Security Event Token
RFC 8417, “Security Event Token”, is a Proposed Standard document published in July 2018 by P. Hunt, M. Jones, W. Denniss, M. Ansari. The canonical text is published by the RFC Editor.
Abstract
This specification defines the Security Event Token (SET) data structure. A SET describes statements of fact from the perspective of an issuer about a subject. These statements of fact represent an event that occurred directly to or about a security subject, for example, a statement about the issuance or revocation of a token on behalf of a subject. This specification is intended to enable representing security- and identity-related events. A SET is a JSON Web Token (JWT), which can be optionally signed and/or encrypted. SETs can be distributed via protocols such as HTTP.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8417 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8416 Simplified Local Internet Number Resource Management with the RPKI
- RFC 8418 Use of the Elliptic Curve Diffie-Hellman Key Agreement Algorithm with X25519 and X448 in the Cryptographic Message Syntax
- RFC 8415 Dynamic Host Configuration Protocol for IPv6
- RFC 8419 Use of Edwards-Curve Digital Signature Algorithm Signatures in the Cryptographic Message Syntax
- RFC 8414 OAuth 2.0 Authorization Server Metadata
- RFC 8420 Using the Edwards-Curve Digital Signature Algorithm in the Internet Key Exchange Protocol Version 2
- RFC 8413 Framework for Scheduled Use of Resources
- RFC 8421 Guidelines for Multihomed and IPv4/IPv6 Dual-Stack Interactive Connectivity Establishment