File tree 1 file changed +11
-9
lines changed
1 file changed +11
-9
lines changed Original file line number Diff line number Diff line change 40
40
</address >
41
41
</author >
42
42
43
- <date day =" 8 " month =" July" year =" 2024" />
43
+ <date day =" 22 " month =" July" year =" 2024" />
44
44
45
45
<area >Security</area >
46
46
<workgroup >OAuth Working Group</workgroup >
797
797
This allows the resource server to support clients that may or may not implement this specification,
798
798
and allows clients to choose their preferred authentication scheme.
799
799
</t >
800
- <t >
801
- A fair question is whether allowing clients to choose from among
802
- supported authentication methods represents an opportunity for a downgrade attack.
803
- Since resource servers will only enumerate authentication methods acceptable to them, by definition,
804
- any choice made by the client from among them is one that the resource server is OK with.
805
- Thus, the resource server allowing the use of different supported authentication methods
806
- does not represent an opportunity for a downgrade attack.
807
- </t >
808
800
</section >
809
801
810
802
</section >
1563
1555
<section anchor =" History" title =" Document History" >
1564
1556
<t >[[ to be removed by the RFC Editor before publication as an RFC ]]</t >
1565
1557
1558
+ <t >
1559
+ -07
1560
+ <list style =" symbols" >
1561
+ <t >
1562
+ Removed extraneous paragraph about downgrade attacks discussing
1563
+ an issue that's already addressed elsewhere in the specification.
1564
+ </t >
1565
+ </list >
1566
+ </t >
1567
+
1566
1568
<t >
1567
1569
-06
1568
1570
<list style =" symbols" >
You can’t perform that action at this time.
0 commit comments