WebAuth - Replacement for HTTPS Client Certificate Authentication

Maybe of interest for authentication to payment systems
(although ideally you would rather just sign something):

http://webpki.org/papers/PKI/webauth.pdf

Comments are welcome!

There are 3 independent possible standards targets in this proposal:

1. Browser bindings for JSON protocol invocations

2. JSON Clear-text Signature:
https://openkeystore.googlecode.com/svn/resources/trunk/docs/JSON-Clear-Text-Signature-Scheme.pdf

3. And then WebAuth itself

Cheers
Anders

Received on Friday, 25 October 2013 10:48:40 UTC