Web Authorization Protocol (oauth)

Slides:



Advertisements
Similar presentations
IETF Calsify.
Advertisements

Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
IETF 90: NetExt WG Meeting. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet- Draft.
IETF 79 - Beijing, China1 Martini Working Group IETF 79 Beijing Chairs: Bernard Spencer
CCAMP Working Group Online Agenda and Slides at: Data tracker:
Web Authorization Protocol (oauth) IETF 90, Toronto Chairs: Hannes Tschofenig, Derek Atkins Responsible AD: Kathleen Moriarty Mailing List:
Web Authorization Protocol (oauth) Hannes Tschofenig.
OAuth WG Blaine Cook, Hannes Tschofenig. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft.
Authentication and Authorization for Constrained Environment (ACE) WG Chairs: Kepeng Li, Hannes
IETF 89, LONDON, UK LISP Working Group. 2 Agenda and slides:  lisp.html Audio Stream 
Transport Layer Security (TLS) IETF-84 Chairs: Eric Rescorla Joe Salowey.
IETF #81 - NETCONF WG session 1 NETCONF WG IETF 81, Quebec City, Canada MONDAY, July 25, Bert Wijnen Mehmet Ersue.
Agenda Behcet Sarikaya Dirk von Hugo November 2012 FMC BOF IETF
IETF #82 - NETCONF WG session 1 NETCONF WG IETF 82, Taipei, Taiwan TUESDAY, November 15, Afternoon Session III Bert Wijnen Mehmet Ersue.
Agenda Stig Venaas Behcet Sarikaya November 2011 Multimob WG IETF
Alternatives to Content Classification for Operator Resource Deployment (ACCORD) BOF Chairs: Gonzalo Camarillo & Pete Resnick.
Audio/Video Transport Extensions (avtext) Working Group Keith Drage Magnus Westerlund Jabber room:
OPSAWG chairs: Scott Bradner Christopher Liljenstolpe.
1 Chairs: Pascal Thubert Thomas Watteyne Mailing list: Jabber: Etherpad for minutes:
Agenda Wednesday, July 29, :00 – 15:00 Congresshall B Please join the Jabber room: LEDBAT WG IETF 75.
Emergency Context Resolution with Internet Technologies (ECRIT) Chairs: Marc Linsner & Roger Marshall Standing In for the Chairs: Brian Rosen IETF 94.
STIR Secure Telephone Identity Revisited
LMAP WG IETF 97 – Seoul, SK November 17, 2016 Dan Romascanu Jason Weil
Agenda Stig Venaas Behcet Sarikaya November 2010
NETCONF WG IETF 93 - Prague, Czech Republic THURSDAY, July 23, 2015
Chairs: Derek Atkins and Hannes Tschofenig
SIPREC WG, Interim virtual meeting , GMT-4
Extensible Messaging and Presence Protocol (XMPP) WG
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
Authentication and Authorization for Constrained Environment (ACE)
Agenda OAuth WG IETF 87 July, 2013.
IETF101 London Web Authorization Protocol (OAuth)
MODERN Working Group IETF 97 November 14, 2016.
Network Virtualization Overlays (NVO3) Working Group IETF 97, November 2016, Seoul Chairs: Secretary: Sam Aldrin Matthew Bocci.
Wednesday, 9:30-12:00 Morning session I, Van Horne
Tuesday , 9:30-12:00 Morning session I, Buckingham
Joint OPS Area and OPSAWG Meeting
P2PSIP WG IETF 84 P2PSIP WG Agenda & Status Tuesday, July 31st, 2012
Kathleen Moriarty, Trusted Execution Environment Provisioning (TEEP) BoF IETF-100 November 2017 Chairs: Nancy Cam-Winget,
SPRING IETF-98 Tuesday, March 28.
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
Singapore – IETF 100 – November 2017
Thursday, 20th of July 2017.
Web Authorization Protocol (oauth)
Agenda IETF 82 Taipei November 14, 2011
Multiple Interfaces (MIF) WG
JSON Object Signing and Encryption (JOSE) Working Group
SIPREC WG, Interim Meeting , GMT/UTC
Flexible Ethernet (Side meeting)
Joint Ops Area and OpsA WG
Joint NTP and TICTOC Meeting
Chairs: Samita Chakrabarti, Gabriel Montenegro
IETF DTN Working Group July 17th, 2017 Chairs:
Web Authorization Protocol (OAuth) WG Chairs: Hannes Tschofenig, Rifaat Shekh-Yusef, Security AD: Roman.
IETF102 Montreal Web Authorization Protocol (OAuth)
Web Authorization Protocol (OAuth) WG Chairs: Hannes Tschofenig, Rifaat Shekh-Yusef, Security AD: Roman.
20th July 2017 Gorry Fairhurst Wes Eddy David Black WG chairs
Tuesday (July 23rd, 2019) Two sessions ( minutes)
Web Authorization Protocol (OAuth) WG Chairs: Hannes Tschofenig, Rifaat Shekh-Yusef, Security AD: Roman.
SIPREC WG, Interim virtual meeting , GMT
Agenda Wednesday, March 30, :00 – 11:30 AM
TEAS CCAMP MPLS PCE Working Groups
SIPBRANDY Chair Slides
Multiple Interfaces (MIF) WG
Interface to Network Security Functions (I2NSF)
Scott Bradner & Martin Thomson
NETCONF WG IETF 80, Prague, Czech Republic March 31,
IETF 100 Singapore MBONED.
Web Authorization Protocol (OAuth)
Audio/Video Transport Extensions (avtext) Working Group
Presentation transcript:

Web Authorization Protocol (oauth) WG Chairs: Hannes Tschofenig, hannes.tschofenig@gmx.net Rifaat Shekh-Yusef, rifaat.ietf@gmail.com Security AD: Eric Rescorla, ekr@rtfm.com Mailing List: oauth@ietf.org To Subscribe: https://www.ietf.org/mailman/listinfo/oauth

Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made within the context of an IETF activity is considered an "IETF Contribution". Such statements include oral statements in IETF sessions, as well as written and electronic communications made at any time or place, which are addressed to: The IETF plenary session The IESG, or any member thereof on behalf of the IESG Any IETF mailing list, including the IETF list itself, any working group or design team list, or any other list functioning under IETF auspices Any IETF working group or portion thereof Any Birds of a Feather (BOF) session The IAB or any member thereof on behalf of the IAB The RFC Editor or the Internet-Drafts function All IETF Contributions are subject to the rules of RFC 5378 and RFC 3979 (updated by RFC 4879). Statements made outside of an IETF session, mailing list or other function, that are clearly not intended to be input to an IETF activity, group or function, are not IETF Contributions in the context of this notice.  Please consult RFC 5378 and RFC 3979 for details. A participant in any IETF activity is deemed to accept all IETF rules of process, as documented in Best Current Practices RFCs and IESG Statements. A participant in any IETF activity acknowledges that written, audio and video records of meetings may be made and may be available to the public.

Requests Jabber Scribe Minute Taker Blue Sheets

Status Authorization Server Metadata  in AD evaluation JWT Secured Authorization Request (JAR)  in IESG evaluation OAuth 2.0 for Native Apps  in approved-announcement to be sent Mutual TLS Profiles for OAuth Clients  new WG item Token Exchange & Device Flow  in WGLC

OAuth Security Workshop 2017

OAuth Security Workshop ETH Zurich, July 13th & 14th 2017 All info available at https://zisc.ethz.ch/oauth-security-workshop-2017/ Great event for exchanging ideas between researchers & standards experts. Content Formal analysis of OAuth/OpenID Connect Crypto-related attacks New ideas for OAuth Discussions on what we could improve

Agenda Tuesday Afternoon session I (13:30-15:30) Chairs update Mutual TLS Profile for OAuth 2.0 (Brian Campbell) OAuth Security Topics (Torsten Lodderstedt) OAuth 2.0 Incremental Authorization (William Denniss) JSON Web Token Best Current Practices (Mike Jones) * Agenda Bashing and Status Update (Chairs, 5 mins) * Authentication and Authorization for Constrained Environments (ACE) Open issue about PoP Key Semantics for CWTs (Michael B. Jones, 15 mins) - https://datatracker.ietf.org/doc/draft-jones-ace-cwt-proof-of-possession/ * CBOR Web Token (Michael B. Jones, 5 mins) - https://datatracker.ietf.org/doc/draft-ietf-ace-cbor-web-token/ * Authorization using OAuth 2.0 (Ludwig Seitz, 10 mins) - https://datatracker.ietf.org/doc/draft-ietf-ace-oauth-authz/ * DTLS Profile for ACE (Olaf Bergmann, 10 mins) - https://datatracker.ietf.org/doc/draft-ietf-ace-dtls-authorize/ * OSCOAP profile of ACE (Francesca Palombini, 5 mins) - https://tools.ietf.org/html/draft-seitz-ace-oscoap-profile * IPsec profile of ACE (Marco Tiloca, 10 mins) - https://datatracker.ietf.org/doc/draft-aragon-ace-ipsec-profile/ * MQTT-TLS profile of ACE (Anthony Kirby, 15 mins) - https://datatracker.ietf.org/doc/draft-sengul-ace-mqtt-tls-profile/ * Ephemeral Diffie-Hellman Over COSE (EDHOC) (John Mattsson, 10 mins) - https://tools.ietf.org/html/draft-selander-ace-cose-ecdhe-07 * EST over secure CoAP (EST-coaps) (Peter van der Stok, 10 mins) - https://datatracker.ietf.org/doc/draft-vanderstok-ace-coap-est/ * Joining of OSCOAP multicast groups in ACE (Marco Tiloca, 10 mins) - https://datatracker.ietf.org/doc/draft-tiloca-ace-oscoap-joining/ * Raw-Public-Key and Pre-Shared-Key as OAuth client credentials (Samuel Erdtman, 10 mins) - https://datatracker.ietf.org/doc/draft-erdtman-ace-rpcc/ * Wrap-up (Chairs, 5 min)