[OAUTH-WG] OAuth 2.0 Bearer Token Specification Draft -17

Mike Jones <Michael.Jones@microsoft.com> Sat, 18 February 2012 00:19 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D85C411E80AE for <oauth@ietfa.amsl.com>; Fri, 17 Feb 2012 16:19:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.784
X-Spam-Level:
X-Spam-Status: No, score=-3.784 tagged_above=-999 required=5 tests=[AWL=-0.186, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZOxWfPa-UfEq for <oauth@ietfa.amsl.com>; Fri, 17 Feb 2012 16:19:51 -0800 (PST)
Received: from DB3EHSOBE005.bigfish.com (db3ehsobe005.messaging.microsoft.com [213.199.154.143]) by ietfa.amsl.com (Postfix) with ESMTP id 7179111E809F for <oauth@ietf.org>; Fri, 17 Feb 2012 16:19:50 -0800 (PST)
Received: from mail30-db3-R.bigfish.com (10.3.81.249) by DB3EHSOBE005.bigfish.com (10.3.84.25) with Microsoft SMTP Server id 14.1.225.23; Sat, 18 Feb 2012 00:19:49 +0000
Received: from mail30-db3 (localhost [127.0.0.1]) by mail30-db3-R.bigfish.com (Postfix) with ESMTP id 684411E0319 for <oauth@ietf.org>; Sat, 18 Feb 2012 00:19:49 +0000 (UTC)
X-SpamScore: -19
X-BigFish: VS-19(zzc85fhzz1202hzz1033IL8275eh8275bh8275dha1495iz2fh2a8h668h839h)
X-Forefront-Antispam-Report: CIP:131.107.125.8; KIP:(null); UIP:(null); IPV:NLI; H:TK5EX14HUBC102.redmond.corp.microsoft.com; RD:none; EFVD:NLI
Received-SPF: pass (mail30-db3: domain of microsoft.com designates 131.107.125.8 as permitted sender) client-ip=131.107.125.8; envelope-from=Michael.Jones@microsoft.com; helo=TK5EX14HUBC102.redmond.corp.microsoft.com ; icrosoft.com ;
Received: from mail30-db3 (localhost.localdomain [127.0.0.1]) by mail30-db3 (MessageSwitch) id 1329524387988202_27208; Sat, 18 Feb 2012 00:19:47 +0000 (UTC)
Received: from DB3EHSMHS006.bigfish.com (unknown [10.3.81.254]) by mail30-db3.bigfish.com (Postfix) with ESMTP id EC42020004A for <oauth@ietf.org>; Sat, 18 Feb 2012 00:19:47 +0000 (UTC)
Received: from TK5EX14HUBC102.redmond.corp.microsoft.com (131.107.125.8) by DB3EHSMHS006.bigfish.com (10.3.87.106) with Microsoft SMTP Server (TLS) id 14.1.225.23; Sat, 18 Feb 2012 00:19:47 +0000
Received: from TK5EX14MBXC284.redmond.corp.microsoft.com ([169.254.1.12]) by TK5EX14HUBC102.redmond.corp.microsoft.com ([157.54.7.154]) with mapi id 14.02.0247.005; Fri, 17 Feb 2012 16:19:44 -0800
From: Mike Jones <Michael.Jones@microsoft.com>
To: "oauth@ietf.org" <oauth@ietf.org>
Thread-Topic: OAuth 2.0 Bearer Token Specification Draft -17
Thread-Index: Aczt0v/Ld5jNP7/gRVOp2UhqhBWJKg==
Date: Sat, 18 Feb 2012 00:19:43 +0000
Message-ID: <4E1F6AAD24975D4BA5B1680429673943663AB2D4@TK5EX14MBXC284.redmond.corp.microsoft.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [157.54.51.76]
Content-Type: multipart/alternative; boundary="_000_4E1F6AAD24975D4BA5B1680429673943663AB2D4TK5EX14MBXC284r_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
Subject: [OAUTH-WG] OAuth 2.0 Bearer Token Specification Draft -17
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 18 Feb 2012 00:19:52 -0000

Draft 17 of the OAuth 2.0 Bearer Token Specification<http://tools.ietf.org/html/draft-ietf-oauth-v2-bearer> has been published.  This version changes the RFCs referenced for certificate chain verification.  The wording was proposed by Alexey Melnikov as part of the Gen-ART review.

It contains the following changes:

  *   Restore RFC 2818 reference for server identity verification and add RFC 5280 reference for certificate revocation lists, per Gen-ART review comments.

The draft is available at:

*         http://tools.ietf.org/html/draft-ietf-oauth-v2-bearer-17
A HTML-formatted version is available at:

*         http://self-issued.info/docs/draft-ietf-oauth-v2-bearer-17.html

                                                            -- Mike