{"id":2271,"date":"2022-05-04T07:58:47","date_gmt":"2022-05-04T14:58:47","guid":{"rendered":"https:\/\/self-issued.info\/?p=2271"},"modified":"2022-05-04T07:58:47","modified_gmt":"2022-05-04T14:58:47","slug":"oauth-dpop-specification-addressing-wglc-comments","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=2271","title":{"rendered":"OAuth DPoP Specification Addressing WGLC Comments"},"content":{"rendered":"<p><span class=\"plain\"><img decoding=\"async\" align=\"right\" alt=\"OAuth logo\" src=\"https:\/\/self-issued.info\/images\/oauth_logo_120x120.png\"><\/span><a href=\"https:\/\/twitter.com\/__b_c\">Brian Campbell<\/a> has published an updated OAuth DPoP draft addressing the Working Group Last Call (WGLC) comments received.  All changes were editorial in nature.  The most substantive change was further clarifying that either <code>iat<\/code> or <code>nonce<\/code> can be used alone in validating the timeliness of the proof, somewhat deemphasizing <code>jti<\/code> tracking.<\/p>\n<p>As Brian reminded us during the <a href=\"https:\/\/oauth.secworkshop.events\/osw2022\">OAuth Security Workshop<\/a> today, the name DPoP was inspired by a Deutsche POP poster he saw on the S-Bahn during the March 2019 OAuth Security Workshop in Stuttgart:<\/p>\n<p><a href=\"https:\/\/twitter.com\/__b_c\/status\/1108974390052638720\"><img decoding=\"async\" src=\"https:\/\/self-issued.info\/images\/DeutschePop.jpg\" alt=\"Deutsche POP in Stuttgart\"><\/a><\/p>\n<p>He considered it an auspicious sign seeing another Deutsche PoP sign in the Vienna U-Bahn during IETF 113 the same day WGLC was requested!<\/p>\n<p><a href=\"https:\/\/twitter.com\/__b_c\/status\/1507438926226731019\"><img decoding=\"async\" src=\"https:\/\/self-issued.info\/images\/ViennaDeutschePop.jpg\" alt=\"Deutsche POP in Vienna\"><\/a><\/p>\n<p>The specification is available at:<\/p>\n<ul>\n<li><a href=\"https:\/\/tools.ietf.org\/id\/draft-ietf-oauth-dpop-08.html\">https:\/\/tools.ietf.org\/id\/draft-ietf-oauth-dpop-08.html<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Brian Campbell has published an updated OAuth DPoP draft addressing the Working Group Last Call (WGLC) comments received. All changes were editorial in nature. The most substantive change was further clarifying that either iat or nonce can be used alone in validating the timeliness of the proof, somewhat deemphasizing jti tracking. As Brian reminded us [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,32,26,25],"tags":[],"class_list":["post-2271","post","type-post","status-publish","format-standard","hentry","category-events","category-ietf","category-oauth","category-specifications"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2271","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2271"}],"version-history":[{"count":2,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2271\/revisions"}],"predecessor-version":[{"id":2273,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2271\/revisions\/2273"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2271"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2271"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2271"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}