3 ms·
As I've opined here [1] I think OIDC is not a good example for an authentication protocol. As you are already into spec reading, you could take a look how SSH a
by Perseids 4y ago
As I've opined here [1] I think OIDC is not a good example for an authentication protocol. As you are already into spec reading, you could take a look how SSH and TLS 1.3 (especially mutually authenticated TLS) handle the same topic. (All available freely as IETF RFCs.) And if you're interested in the cryptography, your can't go wrong with Cryptography Engineering (ISBN: 978-0470474242) by Ferguson, Schneier and Kohno.
[1] https://news.ycombinator.com/item?id=31259826 https://news.ycombinator.com/item?id=31259826