<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.lodderstedt-oauth-security-topics" target="https://datatracker.ietf.org/doc/html/draft-lodderstedt-oauth-security-topics-00">
   <front>
      <title>OAuth Security Topics</title>
      <author initials="T." surname="Lodderstedt" fullname="Torsten Lodderstedt">
         <organization>Deutsche Telekom AG</organization>
      </author>
      <author initials="J." surname="Bradley" fullname="John Bradley">
         <organization>Ping Identity</organization>
      </author>
      <author initials="A." surname="Labunets" fullname="Andrey Labunets">
         <organization>Facebook</organization>
      </author>
      <date month="November" day="13" year="2016" />
      <abstract>
	 <t>   This draft gives a comprehensive overview on open OAuth security
   topics.  It is intended to serve as a tool for the OAuth working
   group to systematically address these open security topics,
   recommending mitigations, and potentially also defining OAuth
   extensions needed to cope with the respective security threats.  This
   draft will potentially become a BCP over time.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-lodderstedt-oauth-security-topics-00" />
   
</reference>
