Re: [apps-discuss] What auth server supplies email addresses? Was webfinger discussion

"Paul E. Jones" <paulej@packetizer.com> Wed, 28 March 2012 22:13 UTC

Return-Path: <paulej@packetizer.com>
X-Original-To: apps-discuss@ietfa.amsl.com
Delivered-To: apps-discuss@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CAEA221E8101 for <apps-discuss@ietfa.amsl.com>; Wed, 28 Mar 2012 15:13:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.494
X-Spam-Level:
X-Spam-Status: No, score=-2.494 tagged_above=-999 required=5 tests=[AWL=0.105, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k5N5fGmnJjny for <apps-discuss@ietfa.amsl.com>; Wed, 28 Mar 2012 15:13:34 -0700 (PDT)
Received: from dublin.packetizer.com (dublin.packetizer.com [75.101.130.125]) by ietfa.amsl.com (Postfix) with ESMTP id F2B0D21E80FB for <apps-discuss@ietf.org>; Wed, 28 Mar 2012 15:13:33 -0700 (PDT)
Received: from sydney (rrcs-98-101-148-48.midsouth.biz.rr.com [98.101.148.48]) (authenticated bits=0) by dublin.packetizer.com (8.14.5/8.14.5) with ESMTP id q2SMDVbn029512 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Wed, 28 Mar 2012 18:13:32 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=packetizer.com; s=dublin; t=1332972813; bh=SGZgQ6kYIlORcpQt7kidallyq0B+DCIL2bpEIggDHyI=; h=From:To:References:In-Reply-To:Subject:Date:Message-ID: MIME-Version:Content-Type:Content-Transfer-Encoding; b=i2k0LjigPwQqolshHagmPZQkY0QSW6Vh7p+58EO/YnyaSnhT6kwQFk9tr+hRpUH9Z wb46VtRsSrImHp3zeqrG7RvQebxc1OsxROHvRUe404T+riHPPSjTrliBh6cgb/PJvv JZ/CXOYtQgvPinPiAttA38FZxm1IkHd2AVQa5RWU=
From: "Paul E. Jones" <paulej@packetizer.com>
To: 'Alessandro Vesely' <vesely@tana.it>, apps-discuss@ietf.org
References: <053201cd0b5d$c08c80f0$41a582d0$@packetizer.com> <20120326150556.GC3557@mail.yitter.info> <CAA1s49V0M7N1pLua+ORxGWmsrd_yAA_KQ0Piqjg8VuWJ5=G+Lg@mail.gmail.com> <20120327084709.GB11491@mail.yitter.info> <00ac01cd0c34$cfc96f10$6f5c4d30$@packetizer.com> <CABP7RbdtMYtqgV=NepJMNintjF9hb4h6wv2ttc5bDVqE=yAvPA@mail.gmail.com> <00d201cd0c3a$b3672410$1a356c30$@packetizer.com> <CABP7Rbdcb_xTjLv+Y8brzvhuNiae0pOJKm-9qhHrQMg+xUYPVw@mail.gmail.com> <4F72F5C0.70106@tana.it>
In-Reply-To: <4F72F5C0.70106@tana.it>
Date: Wed, 28 Mar 2012 18:13:37 -0400
Message-ID: <024101cd0d30$06d70ac0$14852040$@packetizer.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQEg174HJISLlkWDD0VVkXSpmVuZQwKMareXAWwgTx8BwaaRJQGG5wouAU3B5AYBuFTkWgIDrH2CAm7QUeSXYuMTgA==
Content-Language: en-us
Subject: Re: [apps-discuss] What auth server supplies email addresses? Was webfinger discussion
X-BeenThere: apps-discuss@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: General discussion of application-layer protocols <apps-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/apps-discuss>
List-Post: <mailto:apps-discuss@ietf.org>
List-Help: <mailto:apps-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Mar 2012 22:13:34 -0000

Get an email address from what ID?  A Webfinger "acct" URI?

Paul

> -----Original Message-----
> From: apps-discuss-bounces@ietf.org [mailto:apps-discuss-bounces@ietf.org]
> On Behalf Of Alessandro Vesely
> Sent: Wednesday, March 28, 2012 7:28 AM
> To: apps-discuss@ietf.org
> Subject: [apps-discuss] What auth server supplies email addresses? Was
> webfinger discussion
> 
> I reproach myself for having missed the Internet Society Panel on OpenID
> and OAuth yesterday morning.  I'll try and find the recording.  Meanwhile,
> does someone know if there is a way to get an email address from an id?
> 
> On Wed 28/Mar/2012 12:40:20 +0200 James M Snell wrote:
> >
> >   If I want to know about user "bob@example.org", send a GET request to:
> >   http://example.org/.well-known/finger/{md5(acct:bob@example.org)} and
> >   see what I get back.
> 
> That implies the address is known.  Couldn't one use just
> 
>    http://example.org/.well-known/finger/{opaque-token}
> 
> and, possibly,
> 
>    http://example.org/.well-known/finger/{opaque-token}/email-addr?
> 
> The idea is that the relevant user, well, Bob in this case, can be logged
> in more or less at the same time as he triggered an automatic query of
> that url.
> For example, he might be buying a DVD at Amazon's.  Bob's server might let
> him choose whether to supply his plain email address or any variant
> thereof, possibly offering to update Sieve scripts while it's at it.
> 
> Is perhaps SCIM, or whatever other framework, nearer to such kind of use
> cases?  It could be used as a better double-opt-in...  (Yes, I'm the one
> who asked what's the difference between Webfinger and SCIM on Monday, and
> I'm apparently still unclear on that.)
> 
> _______________________________________________
> apps-discuss mailing list
> apps-discuss@ietf.org
> https://www.ietf.org/mailman/listinfo/apps-discuss