Asymmetric Tokens and server issuing challenges #11521
Labels
A-registry-authentication
Area: registry authentication and authorization (authn authz)
S-triage
Status: This issue is waiting on initial triage.
Z-asymmetric-token
Nightly: asymmetric-token authentication
The 3231 RFC describes that servers can issue a one time challenge to better protect against token reuse. This was not implemented in #10771 and should be implement it before stabilization.
The text was updated successfully, but these errors were encountered: