Skip to content

mTLS with DPoP#2080

Merged
josephdecock merged 3 commits intomainfrom
jmdc/mtls-with-dpop
Jun 27, 2025
Merged

mTLS with DPoP#2080
josephdecock merged 3 commits intomainfrom
jmdc/mtls-with-dpop

Conversation

@josephdecock
Copy link
Member

If both an mTLS certificate and dpop proof are sent to the token endpoint, bind the resulting token to the proof. We assume mtls is being used for client auth (which is the only reasonable way both mTLS and DPOP would be sent).

@josephdecock josephdecock added this to the is-7.3.0 milestone Jun 27, 2025
@josephdecock josephdecock self-assigned this Jun 27, 2025
@josephdecock josephdecock requested a review from bhazen as a code owner June 27, 2025 16:34
@josephdecock josephdecock added the area/products/is IdentityServer label Jun 27, 2025
@josephdecock josephdecock changed the title MTls with dpop mTLS with dpop Jun 27, 2025
@josephdecock josephdecock changed the title mTLS with dpop mTLS with DPoP Jun 27, 2025
@josephdecock josephdecock force-pushed the jmdc/mtls-with-dpop branch from 6321e20 to 525d32f Compare June 27, 2025 17:20
If both an mTLS certificate and dpop proof are
sent to the token endpoint, bind the resulting
token to the proof. We assume mtls is being used
for client auth (which is the only reasonable way
both mTLS and DPOP would be sent).
@josephdecock josephdecock force-pushed the jmdc/mtls-with-dpop branch from 525d32f to 78d7e53 Compare June 27, 2025 18:23
@josephdecock josephdecock merged commit 6b811df into main Jun 27, 2025
16 checks passed
@josephdecock josephdecock deleted the jmdc/mtls-with-dpop branch June 27, 2025 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/products/is IdentityServer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants