view mod_s2s_auth_monkeysphere/README.markdown @ 5796:93d6e9026c1b

mod_http_oauth2: Do not enforce PKCE on Device and OOB flows PKCE does not appear to be used with the Device flow. I have found no mention of any interaction between those standards. Since no data is delivered via redirects in these cases, PKCE may not serve any purpose. This is mostly a problem because we reuse the authorization code to implement the Device and OOB flows.
author Kim Alvefur <zash@zash.se>
date Fri, 15 Dec 2023 12:10:07 +0100
parents 8d1141025b43
children
line wrap: on
line source

---
labels:
- 'Stage-Alpha'
- 'Type-S2SAuth'
summary: Monkeysphere certificate checking for s2s
---

## Introduction

[Monkeysphere](http://web.monkeysphere.info/) is a project aiming to
introduce PGP's web of trust to protocols such as SSH and TLS (which
XMPP uses).

## Details

This module is currently just a prototype, it has numerous issues and is
**not** suitable for production use.

## Compatibility

  ------- -----------------------------
  trunk   Works (not tested recently)
  0.11    Works (not tested)
  0.10    Does not work
  0.9     Does not work
  ------- -----------------------------