This message starts a WG Last Call for: draft-ietf-oauth-attestation-based-client-auth-11
This Working Group Last Call ends on 2026-09-22 Abstract: This specification defines an extension to the OAuth 2.0 protocol (RFC 6749) that enables a client instance to include a key-bound attestation when interacting with an Authorization Server or Resource Server. This mechanism allows a client instance to prove its authenticity verified by a client attester without revealing its target audience to that attester. It may also serve as a mechanism for client authentication as per OAuth 2.0. File can be retrieved from: https://www.ietf.org/archive/id/draft-ietf-oauth-attestation-based-client-auth-11.txt Please review and indicate your support or objection to proceed with the publication of this document by replying to this email keeping [email protected] in copy. Objections should be explained and suggestions to resolve them are highly appreciated. Authors, and WG participants in general, are reminded of the Intellectual Property Rights (IPR) disclosure obligations described in BCP 79 [1]. Appropriate IPR disclosures required for full conformance with the provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. Sanctions available for application to violators of IETF IPR Policy can be found at [3]. Thank you. [1] https://datatracker.ietf.org/doc/bcp78/ [2] https://datatracker.ietf.org/doc/bcp79/ [3] https://datatracker.ietf.org/doc/rfc6701/ The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ietf-oauth-attestation-based-client-auth/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-ietf-oauth-attestation-based-client-auth-11.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-ietf-oauth-attestation-based-client-auth-11 _______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
