Skip to content

Support the access token binding to the client MTLS authentication #4482

@sberyozkin

Description

@sberyozkin

Description
When the client uses the same certificate to authenticate to both IDP when requesting a token and Quarkus adapter, it can help the adapter to link the access token to the client certificate thus achieving an extra guarantee that the token is coming from the same client which requested it from IDP. Per the KC team recommendation

Hi Stian @stianst, Pedro, @pedroigor FYI

Metadata

Metadata

Assignees

Type

No type

Projects

Status

Done

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions