[Openid-specs-ab] Spec call notes 25-Jul-16

Mike Jones Michael.Jones at microsoft.com
Mon Jul 25 22:55:07 UTC 2016


Spec call notes 25-Jul-16

Nat Sakimura
Phil Hunt
Prateek Mishra
Mike Jones
Brian Campbell

Agenda
                Adoption of SCIM Profile specification
                Adoption of OpenID Connect Federation specification
                EAP Reminder
                Open Issues

Adoption of SCIM Profile specification
                http://openid.net/specs/openid-connect-scim-profile-1_0-00.html
                Reviewers should consider the following things...
                Whether UserInfo and SCIM can be used at the same time or whether it's either/or
                Should there be standardized scopes for SCIM or reuse the UserInfo scope values
                Whether SCIM access is determined at registration time or dynamically
                                The spec currently determines behaviors at client registration time
                Prateek asked whether we want standard terminology
                Phil said that we could define OAuth scopes for SCIM
                                Mike suggested that Phil define the scopes for now in the current draft
                There's not yet a mechanism for requesting the SCIM endpoint

Phil asked about encoding logic of OAuth 2.3.1 and then HTTP Basic
                Mike clarified that it's a two-encoding process
                Phil will send e-mail to the OAuth list about this

Adoption of OpenID Connect Federation specification
                http://openid.net/specs/openid-connect-federation-1_0-00.html
                Roland is working on a spec update
                Mike explained that this enables InCommon-like large federations

EAP Reminder
                Mike reminded people that two specs were submitted to the EAP working group for adoption
                                OpenID Connect Token Bound Authentication
                                                http://self-issued.info/docs/openid-connect-token-bound-authentication-1_0-00.html
                                OpenID Connect Extended Authentication Profile (EAP) ACR Values 1.0
                                                http://self-issued.info/docs/openid-connect-eap-acr-values-1_0-00.html
                People who are members of the EAP working group should have a look at them

Open Issues
                We discussed new issues #996 and #997

Next Call
                Our next call will be Thursday, August 4 at 7am Pacific Time
                See the calendar at http://openid.net/wg/connect/ to see the call times in your local time
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20160725/7864708d/attachment.html>


More information about the Openid-specs-ab mailing list