|
1.
|
Clear description of the referenced document:
|
|
|
|
Name:
|
IETF RFC 8725
|
|
Title:
|
RFC 8725: JSON Web Token Best Current Practices, IETF, February 2020
|
|
|
2.
|
Status of approval:
|
|
|
RFC 8725 was published as an IETF Best Current Practice (BCP 225) in February 2020. Finalized IETF document.
|
|
3.
|
Justification for the specific reference:
|
|
|
RFC 8725 defines best current practices for secure implementation of JSON Web Tokens (JWTs). X.f2sp Section 7.3.4 contains a shall/should requirement: authorization servers "shall adhere to [RFC8725]" for JWT security practices. JWTs are used throughout the FAPI 2.0 Security Profile for access tokens, client assertions, and authorization server metadata. Incorporation of the full text is inappropriate as only the JWT security guidance is referenced. Freely available. No ITU-T or ISO/IEC equivalent.
|
|
4.
|
Current information, if any, about IPR issues:
|
|
|
No known patent claims. Freely available.
|
|
5.
|
Other useful information describing the "Quality" of the document:
|
|
|
Published February 2020 (BCP 225). Widely referenced in JWT-based security specifications and implementations. Freely available at https://www.rfc-editor.org/rfc/rfc8725.
|
|
6.
|
The degree of stability or maturity of the document:
|
|
|
Finalized IETF Best Current Practice (BCP 225). Stable since February 2020.
|
|
7.
|
Relationship with other existing or emerging documents:
|
|
|
Referenced alongside RFC 7519 (JWT) in OAuth 2.0 and OpenID Connect security profiles. No ITU-T/ISO/IEC equivalent.
|
|
8.
|
Any explicit references within that referenced document should also be listed:
|
|
|
Normative references within RFC 8725: RFC 2119, RFC 7515, RFC 7516, RFC 7518, RFC 7519, RFC 8174. All IETF documents; IETF is qualified under Annex B.
|
|
9.
|
Qualification of
ISOC/IETF:
|
|
|
9.1-9.6 Decisions of ITU Council to admit ISOC to participate in the work of the Sector (June 1995 and June 1996).
9.7 The Internet Engineering Steering Group (IESG) is responsible for ongoing maintenance of the RFCs when the need arises. Comments on RFCs and corresponding changes are accommodated through the existing standardization process.
9.8 Each revision of a given RFC has a different RFC number, so no confusion is possible. All RFCs always remain available on-line. An index of RFCs and their status may be found in the IETF archives at http://www.rfc-editor.org/rfc.html.
|
|
10.
|
Other (for any supplementary information):
|
|
|
|