This version of the management spec includes the changed language to the security considerations section discussed on the list after IETF92, changing the recommendation for rate-limiting for one of minimum token entropy to prevent token guessing attacks against the registration access token.
Please review the diffs and comment on the list here if anything needs to be tweaked. — Justin > On Apr 6, 2015, at 1:06 PM, <[email protected]> > <[email protected]> wrote: > > > A New Internet-Draft is available from the on-line Internet-Drafts > directories. > This draft is a work item of the Web Authorization Protocol Working Group of > the IETF. > > Title : OAuth 2.0 Dynamic Client Registration Management > Protocol > Authors : Justin Richer > Michael B. Jones > John Bradley > Maciej Machulak > Filename : draft-ietf-oauth-dyn-reg-management-13.txt > Pages : 18 > Date : 2015-04-06 > > Abstract: > This specification defines methods for management of dynamic OAuth > 2.0 client registrations for use cases in which the properties of a > registered client may need to be changed during the lifetime of the > client. Not all authorization servers supporting dynamic client > registration will support these management methods. > > > The IETF datatracker status page for this draft is: > https://datatracker.ietf.org/doc/draft-ietf-oauth-dyn-reg-management/ > > There's also a htmlized version available at: > http://tools.ietf.org/html/draft-ietf-oauth-dyn-reg-management-13 > > A diff from the previous version is available at: > http://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-dyn-reg-management-13 > > > Please note that it may take a couple of minutes from the time of submission > until the htmlized version and diff are available at tools.ietf.org. > > Internet-Drafts are also available by anonymous FTP at: > ftp://ftp.ietf.org/internet-drafts/ > > _______________________________________________ > OAuth mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/oauth
signature.asc
Description: Message signed with OpenPGP using GPGMail
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
