Markdown Version | Session Recording

Session Date/Time: 21 May 2024 16:00

OAUTH

Summary

This interim meeting of the OAUTH Working Group focused on the "Attestation-Based Client Authentication" draft. Key discussions included the proposed shift from body-based client assertions to a header-based syntax for attestation, the ongoing debate regarding the draft's naming to better reflect its purpose, and the implications of optional DPoP integration with attested keys. A strong consensus was reached to move forward with the header-based syntax. The DPoP integration and overall draft naming require further discussion.

Key Discussion Points

1. Introduction to Attestation-Based Client Authentication

2. Discussion Point 1: Moving to Header-Based Syntax

3. Discussion Point 2: Naming of the Draft

4. Discussion Point 3: Optional DPoP Integration

5. Discussion Point 4: Nonce Fetching

Decisions and Action Items

Next Steps