FAPI part 2 - Request Object Endpoint (Successful Response Parameters)

Issue #161 resolved
Torsten Lodderstedt created an issue

what is the purpose of including iss and aud in the response?

Is the client supposed to somehow check the values?

Comments (7)

  1. Nat Sakimura

    It is a bit of precaution - one of the security targets was to adhere to BCM principles for secure authentication protocols that recommend each protocol messages to identify all the parties involved. So, yes. the client should check that iss value is an expected one and aud value is its client ID. Do we need to spell it out? (Maybe)

  2. Torsten Lodderstedt reporter

    The AS authenticates towards the client with its TLS cert, so it’s not obvious to me why this is needed. Can we discuss this on the next call?

  3. Log in to comment