Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Comment on Updates to Audience Values for OAuth 2.0 Authorization Servers by Progress Report on Handling an Actionable Security Vulnerability – Mike Jones: self-issued

Дата публикации: 29-05-2026 13:21:00

[…] I described when writing about a spec we created to address the problems, the security vulnerability was identified during […]

Основное содержимое страницы с новостью.

OAuth logoA new version of the Updates to Audience Values for OAuth 2.0 Authorization Servers specification has been published that incorporates feedback from the OAuth working group during IETF 122. I look forward to a vigorous and useful discussion of the specification at IETF 123 in Madrid.

This specification updates a set of existing OAuth specifications to address a security vulnerability identified during formal analysis of a previous version of the OpenID Federation specification. The vulnerability resulted from ambiguities in the treatment of the audience values of tokens intended for the authorization server. The updates to these specifications close that vulnerability in the affected OAuth specifications – especially JWT client authentication in RFC 7523. In parallel, the OpenID Foundation has also updated affected OpenID specifications, including OpenID Federation and FAPI 2.0.

As summarized in the history entries, the changes in this draft were:

  • Focused RFC 7523 updates on JWT client authentication case.
  • Described client responsibilities for the audience value of authorization grants. No longer mandate that the audience for authorization grants be the issuer identifier, so as to make a minimum of breaking changes.
  • Deprecated the use of SAML assertions for client authentication.

Finally, Filip Skokan was added as an author, in recognition of his significant contributions to the work. Thanks to Filip and Brian Campbell for their work with me on this specification.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1 Comment on OpenID Connect RP Metadata Choices is an Implementer’s Draft by Final OpenID Connect RP Metadata Choices Specification – Mike Jones: self-issued 011.2301-04-2026
2 Comment on Initial Drafts of 1.1 OpenID Federation Specs by Final 1.1 OpenID Federation Specs – Mike Jones: self-issued 017.7511-05-2026
3 Comment on Post-Quantum Presentation at TDI 2026 by Post-Quantum Signatures for JOSE and COSE – Mike Jones: self-issued 024.1320-05-2026
4 Comment on OpenID Federation Interop Event at TIIME 2026 in Amsterdam by The Journey to OpenID Federation 1.0 is Complete – Mike Jones: self-issued 020.3618-02-2026
5 Comment on FIDO2 CTAP 2.3 standard and Server Requirements published by Post-Quantum Signatures for JOSE and COSE – Mike Jones: self-issued 025.7120-05-2026
6Nissan blames Oracle vulnerability for data breach0730-06-2026
7X-post: Hardening GitHub Actions workflows across the WordPress organisation09.8313-07-2026
8How Linux Security Teams Spot Vulnerabilities Before CVEs Are Published0714-07-2026
9Glasswing update reveals Mythos false positive levels0526-05-2026
10New GitHub Zero-Day Exposed Developer Tokens to Attackers-5704-06-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 15.31. Источник: self-issued.info.