FYI, I blogged about this at http://self-issued.info/?p=1660 and as 
@selfissued<https://twitter.com/selfissued>.

                                                                -- Mike

From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Brian Campbell
Sent: Monday, March 13, 2017 2:32 PM
To: oauth <oauth@ietf.org>; IETF Tokbind WG <unbeara...@ietf.org>
Subject: [OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-token-binding-02.txt

I'm pleased to announce that (with the diligent help of my distinguished 
co-authors) draft -02 of "OAuth 2.0 Token 
Binding"<https://tools.ietf.org/html/draft-ietf-oauth-token-binding-02> has 
been published. The changes from the prior draft are listed below with support 
for Token Binding of authorization codes and lots of new examples being the 
largest changes.

   o  Added a section on Token Binding for authorization codes with one
      variation for native clients and one for web server clients.
   o  Updated language to reflect that the binding is to the token
      binding key pair and that proof-of-possession of that key is done
      on the TLS connection.
   o  Added a bunch of examples.
   o  Added a few Open Issues so they are tracked in the document.
   o  Updated the Token Binding and OAuth Metadata references.
   o  Added William Denniss as an author.

---------- Forwarded message ----------
From: <internet-dra...@ietf.org<mailto:internet-dra...@ietf.org>>
Date: Mon, Mar 13, 2017 at 3:14 PM
Subject: [OAUTH-WG] I-D Action: draft-ietf-oauth-token-binding-02.txt
To: i-d-annou...@ietf.org<mailto:i-d-annou...@ietf.org>
Cc: oauth@ietf.org<mailto:oauth@ietf.org>



A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Web Authorization Protocol of the IETF.

        Title           : OAuth 2.0 Token Binding
        Authors         : Michael B. Jones
                          John Bradley
                          Brian Campbell
                          William Denniss
        Filename        : draft-ietf-oauth-token-binding-02.txt
        Pages           : 26
        Date            : 2017-03-13

Abstract:
   This specification enables OAuth 2.0 implementations to apply Token
   Binding to Access Tokens, Authorization Codes, and Refresh Tokens.
   This cryptographically binds these tokens to a client's Token Binding
   key pair, possession of which is proven on the TLS connections over
   which the tokens are intended to be used.  This use of Token Binding
   protects these tokens from man-in-the-middle and token export and
   replay attacks.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-token-binding/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-oauth-token-binding-02

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-token-binding-02


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at 
tools.ietf.org<http://tools.ietf.org>.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
OAuth mailing list
OAuth@ietf.org<mailto:OAuth@ietf.org>
https://www.ietf.org/mailman/listinfo/oauth

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to