Committed to connecting the world

  •  

ITU-T work programme

Home : ITU-T Home : ITU-T Work Programme : X.2312     
  ITU-T A.5 justification information for referenced document IETF RFC 8705  in draft X.2312
1. Clear description of the referenced document:
Name: IETF RFC 8705
Title: RFC 8705: OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens, IETF, February 2020
2. Status of approval:
RFC 8705 was published as an IETF Proposed Standard in February 2020. Finalized IETF document.
3. Justification for the specific reference:
RFC 8705 defines Mutual TLS (MTLS) client authentication for OAuth 2.0 and certificate-bound (sender-constrained) access tokens. X.f2sp mandates MTLS as one of two required mechanisms for both sender-constraining (shall requirement, Section 7.3.2.1) and client authentication (shall requirement, Section 7.3.2.1 and 7.3.3.1). Section 7.2.2 also references RFC 8705 for mtls_endpoint_aliases discovery. Incorporation of the full text is inappropriate as MTLS is a protocol extension to TLS and OAuth 2.0. Freely available. No ITU-T or ISO/IEC equivalent.
4. Current information, if any, about IPR issues:
No known patent claims. IETF IPR database lists no relevant patents. Freely available.
5. Other useful information describing the "Quality" of the document:
Published February 2020. Widely implemented in financial-grade API deployments (Open Banking UK, Brazil Open Finance, Australia CDR, etc.). Freely available at https://www.rfc-editor.org/rfc/rfc8705.
6. The degree of stability or maturity of the document:
Stable, finalized IETF Proposed Standard. Not revised since February 2020.
7. Relationship with other existing or emerging documents:
One of the two sender-constraining mechanisms defined in X.f2sp (alongside RFC 9449/DPoP). Referenced by FAPI 1.0 and FAPI 2.0. No ITU-T/ISO/IEC equivalent.
8. Any explicit references within that referenced document should also be listed:
Normative references within RFC 8705: RFC 2119, RFC 5280, RFC 6125, RFC 6749, RFC 7519, RFC 7591, RFC 8174, RFC 8446. All IETF documents; IETF is qualified under Annex B.
9. Qualification of ISOC/IETF:
9.1-9.6     Decisions of ITU Council to admit ISOC to participate in the work of the Sector (June 1995 and June 1996).
9.7     The Internet Engineering Steering Group (IESG) is responsible for ongoing maintenance of the RFCs when the need arises. Comments on RFCs and corresponding changes are accommodated through the existing standardization process.
9.8     Each revision of a given RFC has a different RFC number, so no confusion is possible. All RFCs always remain available on-line. An index of RFCs and their status may be found in the IETF archives at http://www.rfc-editor.org/rfc.html.
10. Other (for any supplementary information):
Note: This form is based on Recommendation ITU-T A.5