Hello ACE,

We have recently submitted an updated version of draft-tiloca-ace-revoked-token-notification

https://tools.ietf.org/html/draft-tiloca-ace-revoked-token-notification-04

The document describes how an Authorization Server can notify Clients and Resource Servers of revoked but yet not expired Access Tokens. This is achieved by means of a Token Revocation List (TRL) resource at the AS, that a device can access and observe by using resource observation for CoAP. The approach complements token introspection at the AS, and does not require additional endpoints on Clients and Resource Servers.

This version further builds on the major update in version -02, also including an Appendix B on advanced operating modes, following input from Ben Kaduk and based on the Series Transfer Pattern [1]. Changes cover especially:

1) Early, high-level clarifications on the full-query and diff-query modes of operation.

2) Error handling on the Authorization Server.

3) Definition of a media-type for messages exchanged in the advanced full-query and diff-query modes of Appendix B, with parameters transported in a CBOR map.


Comments are very welcome!

Best,
/Marco

[1] https://tools.ietf.org/html/draft-bormann-t2trg-stp-03


-------- Forwarded Message --------
Subject: New Version Notification for draft-tiloca-ace-revoked-token-notification-04.txt
Date:   Mon, 22 Feb 2021 09:10:57 -0800
From:   [email protected]
To: Francesca Palombini <[email protected]>, Grace Lewis <[email protected]>, Ludwig Seitz <[email protected]>, Marco Tiloca <[email protected]>, Sebastian Echeverria <[email protected]>




A new version of I-D, draft-tiloca-ace-revoked-token-notification-04.txt
has been successfully submitted by Marco Tiloca and posted to the
IETF repository.

Name: draft-tiloca-ace-revoked-token-notification
Revision: 04
Title: Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments (ACE) Framework
Document date: 2021-02-22
Group: Individual Submission
Pages: 34
URL: https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchive%2Fid%2Fdraft-tiloca-ace-revoked-token-notification-04.txt&amp;data=04%7C01%7Cmarco.tiloca%40ri.se%7C7897294807d74097cf0308d8d754d372%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C637496106605785209%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=ADXtKeAMb6uJSCcpgbGho6jwpL9ym6CWn8Iwa65KUMU%3D&amp;reserved=0 Status: https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-tiloca-ace-revoked-token-notification%2F&amp;data=04%7C01%7Cmarco.tiloca%40ri.se%7C7897294807d74097cf0308d8d754d372%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C637496106605790187%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=qPG2C6L7D0MWl7h%2BHSdlOmhab9ePjw%2FDcRtCATprhyo%3D&amp;reserved=0 Htmlized: https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Fdraft-tiloca-ace-revoked-token-notification&amp;data=04%7C01%7Cmarco.tiloca%40ri.se%7C7897294807d74097cf0308d8d754d372%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C637496106605790187%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=y%2BDTLEV5HOlwMcQw4rxBDko74O2pbPLV258qIsxFMnc%3D&amp;reserved=0 Htmlized: https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.ietf.org%2Fhtml%2Fdraft-tiloca-ace-revoked-token-notification-04&amp;data=04%7C01%7Cmarco.tiloca%40ri.se%7C7897294807d74097cf0308d8d754d372%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C637496106605790187%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=IYZz4BpvRLj%2FiJQRQllc9fnrTqw%2BrwVI0DpdUb3WKyc%3D&amp;reserved=0 Diff: https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Frfcdiff%3Furl2%3Ddraft-tiloca-ace-revoked-token-notification-04&amp;data=04%7C01%7Cmarco.tiloca%40ri.se%7C7897294807d74097cf0308d8d754d372%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C637496106605790187%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=0nJbwaAhx0KUvXEM%2FLaam9hqO1ujRf77%2BpixvwxZlok%3D&amp;reserved=0

Abstract:
This document specifies a method of the Authentication and
Authorization for Constrained Environments (ACE) framework, which
allows an Authorization Server to notify Clients and Resource Servers
(i.e., registered devices) about revoked Access Tokens. The method
relies on resource observation for the Constrained Application
Protocol (CoAP), with Clients and Resource Servers observing a Token
Revocation List on the Authorization Server. Resulting unsolicited
notifications of revoked Access Tokens complement alternative
approaches such as token introspection, while not requiring
additional endpoints on Clients and Resource Servers.



Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat


Attachment: OpenPGP_signature
Description: OpenPGP digital signature

_______________________________________________
Ace mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ace

Reply via email to