 20 Jan 2020, at 18:33, Richard Backman, Annabelle > wrote: > > I would like to discuss HTTP Message Signatures > <https://tools.ietf.org/html/draft-richanna-http-message-signatures-00> as a