Hi,

the following changed were applied to the revocation draft:
- focused draft on client-initiated token revocation, cut out self-care/portal stuff
- added implementation note on access token revocation.
- extended abstract
- removed normative language from introduction

regards,
Torsten.

Am 18.11.2012 17:37, schrieb internet-dra...@ietf.org:
A New Internet-Draft is available from the on-line Internet-Drafts directories.
  This draft is a work item of the Web Authorization Protocol Working Group of 
the IETF.

        Title           : Token Revocation
        Author(s)       : Torsten Lodderstedt
                           Stefanie Dronia
                           Marius Scurtescu
        Filename        : draft-ietf-oauth-revocation-02.txt
        Pages           : 7
        Date            : 2012-11-18

Abstract:
    This document proposes an additional endpoint for OAuth authorization
    servers, which allows clients to notify the authorization server that
    a previously obtained refresh or access token is no longer needed.
    This allows the authorization server to cleanup security credentials.
    A revocation request will invalidate the actual token and, if
    applicable, other tokens based on the same access grant.



The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-revocation

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-oauth-revocation-02

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-revocation-02


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to