In section 3:
Challenge: A String that is the input to a cryptographic challenge-
response pattern. This is traditionally called a nonce within
OAuth
Remove the second sentence. Note that the issue #154 has already proposed this removal.
In section 8 (Challenge Retrieval)
This section defines an optional mechanism that allows a Client to
request a fresh Challenge from the Authorization Server to be
included in the Client Attestation PoP JWT. This construct may be
similar or equivalent to a nonce, see Section 3.
Remove the second sentence.