<div dir="ltr">Shouldn't "risc" (the profile name) be part of the URI?<div><br></div><div>Can you point to some of these other specifications and URIs?</div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature">Marius</div></div>
<br><div class="gmail_quote">On Wed, Apr 12, 2017 at 1:25 PM, Mike Jones <span dir="ltr"><<a href="mailto:Michael.Jones@microsoft.com" target="_blank">Michael.Jones@microsoft.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="blue" vlink="purple">
<div class="m_5364652117048815074WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#002060">I’d suggest that RISC event names be <a href="http://openid.net" target="_blank">openid.net</a> URIs.  For instance, I’d use the event name
</span><span style="font-size:11.0pt;font-family:"Courier New";color:#002060"><a href="http://schemas.openid.net/event/account-deleted" target="_blank">http://schemas.openid.net/<wbr>event/account-deleted</a></span><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#002060"> for the Account Deleted event that Marius described. 
 That would be consistent with how other things have been historically named in OpenID specifications.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#002060"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#002060">                              <wbr>                              <wbr>    -- Mike<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#002060"><u></u> <u></u></span></p>
<div>
<div style="border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> Openid-specs-risc [mailto:<a href="mailto:openid-specs-risc-bounces@lists.openid.net" target="_blank">openid-specs-risc-<wbr>bounces@lists.openid.net</a>]
<b>On Behalf Of </b>Phil Hunt (IDM)<br>
<b>Sent:</b> Tuesday, April 11, 2017 3:00 PM<br>
<b>To:</b> Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank">mscurtescu@google.com</a>><br>
<b>Cc:</b> <a href="mailto:openid-specs-risc@lists.openid.net" target="_blank">openid-specs-risc@lists.<wbr>openid.net</a><br>
<b>Subject:</b> Re: [Openid-specs-risc] RISC event URIs<u></u><u></u></span></p>
</div>
</div><div><div class="h5">
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">That said. It is perfectly ok for risc to use urns while the core spec specified uri. <u></u><u></u></p>
</div>
<div id="m_5364652117048815074AppleMailSignature">
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div id="m_5364652117048815074AppleMailSignature">
<p class="MsoNormal">There would just be no central event registry except within risc. <br>
<br>
Phil<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
On Apr 11, 2017, at 2:37 PM, Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank">mscurtescu@google.com</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class="MsoNormal">Good point, will start the discussion on the secevent list.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><br clear="all">
<u></u><u></u></p>
<div>
<div>
<p class="MsoNormal">Marius<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">On Tue, Apr 11, 2017 at 2:34 PM, Hardt, Dick <<a href="mailto:dick@amazon.com" target="_blank">dick@amazon.com</a>> wrote:<u></u><u></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">I think the format of these should be decided in secevent.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">I think your proposal of secevents starting with “urn:ietf:params:secevent:<wbr>event-type:” is one worth proposing in
 secevent.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">"urn:ietf:params:secevent:aud-<wbr>client-id:<client-id>" is clearly a secevent discussion item</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#888888"> </span><span style="color:#888888"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#888888">/Dick</span><span style="color:#888888"><u></u><u></u></span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> </span><u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in">
On 4/11/17, 2:16 PM, someone claiming to be "Marius Scurtescu" <<a href="mailto:mscurtescu@google.com" target="_blank">mscurtescu@google.com</a>> wrote:<u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">
 <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">
"urn:ietf:params:secevent:<wbr>event-type:risc:sessions-<wbr>revoked" would be an event URI, the key under the "events" claim
<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-left:.5in">
 <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">
"urn:ietf:params:secevent:aud-<wbr>client-id:<client-id>" would be the aud claim, and this solves the "SET re-played as an access token" issue<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">
 <u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-left:.5in">
<br clear="all">
<u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in">
Marius<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in">
 <u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-left:.5in">
On Tue, Apr 11, 2017 at 2:07 PM, Hardt, Dick <<a href="mailto:dick@amazon.com" target="_blank">dick@amazon.com</a>> wrote:<u></u><u></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt">
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in">
<span style="font-size:11.0pt;font-family:"Calibri",sans-serif">Where are you thinking this is in the secevent SET Marius?</span><u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in">
<span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> </span><u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
On 4/11/17, 10:56 AM, someone claiming to be "Openid-specs-risc on behalf of Marius Scurtescu" <<a href="mailto:openid-specs-risc-bounces@lists.openid.net" target="_blank">openid-specs-risc-bounces@<wbr>lists.openid.net</a> on behalf of
<a href="mailto:mscurtescu@google.com" target="_blank">mscurtescu@google.com</a>> wrote:<u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
 <u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
While talking about events, we should also decide how the event URI will look like for RISC.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
 <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
I propose we use URN sub-delegation for "ietf" namespace (RFC 3553), something like:<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
urn:ietf:params:secevent:<wbr>event-type:risc:sessions-<wbr>revoked<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
urn:ietf:params:secevent:<wbr>event-type:risc:tokens-revoked<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
urn:ietf:params:secevent:<wbr>event-type:risc:account-<wbr>deleted<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
urn:ietf:params:secevent:<wbr>event-type:risc:all ?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
 <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
Maybe instead of "event-type" in the above URNs we should use "profile"? Since "risc" above signifies a whole class of event type and not a particular one:<u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
urn:ietf:params:secevent:<wbr>profile:risc:sessions-revoked<u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
...<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
 <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
We can use this scheme for other RISC related URNs, like a prefixed aud:<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
urn:ietf:params:secevent:aud-<wbr>client-id:<client-id><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
 <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
Thoughts?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
 <u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:1.0in">
Marius<u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
<p class="MsoNormal" style="margin-left:.5in">
 <u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</blockquote>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class="MsoNormal">______________________________<wbr>_________________<br>
Openid-specs-risc mailing list<br>
<a href="mailto:Openid-specs-risc@lists.openid.net" target="_blank">Openid-specs-risc@lists.<wbr>openid.net</a><br>
<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__lists.openid.net_mailman_listinfo_openid-2Dspecs-2Drisc&d=DwICAg&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=xWx68AhS5M_By2Kzn2sWKxgaTcobfi-OdzG-BY75oQ0&s=GlmLO4LTDZglq1yIkAKmtEZG9Fwx_e5fxSEQGspbwAo&e=" target="_blank">https://urldefense.proofpoint.<wbr>com/v2/url?u=http-3A__lists.<wbr>openid.net_mailman_listinfo_<wbr>openid-2Dspecs-2Drisc&d=<wbr>DwICAg&c=<wbr>RoP1YumCXCgaWHvlZYR8PQcxBKCX5Y<wbr>TpkKY057SbK10&r=<wbr>JBm5biRrKugCH0FkITSeGJxPEivzjW<wbr>wlNKe4C_lLIGk&m=xWx68AhS5M_<wbr>By2Kzn2sWKxgaTcobfi-OdzG-<wbr>BY75oQ0&s=<wbr>GlmLO4LTDZglq1yIkAKmtEZG9Fwx_<wbr>e5fxSEQGspbwAo&e=</a>
<u></u><u></u></p>
</div>
</blockquote>
</div></div></div>
</div>

</blockquote></div><br></div>