This specification details the threats, attack consequences, security considerations, and best practices that must be taken into account when developing browser-based applications that use OAuth 2.0.
Recently published RFCs
Recently published RFCs
This document specifies the "Incremental" HTTP header field, which instructs HTTP intermediaries to forward the HTTP message
Recently published RFCs
This document specifies a transport for the client-server and symmetric modes of the Network Time Protocol (NTP) that encapsulates NTP messages in messages of the Precision Time Protocol (PTP). This transport enables hardware timestamping in network…
Recently published RFCs
A Point-to-Multipoint (P2MP) tree in a Segment Routing (SR) domain carries traffic from a Root to a set of Leaves. This document specifies extensions to BGP encodings and procedures for P2MP trees and Ingress Replication used in BGP/MPLS IP VPNs and…
Recently published RFCs
This document describes limitations of the existing range of dynamic IPv6 multicast addresses specified in "Allocation Guidelines for IPv6 Multicast Addresses" (RFC 3307). It updates RFC 3307 by replacing these allocations with a new IANA registry in…
Recently published RFCs
This document defines a new GeneralName.otherName for inclusion in the X.509 Subject Alternative Name (SAN) and Issuer Alternative Name (IAN) extensions to carry an IEEE Media Access Control (MAC) address. The new name form makes it possible to bind…
Recently published RFCs
This document provides guidelines and documents best current practice for operating authoritative DNS servers, recursive resolvers, and stub resolvers in a mixed IPv4/IPv6 environment. This document recommends that both authoritative DNS servers and…
Recently published RFCs
This document specifies a framework that enables enterprise telephony Session Initiation Protocol (SIP) networks to solicit and obtain a
Recently published RFCs
This document describes threats against cross-device flows along with practical mitigations, protocol selection guidance, and a summary of formal analysis results identified as relevant to the security of cross-device flows. It serves as a security…
Recently published RFCs
This document defines three hybrid key agreement mechanisms for TLS 1.3 – X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 – that combine the post-quantum ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism) with an ECDHE (Ephemeral…