<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><meta http-equiv="Content-Type" content="text/html charset=utf-8" class=""><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">3pm Monday before the Connect call is open.   <div class=""><br class=""></div><div class="">I can only join for 30min at 9:30 Tuesday because of another call I have at 10am.</div><div class=""><br class=""></div><div class="">John B.<br class=""><div class=""><blockquote type="cite" class=""><div class="">On Aug 4, 2017, at 12:51 PM, Marius Scurtescu <<a href="mailto:mscurtescu@google.com" class="">mscurtescu@google.com</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div dir="ltr" class="">Yes, we need a call. We have the regular call scheduled for Monday morning at 9:30 AM PST, but unfortunately I will be traveling at that time. Adam is on vacation next week.<div class=""><br class=""></div><div class="">Would it be OK to shift the Monday call either to Monday afternoon 3 pm, or Tuesday morning 9:30 am?</div></div><div class="gmail_extra"><br clear="all" class=""><div class=""><div class="gmail_signature" data-smartmail="gmail_signature">Marius</div></div>
<br class=""><div class="gmail_quote">On Thu, Aug 3, 2017 at 9:31 PM, Mike Jones <span dir="ltr" class=""><<a href="mailto:Michael.Jones@microsoft.com" target="_blank" class="">Michael.Jones@microsoft.com</a>></span> wrote:<br class=""><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="blue" vlink="purple" class="">
<div class="m_-8107292078757266690WordSection1"><p class="MsoNormal"><span style="color:#002060" class="">I agree that a call would be productive at this point.<u class=""></u><u class=""></u></span></p><p class="MsoNormal"><span style="color:#002060" class=""><u class=""></u> <u class=""></u></span></p><p class="MsoNormal"><span style="color:#002060" class="">                              <wbr class="">                         Best wishes,<u class=""></u><u class=""></u></span></p><p class="MsoNormal"><span style="color:#002060" class="">                              <wbr class="">                         -- Mike<u class=""></u><u class=""></u></span></p><p class="MsoNormal"><a name="m_-8107292078757266690__MailEndCompose" class=""><span style="color:#002060" class=""><u class=""></u> <u class=""></u></span></a></p>
<span class=""></span>
<div class="">
<div style="border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0in 0in 0in" class=""><p class="MsoNormal"><b class="">From:</b> Openid-specs-risc [mailto:<a href="mailto:openid-specs-risc-bounces@lists.openid.net" target="_blank" class="">openid-specs-risc-<wbr class="">bounces@lists.openid.net</a>]
<b class="">On Behalf Of </b>Phil Hunt (IDM)<br class="">
<b class="">Sent:</b> Thursday, August 3, 2017 7:19 PM<br class="">
<b class="">To:</b> Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank" class="">mscurtescu@google.com</a>><br class="">
<b class="">Cc:</b> <a href="mailto:openid-specs-risc@lists.openid.net" target="_blank" class="">openid-specs-risc@lists.<wbr class="">openid.net</a><span class=""><br class="">
<b class="">Subject:</b> Re: [Openid-specs-risc] issuer conflict<u class=""></u><u class=""></u></span></p>
</div>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class=""><p class="MsoNormal">I think we need to do a call and walk through the bootstrap cases for implicit federation vs explicit. <u class=""></u><u class=""></u></p>
</div><div class=""><div class="h5">
<div id="m_-8107292078757266690AppleMailSignature" class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div id="m_-8107292078757266690AppleMailSignature" class=""><p class="MsoNormal">Depending on how things start, how asserting parties know the user is very different. <br class="">
<br class="">
Phil<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal" style="margin-bottom:12.0pt"><br class="">
On Aug 3, 2017, at 6:59 PM, Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank" class="">mscurtescu@google.com</a>> wrote:<u class=""></u><u class=""></u></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class="">
<div class="">
<div class="">
<div class=""><p class="MsoNormal">On Thu, Aug 3, 2017 at 4:00 PM, John Bradley <<a href="mailto:ve7jtb@ve7jtb.com" target="_blank" class="">ve7jtb@ve7jtb.com</a>> wrote:<u class=""></u><u class=""></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class=""><p class="MsoNormal">I suggested an array if there are multiple values that want to be published for some reason.<u class=""></u><u class=""></u></p>
<div class=""><p class="MsoNormal">Otherwise you limit yourself to one scope for all the aliases.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Perhaps it is more of a SET issue than RISC but this all started with the proposition that sub might not be scoped to the issuer in cases where a RP is sending to a IdP. <u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">So when Facebook sends to Google it would not need to scope its own identifiers.   But if it is talking about a account that google has identified as having the email address
<a href="mailto:self-issued@hotmail.com" target="_blank" class="">self-issued@hotmail.com</a> then it would scope it.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">RISC events sent by Facebook to Google should always use an identifier scoped to Google. Assuming Facebook is an OAuth 2 client and Google the IdP. Facebook could know the Google issued sub or the email address associated with the account
 (which could be a non-Google managed email). Identifiers issued by Facebook are meaningless to Google. If Facebook is the IdP and Google the RP, then Facebook issued identifiers would work.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">If you are aware of a use case when the identifier needs to be explicitly scoped then let's add it to:<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__tools.ietf.org_html_draft-2Dscurtescu-2Dsecevent-2Drisc-2Duse-2Dcases&d=DwMFaQ&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=g-XR90LJbGJs22ZRyHyrQImdiSKuOUnSx-uMihcBj0E&s=OX-mKgdgZCEmFXFwEXGLt-kVgWVuGo1ALdObEvqys0U&e=" target="_blank" class="">https://tools.ietf.org/html/<wbr class="">draft-scurtescu-secevent-risc-<wbr class="">use-cases</a><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Currently we are not tracking any use case like that.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Email may not be the best example because we mistakenly believe that addresses uniquely point to one individual. <u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">They might but if it is not a email and just an account identifier then knowing who’s it is important.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Confusing of account identifiers and email addresses is a horse that has left the barn.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">If the subject were just account numbers that could easily collide then scoping has a clearer value.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">An IdP could use account identifiers, or numbers, but these would be expressed as the sub claim and sub is always scoped to the IdP issuer. No other scoping is needed IMO.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"> <u class=""></u><u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Phone numbers have similar issues.  They have a higher turn over and reuse than email.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">If the sub email phone etc is scoped to the issuer use the top level elements.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">In cases where it is different ave a alias object that makes the scoping explicit.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">I think email and phone is always global and does not need scoping. If not, then we need to clarify this.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">sub is scoped by iss.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"> <u class=""></u><u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">You might have both in a SET if the sender wants to expose its sub and also explicitly include a alias that the receiver understands like a phone number.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Yes, both can be present.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">I think we are saying the same thing.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Here is proposal 3 again:<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Top level claims when there is no iss conflict:<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">{</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "jti": "<wbr class="">3d0c3cf797584bd193bd0fb1bd4e7d<wbr class="">30",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "iat": 1458496025,</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "iss": "<a href="https://tr.example.com/" target="_blank" class="">https://tr.example.com</a>",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "aud": "<a href="https://rv.example.com/" target="_blank" class="">https://rv.example.com/</a>",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "sub": "47635747",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "email": "<a href="mailto:user@example.com" target="_blank" class="">user@example.com</a>",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "phone_number": "123-555-9876,</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "events": {</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">    "urn:ietf:params:risc:event:<wbr class="">sessions-revoked": {},</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">    "urn:ietf:params:risc:event:<wbr class="">tokens-revoked": {}</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  }</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">}</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">And nested object when there is an iss conflict:<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">{</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "jti": "<wbr class="">3d0c3cf797584bd193bd0fb1bd4e7d<wbr class="">30",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "iat": 1458496025,</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "iss": "<a href="https://tr.example.com/" target="_blank" class="">https://tr.example.com</a>",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "aud": "<a href="https://rv.example.com/" target="_blank" class="">https://rv.example.com/</a>",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "risc_subject": {</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">    "iss": "<a href="https://example.com/" target="_blank" class="">https://example.com</a>",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">    "sub": "47635747",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">    "email": "<a href="mailto:user@example.com" target="_blank" class="">user@example.com</a>",</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">    "phone_number": "123-555-9876,</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  },</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  "events": {</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">    "urn:ietf:params:risc:event:<wbr class="">sessions-revoked": {},</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">    "urn:ietf:params:risc:event:<wbr class="">tokens-revoked": {}</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">  }</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.5pt;font-family:"Courier New"" class="">}</span><span style="font-size:9.5pt" class=""><u class=""></u><u class=""></u></span></p>
</div>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">sub, email and phone_number form a set of claims that point to a person, at least one of these claims must be preset.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Sounds good?<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">John B.<u class=""></u><u class=""></u></p>
</div>
<div class="">
<div class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class=""><p class="MsoNormal">On Aug 3, 2017, at 6:23 PM, Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank" class="">mscurtescu@google.com</a>> wrote:<u class=""></u><u class=""></u></p>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<div class="">
<div class="">
<div class=""><p class="MsoNormal">On Thu, Aug 3, 2017 at 2:41 PM, John Bradley <<a href="mailto:ve7jtb@ve7jtb.com" target="_blank" class="">ve7jtb@ve7jtb.com</a>> wrote:<u class=""></u><u class=""></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class=""><p class="MsoNormal">Each alias might have a different issuer/scope.<u class=""></u><u class=""></u></p>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Maybe, but let's get concrete since I believe we have to define each alias. What else than iss+sub, email and phone_number?<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Email is also tricky, as foreign emails are often used as the username.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Right, and I think that's irrelevant in this case. If not, then why not?<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"> <u class=""></u><u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">That email address used as a name may or may not be validated.  <u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Good point, and again not sure how is this relevant to SET. The add/remove APIs most likely will have to also provide the "email_verified" claim along with "email", but that's a different draft.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"> <u class=""></u><u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">I still have a test Facebook account with a email as the login name that has never been validated after nearly two years. <u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Right, it is a common case. Also, if the email was validated 8 years ago, what value does that validation still have?<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"> <u class=""></u><u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">So is talking about “<a href="mailto:self-issued@hotmail,.com" target="_blank" class="">self-issued@hotmail,.com</a>” scope Facebook the same as
<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__sef-2Dissued.com_&d=DwMFaQ&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=g-XR90LJbGJs22ZRyHyrQImdiSKuOUnSx-uMihcBj0E&s=dtZNC7Ug_OjhPH2dXU2AD0ubqcbveLV8e91TJqDzyRM&e=" target="_blank" class="">
sef-issued.com</a> scope google vs scope Microsoft the same or different?<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Are some usernames with issuers and only the MS scoped one a real email?<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">In general you have a identifier string of some sort scoped to a responsible authority.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">I don’t really care if you want to have <u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">{“val”: “<a href="mailto:self-issued@hotmail,.com" target="_blank" class="">self-issued@hotmail,.com</a>”,  “scope”: “Facebook” , “type”: “email”}<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Or create specific claims that combine type and val.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Not sure I completely follow. What does "scope Facebook" mean with regards to  <a href="mailto:self-issued@hotmail,.com" target="_blank" class="">self-issued@hotmail,.com</a>? Microsoft is authoritative over that email address, and how does one discover that is
 a different question.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">If Google is sending a RISC event to Facebook and the subject is "<a href="mailto:email=self-issued@hotmail,.com" target="_blank" class="">email=self-issued@hotmail,.<wbr class="">com</a>" then scope=Facebook I think is implied (the fact that Facebook knows the user as <a href="mailto:self-issued@hotmail,.com" target="_blank" class="">self-issued@hotmail,.com</a>).
 How would an explicit scope help here? Do you have a use case in mind?<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">I suspect that having it be a object will allow for cleanly adding other meta-data later.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">I think everyone agrees it should be an object. You suggested that the value could be an array, I am not sure I understand the need for that.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"> <u class=""></u><u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">I do think that it is a new claim separate from the existing sub, and needs the context of who is the responsible authority for the identifier or it will get very messy.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Right, but I think who is responsible for the identifier (scope?) is clear by the context (transmitter and receiver).<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"> <u class=""></u><u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">John B.<u class=""></u><u class=""></u></p>
</div>
<div class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class=""><p class="MsoNormal">On Aug 3, 2017, at 4:36 PM, Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank" class="">mscurtescu@google.com</a>> wrote:<u class=""></u><u class=""></u></p>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<div class="">
<div class="">
<div class=""><p class="MsoNormal">On Thu, Aug 3, 2017 at 12:02 PM, John Bradley <<a href="mailto:ve7jtb@ve7jtb.com" target="_blank" class="">ve7jtb@ve7jtb.com</a>> wrote:<u class=""></u><u class=""></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class=""><p class="MsoNormal">Alias or aka <u class=""></u><u class=""></u></p>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">I am issuer foo and the subject is bar in my context.   I also know them as “<a href="mailto:self-issued@hotmail.com" target="_blank" class="">self-issued@hotmail.com</a>” in the context of Facebook and
<span class="m_-8107292078757266690gc-cs-link">+15555551235</span> in the context of phone number.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">That leaves the current definitions of sub and its unchanged.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">All the different ways the identity can be referred to must be defined by the profile. Right?<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">For the RISC profile I had in mind:<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">- iss+sub<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">- email<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">- phone_number<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Obviously this is inspired by OpenID Connect, the same claims can be present in an Id Token.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">If the above makes sense, then not sure if an array is needed.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">John B.<u class=""></u><u class=""></u></p>
</div>
<div class="">
<div class="">
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class=""><p class="MsoNormal">On Aug 3, 2017, at 2:57 PM, Phil Hunt (IDM) <<a href="mailto:phil.hunt@oracle.com" target="_blank" class="">phil.hunt@oracle.com</a>> wrote:<u class=""></u><u class=""></u></p>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<div class="">
<div class=""><p class="MsoNormal">Agreed. <br class="">
<br class="">
Phil<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal" style="margin-bottom:12.0pt"><br class="">
On Aug 3, 2017, at 11:56 AM, John Bradley <<a href="mailto:ve7jtb@ve7jtb.com" target="_blank" class="">ve7jtb@ve7jtb.com</a>> wrote:<u class=""></u><u class=""></u></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class=""><p class="MsoNormal">Identity or whatever it is called may actually want to be an array, as there might be multiple synonyms.<u class=""></u><u class=""></u></p>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">That is why I was thinking of it more as an alias of sub + iss.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class="">
<div class="">
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class=""><p class="MsoNormal">On Aug 3, 2017, at 1:49 PM, Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank" class="">mscurtescu@google.com</a>> wrote:<u class=""></u><u class=""></u></p>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<div class="">
<div class="">
<div class=""><p class="MsoNormal">On Thu, Aug 3, 2017 at 10:39 AM, Phil Hunt <<a href="mailto:phil.hunt@oracle.com" target="_blank" class="">phil.hunt@oracle.com</a>> wrote:<u class=""></u><u class=""></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class=""><p class="MsoNormal">yes.  Instead of using “sub”  you might define an attribute “identity” and it could be used as follows:<u class=""></u><u class=""></u></p>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">“identity”:{<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “typ”:”oidc”,<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “sub”:”<wbr class="">8100552e17554422b6207b7bd7a9bc<wbr class="">76”,<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “iss”:”<a href="http://myidp.example.com/" target="_blank" class="">myidp.example.com</a>"<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">}<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Or:<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">“identity”:{<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “typ”:”scim”,<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “$ref”:”<a href="https://scim.example.com/Users/8100552e17554422b6207b7bd7a9bc76" target="_blank" class="">https://scim.example.<wbr class="">com/Users/<wbr class="">8100552e17554422b6207b7bd7a9bc<wbr class="">76</a>”<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">}<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Or<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">(not sure these are the right claims, but you might include some claims from MODRNA like carrier identifiers if they are available)<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">“identity”:{<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “typ”:”phone”,<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “telephoneNumber”:”+<wbr class="">16041234567”<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “carrier”: <somevalue>  <u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">}<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">“identity”:{<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “typ”:”emails”,<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">  “mail”:”<a href="mailto:john.doe@example.com" target="_blank" class="">john.doe@example.com</a>”<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">}<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Note “identity” could be used at the top level or embedded in events payload.  Top level if there is need to have multiple event types are expressed at once.  Or, if part of the core spec to provide a consistent pattern for identifiers
 and to establish a registry of identifier types.  Regardless at the top level, then “identity” would have to be registered as a JWT claim.<u class=""></u><u class=""></u></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">This is a separate discussion we should have, I was proposing something different here, but I was trying to focus on the issuer conflict first.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">That being said, I don't see why a typ claim is needed here. We can use the exact same claims as in an Id Token. SCIM needs a different profile than RISC.<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Your examples from above using Id Token claims (minus the SCIM example):<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">“identity”:{</span><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">  “sub”:”<wbr class="">8100552e17554422b6207b7bd7a9bc<wbr class="">76”,</span><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">  “iss”:”<a href="http://myidp.example.com/" target="_blank" class="">myidp.example.com</a>"</span><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">}</span><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">“identity”:{</span><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">  “phone_number”:”+16041234567”</span><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">}</span><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">“identity”:{</span><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">  “email”:”<a href="mailto:john.doe@example.com" target="_blank" class="">john.doe@example.com</a>”</span><u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-family:"Courier New"" class="">}</span><u class=""></u><u class=""></u></p>
</div>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-"><u class=""></u> <u class=""></u></span></p>
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class="">
<div class=""><p class="MsoNormal">Phil<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">Oracle Corporation, Identity Cloud Services Architect & Standards<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal">@independentid<u class=""></u><u class=""></u></p>
</div>
<div class=""><p class="MsoNormal"><a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__www.independentid.com_&d=DwMFaQ&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=g-XR90LJbGJs22ZRyHyrQImdiSKuOUnSx-uMihcBj0E&s=EvUUqTsPqYyUuG705IQ1fE0g8wpPX5VG6xbOnpVHvsQ&e=" target="_blank" class="">www.independentid.com</a><u class=""></u><u class=""></u></p>
</div>
</div>
</div>
</div><p class="MsoNormal"><a href="mailto:phil.hunt@oracle.com" target="_blank" class="">phil.hunt@oracle.com</a><u class=""></u><u class=""></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<div class="">
<div class="">
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class=""><p class="MsoNormal">On Aug 3, 2017, at 10:28 AM, Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank" class="">mscurtescu@google.com</a>> wrote:<u class=""></u><u class=""></u></p>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<div class="">
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">On Thu, Aug 3, 2017 at 9:42 AM, John Bradley<span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span><<a href="mailto:ve7jtb@ve7jtb.com" target="_blank" class="">ve7jtb@ve7jtb.com</a>><span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>wr<wbr class="">ote:<u class=""></u><u class=""></u></span></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">I guess in principal sub could be a dictionary with a val and other meta data like a optional issuer.<u class=""></u><u class=""></u></span></p>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">We do that with sub in <a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__openid.net_specs_openid-2Dconnect-2Dcore-2D1-5F0.html-23IndividualClaimsRequests&d=DwMFaQ&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=0XvWuopUa1rUzdTHlWsUVZI7PePtDaGu3VrMUlwE2yU&s=VzfByRviJEJHNZfefEzIWK8KsuPhKsf_RXi6eOTxbeI&e=" target="_blank" class="">Connect
 claims requests</a>.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">However in responses sub is defined in <u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__tools.ietf.org_html_rfc7519-23section-2D4.1.2&d=DwMFaQ&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=0XvWuopUa1rUzdTHlWsUVZI7PePtDaGu3VrMUlwE2yU&s=5GZBJpUnQsgSTinzQRg5GLOPDs6YuqtEr_PEMy9JsMQ&e=" target="_blank" class="">https://tools.ietf.org/html/<wbr class="">rfc7519#section-4.1.2</a> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>as
 a string.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">One option might be to have a new claim.  sub-d that is a dictionary that you could use when you need a more complicated sub with a SubjectNameIdFormat and scope.   How could
 that go wrong:)<u class=""></u><u class=""></u></span></p>
</div>
</div>
</blockquote>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">That is option 3, right?<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""> <u class=""></u><u class=""></u></span></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">John B.<u class=""></u><u class=""></u></span></p>
</div>
<div class="">
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""> <u class=""></u><u class=""></u></span></p>
<div class="">
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">On Aug 3, 2017, at 12:19 PM, Phil Hunt (IDM) <<a href="mailto:phil.hunt@oracle.com" target="_blank" class="">phil.hunt@oracle.com</a>> wrote:<u class=""></u><u class=""></u></span></p>
</div><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
<div class="">
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">Lets not forget that we also have cases where subject is identified by email or telephone or other identifier (implicit fed cases). <u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">Risc needs to have a subject type attribute to inform parsers how to identify the subject. The next question whether sub gets re-used as a general purpose attribute or whether
 specific attributes are used for each type (email, telephone). <br class="">
<br class="">
In solving this broader requirement the sub/iss problem may also be resolved. <u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><br class="">
Phil<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><br class="">
On Aug 3, 2017, at 1:52 AM, Nat Sakimura <<a href="mailto:sakimura@gmail.com" target="_blank" class="">sakimura@gmail.com</a>> wrote:<u class=""></u><u class=""></u></span></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class=""><p class=""><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">My preference: If all SET only supports a single iss/sub pair, then 1. If a SET can have events for multiple iss/sub pair, then 2.<span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span><u class=""></u><u class=""></u></span></p><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">2017</span><span style="font-size:9.0pt;font-family:"MS Gothic"" class="">年</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">8</span><span style="font-size:9.0pt;font-family:"MS Gothic"" class="">月</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">3</span><span style="font-size:9.0pt;font-family:"MS Gothic"" class="">日</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">(</span><span style="font-size:9.0pt;font-family:"MS Gothic"" class="">木</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">)
 7:49 Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank" class="">mscurtescu@google.com</a>>:<u class=""></u><u class=""></u></span></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">Each SET profile must define or clarify several aspects of the specs. For RISC most of these must only be only specified (like key resolution), but there is at least one issue
 for which we don't have an agreed on solution.<u class=""></u><u class=""></u></span></p>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">In some use cases the issuer of the SET is different from the issuer of the subject identifier, and at least in those cases there cannot be only one top level "iss" claim.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">Here are the proposals I am aware of to solve this issue:<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">1. Move iss+sub to the event level. The drawback of this approach is redundancy when multiple events are present in the SET.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">{</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"jti": "<wbr class="">3d0c3cf797584bd193bd0fb1bd4e7d<wbr class="">30",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iat": 1458496025,</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://tr.example.com/" target="_blank" class="">https://tr.example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"aud": "<a href="https://rv.example.com/" target="_blank" class="">https://rv.example.com/</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"events": {</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">sessions-revoked":</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>{</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">     <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://example.com/" target="_blank" class="">https://example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">     <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"sub": "47635747",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>},</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">tokens-revoked":</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>{</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">     <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://example.com/" target="_blank" class="">https://example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">     <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"sub": "47635747",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">1.1 Move only the subject "iss" to the event level and leave "sub" at the top level (next to the SET "iss"). I find this solution very confusing.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">{</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"jti": "<wbr class="">3d0c3cf797584bd193bd0fb1bd4e7d<wbr class="">30",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iat": 1458496025,</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://tr.example.com/" target="_blank" class="">https://tr.example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"sub": "47635747",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"aud": "<a href="https://rv.example.com/" target="_blank" class="">https://rv.example.com/</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"events": {</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">sessions-revoked":</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>{</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">     <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://example.com/" target="_blank" class="">https://example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>},</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">tokens-revoked":</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>{</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">     <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://example.com/" target="_blank" class="">https://example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">2. Move iss+sub immediately under the "events" claim. No redundancy in this case.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">{</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"jti": "<wbr class="">3d0c3cf797584bd193bd0fb1bd4e7d<wbr class="">30",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iat": 1458496025,</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://tr.example.com/" target="_blank" class="">https://tr.example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"aud": "<a href="https://rv.example.com/" target="_blank" class="">https://rv.example.com/</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"events": {</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://example.com/" target="_blank" class="">https://example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"sub": "47635747",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">sessions-revoked": {},</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">tokens-revoked": {}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">3. Move iss+sub to a new nested claim.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">{</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"jti": "<wbr class="">3d0c3cf797584bd193bd0fb1bd4e7d<wbr class="">30",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iat": 1458496025,</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://tr.example.com/" target="_blank" class="">https://tr.example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"aud": "<a href="https://rv.example.com/" target="_blank" class="">https://rv.example.com/</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"target": {</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://example.com/" target="_blank" class="">https://example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"sub": "47635747",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>},</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"events": {</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">sessions-revoked": {},</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">tokens-revoked": {}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">4. Define a new top level issuer claim either for the SET or for the subject.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">{</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"jti": "<wbr class="">3d0c3cf797584bd193bd0fb1bd4e7d<wbr class="">30",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iat": 1458496025,</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss": "<a href="https://tr.example.com/" target="_blank" class="">https://tr.example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"iss-sub": "<a href="https://example.com/" target="_blank" class="">https://example.com</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"sub": "47635747",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"aud": "<a href="https://rv.example.com/" target="_blank" class="">https://rv.example.com/</a>",</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"events": {</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">sessions-revoked": {},</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">   <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>"urn:ietf:params:risc:event:<wbr class="">tokens-revoked": {}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class=""> <span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span>}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Courier New"" class="">}</span><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u><u class=""></u></span></p>
</div>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">An open question is if this new iss+sub solution should be always required or if a top level iss+sub should also be allowed (when there is no conflict). I vote for having
 only one way for simplicity.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">Once we decide on a solution we can start working on the RISC profile draft.<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">Thoughts?<u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">Marius<u class=""></u><u class=""></u></span></p>
</div>
</div>
</div><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">______________________________<wbr class="">_________________<br class="">
Openid-specs-risc mailing list<br class="">
<a href="mailto:Openid-specs-risc@lists.openid.net" target="_blank" class="">Openid-specs-risc@lists.<wbr class="">openid.net</a><br class="">
<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__lists.openid.net_mailman_listinfo_openid-2Dspecs-2Drisc&d=DwMFaQ&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=oELWrk4I8hITS0xtNBEzkxMNmGjdHfFGkwNTJluxMQM&s=WH0oHORcbz6GzolvV9301ap4nCL-qYRmD7wWIWPJnL8&e=" target="_blank" class="">http://lists.openid.net/<wbr class="">mailman/listinfo/openid-specs-<wbr class="">risc</a><u class=""></u><u class=""></u></span></p>
</blockquote>
</div>
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">--<span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span><u class=""></u><u class=""></u></span></p>
</div>
<div class=""><p class=""><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">Nat Sakimura<u class=""></u><u class=""></u></span></p><p class=""><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">Chairman of the Board, OpenID Foundation<u class=""></u><u class=""></u></span></p>
</div>
</div>
</blockquote>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt" class="">
<div class=""><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">______________________________<wbr class="">_________________<br class="">
Openid-specs-risc mailing list<br class="">
<a href="mailto:Openid-specs-risc@lists.openid.net" target="_blank" class="">Openid-specs-risc@lists.<wbr class="">openid.net</a><br class="">
<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__lists.openid.net_mailman_listinfo_openid-2Dspecs-2Drisc&d=DwICAg&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=oELWrk4I8hITS0xtNBEzkxMNmGjdHfFGkwNTJluxMQM&s=WH0oHORcbz6GzolvV9301ap4nCL-qYRmD7wWIWPJnL8&e=" target="_blank" class="">https://urldefense.proofpoint.<wbr class="">com/v2/url?u=http-3A__lists.<wbr class="">openid.net_mailman_listinfo_<wbr class="">openid-2Dspecs-2Drisc&d=<wbr class="">DwICAg&c=<wbr class="">RoP1YumCXCgaWHvlZYR8PQcxBKCX5Y<wbr class="">TpkKY057SbK10&r=<wbr class="">JBm5biRrKugCH0FkITSeGJxPEivzjW<wbr class="">wlNKe4C_lLIGk&m=<wbr class="">oELWrk4I8hITS0xtNBEzkxMNmGjdHf<wbr class="">FGkwNTJluxMQM&s=<wbr class="">WH0oHORcbz6GzolvV9301ap4nCL-<wbr class="">qYRmD7wWIWPJnL8&e=</a><span class="m_-8107292078757266690gmail-m211135882081915750gmail-m-5154919286245319102m922368068620098186gmail-m-2518339591068322597apple-converted-space"> </span><u class=""></u><u class=""></u></span></p>
</div>
</blockquote>
</div><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class="">______________________________<wbr class="">_________________<br class="">
Openid-specs-risc mailing list<br class="">
<a href="mailto:Openid-specs-risc@lists.openid.net" target="_blank" class="">Openid-specs-risc@lists.<wbr class="">openid.net</a><br class="">
<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__lists.openid.net_mailman_listinfo_openid-2Dspecs-2Drisc&d=DwMFaQ&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=0XvWuopUa1rUzdTHlWsUVZI7PePtDaGu3VrMUlwE2yU&s=EIvVFfL8djzqG2zMxSY4EPjMuBglQoE0xKzdgiOiOK8&e=" target="_blank" class="">http://lists.openid.net/<wbr class="">mailman/listinfo/openid-specs-<wbr class="">risc</a><u class=""></u><u class=""></u></span></p>
</div>
</blockquote>
</div><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><u class=""></u> <u class=""></u></span></p>
</div>
</div>
</div>
</div><p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Helvetica",sans-serif" class=""><br class="">
______________________________<wbr class="">_________________<br class="">
Openid-specs-risc mailing list<br class="">
<a href="mailto:Openid-specs-risc@lists.openid.net" target="_blank" class="">Openid-specs-risc@lists.<wbr class="">openid.net</a><br class="">
<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__lists.openid.net_mailman_listinfo_openid-2Dspecs-2Drisc&d=DwMFaQ&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=0XvWuopUa1rUzdTHlWsUVZI7PePtDaGu3VrMUlwE2yU&s=EIvVFfL8djzqG2zMxSY4EPjMuBglQoE0xKzdgiOiOK8&e=" target="_blank" class="">http://lists.openid.net/<wbr class="">mailman/listinfo/openid-specs-<wbr class="">risc</a><u class=""></u><u class=""></u></span></p>
</blockquote>
</div>
</div>
</div>
</div>
</blockquote>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
</div>
</div>
</div>
</blockquote>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
</div>
</div>
</blockquote>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
</div>
</blockquote>
</div>
</div>
</blockquote>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
</div>
</div>
</div>
</blockquote>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
</div>
</div>
</blockquote>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
</div>
</div>
</div>
</blockquote>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
</div>
</div>
</blockquote>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
</div>
</div>
</div>
</blockquote>
</div></div></div>
</div>

</blockquote></div><br class=""></div>
_______________________________________________<br class="">Openid-specs-risc mailing list<br class=""><a href="mailto:Openid-specs-risc@lists.openid.net" class="">Openid-specs-risc@lists.openid.net</a><br class=""><a href="http://lists.openid.net/mailman/listinfo/openid-specs-risc" class="">http://lists.openid.net/mailman/listinfo/openid-specs-risc</a><br class=""></div></blockquote></div><br class=""></div></div></body></html>