<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-ligatures:standardcontextual;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
span.E-MailFormatvorlage17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:70.85pt 70.85pt 2.0cm 70.85pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=DE link="#0563C1" vlink="#954F72" style='word-wrap:break-word'><div class=WordSection1><p class=MsoNormal>Hi,<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><span lang=EN-US>I have a request from a RP that wants to use the public client type [1]. Until now we only had clients that used client secret for authentication.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>We use XML Metadata as described in [2] to configure the RPs in the IdP. All our current clients have token_endpoint_auth_method set to “client_secret_post” or “client_secret_basic”.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>The documentation regarding the default value [3] and the release notes of 1.1.0 of OIDCRelyingPartyAuthnConfiguration [4] only list “client_secret_basic”, “client_secret_post”, “client_secret_jwt” and “private_key_jwt” as options.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Also [2] states “Only one value per entity” for client_secret.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US>I looked into the code [5] and if I understand it corretly “none” should be an option for token_endpoint_auth_method.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US>Can I configure token_endpoint_auth_method to “none” an don’t set a client_secret to accept a public client?<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US>If this is True I would suggest rephrasing the “Only one value per entity” on [2] to “Zero or one value per entity” and describing the available options including “none” somewhere.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US>[1] <a href="https://datatracker.ietf.org/doc/html/rfc6749#section-2.1">https://datatracker.ietf.org/doc/html/rfc6749#section-2.1</a><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>[2] <a href="https://shibboleth.atlassian.net/wiki/spaces/SC/pages/1912406916/OAuthRPMetadataProfile">https://shibboleth.atlassian.net/wiki/spaces/SC/pages/1912406916/OAuthRPMetadataProfile</a><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>[3] <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376879082/OPProfileConfiguration-ClientAuthentication">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376879082/OPProfileConfiguration-ClientAuthentication</a><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>[4] <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3239968769/OIDCRelyingPartyAuthnConfigurationReleaseNotes">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3239968769/OIDCRelyingPartyAuthnConfigurationReleaseNotes</a><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>[5] <a href="https://git.shibboleth.net/view/?p=java-idp-oidc.git;a=blob;f=idp-oidc-extension-impl/src/main/java/net/shibboleth/idp/plugin/oidc/op/authn/impl/ValidateClientAuthenticationType.java#l165">https://git.shibboleth.net/view/?p=java-idp-oidc.git;a=blob;f=idp-oidc-extension-impl/src/main/java/net/shibboleth/idp/plugin/oidc/op/authn/impl/ValidateClientAuthenticationType.java#l165</a><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'>Kind regards<o:p></o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'>Clemens (Bergmann)<o:p></o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'><o:p> </o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'>-- <o:p></o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'>Clemens Bergmann<o:p></o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'>[er/ihm; he/him]<o:p></o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'>Gruppe Nutzermanagement und Entwicklung<o:p></o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'>Technische Universität Darmstadt<o:p></o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'>Hochschulrechenzentrum, Alexanderstraße 2, 64283 Darmstadt<o:p></o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'>Tel. +49 6151 16 71184<o:p></o:p></span></p><p class=MsoNormal><span style='mso-ligatures:none'><a href="http://www.hrz.tu-darmstadt.de/"><span style='color:#0563C1'>http://www.hrz.tu-darmstadt.de/</span></a><o:p></o:p></span></p><p class=MsoNormal><o:p> </o:p></p></div></body></html>