Skip to content

Commit c47489f

Browse files
Apply suggestions from code review
Co-authored-by: Tobias Looker <[email protected]>
1 parent 02add0a commit c47489f

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

draft-ietf-oauth-attestation-based-client-auth.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -529,7 +529,7 @@ Upon receiving a Client Attestation, the receiving server MUST ensure the follow
529529

530530
The Authorization Server SHOULD communicate support and requirement for authentication with Attestation-Based Client Authentication by using the value `attest_jwt_client_auth` in the `token_endpoint_auth_methods_supported` within its published metadata. The client SHOULD fetch and parse the Authorization Server metadata and recognize the requirement the requirement for client authentication using Attestation-Based Client Authentication if the given parameters are present.
531531

532-
The Authorization Server SHOULD communicate supported algorithms for client attestations by using `client_attestation_signing_alg_values_supported` and `client_attestation_pop_signing_alg_values_supported` within its published metadata. This enables the client to validate that its client attestation is understood by the Authorization Server prior to authentication. The client MAY try to get a new client attestation with different algorithms.
532+
The Authorization Server SHOULD communicate supported algorithms for client attestations by using `client_attestation_signing_alg_values_supported` and `client_attestation_pop_signing_alg_values_supported` within its published metadata. This enables the client to validate that its client attestation is understood by the Authorization Server prior to authentication. The client MAY try to get a new client attestation with different algorithms. The Authorization Server MUST include `client_attestation_signing_alg_values_supported` and `client_attestation_pop_signing_alg_values_supported` in its published metadata if the `token_endpoint_auth_methods_supported` includes `attest_jwt_client_auth`.
533533

534534
## Reuse of a Client Attestation JWT
535535

@@ -614,15 +614,15 @@ This specification requests registration of the following values in the IANA "OA
614614

615615
## OAuth Authorization Server Metadata Registration
616616

617-
This specification requests registration of the following values in the IANA "OAuth Authorization Server Metadata" registry of {{IANA.OAuth.Params}} established by [RFC8414].
617+
This specification requests registration of the following values in the IANA "OAuth Authorization Server Metadata" registry of {{IANA.OAuth.Params}} established by {{RFC8414}}.
618618

619619
* Metadata Name: client_attestation_signing_alg_values_supported
620-
* Metadata Description: JSON array containing a list of algorithms supported by the authorization server for client attestation signing
620+
* Metadata Description: JSON array containing a list of the JWS signing algorithms supported by the authorization server for the signature on the Client Attestation JWT.
621621
* Change Controller: IETF
622622
* Reference: [](#checking-http-requests-with-client-attestations) of this specification
623623

624624
* Metadata Name: client_attestation_pop_signing_alg_values_supported
625-
* Metadata Description: JSON array containing a list of algorithms supported by the authorization server for client attestation proof of possession signing
625+
* Metadata Description: JSON array containing a list of the JWS signing algorithms supported by the authorization server for the signature on the Client Attestation PoP JWT.
626626
* Change Controller: IETF
627627
* Reference: this specification
628628

0 commit comments

Comments
 (0)