OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens
RFC 8705, “OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens”, is a Proposed Standard document published in February 2020 by B. Campbell, J. Bradley, N. Sakimura, T. Lodderstedt. The canonical text is published by the RFC Editor.
Abstract
This document describes OAuth client authentication and certificate-bound access and refresh tokens using mutual Transport Layer Security (TLS) authentication with X.509 certificates. OAuth clients are provided a mechanism for authentication to the authorization server using mutual TLS, based on either self-signed certificates or public key infrastructure (PKI). OAuth authorization servers are provided a mechanism for binding access tokens to a client's mutual-TLS certificate, and OAuth protected resources are provided a method for ensuring that such an access token presented to it was issued to the client presenting the token.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8705 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8704 Enhanced Feasible-Path Unicast Reverse Path Forwarding
- RFC 8706 Restart Signaling for IS-IS
- RFC 8707 Resource Indicators for OAuth 2.0
- RFC 8703 Dynamic Link Exchange Protocol Link Identifier Extension
- RFC 8708 Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax
- RFC 8702 Use of the SHAKE One-Way Hash Functions in the Cryptographic Message Syntax
- RFC 8709 Ed25519 and Ed448 Public Key Algorithms for the Secure Shell Protocol
- RFC 8701 Applying Generate Random Extensions And Sustain Extensibility to TLS Extensibility