Without specification,
software is incomplete.

The hardest part of the software task is arriving at a complete and consistent specification, and much of the essence of building a program is in fact the debugging of the specification.
— Fred Brooks

Legacy Drafts

Our specification work started out as Internet-Drafts according to the IETF workflow. We still follow many of their conventions, in order to ease eventual standardization there.

The more urgent aim is to publish reference sources, however. Documents in this section will eventually be updated into PIEs, or obsoleted.

CAProck Distributed Authorization Scheme
CAProck is a distributed authorization scheme based on cryptographic capabilities [I-D.draft-jfinkhaeuser-caps-for-distributed-auth]. This document describes the schemes additional constraints over the base document, and introduces a method for dealing with revocation of authorization. The result is a complete distributed authorization scheme.
Versions:
00