Last Call Review of draft-ietf-oauth-jwt-bcp-04
review-ietf-oauth-jwt-bcp-04-secdir-lc-perlman-2019-04-04-00

Request Review of draft-ietf-oauth-jwt-bcp
Requested rev. no specific revision (document currently at 06)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2019-04-08
Requested 2019-03-25
Draft last updated 2019-04-04
Completed reviews Secdir Last Call review of -04 by Radia Perlman (diff)
Genart Last Call review of -04 by Brian Carpenter (diff)
Genart Telechat review of -06 by Brian Carpenter
Assignment Reviewer Radia Perlman
State Completed
Review review-ietf-oauth-jwt-bcp-04-secdir-lc-perlman-2019-04-04
Reviewed rev. 04 (document currently at 06)
Review result Ready
Review completed: 2019-04-04

Review
review-ietf-oauth-jwt-bcp-04-secdir-lc-perlman-2019-04-04

Sorry...mistyped the recipients, so I'm resending

---------- Forwarded message ---------
From: Radia Perlman <radiaperlman@gmail.com>
Date: Sat, Mar 30, 2019 at 10:27 PM
Subject: Secdir review of draft-ietf-oauth-jwt-bcp-04
To: <draft-ietf-draft-sheffer-oauth-jwt-bcp.all@ietf.org>, iesg@ietf.org <
iesg@ietf.org>, secdir@ietf.org <secdir@ietf.org>


I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG. These
comments were written primarily for the benefit of the security area
directors. Document editors and WG chairs should treat these comments just
like any other last call comments.

The summary is READY

This document is a well-written and well-thought-through listing of best
practices for using JSON web tokens.  I could not find any of the advice
that I disagreed with, nor could I think of any more issues that the draft
could have addressed.


Radia