Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Client attestation and posture #44

Closed
jricher opened this issue Nov 13, 2020 · 4 comments
Closed

Client attestation and posture #44

jricher opened this issue Nov 13, 2020 · 4 comments

Comments

@jricher
Copy link
Collaborator

jricher commented Nov 13, 2020

§2.3 Identifying the RC: Editor's note:

Additional client attestation frameworks will eventually need to be addressed here. For example, the organization the client represents, or a family of client software deployed in a cluster, or the posture of the device the client is installed on. These all need to be separable from the client's key and potentially the instance identifier.

@fimbault
Copy link
Collaborator

As per a comment during IETF110, see https://tools.ietf.org/html/draft-ietf-rats-eat-09

@aaronpk
Copy link
Collaborator

aaronpk commented Feb 8, 2022

I would love to see a way to be able to integrate support for Apple's App Attestation for example.

https://developer.apple.com/documentation/devicecheck/validating_apps_that_connect_to_your_server

Note to self to look at the OAuth Assertion Framework for this.

@jricher
Copy link
Collaborator Author

jricher commented Feb 10, 2022

Might want to also look at https://www.ietf.org/archive/id/draft-ietf-acme-client-04.html

@mavarley
Copy link

mavarley commented Apr 8, 2022

Client attestation has come up on the https://github.com/w3c-ccg/vc-api context; and GNAP is being considered as an authorization protocol - so having a place for a client to provide its qualifications to act as a client to the AS will be important.

Sorry this is vague - I don't want to presume an implementation yet, just highlighting it remains an important extension point for at least one use case.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants