@@ -230,13 +230,13 @@ public ValueTask HandleAsync(ProcessAuthenticationContext context)
230230 if ( context . TokenEndpointClientAuthenticationMethod is ClientAuthenticationMethods . TlsClientAuth &&
231231 _options . CurrentValue . TlsClientAuthenticationCertificateSelector ( context . Registration ) is not null )
232232 {
233- context . UserInfoEndpointTokenBindingMethods . Add ( TokenBindingMethods . TlsClientCertificate ) ;
233+ context . UserInfoEndpointTokenBindingMethods . Add ( TokenBindingMethods . Private . TlsClientCertificate ) ;
234234 }
235235
236236 else if ( context . TokenEndpointClientAuthenticationMethod is ClientAuthenticationMethods . SelfSignedTlsClientAuth &&
237237 _options . CurrentValue . SelfSignedTlsClientAuthenticationCertificateSelector ( context . Registration ) is not null )
238238 {
239- context . UserInfoEndpointTokenBindingMethods . Add ( TokenBindingMethods . SelfSignedTlsClientCertificate ) ;
239+ context . UserInfoEndpointTokenBindingMethods . Add ( TokenBindingMethods . Private . SelfSignedTlsClientCertificate ) ;
240240 }
241241
242242 return default ;
@@ -661,16 +661,16 @@ public ValueTask HandleAsync(TContext context)
661661 // If both a client authentication method and one or multiple token binding methods were negotiated,
662662 // make sure they are compatible (e.g that they all use a CA-issued or self-signed X.509 certificate).
663663 if ( ( context . ClientAuthenticationMethod is ClientAuthenticationMethods . TlsClientAuth &&
664- context . TokenBindingMethods . Contains ( TokenBindingMethods . SelfSignedTlsClientCertificate ) ) ||
664+ context . TokenBindingMethods . Contains ( TokenBindingMethods . Private . SelfSignedTlsClientCertificate ) ) ||
665665 ( context . ClientAuthenticationMethod is ClientAuthenticationMethods . SelfSignedTlsClientAuth &&
666- context . TokenBindingMethods . Contains ( TokenBindingMethods . TlsClientCertificate ) ) )
666+ context . TokenBindingMethods . Contains ( TokenBindingMethods . Private . TlsClientCertificate ) ) )
667667 {
668668 throw new InvalidOperationException ( SR . GetResourceString ( SR . ID0456 ) ) ;
669669 }
670670
671671 // Attach a flag indicating that a client certificate should be used in the TLS handshake.
672672 if ( context . ClientAuthenticationMethod is ClientAuthenticationMethods . TlsClientAuth ||
673- context . TokenBindingMethods . Contains ( TokenBindingMethods . TlsClientCertificate ) )
673+ context . TokenBindingMethods . Contains ( TokenBindingMethods . Private . TlsClientCertificate ) )
674674 {
675675 builder . Append ( '\u001f ' ) ;
676676
@@ -681,7 +681,7 @@ public ValueTask HandleAsync(TContext context)
681681
682682 // Attach a flag indicating that a self-signed client certificate should be used in the TLS handshake.
683683 else if ( context . ClientAuthenticationMethod is ClientAuthenticationMethods . SelfSignedTlsClientAuth ||
684- context . TokenBindingMethods . Contains ( TokenBindingMethods . SelfSignedTlsClientCertificate ) )
684+ context . TokenBindingMethods . Contains ( TokenBindingMethods . Private . SelfSignedTlsClientCertificate ) )
685685 {
686686 builder . Append ( '\u001f ' ) ;
687687
0 commit comments