This change and other updates addressing review comments has been published at https://www.ietf.org/archive/id/draft-ietf-oauth-rfc8725bis-08.html. Per the history entry, the changes were:
* Clarified that Nested JWT validation applies when Nested JWTs are supported (SECDIR review). * Applied IESG ballot comments by Ketan Talaulikar (Introduction relationships, Compact Serialization and typ prefix citations). * Updated Appendix A (Changes from RFC 8725) with complete bullets and section references. * Added an informative mention of fully-specified JOSE algorithm identifiers ([RFC9864<https://www.ietf.org/archive/id/draft-ietf-oauth-rfc8725bis-08.html#RFC9864>]). * Made the [I-D.ietf-jose-deprecate-none-rsa15<https://www.ietf.org/archive/id/draft-ietf-oauth-rfc8725bis-08.html#I-D.ietf-jose-deprecate-none-rsa15>] reference normative and rewrote the text on "alg":"none" and RSA-PKCS1 v1.5 accordingly. * Corrected section reference and itemized list syntax and removed extraneous spaces in the source. * Applied spelling and grammar corrections. Thanks to all the reviewers! Cheers, -- Mike P.S. Yes, we’re aware that Mike Bishop just filed some helpful comments. We’ll address those in -09 but we wanted to get this much-awaited set of changes out now. From: Michael Jones <[email protected]> Sent: Sunday, August 9, 2026 6:11 PM To: Deb Cooley <[email protected]>; [email protected] Cc: Web Authorization Protocol Working Group <[email protected]> Subject: RE: Change to draft-ietf-oauth-rfc8725bis https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/pull/58 makes the draft-ietf-jose-deprecate-none-rsa15 reference normative and rewrites the text on "alg":"none" and RSA-PKCS1 v1.5 accordingly. None of the changes should be surprising. Best wishes, -- Mike From: Deb Cooley <[email protected]<mailto:[email protected]>> Sent: Friday, August 7, 2026 11:48 AM To: Michael Jones <[email protected]<mailto:[email protected]>>; [email protected]<mailto:[email protected]> Cc: Web Authorization Protocol Working Group <[email protected]<mailto:[email protected]>> Subject: Re: Change to draft-ietf-oauth-rfc8725bis What's the status of the update? Are you waiting on me (if can you resend)? Deb On Fri, Jul 31, 2026 at 5:42 AM Deb Cooley <[email protected]<mailto:[email protected]>> wrote: To give us time to work through the details, I'm going to move this draft to the next telechat (20 Aug). I'd rather get this right than fast. Deb On Thu, Jul 30, 2026 at 6:15 PM Deb Cooley <[email protected]<mailto:[email protected]>> wrote: That works for me. I thought of many other (bad) options, including asking the jose draft to update 8725bis, but that only works once we have an RFC number for 8725bis. Deb On Thu, Jul 30, 2026 at 4:13 PM Michael Jones <[email protected]<mailto:[email protected]>> wrote: We can do this. JOSE chairs (Karen, John, Michael), can you attempt to move draft-ietf-jose-deprecate-none-rsa15 along promptly, if we’re going to take a normative reference? (It historically has been pretty slow-moving.) I’d like us to write the text in such a way that we can easily downgrade the draft-ietf-jose-deprecate-none-rsa15 reference from normative back to informative while in the RFC Editor’s queue, should the other draft get hung up. -- Mike From: Deb Cooley <[email protected]<mailto:[email protected]>> Sent: Thursday, July 30, 2026 8:23 AM To: [email protected]<mailto:[email protected]> Cc: Web Authorization Protocol Working Group <[email protected]<mailto:[email protected]>>; [email protected]<mailto:[email protected]> Subject: Change to draft-ietf-oauth-rfc8725bis I've been thinking about Section 3.2 and the jose draft deprecate none. Since the jose draft is through wglc (waiting for a shepherd write up, I believe - jose chairs are cc'd), I'd like to make that draft normative in 8725bis. This would make the guidance stronger in an area where there have historically been issues. I'm asking for a rewrite of Para 3 using the jose draft as a normative reference, making the BCP14 language 'MUST NOT'. In addition, bullet 1 can also be stronger as the 'deprecate none' draft also deprecated PKCS1 v1.5. Currently, it says 'avoid'. Let me know what you think. Deb
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
