Hello ACE,

We have submitted an updated version of
draft-tiloca-ace-revoked-token-notification

https://tools.ietf.org/html/draft-tiloca-ace-revoked-token-notification-01

The document describes how an Authorization Server can notify Clients
and Resource Servers of revoked but yet not expired Access Tokens. This
is achieved by means of a Token Revocation List (TRL) resource at the
AS, that a device can access and observe by using resource observation
for CoAP. The approach complements token introspection at the AS, and
does not require additional endpoints on Clients and Resource Servers.

This update is especially about:

1) Addressing the review at [1] from Travis and further additional input
from Jim (thank you both!).

2) Having a single TRL resource at the AS, rather than one per device as
in -00.

3) Handling administrators as special requesters.

4) Query of the TRL resource in full mode (all current revoked tokens)
or diff mode (just the latest recent updates concerning revoked tokens).

5) Improved security considerations.


Comments are very welcome.

Best,
/Marco

[1] https://mailarchive.ietf.org/arch/msg/ace/1UK5QuLh4kmzlH211JBtotdchfQ/


-------- Forwarded Message --------
Subject:        New Version Notification for
draft-tiloca-ace-revoked-token-notification-01.txt
Date:   Mon, 09 Mar 2020 12:25:20 -0700
From:   internet-dra...@ietf.org
To:     Grace Lewis <gle...@sei.cmu.edu>, Sebastian Echeverria
<sechever...@sei.cmu.edu>, Ludwig Seitz <ludwig.se...@combitech.se>,
Francesca Palombini <francesca.palomb...@ericsson.com>, Marco Tiloca
<marco.til...@ri.se>




A new version of I-D, draft-tiloca-ace-revoked-token-notification-01.txt
has been successfully submitted by Marco Tiloca and posted to the
IETF repository.

Name: draft-tiloca-ace-revoked-token-notification
Revision: 01
Title: Notification of Revoked Access Tokens in the Authentication and
Authorization for Constrained Environments (ACE) Framework
Document date: 2020-03-09
Group: Individual Submission
Pages: 16
URL:
https://www.ietf.org/internet-drafts/draft-tiloca-ace-revoked-token-notification-01.txt
Status:
https://datatracker.ietf.org/doc/draft-tiloca-ace-revoked-token-notification/
Htmlized:
https://tools.ietf.org/html/draft-tiloca-ace-revoked-token-notification-01
Htmlized:
https://datatracker.ietf.org/doc/html/draft-tiloca-ace-revoked-token-notification
Diff:
https://www.ietf.org/rfcdiff?url2=draft-tiloca-ace-revoked-token-notification-01

Abstract:
This document specifies a method of the Authentication and
Authorization for Constrained Environments (ACE) framework, which
allows an Authorization Server to notify Clients and Resource Servers
(i.e., registered devices) about revoked Access Tokens. The method
relies on resource observation for the Constrained Application
Protocol (CoAP), with Clients and Resource Servers observing a Token
Revocation List on the Authorization Server. Resulting unsolicited
notifications of revoked Access Tokens complement alternative
approaches such as token introspection, while not requiring
additional endpoints on Clients and Resource Servers.



Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat


Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Ace mailing list
Ace@ietf.org
https://www.ietf.org/mailman/listinfo/ace

Reply via email to