Skip to content

Commit 269f260

Browse files
author
ID Bot
committed
Script updating gh-pages from 8e9bc4f. [ci skip]
1 parent aea3777 commit 269f260

3 files changed

Lines changed: 121 additions & 100 deletions

File tree

comments_by_denis_3/draft-ietf-oauth-status-list.html

Lines changed: 50 additions & 40 deletions
Original file line numberDiff line numberDiff line change
@@ -1049,7 +1049,7 @@
10491049
</tr></thead>
10501050
<tfoot><tr>
10511051
<td class="left">Looker, et al.</td>
1052-
<td class="center">Expires 5 January 2026</td>
1052+
<td class="center">Expires 8 January 2026</td>
10531053
<td class="right">[Page]</td>
10541054
</tr></tfoot>
10551055
</table>
@@ -1062,12 +1062,12 @@
10621062
<dd class="internet-draft">draft-ietf-oauth-status-list-latest</dd>
10631063
<dt class="label-published">Published:</dt>
10641064
<dd class="published">
1065-
<time datetime="2025-07-04" class="published">4 July 2025</time>
1065+
<time datetime="2025-07-07" class="published">7 July 2025</time>
10661066
</dd>
10671067
<dt class="label-intended-status">Intended Status:</dt>
10681068
<dd class="intended-status">Standards Track</dd>
10691069
<dt class="label-expires">Expires:</dt>
1070-
<dd class="expires"><time datetime="2026-01-05">5 January 2026</time></dd>
1070+
<dd class="expires"><time datetime="2026-01-08">8 January 2026</time></dd>
10711071
<dt class="label-authors">Authors:</dt>
10721072
<dd class="authors">
10731073
<div class="author">
@@ -1125,7 +1125,7 @@ <h2 id="name-status-of-this-memo">
11251125
time. It is inappropriate to use Internet-Drafts as reference
11261126
material or to cite them other than as "work in progress."<a href="#section-boilerplate.1-3" class="pilcrow"></a></p>
11271127
<p id="section-boilerplate.1-4">
1128-
This Internet-Draft will expire on 5 January 2026.<a href="#section-boilerplate.1-4" class="pilcrow"></a></p>
1128+
This Internet-Draft will expire on 8 January 2026.<a href="#section-boilerplate.1-4" class="pilcrow"></a></p>
11291129
</section>
11301130
</div>
11311131
<div id="copyright">
@@ -1972,9 +1972,9 @@ <h3 id="name-status-list-token-in-cwt-fo">
19721972
d2845820a2012610781a6170706c69636174696f6e2f7374617475736c6973742b63
19731973
7774a1044231325850a502782168747470733a2f2f6578616d706c652e636f6d2f73
19741974
74617475736c697374732f31061a648c5bea041a8898dfea19fffe19a8c019fffda2
1975-
646269747301636c73744a78dadbb918000217015d584081fbd9f69a0d587cfe600b
1976-
ace3b48f241b530ea8fcf799b201f7b31832e8ee097c1d96a2370361c23bb10e4a3b
1977-
d1477df4c634615009b2f0e6babde1614e4f38
1975+
646269747301636c73744a78dadbb918000217015d58401519d5453353c2f96b725d
1976+
6a44334fcd61ccced90d2d79eeee04ce709e42bccb0cad0527e987eebb12fc331750
1977+
ce5830ccccd2786c9768159efe99073e14c242
19781978
</pre><a href="#section-5.2-9" class="pilcrow"></a>
19791979
</div>
19801980
<p id="section-5.2-10">The following is the CBOR Annotated Hex output of the example above:<a href="#section-5.2-10" class="pilcrow"></a></p>
@@ -1999,12 +1999,12 @@ <h3 id="name-status-list-token-in-cwt-fo">
19991999
6269747301636c73744a78da # "bits\x01clstJxÚ"
20002000
dbb918000217015d # "Û¹\x18\x00\x02\x17\x01]"
20012001
58 40 # bytes(64)
2002-
81fbd9f69a0d587cfe600bac # "\x81ûÙö\x9a\x0dX|þ`\x0b¬"
2003-
e3b48f241b530ea8fcf799b2 # "ã´\x8f$\x1bS\x0e¨ü÷\x99²"
2004-
01f7b31832e8ee097c1d96a2 # "\x01÷³\x182èî\x09|\x1d\x96¢"
2005-
370361c23bb10e4a3bd1477d # "7\x03aÂ;±\x0eJ;ÑG}"
2006-
f4c634615009b2f0e6babde1 # "ôÆ4aP\x09²ð溽á"
2007-
614e4f38 # "aNO8"
2002+
1519d5453353c2f96b725d6a # "\x15\x19ÕE3SÂùkr]j"
2003+
44334fcd61ccced90d2d79ee # "D3OÍaÌÎÙ\x0d-yî"
2004+
ee04ce709e42bccb0cad0527 # "î\x04Îp\x9eB¼Ë\x0c\xad\x05'"
2005+
e987eebb12fc331750ce5830 # "é\x87î»\x12ü3\x17PÎX0"
2006+
ccccd2786c9768159efe9907 # "ÌÌÒxl\x97h\x15\x9eþ\x99\x07"
2007+
3e14c242 # "&gt;\x14ÂB"
20082008
</pre><a href="#section-5.2-11" class="pilcrow"></a>
20092009
</div>
20102010
</section>
@@ -2145,9 +2145,9 @@ <h3 id="name-referenced-token-in-cose">
21452145
d28443a10126a1044231325866a502653132333435017368747470733a2f2f657861
21462146
6d706c652e636f6d061a648c5bea041a8898dfea19ffffa16b7374617475735f6c69
21472147
7374a2636964780063757269782168747470733a2f2f6578616d706c652e636f6d2f
2148-
7374617475736c697374732f315840296685e1cc92168d240c3759069f837241c1cc
2149-
56b9ee9021b462dbea9cafec4ad7ed1e05ede9c028fce149e9ac3a07f403f0883e20
2150-
c9df6e4dc66a1d34dfb634
2148+
7374617475736c697374732f315840c08b0fd07730325893af84208f1295e7639c11
2149+
00f13af6dbe6d12ba48a26e02c55fb405978ca09cab020fd768f4736f0e744955040
2150+
ff9ba3476a8257d6b68c10
21512151
</pre><a href="#section-6.3-6" class="pilcrow"></a>
21522152
</div>
21532153
<p id="section-6.3-7">The following is the CBOR Annotated Hex output of the example above:<a href="#section-6.3-7" class="pilcrow"></a></p>
@@ -2172,12 +2172,12 @@ <h3 id="name-referenced-token-in-cose">
21722172
2e636f6d2f7374617475736c # ".com/statusl"
21732173
697374732f31 # "ists/1"
21742174
58 40 # bytes(64)
2175-
296685e1cc92168d240c3759 # ")f\x85áÌ\x92\x16\x8d$\x0c7Y"
2176-
069f837241c1cc56b9ee9021 # "\x06\x9f\x83rAÁÌV¹î\x90!"
2177-
b462dbea9cafec4ad7ed1e05 # "´bÛê\x9c¯ìJ×í\x1e\x05"
2178-
ede9c028fce149e9ac3a07f4 # "íéÀ(üáIé¬:\x07ô"
2179-
03f0883e20c9df6e4dc66a1d # "\x03ð\x88&gt; ÉßnMÆj\x1d"
2180-
34dfb634 # "4ß¶4"
2175+
c08b0fd07730325893af8420 # "À\x8b\x0fÐw02X\x93¯\x84 "
2176+
8f1295e7639c1100f13af6db # "\x8f\x12\x95çc\x9c\x11\x00ñ:öÛ"
2177+
e6d12ba48a26e02c55fb4059 # "æÑ+¤\x8a&amp;à,Uû@Y"
2178+
78ca09cab020fd768f4736f0 # "xÊ\x09ʰ ýv\x8fG6ð"
2179+
e744955040ff9ba3476a8257 # "çD\x95P@ÿ\x9b£Gj\x82W"
2180+
d6b68c10 # "Ö¶\x8c\x10"
21812181
</pre><a href="#section-6.3-8" class="pilcrow"></a>
21822182
</div>
21832183
<p id="section-6.3-9">ISO mdoc <span>[<a href="#ISO.mdoc" class="cite xref">ISO.mdoc</a>]</span> may utilize the Status List mechanism by introducing the <code>status</code> parameter in the Mobile Security Object (MSO) as specified in Section 9.1.2. The <code>status</code> parameter uses the same encoding as a CWT as defined in <a href="#referenced-token-cose" class="auto internal xref">Section 6.3</a>.<a href="#section-6.3-9" class="pilcrow"></a></p>
@@ -2362,7 +2362,7 @@ <h3 id="name-status-list-request">
23622362
</h3>
23632363
<p id="section-8.1-1">To obtain the Status List Token, the Relying Party <span class="bcp14">MUST</span> send an HTTP GET request to the URI provided in the Referenced Token.<a href="#section-8.1-1" class="pilcrow"></a></p>
23642364
<p id="section-8.1-2">The HTTP endpoint <span class="bcp14">SHOULD</span> support the use of Cross-Origin Resource Sharing (CORS) <span>[<a href="#CORS" class="cite xref">CORS</a>]</span> and/or other methods as appropriate to enable Browser-based clients to access it, unless ecosystems using this specification choose not to support Browser-based clients.<a href="#section-8.1-2" class="pilcrow"></a></p>
2365-
<p id="section-8.1-3">The Relying Party <span class="bcp14">MUST</span> send the following Accept-Header to indicate the requested response type:<a href="#section-8.1-3" class="pilcrow"></a></p>
2365+
<p id="section-8.1-3">The Relying Party <span class="bcp14">SHOULD</span> send the following Accept HTTP Header to indicate the requested response type unless the Content-Type of Status List Tokens in the respective ecosystem is known or the Relying Party supports both formats:<a href="#section-8.1-3" class="pilcrow"></a></p>
23662366
<ul class="normal">
23672367
<li class="normal" id="section-8.1-4.1">
23682368
<p id="section-8.1-4.1.1">"application/statuslist+jwt" for Status List Token in JWT format<a href="#section-8.1-4.1.1" class="pilcrow"></a></p>
@@ -2391,8 +2391,8 @@ <h3 id="name-status-list-request">
23912391
yJleHAiOjIyOTE3MjAxNzAsImlhdCI6MTY4NjkyMDE3MCwiaXNzIjoiaHR0cHM6Ly9le
23922392
GFtcGxlLmNvbSIsInN0YXR1c19saXN0Ijp7ImJpdHMiOjEsImxzdCI6ImVOcmJ1UmdBQ
23932393
WhjQlhRIn0sInN1YiI6Imh0dHBzOi8vZXhhbXBsZS5jb20vc3RhdHVzbGlzdHMvMSIsI
2394-
nR0bCI6NDMyMDB9.RED_faczKf5dICkcmD9gXKTQY-OFbk-4Uauta_nneSChyQF961al
2395-
Jn5hYk8O2fjen7-YApPDwU7cCsNwLGUmOw
2394+
nR0bCI6NDMyMDB9.OB9gtp7hDn1WjOqPD6rFktTSCQN8bleKhReUa4mCK5XDb2FuWXJD
2395+
3nldm9VQqe4YYQQ2xuFgIbkhKxtgPTgK5A
23962396
</pre><a href="#section-8.1-10" class="pilcrow"></a>
23972397
</div>
23982398
</section>
@@ -2498,8 +2498,8 @@ <h3 id="name-historical-resolution">
24982498
yJleHAiOjIyOTE3MjAxNzAsImlhdCI6MTY4NjkyMDE3MCwiaXNzIjoiaHR0cHM6Ly9le
24992499
GFtcGxlLmNvbSIsInN0YXR1c19saXN0Ijp7ImJpdHMiOjEsImxzdCI6ImVOcmJ1UmdBQ
25002500
WhjQlhRIn0sInN1YiI6Imh0dHBzOi8vZXhhbXBsZS5jb20vc3RhdHVzbGlzdHMvMSIsI
2501-
nR0bCI6NDMyMDB9.RED_faczKf5dICkcmD9gXKTQY-OFbk-4Uauta_nneSChyQF961al
2502-
Jn5hYk8O2fjen7-YApPDwU7cCsNwLGUmOw
2501+
nR0bCI6NDMyMDB9.OB9gtp7hDn1WjOqPD6rFktTSCQN8bleKhReUa4mCK5XDb2FuWXJD
2502+
3nldm9VQqe4YYQQ2xuFgIbkhKxtgPTgK5A
25032503
</pre><a href="#section-8.4-7" class="pilcrow"></a>
25042504
</div>
25052505
</section>
@@ -2593,14 +2593,18 @@ <h3 id="name-status-list-aggregation-in-">
25932593
<h2 id="name-x509-certificate-extended-k">
25942594
<a href="#section-10" class="section-number selfRef">10. </a><a href="#name-x509-certificate-extended-k" class="section-name selfRef">X.509 Certificate Extended Key Usage Extension</a>
25952595
</h2>
2596-
<p id="section-10-1"><span>[<a href="#RFC5280" class="cite xref">RFC5280</a>]</span> specifies the Extended Key Usage (EKU) X.509 certificate extension for use on end entity certificates. The extension indicates one or more purposes for which the certified public key is valid. The EKU extension can be used in conjunction with the Key Usage (KU) extension, which indicates the set of basic cryptographic operations for which the certified key may be used. A certificate's issuer explicitly delegates Status List Token signing authority by issuing a X.509 certificate containing the KeyPurposeId defined below in the extended key usage extension.<a href="#section-10-1" class="pilcrow"></a></p>
2596+
<p id="section-10-1"><span>[<a href="#RFC5280" class="cite xref">RFC5280</a>]</span> specifies the Extended Key Usage (EKU) X.509 certificate extension for use on end entity certificates. The extension indicates one or more purposes for which the certified public key is valid. The EKU extension can be used in conjunction with the Key Usage (KU) extension, which indicates the set of basic cryptographic operations for which the certified key may be used. A certificate's issuer explicitly delegates Status List Token signing authority by issuing a X.509 certificate containing the KeyPurposeId defined below in the extended key usage extension.
2597+
Other specifications <span class="bcp14">MAY</span> choose to re-use this OID for other status mechanisms under the condition that they are registered in the "JWT Status Mechanisms" or "CWT Status Mechanisms" registries.<a href="#section-10-1" class="pilcrow"></a></p>
25972598
<p id="section-10-2">The following OID is defined for usage in the EKU extension<a href="#section-10-2" class="pilcrow"></a></p>
2598-
<p id="section-10-3">```
2599-
id-kp OBJECT IDENTIFIER ::=
2599+
<div class="alignLeft art-text artwork" id="section-10-3">
2600+
<pre>
2601+
id-kp OBJECT IDENTIFIER ::=
26002602
{ iso(1) identified-organization(3) dod(6) internet(1)
2601-
security(5) mechanisms(5) pkix(7) 3 }<a href="#section-10-3" class="pilcrow"></a></p>
2602-
<p id="section-10-4">id-kp-oauthStatusListSigning OBJECT IDENTIFIER ::= { id-kp TBD }
2603-
```<a href="#section-10-4" class="pilcrow"></a></p>
2603+
security(5) mechanisms(5) pkix(7) 3 }
2604+
2605+
id-kp-oauthStatusSigning OBJECT IDENTIFIER ::= { id-kp TBD }
2606+
</pre><a href="#section-10-3" class="pilcrow"></a>
2607+
</div>
26042608
</section>
26052609
</div>
26062610
<div id="Security">
@@ -4551,25 +4555,31 @@ <h2 id="name-document-history">
45514555
<p id="appendix-D-1">-12<a href="#appendix-D-1" class="pilcrow"></a></p>
45524556
<ul class="normal">
45534557
<li class="normal" id="appendix-D-2.1">
4554-
<p id="appendix-D-2.1.1">add Paul's affiliation<a href="#appendix-D-2.1.1" class="pilcrow"></a></p>
4558+
<p id="appendix-D-2.1.1">Allow for extended key usage OID to be used for other status mechanisms<a href="#appendix-D-2.1.1" class="pilcrow"></a></p>
45554559
</li>
45564560
<li class="normal" id="appendix-D-2.2">
4557-
<p id="appendix-D-2.2.1">add feedback from Dan Moore<a href="#appendix-D-2.2.1" class="pilcrow"></a></p>
4561+
<p id="appendix-D-2.2.1">add Paul's affiliation<a href="#appendix-D-2.2.1" class="pilcrow"></a></p>
45584562
</li>
45594563
<li class="normal" id="appendix-D-2.3">
4560-
<p id="appendix-D-2.3.1">change JSON Status List structure to only contain JSON object<a href="#appendix-D-2.3.1" class="pilcrow"></a></p>
4564+
<p id="appendix-D-2.3.1">add feedback from Dan Moore<a href="#appendix-D-2.3.1" class="pilcrow"></a></p>
45614565
</li>
45624566
<li class="normal" id="appendix-D-2.4">
4563-
<p id="appendix-D-2.4.1">further nitpicks<a href="#appendix-D-2.4.1" class="pilcrow"></a></p>
4567+
<p id="appendix-D-2.4.1">change JSON Status List structure to only contain JSON object<a href="#appendix-D-2.4.1" class="pilcrow"></a></p>
45644568
</li>
45654569
<li class="normal" id="appendix-D-2.5">
4566-
<p id="appendix-D-2.5.1">clarifying status and status_list IANA descriptions for JWT/CWT<a href="#appendix-D-2.5.1" class="pilcrow"></a></p>
4570+
<p id="appendix-D-2.5.1">further nitpicks<a href="#appendix-D-2.5.1" class="pilcrow"></a></p>
45674571
</li>
45684572
<li class="normal" id="appendix-D-2.6">
4569-
<p id="appendix-D-2.6.1">clarifying description texts for status and status_list in CBOR<a href="#appendix-D-2.6.1" class="pilcrow"></a></p>
4573+
<p id="appendix-D-2.6.1">clarifying status and status_list IANA descriptions for JWT/CWT<a href="#appendix-D-2.6.1" class="pilcrow"></a></p>
45704574
</li>
45714575
<li class="normal" id="appendix-D-2.7">
4572-
<p id="appendix-D-2.7.1">splitting Linkability Mitigation from Token Lifecycle section in Implementation Consideration<a href="#appendix-D-2.7.1" class="pilcrow"></a></p>
4576+
<p id="appendix-D-2.7.1">clarifying description texts for status and status_list in CBOR<a href="#appendix-D-2.7.1" class="pilcrow"></a></p>
4577+
</li>
4578+
<li class="normal" id="appendix-D-2.8">
4579+
<p id="appendix-D-2.8.1">splitting Linkability Mitigation from Token Lifecycle section in Implementation Consideration<a href="#appendix-D-2.8.1" class="pilcrow"></a></p>
4580+
</li>
4581+
<li class="normal" id="appendix-D-2.9">
4582+
<p id="appendix-D-2.9.1">relax the accept header from must to should<a href="#appendix-D-2.9.1" class="pilcrow"></a></p>
45734583
</li>
45744584
</ul>
45754585
<p id="appendix-D-3">-11<a href="#appendix-D-3" class="pilcrow"></a></p>

0 commit comments

Comments
 (0)