Skip to content

Commit 3b0b446

Browse files
authored
Merge pull request #22 from oauth-wg/ys-18
New section: changes from RFC 8725
2 parents c214a94 + dbd617f commit 3b0b446

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

draft-ietf-oauth-rfc8725bis.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -778,6 +778,20 @@ for their reviews.
778778

779779
--- back
780780

781+
# Changes from RFC 8725 {#changes-from-rfc8725}
782+
783+
This document obsoletes RFC 8725 and provides several significant improvements and additions:
784+
785+
1. Algorithm Verification: Added defensive checking to address incorrect reading of `alg` values as being case-insensitive ({{algorithm-verification}}).
786+
787+
2. Encryption-Signature Confusion: Added mitigation for attacks where verifiers don't distinguish between successful decryption and successful signature validation ({{preventing-confusion}}).
788+
789+
3. PBES2 Count Limits: Added requirements to reject unreasonably large `p2c` (PBES2 Count) values to prevent DoS attacks ({{limit-iterations}}).
790+
791+
4. JWT Format Confusion: Added mitigation for JWT serialization format confusion attacks ({{token-format}}).
792+
793+
5. Compression DoS: Added mitigation for DoS attacks resulting from abuse of compression in JWE ({{limit-decompression}}).
794+
781795
# Document History
782796

783797
[[Note to RFC Editor: please remove before publication.]]

0 commit comments

Comments
 (0)