Hi all, Daniel and I published a new draft version for the iss parameter.
Version 03 addresses the feedback from Roman's AD review, as well as, most of the feedback from Julian Reschke's (artart) and Yoav Nir's (secdir) reviews.
The only comment I could not address is this nit because I don't know how to write the links in markdown so that they are processed by xml2rfc correctly.
Section links to external documents do not appear to be marked up as such (and use a trailing dot in the section number which they should not)
Best regards, Karsten Am 18.11.2021 um 20:59 schrieb internet-dra...@ietf.org:
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : OAuth 2.0 Authorization Server Issuer Identification Authors : Karsten Meyer zu Selhausen Daniel Fett Filename : draft-ietf-oauth-iss-auth-resp-03.txt Pages : 11 Date : 2021-11-18 Abstract: This document specifies a new parameter iss that is used to explicitly include the issuer identifier of the authorization server in the authorization response of an OAuth authorization flow. The iss parameter serves as an effective countermeasure to "mix-up attacks". The IETF datatracker status page for this draft is: https://datatracker.ietf.org/doc/draft-ietf-oauth-iss-auth-resp/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-ietf-oauth-iss-auth-resp-03.html A diff from the previous version is available at: https://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-iss-auth-resp-03 Internet-Drafts are also available by anonymous FTP at: ftp://ftp.ietf.org/internet-drafts/ _______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth
-- Phone: (+49)(0)234 / 45930961 Fax: (+49)(0)234 / 45930960 Mail: karsten.meyerzuselhau...@hackmanit.de PGP: 0EDA AAC6 01DE 3D7F 2123 70F8 4535 C0E7 DB16 F148 Web: www.hackmanit.de Hackmanit GmbH Universitätsstraße 150 (ID 2/469) 44801 Bochum, Germany Vertreten durch: Prof. Dr. Jörg Schwenk, Dr. Juraj Somorovsky, Dr. Christian Mainka, Marcus Niemietz Registergericht: Bochum
OpenPGP_signature
Description: OpenPGP digital signature
_______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth