[OAUTH-WG] I-D Action: draft-ietf-oauth-security-topics-update-00.txt

internet-drafts@ietf.org Mon, 01 December 2025 14:39 UTC

Return-Path: <internet-drafts@ietf.org>
X-Original-To: oauth@ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from [10.244.8.105] (unknown [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id E78B39339750; Mon, 1 Dec 2025 06:39:30 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.54.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <176459997086.3595053.13822720297198266690@dt-datatracker-5bd94c585b-wk4l4>
Date: Mon, 01 Dec 2025 06:39:30 -0800
Message-ID-Hash: MDIMLIRLCHBEZEI5AGV7DSZYHBISLENF
X-Message-ID-Hash: MDIMLIRLCHBEZEI5AGV7DSZYHBISLENF
X-MailFrom: internet-drafts@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: oauth@ietf.org
Subject: [OAUTH-WG] I-D Action: draft-ietf-oauth-security-topics-update-00.txt
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/Z5YOd2vSYu8moj54tT98RFN0mso>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

Internet-Draft draft-ietf-oauth-security-topics-update-00.txt is now
available. It is a work item of the Web Authorization Protocol (OAUTH) WG of
the IETF.

   Title:   Updates to OAuth 2.0 Security Best Current Practice
   Authors: Tim Würtele
            Pedram Hosseyni
            Kaixuan Luo
            Adonis Fung
   Name:    draft-ietf-oauth-security-topics-update-00.txt
   Pages:   20
   Dates:   2025-12-01

Abstract:

   This document updates the set of best current security practices for
   OAuth 2.0 by extending the security advice given in RFC 6749, RFC
   6750, and RFC 9700, to cover new threats that have been discovered
   since the former documents have been published.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-security-topics-update/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ietf-oauth-security-topics-update-00.html

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts