Cloud & Web Security, writes about info sec, cryptography, and leadership. Likes cartoon 🐍
Jun 11, 2021 • 9 tweets • 3 min read
Ah how about
Client-Cert HTTP Header Field: Conveying Client Certificate Information from TLS Terminating Reverse Proxies to Origin Server Applications
For tonight’s light reading
Brian Campbell produces a lot of interesting things. Let’s see what’s inside.
Jun 10, 2021 • 8 tweets • 3 min read
Tonight’s light reading
OAuth 2.0 Authorization Server Issuer Identification
Okay, so this is something that addresses the conversation in GNAP right now.
A mix-up attack is where a client, which interacts with multiple AS uses one that has become compromised (AAS) and it is proxying & rewriting from an uncompromised AS (HAS)