CurrentEXPERIMENTALIETF stream

RFC 7486: HTTP Origin-Bound Authentication (HOBA)

In plain English — editorial summary, not part of the RFC

HTTP Origin-Bound Authentication (HOBA) is a digital-signature-based design for an HTTP authentication method. The design can also be used in JavaScript-based authentication embedded in HTML. HOBA is an alternative to HTTP authentication schemes that require passwords and therefore avoids all problems related to passwords, such as leakage of server-side password databases.

Document record

Document ID
RFC7486
Published
March 2015
Authors
S. Farrell; P. Hoffman; M. Thomas
Status
EXPERIMENTAL
Stream
IETF
Area
sec
Pages
28
Also known as

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/7486-http-origin-bound-authentication-hoba