Skip to content

Insert client certificate hash in AT if provided#1083

Open
Ivan240103 wants to merge 2 commits intodevelopfrom
rfc8705-integration-at-cert-binding
Open

Insert client certificate hash in AT if provided#1083
Ivan240103 wants to merge 2 commits intodevelopfrom
rfc8705-integration-at-cert-binding

Conversation

@Ivan240103
Copy link
Collaborator

RFC 8705 integration: if the client establishes a mTLS connection using a valid certificate, the thumbprint of that certificate is included in the Access Token. When the client requests protected resources, it must establish a mTLS connection using the same valid certificate, if not the request is rejected.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens

2 participants