RFC 8705rfcFebruary 2020

OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens

This document describes OAuth client authentication and certificate-bound access and refresh tokens using mutual Transport Layer Security (TLS) authentication with X.509 certificates. OAuth clients are provided a mechanism for authentication to the authorization server using mutual TLS, based on either self-signed certificates or public key infrastructure (PKI). OAuth authorization servers are provided a mechanism for binding access tokens to a client's mutual-TLS certificate, and OAuth protected resources are provided a method for ensuring that such an access token presented to it was issued to the client presenting the token.

Utilisation dans STET

  • VersionsToutes les versions

    `tls_client_auth` is the only accepted `token_endpoint_auth_method` (mutual TLS with an eIDAS QWAC), per the PSD2 mTLS requirement.

  • Versions1.6.21.6.3

    The `tls_client_auth_subject_dn` client-metadata field (expected certificate subject DN) became required by the Framework.

Métadonnées factuelles: IETF Datatracker (doc.json) + BibXML.