Presentation is loading. Please wait.

Presentation is loading. Please wait.

PoP: AS <-> Client Key Distribution

Similar presentations


Presentation on theme: "PoP: AS <-> Client Key Distribution"— Presentation transcript:

1 PoP: AS <-> Client Key Distribution
draft-ietf-oauth-pop-key-distribution John Bradley, Phil Hunt, Mike Jones, Hannes Tschofenig

2 Open Issues Security considerations for the use of PoP tokens with public clients. Guidance for use of asymmetric cryptography with resource servers in different origins. Allow client to tell server which key to associate with access token. We want to have an access token bound to a key. We want to allow a client to request a new PoP access token based on a refresh token (without a code). The need for a PoP refresh token may arrive later and may use token binding. Security consideration needs to say that the PoP tokens require confidential clients if requesting new PoP tokens with different keys are desired.


Download ppt "PoP: AS <-> Client Key Distribution"

Similar presentations


Ads by Google