<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Wed, Apr 12, 2017 at 1:31 PM, Marius Scurtescu <span dir="ltr"><<a href="mailto:mscurtescu@google.com" target="_blank" class="gmail-cremed cremed">mscurtescu@google.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Shouldn't "risc" (the profile name) be part of the URI?</div></blockquote><div><br></div><div>Similarly, what about "ietf" and "secevent" being part of the URI?</div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div><br></div><div>Can you point to some of these other specifications and URIs?</div></div><div class="gmail_extra"><span class="gmail-HOEnZb"><font color="#888888"><br clear="all"><div><div class="gmail-m_4690585652410678300gmail_signature">Marius</div></div></font></span><div><div class="gmail-h5">
<br><div class="gmail_quote">On Wed, Apr 12, 2017 at 1:25 PM, Mike Jones <span dir="ltr"><<a href="mailto:Michael.Jones@microsoft.com" target="_blank" class="gmail-cremed cremed">Michael.Jones@microsoft.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US">
<div class="gmail-m_4690585652410678300m_5364652117048815074WordSection1">
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif;color:rgb(0,32,96)">I’d suggest that RISC event names be <a href="http://openid.net" target="_blank" class="gmail-cremed cremed">openid.net</a> URIs. For instance, I’d use the event name
</span><span style="font-size:11pt;font-family:"courier new";color:rgb(0,32,96)"><a href="http://schemas.openid.net/event/account-deleted" target="_blank" class="gmail-cremed cremed">http://schemas.openid.net/even<wbr>t/account-deleted</a></span><span style="font-size:11pt;font-family:calibri,sans-serif;color:rgb(0,32,96)"> for the Account Deleted event that Marius described.
That would be consistent with how other things have been historically named in OpenID specifications.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif;color:rgb(0,32,96)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif;color:rgb(0,32,96)"> <wbr> <wbr> -- Mike<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif;color:rgb(0,32,96)"><u></u> <u></u></span></p>
<div>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(225,225,225);padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11pt;font-family:calibri,sans-serif">From:</span></b><span style="font-size:11pt;font-family:calibri,sans-serif"> Openid-specs-risc [mailto:<a href="mailto:openid-specs-risc-bounces@lists.openid.net" target="_blank" class="gmail-cremed cremed">openid-specs-risc-boun<wbr>ces@lists.openid.net</a>]
<b>On Behalf Of </b>Phil Hunt (IDM)<br>
<b>Sent:</b> Tuesday, April 11, 2017 3:00 PM<br>
<b>To:</b> Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank" class="gmail-cremed cremed">mscurtescu@google.com</a>><br>
<b>Cc:</b> <a href="mailto:openid-specs-risc@lists.openid.net" target="_blank" class="gmail-cremed cremed">openid-specs-risc@lists.openid<wbr>.net</a><br>
<b>Subject:</b> Re: [Openid-specs-risc] RISC event URIs<u></u><u></u></span></p>
</div>
</div><div><div class="gmail-m_4690585652410678300h5">
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">That said. It is perfectly ok for risc to use urns while the core spec specified uri. <u></u><u></u></p>
</div>
<div id="gmail-m_4690585652410678300m_5364652117048815074AppleMailSignature">
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div id="gmail-m_4690585652410678300m_5364652117048815074AppleMailSignature">
<p class="MsoNormal">There would just be no central event registry except within risc. <br>
<br>
Phil<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12pt"><br>
On Apr 11, 2017, at 2:37 PM, Marius Scurtescu <<a href="mailto:mscurtescu@google.com" target="_blank" class="gmail-cremed cremed">mscurtescu@google.com</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="margin-top:5pt;margin-bottom:5pt">
<div>
<div>
<p class="MsoNormal">Good point, will start the discussion on the secevent list.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><br clear="all">
<u></u><u></u></p>
<div>
<div>
<p class="MsoNormal">Marius<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">On Tue, Apr 11, 2017 at 2:34 PM, Hardt, Dick <<a href="mailto:dick@amazon.com" target="_blank" class="gmail-cremed cremed">dick@amazon.com</a>> wrote:<u></u><u></u></p>
<blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif">I think the format of these should be decided in secevent.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif">I think your proposal of secevents starting with “urn:ietf:params:secevent:even<wbr>t-type:” is one worth proposing in
secevent.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif">"urn:ietf:params:secevent:aud-<wbr>client-id:<client-id>" is clearly a secevent discussion item</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif;color:rgb(136,136,136)"> </span><span style="color:rgb(136,136,136)"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif;color:rgb(136,136,136)">/Dick</span><span style="color:rgb(136,136,136)"><u></u><u></u></span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif"> </span><u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
On 4/11/17, 2:16 PM, someone claiming to be "Marius Scurtescu" <<a href="mailto:mscurtescu@google.com" target="_blank" class="gmail-cremed cremed">mscurtescu@google.com</a>> wrote:<u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
"urn:ietf:params:secevent:even<wbr>t-type:risc:sessions-revoked" would be an event URI, the key under the "events" claim
<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
"urn:ietf:params:secevent:aud-<wbr>client-id:<client-id>" would be the aud claim, and this solves the "SET re-played as an access token" issue<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
<br clear="all">
<u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
Marius<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:0.5in">
<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
On Tue, Apr 11, 2017 at 2:07 PM, Hardt, Dick <<a href="mailto:dick@amazon.com" target="_blank" class="gmail-cremed cremed">dick@amazon.com</a>> wrote:<u></u><u></u></p>
<blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin:5pt 0in 5pt 4.8pt">
<div>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
<span style="font-size:11pt;font-family:calibri,sans-serif">Where are you thinking this is in the secevent SET Marius?</span><u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:0.5in">
<span style="font-size:11pt;font-family:calibri,sans-serif"> </span><u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:1in">
On 4/11/17, 10:56 AM, someone claiming to be "Openid-specs-risc on behalf of Marius Scurtescu" <<a href="mailto:openid-specs-risc-bounces@lists.openid.net" target="_blank" class="gmail-cremed cremed">openid-specs-risc-bounces@lis<wbr>ts.openid.net</a> on behalf of
<a href="mailto:mscurtescu@google.com" target="_blank" class="gmail-cremed cremed">mscurtescu@google.com</a>> wrote:<u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
<u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:1in">
While talking about events, we should also decide how the event URI will look like for RISC.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
I propose we use URN sub-delegation for "ietf" namespace (RFC 3553), something like:<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
urn:ietf:params:secevent:event<wbr>-type:risc:sessions-revoked<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
urn:ietf:params:secevent:event<wbr>-type:risc:tokens-revoked<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
urn:ietf:params:secevent:event<wbr>-type:risc:account-deleted<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
urn:ietf:params:secevent:event<wbr>-type:risc:all ?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
Maybe instead of "event-type" in the above URNs we should use "profile"? Since "risc" above signifies a whole class of event type and not a particular one:<u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:1in">
urn:ietf:params:secevent:profi<wbr>le:risc:sessions-revoked<u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
...<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
We can use this scheme for other RISC related URNs, like a prefixed aud:<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
urn:ietf:params:secevent:aud-c<wbr>lient-id:<client-id><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
Thoughts?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:1in">
<u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:1in">
Marius<u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
<p class="MsoNormal" style="margin-left:0.5in">
<u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</blockquote>
<blockquote style="margin-top:5pt;margin-bottom:5pt">
<div>
<p class="MsoNormal">______________________________<wbr>_________________<br>
Openid-specs-risc mailing list<br>
<a href="mailto:Openid-specs-risc@lists.openid.net" target="_blank" class="gmail-cremed cremed">Openid-specs-risc@lists.openid<wbr>.net</a><br>
<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__lists.openid.net_mailman_listinfo_openid-2Dspecs-2Drisc&d=DwICAg&c=RoP1YumCXCgaWHvlZYR8PQcxBKCX5YTpkKY057SbK10&r=JBm5biRrKugCH0FkITSeGJxPEivzjWwlNKe4C_lLIGk&m=xWx68AhS5M_By2Kzn2sWKxgaTcobfi-OdzG-BY75oQ0&s=GlmLO4LTDZglq1yIkAKmtEZG9Fwx_e5fxSEQGspbwAo&e=" target="_blank" class="gmail-cremed cremed">https://urldefense.proofpoint.<wbr>com/v2/url?u=http-3A__lists.op<wbr>enid.net_mailman_listinfo_open<wbr>id-2Dspecs-2Drisc&d=DwICAg&c=R<wbr>oP1YumCXCgaWHvlZYR8PQcxBKCX5YT<wbr>pkKY057SbK10&r=JBm5biRrKugCH0F<wbr>kITSeGJxPEivzjWwlNKe4C_lLIGk&<wbr>m=xWx68AhS5M_By2Kzn2sWKxgaTcob<wbr>fi-OdzG-BY75oQ0&s=GlmLO4LTDZgl<wbr>q1yIkAKmtEZG9Fwx_e5fxSEQGspbwA<wbr>o&e=</a>
<u></u><u></u></p>
</div>
</blockquote>
</div></div></div>
</div>
</blockquote></div><br></div></div></div>
</blockquote></div><br></div></div>