Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SPKI (RFCs 2692 & 2693) offers a well-developed, well-thought-out framework which meets all your needs: SPKI certificates can contain state, and thus support server statelessness; SPKI certificates can be used as OAuth tokens; SPKI certificates support custom claims (and in fact go so far as to define a well-formed claim calculus which can be implemented easily, and which supports just about anything one would wish to do); and SPKI certificates are far, far simpler than X.509.

Take a look: https://tools.ietf.org/html/rfc2692 & https://tools.ietf.org/html/rfc2693



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: