[Openid-specs-heart] UMA HEART profile(s) should provide identifying URI and other accoutrements

Eve Maler eve.maler at forgerock.com
Sat Nov 28 17:31:30 UTC 2015


The UMA Core spec provides advice
<https://docs.kantarainitiative.org/uma/draft-uma-core.html#profiles> on
documenting various pieces of information when writing third-party profiles
of UMA. We should follow that advice in our own profiles. For convenience,
here are the relevant items:

General to all types of profiles:

   - Specify a URI that uniquely identifies the profile.
   - Identify the responsible author and provide postal or electronic
   contact information.
   - Supply references to any previously defined profiles that the profile
   updates or obsoletes.
   - Define any additional or changed error states.
   - Specify any conformance and interoperability considerations.
   - Supply any additional security and privacy considerations.

For profiles of UMA:

   -

   Specify the set of interactions between endpoint entities involved in
   the profile, calling out any restrictions on ordinary UMA operations and
   any extension properties used in message formats.

For claim token format profiles (eventually):

   - Specify any related or additional error_details hints.
   - Specify any constraints on the claim token format vs. a standard
   definition for it in a specification.
   - Specify any mutual interpretation details of claim token formats by
   authorization servers and clients.


*Eve Maler*ForgeRock Office of the CTO | VP Innovation & Emerging Technology
Cell +1 425.345.6756 | Skype: xmlgrrl | Twitter: @xmlgrrl
Join our ForgeRock.org OpenUMA <http://forgerock.org/openuma/> community!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-heart/attachments/20151128/a1a55195/attachment.html>


More information about the Openid-specs-heart mailing list