[OAUTH-WG] I-D Action: draft-ietf-oauth-security-topics-update-00.txt
internet-drafts@ietf.org Mon, 01 December 2025 14:39 UTC
Return-Path: <internet-drafts@ietf.org>
X-Original-To: oauth@ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from [10.244.8.105] (unknown [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id E78B39339750; Mon, 1 Dec 2025 06:39:30 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.54.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <176459997086.3595053.13822720297198266690@dt-datatracker-5bd94c585b-wk4l4>
Date: Mon, 01 Dec 2025 06:39:30 -0800
Message-ID-Hash: MDIMLIRLCHBEZEI5AGV7DSZYHBISLENF
X-Message-ID-Hash: MDIMLIRLCHBEZEI5AGV7DSZYHBISLENF
X-MailFrom: internet-drafts@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: oauth@ietf.org
Subject: [OAUTH-WG] I-D Action: draft-ietf-oauth-security-topics-update-00.txt
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/Z5YOd2vSYu8moj54tT98RFN0mso>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
Internet-Draft draft-ietf-oauth-security-topics-update-00.txt is now
available. It is a work item of the Web Authorization Protocol (OAUTH) WG of
the IETF.
Title: Updates to OAuth 2.0 Security Best Current Practice
Authors: Tim Würtele
Pedram Hosseyni
Kaixuan Luo
Adonis Fung
Name: draft-ietf-oauth-security-topics-update-00.txt
Pages: 20
Dates: 2025-12-01
Abstract:
This document updates the set of best current security practices for
OAuth 2.0 by extending the security advice given in RFC 6749, RFC
6750, and RFC 9700, to cover new threats that have been discovered
since the former documents have been published.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-security-topics-update/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ietf-oauth-security-topics-update-00.html
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
- [OAUTH-WG] I-D Action: draft-ietf-oauth-security-… internet-drafts