Groups
Groups
Sign in
Groups
Groups
openid-federation-interop
Conversations
About
Send feedback
Help
Signed requests
13 views
Skip to first unread message
Roland Hedberg
unread,
Apr 21, 2020, 2:40:15 PM
4/21/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to openid-feder...@googlegroups.com
Hi!
Don’t know if you’ve seen the discussion about the use of private_key_jwt in automatic registration.
A proposal on using signed request objects instead was made both by Joseph and Brian.
I actually like that proposal.
So, I will implement it. Just to see how it would work. Definitely no big deal.
What about you ?
— Roland
Vladimir Dzhuvinov
unread,
Apr 21, 2020, 2:58:43 PM
4/21/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to openid-feder...@googlegroups.com
Makes sense. It authenticates the client just like private_key_jwt while
adding extra integrity protection of the authZ params.
Vladimir
Reply all
Reply to author
Forward
0 new messages