The following errata report has been held for document update 
for RFC6819, "OAuth 2.0 Threat Model and Security Considerations". 

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=6819&eid=4267

--------------------------------------
Status: Held for Document Update
Type: Editorial

Reported by: David Gladstone <david.gladst...@nib.co.nz>
Date Reported: 2015-02-09
Held by: Kathleen Moriarty (IESG)

Section: 4.4.1.11

Original Text
-------------
If an authorization server includes a nontrivial amount of entropy

Corrected Text
--------------
If an authorization server includes a trivial amount of entropy

Notes
-----
The threat being described outlines a scenario where too little entropy is 
involved; countermeasures include using non-trivial amounts of entropy.

--------------------------------------
RFC6819 (draft-ietf-oauth-v2-threatmodel-08)
--------------------------------------
Title               : OAuth 2.0 Threat Model and Security Considerations
Publication Date    : January 2013
Author(s)           : T. Lodderstedt, Ed., M. McGloin, P. Hunt
Category            : INFORMATIONAL
Source              : Web Authorization Protocol
Area                : Security
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to