Internet-Draft draft-ietf-oauth-rfc7523bis-04.txt is now available. It is a
work item of the Web Authorization Protocol (OAUTH) WG of the IETF.
Title: Updates to OAuth 2.0 JSON Web Token (JWT) Client Authentication and
Assertion-Based Authorization Grants
Authors: Michael B. Jones
Brian Campbell
Chuck Mortimore
Filip Skokan
Name: draft-ietf-oauth-rfc7523bis-04.txt
Pages: 14
Dates: 2026-01-09
Abstract:
This specification updates the requirements for audience values in
OAuth 2.0 Client Assertion Authentication and Assertion-based
Authorization Grants to address a security vulnerability identified
in the previous requirements for those audience values in multiple
OAuth 2.0 specifications.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc7523bis/
There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-ietf-oauth-rfc7523bis-04
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-oauth-rfc7523bis-04
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]