Hi all,
with this release of the security BCP, I have started to implement
Hannes' feedback from the shepherd's writeup, updated some references,
and made some other editorial changes.
There are no normative changes in this version.
-Daniel
Am 23.10.23 um 18:55 schrieb internet-dra...@ietf.org:
Internet-Draft draft-ietf-oauth-security-topics-24.txt is now available. It is
a work item of the Web Authorization Protocol (OAUTH) WG of the IETF.
Title: OAuth 2.0 Security Best Current Practice
Authors: Torsten Lodderstedt
John Bradley
Andrey Labunets
Daniel Fett
Name: draft-ietf-oauth-security-topics-24.txt
Pages: 62
Dates: 2023-10-23
Abstract:
This document describes best current security practice for OAuth 2.0.
It updates and extends the OAuth 2.0 Security Threat Model to
incorporate practical experiences gathered since OAuth 2.0 was
published and covers new threats relevant due to the broader
application of OAuth 2.0.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-security-topics/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ietf-oauth-security-topics-24.html
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-oauth-security-topics-24
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth
--
Please use my new email address:m...@danielfett.de
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth