Skip to content

Commit

Permalink
Does objectsecurity='edhoc' imply CA based? Probably for lack of othe…
Browse files Browse the repository at this point in the history
…r indications.
  • Loading branch information
chrysn committed Feb 23, 2024
1 parent ab9e003 commit 5d7f56e
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions draft-lenders-core-dnr.md
Original file line number Diff line number Diff line change
Expand Up @@ -248,6 +248,9 @@ svc-params:
- port=61616
~~~~~~~~

The use of objectsecurity="edhoc" with an authenticator-domain-name and no further ACE details indicates
that the client can use CA based authentication of the server.

## DoC over ACE-OSCORE
Using ACE, we require an OAuth context to authenticate the server in addition to the
“objectsecurity” key. We propose three keys “oauth-aud” for the audience, “oauth-scope” for the
Expand Down

0 comments on commit 5d7f56e

Please sign in to comment.