<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Tue, Apr 11, 2017 at 11:14 AM, Phil Hunt <span dir="ltr"><<a href="mailto:phil.hunt@oracle.com" target="_blank" class="cremed">phil.hunt@oracle.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="word-wrap:break-word"><div><br></div><div>This seems to be a subset of the larger list that Adam has presented during the last few F2F meetings.</div><div><br></div><div>Are we talking about a set of MTI events?  Or just the first events to focus in on.</div></div></blockquote><div><br></div><div>First events to focus on. I don't think we can mandate any events, to me it is always up to the issuer.</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="word-wrap:break-word"><div><br></div><div>I think it would be worth while writing down definitions for all of them so we can understand the differences between events.</div><div><br></div><div>Phil</div><div><div><div style="color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div style="color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div style="color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div style="color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div style="color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div style="color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div style="color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div style="color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div style="color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div><span class="m_2539120173074416954Apple-style-span" style="border-collapse:separate;line-height:normal;border-spacing:0px"><div style="word-wrap:break-word"><div><div><div><br></div><div>Oracle Corporation, Identity Cloud Services Architect & Standards</div><div>@independentid</div><div><a href="http://www.independentid.com" target="_blank" class="cremed">www.independentid.com</a></div></div></div></div></span><a href="mailto:phil.hunt@oracle.com" target="_blank" class="cremed">phil.hunt@oracle.com</a></div><div><br></div></div><br class="m_2539120173074416954Apple-interchange-newline"></div><br class="m_2539120173074416954Apple-interchange-newline"></div><br class="m_2539120173074416954Apple-interchange-newline"></div><br class="m_2539120173074416954Apple-interchange-newline"></div><br class="m_2539120173074416954Apple-interchange-newline"></div><br class="m_2539120173074416954Apple-interchange-newline"></div><br class="m_2539120173074416954Apple-interchange-newline"></div><br class="m_2539120173074416954Apple-interchange-newline"></div><br class="m_2539120173074416954Apple-interchange-newline"><br class="m_2539120173074416954Apple-interchange-newline">
</div>
<br><div><blockquote type="cite"><div><div class="h5"><div>On Apr 11, 2017, at 11:02 AM, Mike Jones <<a href="mailto:Michael.Jones@microsoft.com" target="_blank" class="cremed">Michael.Jones@microsoft.com</a>> wrote:</div><br class="m_2539120173074416954Apple-interchange-newline"></div></div><div><div><div class="h5"><div class="m_2539120173074416954WordSection1" style="font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px"><div style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,32,96)">This is useful, Marius.  What are the arguments for each of these events?<u></u><u></u></span></div><div style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,32,96)"><u></u> <u></u></span></div><div style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><b><span style="font-size:11pt;font-family:Calibri,sans-serif">From:</span></b><span style="font-size:11pt;font-family:Calibri,sans-serif"><span class="m_2539120173074416954Apple-converted-space"> </span>Openid-specs-risc [<a href="mailto:openid-specs-risc-bounces@lists.openid.net" style="color:rgb(149,79,114);text-decoration:underline" target="_blank" class="cremed">mailto:openid-specs-risc-<wbr>bounces@lists.openid.net</a>]<span class="m_2539120173074416954Apple-converted-space"> </span><b>On Behalf Of<span class="m_2539120173074416954Apple-converted-space"> </span></b>Marius Scurtescu<br><b>Sent:</b><span class="m_2539120173074416954Apple-converted-space"> </span>Tuesday, April 11, 2017 10:50 AM<br><b>To:</b><span class="m_2539120173074416954Apple-converted-space"> </span><a href="mailto:openid-specs-risc@lists.openid.net" style="color:rgb(149,79,114);text-decoration:underline" target="_blank" class="cremed">openid-specs-risc@lists.<wbr>openid.net</a><br><b>Subject:</b><span class="m_2539120173074416954Apple-converted-space"> </span>[Openid-specs-risc] RISC events supported by Google<u></u><u></u></span></div><div style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><u></u> <u></u></div><div><div style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif">Right now Google supports the following events:<br>- sessions-revoked - it states the Google closed all existing sessions for given subject<br>- tokens-revoked - it states that Google revoked all tokens for given user and recipient (client), no individual token strings provided, applies only to tokens explicitly revoked by the user<br><br>In the near future Google is planning to support:<br>- account-deleted - the account was deleted, an RP should find an alternative way to authenticate the user, while they still have an active session (if Google was only IdP and no other recovery email then account is practically lost)<br>- account-locked - account locked because of possibility of hijacking<br>- account-recovered - user recovered previously locked account<br>- account-reverification-<wbr>requested - account not locked, but all sessions closed and user will be asked to change password on next login<br><br>Potentially in the mid future:<br>- account-identifier-changed - email address changes<br>- other token revocation events (revoked by client through API, revoked by Google for various reasons)<br>- log out events<br><br>Thoughts?<u></u><u></u></div><div><div style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><u></u> <u></u></div></div><div><div style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif">Which of these events do you think you would use and how?<u></u><u></u></div></div><div><div style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><u></u> <u></u></div></div><div><div style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif">What other events would you like to receive from Google (and RISC in general)?<br><br>Thanks,<br>Marius<u></u><u></u></div></div></div></div></div></div><span style="font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">______________________________<wbr>_________________</span><br style="font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px"><span style="font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">Openid-specs-risc mailing list</span><br style="font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px"><a href="mailto:Openid-specs-risc@lists.openid.net" style="color:rgb(149,79,114);text-decoration:underline;font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" target="_blank" class="cremed">Openid-specs-risc@lists.<wbr>openid.net</a><br style="font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px"><a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__lists.openid.net_mailman_listinfo_openid-2Dspecs-2Drisc&d=DwICAg&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=I457x4aQqCx7MBVL6ZjO_SlwfA4PpSO72h__VrpGxBA&s=YQvshO69_ITj0EEukIKbIHcSEKZUY9z-gG7kKzIx8eo&e=" style="color:rgb(149,79,114);text-decoration:underline;font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" target="_blank" class="cremed">https://urldefense.proofpoint.<wbr>com/v2/url?u=http-3A__lists.<wbr>openid.net_mailman_listinfo_<wbr>openid-2Dspecs-2Drisc&d=<wbr>DwICAg&c=<wbr>RoP1YumCXCgaWHvlZYR8PQcxBKCX5Y<wbr>TpkKY057SbK10&r=<wbr>JBm5biRrKugCH0FkITSeGJxPEivzjW<wbr>wlNKe4C_lLIGk&m=<wbr>I457x4aQqCx7MBVL6ZjO_<wbr>SlwfA4PpSO72h__VrpGxBA&s=<wbr>YQvshO69_<wbr>ITj0EEukIKbIHcSEKZUY9z-<wbr>gG7kKzIx8eo&e=</a><span style="font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important"><span class="m_2539120173074416954Apple-converted-space"> </span></span><br style="font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px"></div></blockquote></div><br></div></div></blockquote></div><br></div></div>