[agree-on-direction] 6.1 TLS requirements shoudl be stated

Issue #1621 resolved
Nat Sakimura created an issue

Right now, it just says HTTP GET or HTTP Redirects.

Perhaps we may want to state some TLS requirements with it.

Comments (8)

  1. Kristina Yasuda

    Should we simply say that TLS requirements of RFC6749 and OIDC Core apply? Or should we update the recommendation to TLS 1.3 since both https://www.rfc-editor.org/rfc/rfc6749.html#section-1.6 and https://openid.net/specs/openid-connect-core-1_0.html#TLSRequirements say

    At the time of this writing, TLS version 1.2 [RFC5246] is the most recent version, but has a very limited deployment base and might not be readily available for implementation. TLS version 1.0 [RFC2246] is the most widely deployed version and will provide the broadest interoperability.

  2. Kristina Yasuda

    this sentence? DPoP is not, however, a substitute for a secure transport and MUST always be used in conjunction with HTTPS.? how is this a TLS requirement..?

  3. Kristina Yasuda

    ISO mandates TLS version 1.2 as specified in RFC 5246 and may support TLS version 1.3 as specified in RFC 8446

    i am ok with similar

  4. Log in to comment