oauth2-server/requirements.md
2016-03-23 12:45:37 +00:00

743 B
Executable File

layout title permalink
default Requirements /requirements/

Requirements

In order to prevent man-in-the-middle attacks, the authorization server MUST require the use of TLS with server authentication as defined by RFC2818 for any request sent to the authorization and token endpoints. The client MUST validate the authorization server's TLS certificate as defined by RFC6125 and in accordance with its requirements for server identity authentication.

This library uses key cryptography in order to encrypt and decrypt, as well as verify the integrity of signatures. See the installation page for details on how to generate the keys.