[Openid-specs-risc] Complex Subject Identifiers format member

Tim Cappalli Tim.Cappalli at microsoft.com
Thu May 20 18:56:40 UTC 2021


Good catch Matt.

Could this be as simple as changing 11.1.2 to say "whose value is a Subject Identifier or Complex Subject as defined in section 3.2"?


11.1.2.  SSE Event Subject

   The subject of a SSE event is identified by the "subject" claim
   within the event payload, whose value is a Subject Identifier.  The
   "subject" claim is REQUIRED for all SSE events.  The JWT "sub" claim
   MUST NOT be present in any SET containing a SSE event.
________________________________
From: Openid-specs-risc <openid-specs-risc-bounces at lists.openid.net> on behalf of Matt Domsch via Openid-specs-risc <openid-specs-risc at lists.openid.net>
Sent: Tuesday, May 18, 2021 16:05
To: openid-specs-risc at lists.openid.net <openid-specs-risc at lists.openid.net>
Subject: [Openid-specs-risc] Complex Subject Identifiers format member


The topic of registries of values came up today, which reminded me…



Complex Subject Identifiers defined in SSE do not have a format member [1], though it’s required by Subject Identifiers [2].  I know we didn’t want to make a huge list of possible combinations of complex subject identifiers.

Would it suffice to add a format of “complex” to the SI spec, or assign another collision-resistant string here as SI expects (e.g. “format” : “net.openid.sse.siformat.complex”)?



Thanks,

Matt



[1] https://bitbucket.org/openid/risc/src/master/openid-sse-framework-1_0.txt<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fbitbucket.org%2Fopenid%2Frisc%2Fsrc%2Fmaster%2Fopenid-sse-framework-1_0.txt&data=04%7C01%7Ctim.cappalli%40microsoft.com%7C41c2d7d16e1c4c1c9ede08d91a3845d8%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637569668119917636%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=uU6fsFjQ2pfv%2Fy%2FnRfRrUcOVyeSpzxIQrQfQ%2FAwXbDE%3D&reserved=0>

[2] https://github.com/richanna/secevent/blob/master/draft-ietf-secevent-subject-identifiers.md<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Frichanna%2Fsecevent%2Fblob%2Fmaster%2Fdraft-ietf-secevent-subject-identifiers.md&data=04%7C01%7Ctim.cappalli%40microsoft.com%7C41c2d7d16e1c4c1c9ede08d91a3845d8%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637569668119917636%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=CAQo1pO09Gjyc0qSis07u8RV3nMd4UGCc2C%2F4%2BwrndU%3D&reserved=0>





Matt Domsch
VP, Engineering Fellow
matt.domsch at sailpoint.com<mailto:matt.domsch at sailpoint.com>

mobile: 512-981-6486
www.sailpoint.com<https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.sailpoint.com%2F&data=04%7C01%7Ctim.cappalli%40microsoft.com%7C41c2d7d16e1c4c1c9ede08d91a3845d8%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637569668119927591%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=M29hgPAdnSS7Hj4vVtBPzrfd4v%2FlU1jnxLdxgkE8nHo%3D&reserved=0>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20210520/56c01d0e/attachment.html>


More information about the Openid-specs-risc mailing list