Hi all,

with this release of the security BCP, I have started to implement Hannes' feedback from the shepherd's writeup, updated some references, and made some other editorial changes.

There are no normative changes in this version.

-Daniel

Am 23.10.23 um 18:55 schrieb internet-dra...@ietf.org:
Internet-Draft draft-ietf-oauth-security-topics-24.txt is now available. It is
a work item of the Web Authorization Protocol (OAUTH) WG of the IETF.

    Title:   OAuth 2.0 Security Best Current Practice
    Authors: Torsten Lodderstedt
             John Bradley
             Andrey Labunets
             Daniel Fett
    Name:    draft-ietf-oauth-security-topics-24.txt
    Pages:   62
    Dates:   2023-10-23

Abstract:

    This document describes best current security practice for OAuth 2.0.
    It updates and extends the OAuth 2.0 Security Threat Model to
    incorporate practical experiences gathered since OAuth 2.0 was
    published and covers new threats relevant due to the broader
    application of OAuth 2.0.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-security-topics/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ietf-oauth-security-topics-24.html

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-oauth-security-topics-24

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

--
Please use my new email address:m...@danielfett.de
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to