Committed to connecting the world

  •  

ITU-T work programme

Home : ITU-T Home : ITU-T Work Programme : X.2312     
  ITU-T A.5 justification information for referenced document IETF RFC 7636 in draft X.2312
1. Clear description of the referenced document:
Name: IETF RFC 7636
Title: RFC 7636: Proof Key for Code Exchange by OAuth Public Clients, IETF, September 2015
2. Status of approval:
RFC 7636 was published as an IETF Proposed Standard in September 2015. Finalized IETF document.
3. Justification for the specific reference:
RFC 7636 defines PKCE (Proof Key for Code Exchange), a security extension to the OAuth 2.0 authorization code flow. X.f2sp mandates PKCE as a shall requirement for both authorization servers (Section 7.3.2.2: "shall require PKCE [RFC7636] with S256 as the code challenge method") and clients (Section 7.3.3.2: "shall use PKCE [RFC7636] with S256"). PKCE is one of the core security mechanisms of the FAPI 2.0 profile. Incorporation of the full text is inappropriate as PKCE is an extension mechanism to RFC 6749, not a standalone protocol. Freely available. No ITU-T or ISO/IEC equivalent
4. Current information, if any, about IPR issues:
No known patent claims. IETF IPR database lists no relevant patents. Freely available.
5. Other useful information describing the "Quality" of the document:
Published September 2015. Universally required in modern OAuth 2.0 deployments following major industry security guidance (OAuth Security BCP, FAPI). Implemented in all major authorization servers. Freely available at https://www.rfc-editor.org/rfc/rfc7636.
6. The degree of stability or maturity of the document:
Stable, finalized IETF Proposed Standard. Not revised since September 2015. Considered a mandatory security baseline for OAuth 2.0 code flows.
7. Relationship with other existing or emerging documents:
Widely referenced by OAuth 2.0 security profiles including FAPI 1.0 and FAPI 2.0. Also referenced in the OAuth 2.0 Security BCP (RFC 9700). No ITU-T/ISO/IEC equivalent.
8. Any explicit references within that referenced document should also be listed:
Normative references within RFC 7636: RFC 2119, RFC 3986, RFC 4648, RFC 6234, RFC 6749. All IETF documents; IETF is qualified under Annex B.
9. Qualification of ISOC/IETF:
9.1-9.6     Decisions of ITU Council to admit ISOC to participate in the work of the Sector (June 1995 and June 1996).
9.7     The Internet Engineering Steering Group (IESG) is responsible for ongoing maintenance of the RFCs when the need arises. Comments on RFCs and corresponding changes are accommodated through the existing standardization process.
9.8     Each revision of a given RFC has a different RFC number, so no confusion is possible. All RFCs always remain available on-line. An index of RFCs and their status may be found in the IETF archives at http://www.rfc-editor.org/rfc.html.
10. Other (for any supplementary information):
Note: This form is based on Recommendation ITU-T A.5