[Openid-specs-risc] Complex Subject Identifiers format member

Matt Domsch matt.domsch at sailpoint.com
Thu May 20 19:45:27 UTC 2021


That's clean,  easily parseable, and avoids the whole registry problem.   Good idea.

Matt Domsch
VP, Engineering Fellow
matt.domsch at sailpoint.com<mailto:matt.domsch at sailpoint.com>
mobile: 512-981-6486
www.sailpoint.com<http://www.sailpoint.com/>


From: Tim Cappalli <Tim.Cappalli at microsoft.com>
Sent: Thursday, May 20, 2021 1:57 PM
To: openid-specs-risc at lists.openid.net; Matt Domsch <matt.domsch at sailpoint.com>
Subject: Re: Complex Subject Identifiers format member

Good catch Matt.

Could this be as simple as changing 11.1.2 to say "whose value is a Subject Identifier or Complex Subject as defined in section 3.2"?


11.1.2.  SSE Event Subject

   The subject of a SSE event is identified by the "subject" claim
   within the event payload, whose value is a Subject Identifier.  The
   "subject" claim is REQUIRED for all SSE events.  The JWT "sub" claim
   MUST NOT be present in any SET containing a SSE event.
________________________________
From: Openid-specs-risc <openid-specs-risc-bounces at lists.openid.net<mailto:openid-specs-risc-bounces at lists.openid.net>> on behalf of Matt Domsch via Openid-specs-risc <openid-specs-risc at lists.openid.net<mailto:openid-specs-risc at lists.openid.net>>
Sent: Tuesday, May 18, 2021 16:05
To: openid-specs-risc at lists.openid.net<mailto:openid-specs-risc at lists.openid.net> <openid-specs-risc at lists.openid.net<mailto:openid-specs-risc at lists.openid.net>>
Subject: [Openid-specs-risc] Complex Subject Identifiers format member


The topic of registries of values came up today, which reminded me...



Complex Subject Identifiers defined in SSE do not have a format member [1], though it's required by Subject Identifiers [2].  I know we didn't want to make a huge list of possible combinations of complex subject identifiers.

Would it suffice to add a format of "complex" to the SI spec, or assign another collision-resistant string here as SI expects (e.g. "format" : "net.openid.sse.siformat.complex")?



Thanks,

Matt



[1] https://bitbucket.org/openid/risc/src/master/openid-sse-framework-1_0.txt<https://urldefense.com/v3/__https:/nam06.safelinks.protection.outlook.com/?url=https*3A*2F*2Fbitbucket.org*2Fopenid*2Frisc*2Fsrc*2Fmaster*2Fopenid-sse-framework-1_0.txt&data=04*7C01*7Ctim.cappalli*40microsoft.com*7C41c2d7d16e1c4c1c9ede08d91a3845d8*7C72f988bf86f141af91ab2d7cd011db47*7C1*7C0*7C637569668119917636*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C1000&sdata=uU6fsFjQ2pfv*2Fy*2FnRfRrUcOVyeSpzxIQrQfQ*2FAwXbDE*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUl!!MsNKLpFGsw!ewbqcbA55x_yJeNIMvvKlWGq_YdRwhLiY-27VLgPhpW_aIWRedSk8nozin4ArGMlaes$>

[2] https://github.com/richanna/secevent/blob/master/draft-ietf-secevent-subject-identifiers.md<https://urldefense.com/v3/__https:/nam06.safelinks.protection.outlook.com/?url=https*3A*2F*2Fgithub.com*2Frichanna*2Fsecevent*2Fblob*2Fmaster*2Fdraft-ietf-secevent-subject-identifiers.md&data=04*7C01*7Ctim.cappalli*40microsoft.com*7C41c2d7d16e1c4c1c9ede08d91a3845d8*7C72f988bf86f141af91ab2d7cd011db47*7C1*7C0*7C637569668119917636*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C1000&sdata=CAQo1pO09Gjyc0qSis07u8RV3nMd4UGCc2C*2F4*2BwrndU*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSU!!MsNKLpFGsw!ewbqcbA55x_yJeNIMvvKlWGq_YdRwhLiY-27VLgPhpW_aIWRedSk8nozin4AAQpuElk$>





Matt Domsch
VP, Engineering Fellow
matt.domsch at sailpoint.com<mailto:matt.domsch at sailpoint.com>

mobile: 512-981-6486
www.sailpoint.com<https://urldefense.com/v3/__https:/nam06.safelinks.protection.outlook.com/?url=http*3A*2F*2Fwww.sailpoint.com*2F&data=04*7C01*7Ctim.cappalli*40microsoft.com*7C41c2d7d16e1c4c1c9ede08d91a3845d8*7C72f988bf86f141af91ab2d7cd011db47*7C1*7C0*7C637569668119927591*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C1000&sdata=M29hgPAdnSS7Hj4vVtBPzrfd4v*2FlU1jnxLdxgkE8nHo*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUl!!MsNKLpFGsw!ewbqcbA55x_yJeNIMvvKlWGq_YdRwhLiY-27VLgPhpW_aIWRedSk8nozin4AS9Kede4$>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20210520/63eed228/attachment-0001.html>


More information about the Openid-specs-risc mailing list