[Unbearable] Fwd: [OAUTH-WG] I-D Action: draft-ietf-oauth-token-binding-02.txt

Brian Campbell <bcampbell@pingidentity.com> Mon, 13 March 2017 21:32 UTC

Return-Path: <bcampbell@pingidentity.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 848DE129B52 for <unbearable@ietfa.amsl.com>; Mon, 13 Mar 2017 14:32:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.739
X-Spam-Level:
X-Spam-Status: No, score=-1.739 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, HTML_OBFUSCATE_05_10=0.26, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=pingidentity.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tML1KNYz_c5r for <unbearable@ietfa.amsl.com>; Mon, 13 Mar 2017 14:32:12 -0700 (PDT)
Received: from mail-pg0-x230.google.com (mail-pg0-x230.google.com [IPv6:2607:f8b0:400e:c05::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AE661129B7E for <unbearable@ietf.org>; Mon, 13 Mar 2017 14:32:12 -0700 (PDT)
Received: by mail-pg0-x230.google.com with SMTP id b129so70586867pgc.2 for <unbearable@ietf.org>; Mon, 13 Mar 2017 14:32:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=pingidentity.com; s=gmail; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=VC8kLjlZM6O6jZoBo1G8ELoYx3AM7meVj87HxWLGrUY=; b=YkC6TNf7hRPaguh1p/DW8amKhEalKHEd4GHe7qEFGJ58p7Yctc6wlpEeSBOckHQCoV IgOC1npNUBzpcdyqeARUiJc4AWInH6BSxJGJD2HRYW1DORSnAlQoAhsg6Za0X0MkHCqE IgJnQr1iEi1Sm95HsSOC9Rjw+ujTola5yaIkQ=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=VC8kLjlZM6O6jZoBo1G8ELoYx3AM7meVj87HxWLGrUY=; b=NfvgE8nS0E8MMaJAFzh3G15G1/bJS/TAWgo3M6Z+x/JFe2GUCa84r9DP5So6ltB4Gl BdgeiYsLz/ASmQUEnFnUzcCYN9XECN4spmcEFXl39yD3O9Rh6vyrw4NPbtmDyjTpfrhq TaAFxDJkJd8r5hE8haJWyz4Z5qJ+/2BIiz9zMz4BdHc+tcg678AUYr4C6ZEvS7TAyLOm vjTqdLcP1bpDo6A1wLPQ/hEZr8V+onLG6/MdgspJ0JlyL3MkHPKz6HIbGkUysCYKbl7D GPp/G+X2MpZ4FkcWYbEfsOxhkhk7IxqCywYAbLrodSLg7EP9x2009FCr7pWaUWENr9Dv ZfHA==
X-Gm-Message-State: AMke39l+3gQy7uWtPBVCZ8IR2HiOoKR6miUmumdBSwezZbNCHjxnKGee64C6TFv5FxBdquJmE5p/JP4Scp/AS1Xg
X-Received: by 10.99.247.83 with SMTP id f19mr39297642pgk.158.1489440732147; Mon, 13 Mar 2017 14:32:12 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.100.163.162 with HTTP; Mon, 13 Mar 2017 14:31:41 -0700 (PDT)
In-Reply-To: <148943968790.20370.17735775296781507437@ietfa.amsl.com>
References: <148943968790.20370.17735775296781507437@ietfa.amsl.com>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Mon, 13 Mar 2017 15:31:41 -0600
Message-ID: <CA+k3eCS5tgF0zpGhTbvasJry1XJTqi9_1HeJ+nCKWLHcmjOQMw@mail.gmail.com>
To: oauth <oauth@ietf.org>, IETF Tokbind WG <unbearable@ietf.org>
Content-Type: multipart/alternative; boundary="001a114c325cc11bd6054aa37197"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/FQ0BpeYbvuCBSC7dFefKuPNhiI4>
Subject: [Unbearable] Fwd: [OAUTH-WG] I-D Action: draft-ietf-oauth-token-binding-02.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Mar 2017 21:32:15 -0000

I'm pleased to announce that (with the diligent help of my distinguished
co-authors) draft -02 of "OAuth 2.0 Token Binding"
<https://tools.ietf.org/html/draft-ietf-oauth-token-binding-02> has been
published. The changes from the prior draft are listed below with support
for Token Binding of authorization codes and lots of new examples being the
largest changes.

   o  Added a section on Token Binding for authorization codes with one
      variation for native clients and one for web server clients.
   o  Updated language to reflect that the binding is to the token
      binding key pair and that proof-of-possession of that key is done
      on the TLS connection.
   o  Added a bunch of examples.
   o  Added a few Open Issues so they are tracked in the document.
   o  Updated the Token Binding and OAuth Metadata references.
   o  Added William Denniss as an author.


---------- Forwarded message ----------
From: <internet-drafts@ietf.org>
Date: Mon, Mar 13, 2017 at 3:14 PM
Subject: [OAUTH-WG] I-D Action: draft-ietf-oauth-token-binding-02.txt
To: i-d-announce@ietf.org
Cc: oauth@ietf.org



A New Internet-Draft is available from the on-line Internet-Drafts
directories.
This draft is a work item of the Web Authorization Protocol of the IETF.

        Title           : OAuth 2.0 Token Binding
        Authors         : Michael B. Jones
                          John Bradley
                          Brian Campbell
                          William Denniss
        Filename        : draft-ietf-oauth-token-binding-02.txt
        Pages           : 26
        Date            : 2017-03-13

Abstract:
   This specification enables OAuth 2.0 implementations to apply Token
   Binding to Access Tokens, Authorization Codes, and Refresh Tokens.
   This cryptographically binds these tokens to a client's Token Binding
   key pair, possession of which is proven on the TLS connections over
   which the tokens are intended to be used.  This use of Token Binding
   protects these tokens from man-in-the-middle and token export and
   replay attacks.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-token-binding/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-oauth-token-binding-02

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-token-binding-02


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth