Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DPoP-inspired vs Message Signatures #52

Open
arndt-s opened this issue Jul 15, 2024 · 0 comments
Open

DPoP-inspired vs Message Signatures #52

arndt-s opened this issue Jul 15, 2024 · 0 comments
Labels

Comments

@arndt-s
Copy link
Collaborator

arndt-s commented Jul 15, 2024

Creating a reference-able & umbrella issue for the choice between the DPoP-inspired and the HTTP Message Signatures approach.

Section 1:

For application-level protection we currently propose two alternative solutions, one inspired by DPoP [RFC9449] in Section 4.2 and one which is a profile of HTTP Message Signatures [RFC9421] in Section 4.3. The design team believes that we need to pick one of these two alternatives for standardization, once we have understood their pros and cons.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant