Internet-Draft draft-ietf-oauth-rfc7523bis-07.txt is now available. It is a
work item of the Web Authorization Protocol (OAUTH) WG of the IETF.

   Title:   Updates to OAuth 2.0 JSON Web Token (JWT) Client Authentication and 
Assertion-Based Authorization Grants
   Authors: Michael B. Jones
            Brian Campbell
            Chuck Mortimore
            Filip Skokan
   Name:    draft-ietf-oauth-rfc7523bis-07.txt
   Pages:   15
   Dates:   2026-03-26

Abstract:

   This document updates RFC7521, RFC7522, RFC7523 and RFC9126 with
   respect to the treatment of audience values in OAuth 2.0 Client
   Assertion Authentication and Assertion-based Authorization Grants to
   address a security vulnerability identified in the previous
   requirements for those audience values in multiple OAuth 2.0
   specifications.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc7523bis/

There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-ietf-oauth-rfc7523bis-07

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-oauth-rfc7523bis-07

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to