Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-threatmodel-07.txt

2012-08-16 Thread Torsten Lodderstedt
Hi, we don't plan further changes. regards, Torsten. Am 16.08.2012 19:35, schrieb Stephen Farrell: Thanks, Since this is on the Aug 30 telechat let's not have any further changes without a chair/AD asking. Ta, S On 16 Aug 2012, at 18:19, Torsten Lodderstedt wrote: Hi all, the new revi

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-threatmodel-07.txt

2012-08-16 Thread Stephen Farrell
Thanks, Since this is on the Aug 30 telechat let's not have any further changes without a chair/AD asking. Ta, S On 16 Aug 2012, at 18:19, Torsten Lodderstedt wrote: > Hi all, > > the new revision covers token substitution, which has been added to the core > spec lately. Additionally, it d

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-threatmodel-07.txt

2012-08-16 Thread Torsten Lodderstedt
Hi all, the new revision covers token substitution, which has been added to the core spec lately. Additionally, it describes a similar attack on the code flow, which is prevented by forcing the authorization server to validate that an authorization code had been issued to the calling client.

[OAUTH-WG] I-D Action: draft-ietf-oauth-v2-threatmodel-07.txt

2012-08-16 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol Working Group of the IETF. Title : OAuth 2.0 Threat Model and Security Considerations Author(s) : Torsten Lodderstedt