@cendyne@cendyne.dev Profile picture
Cloud & Web Security, writes about info sec, cryptography, and leadership. Likes cartoon 🐍
Jun 11, 2021 9 tweets 3 min read
Ah how about

Client-Cert HTTP Header Field: Conveying Client Certificate Information from TLS Terminating Reverse Proxies to Origin Server Applications

For tonight’s light reading Brian Campbell produces a lot of interesting things. Let’s see what’s inside.
Jun 10, 2021 8 tweets 3 min read
Tonight’s light reading

OAuth 2.0 Authorization Server Issuer Identification Okay, so this is something that addresses the conversation in GNAP right now.
A mix-up attack is where a client, which interacts with multiple AS uses one that has become compromised (AAS) and it is proxying & rewriting from an uncompromised AS (HAS)