Re: [OAUTH-WG] DPoP - Impementations

Joseph Heenan <joseph@authlete.com> Thu, 11 August 2022 14:12 UTC

Return-Path: <joseph@authlete.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C39BC15DD7F for <oauth@ietfa.amsl.com>; Thu, 11 Aug 2022 07:12:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.903
X-Spam-Level:
X-Spam-Status: No, score=-1.903 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=authlete-com.20210112.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id umPrObF4X1ro for <oauth@ietfa.amsl.com>; Thu, 11 Aug 2022 07:12:46 -0700 (PDT)
Received: from mail-wr1-x431.google.com (mail-wr1-x431.google.com [IPv6:2a00:1450:4864:20::431]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 58B98C15C512 for <oauth@ietf.org>; Thu, 11 Aug 2022 07:12:46 -0700 (PDT)
Received: by mail-wr1-x431.google.com with SMTP id z17so21488344wrq.4 for <oauth@ietf.org>; Thu, 11 Aug 2022 07:12:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=authlete-com.20210112.gappssmtp.com; s=20210112; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:from:to:cc; bh=B2n4jRB3sPwF18+JdZTatz3BIaT3Ndl9uY6FmnH10EQ=; b=SoMAos+IU+96QnHXrabxFDl0hOj500iNiYHS2tfrvipNQEVaIYRZjAdj7IywwiwUDr 4zfGKqSoA4/BNvb3DwCVK0MAiGdLPilcKAE+ONUY0WQWsjt48/RZYzCQhk2PIo3Nmt/e lO64rKBlUT9J6knrDYB6SM2DcOvzjhpUEVSYT070FCYwNKsJUY5g88JC6AOuMqaBKqBR xJM+nYRoygvNB4GrCKknlqFiM5ED+0SHrOIFHFuH0LcBJ9kLnfvZ8+hqA9YaYU1oLZEA JL2ekCV07tm4WDLBG/iAcm8b8fN8rXDg0bkRr0wxG2lrCu2THtlftJLYaoKFv2aecylk zsTQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:x-gm-message-state:from:to:cc; bh=B2n4jRB3sPwF18+JdZTatz3BIaT3Ndl9uY6FmnH10EQ=; b=d1YKM2Ox5Ge7JpE4dq2aQWvmX1FAcCxsPPIwaTFC57UHCunPHrus1CiV6Qnn2ZZHVX BwJLyep1Au5rh1+FdBo7n+HG6rlJKQp81OoDLFgto+POL+PdJy4juJVWKk81ln+QEVzg SOlYOdraLikNPzp2ZqShDnc9XB4j/Zvca0CVR0E00136150AyS3wvFX3/0OQ8gI50VST BxialOn4BAA6N89BpSVxgyNIapaWiSB1JBAade03puG36atUQBa4JY1aOI4aM7ucCg8g afvFoGlRT4C9nqDPWmOw5qhrMRZ7nw6Y3uxOZKcYHI/j1Mtw8QOBPvXgbP52rcjCguYi 9GWg==
X-Gm-Message-State: ACgBeo3b6KJWM3iW/u8e0kXDwCQHwEz+QSzOBA/d5Mtx1gn6DRynNpDP Xa5dtR9QXWmyleaOXJZQwKFRBKt/fMIesmR/
X-Google-Smtp-Source: AA6agR6ALQ1a+amkVZlmqErgXsMa0dY/SLa+M6X+hqOwwTf/7pO6y13FrnSbsId856ByVGGUdgsepQ==
X-Received: by 2002:a5d:6f1c:0:b0:21f:121e:1190 with SMTP id ay28-20020a5d6f1c000000b0021f121e1190mr19361213wrb.589.1660227164682; Thu, 11 Aug 2022 07:12:44 -0700 (PDT)
Received: from smtpclient.apple (static-90-250-10-57.vodafonexdsl.co.uk. [90.250.10.57]) by smtp.gmail.com with ESMTPSA id m7-20020a056000008700b00222ed7ea203sm9629245wrx.100.2022.08.11.07.12.43 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 11 Aug 2022 07:12:44 -0700 (PDT)
From: Joseph Heenan <joseph@authlete.com>
Message-Id: <216F0E57-A1ED-49B8-A930-6D2A191DF563@authlete.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_866023A3-BFD7-425E-9B5E-A8943F941E8E"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.120.41.1.1\))
Date: Thu, 11 Aug 2022 15:12:42 +0100
In-Reply-To: <CADNypP-agKP45tAW7es0M5S_y_Rm_V42obWDTCSPWcXt9h5J1g@mail.gmail.com>
Cc: oauth <oauth@ietf.org>
To: Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>
References: <CADNypP-agKP45tAW7es0M5S_y_Rm_V42obWDTCSPWcXt9h5J1g@mail.gmail.com>
X-Mailer: Apple Mail (2.3696.120.41.1.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/ewmQV7QJy9UqeQPSjo7HX0pfg5Y>
Subject: Re: [OAUTH-WG] DPoP - Impementations
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Aug 2022 14:12:48 -0000

Hi Rifaat

The OpenID Foundation FAPI2 certification tools have implementations of / tests for (most of) DPoP as both an AS/RS & client.

Authlete has implemented DPoP as an AS / RS.

Thanks

Joseph

> On 10 Aug 2022, at 22:39, Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com> wrote:
> 
> All,
> 
> As part of the shepherd write-up for the DPoP document, we are looking for information about implementations of this draft.
> https://datatracker.ietf.org/doc/draft-ietf-oauth-dpop/ <https://datatracker.ietf.org/doc/draft-ietf-oauth-dpop/>
> 
> Please, reply to this email on the mailing list with any implementations that you are aware of to support this document.
> 
> Regards,
>  Rifaat & Hannes
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth