Make clear that requests and responses to resource servers don't have to be bound

Issue #608 resolved
Dave Tonge created an issue

i.e. it is possible to have a signed request, but not a signed response

and its also possible to have a signed response without a signed request

Comments (5)

  1. Tim Würtele

    What is the status on this? The current draft still mandates the RS to cryptographically link the response to the request (Sec. No. 2). Is the plan to basically change the shall in that clause to a may?

  2. Dave Tonge reporter

    make it clear to only sign request signature and request signature input if applicable (i.e. if present)
    also add to the note to explain further

  3. Log in to comment