[DNSOP] Re: Advice sought: DNS record type for FedCM well-known file delegation
S Moonesamy <sm+ietf@elandsys.com> Wed, 08 April 2026 18:46 UTC
Return-Path: <sm@elandsys.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8670AD842CB8 for <dnsop@mail2.ietf.org>; Wed, 8 Apr 2026 11:46:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775673975; bh=iQ3tNOUFJ+oW8pNV14z53BT05HsV0k2kQXHy8EbRLwA=; h=Date:To:From:Subject:In-Reply-To:References; b=NMpyVw810WgJ+1H4ovAAmHec81f2OYXZR147an8jcE6ocn5Ityqi01RMYr9myeFdC M5c2uRzdnSYsJwhgrBO4CtD6AH4R1kfv5s+mHn+I+KMZYTW/orW1f/JvehqNb+OHKV jN/912ar2LPC6HqHaX4l54HBFCE9BWn0IOsTuBvU=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.7
X-Spam-Level:
X-Spam-Status: No, score=-1.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=fail (1024-bit key) reason="fail (message has been altered)" header.d=elandsys.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gjZ-_Vx5qS7A for <dnsop@mail2.ietf.org>; Wed, 8 Apr 2026 11:46:14 -0700 (PDT)
Received: from mx.ipv6.elandsys.com (mx.ipv6.elandsys.com [IPv6:2001:470:f329:1::1]) by mail2.ietf.org (Postfix) with ESMTP id 4069AD842BA8 for <dnsop@ietf.org>; Wed, 8 Apr 2026 11:45:58 -0700 (PDT)
Received: from DESKTOP-K6V9C2L.elandsys.com ([102.117.86.69]) (authenticated bits=0) by mx.elandsys.com (8.15.2/8.14.5) with ESMTPSA id 638IjL36010536 (version=TLSv1 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 8 Apr 2026 11:45:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=elandsys.com; s=mail; t=1775673955; x=1775760355; i=@elandsys.com; bh=iQ3tNOUFJ+oW8pNV14z53BT05HsV0k2kQXHy8EbRLwA=; h=Date:To:From:Subject:In-Reply-To:References; b=bF7l6gDYzS4QjWarnzcEI/Njr0WBxr+yjp4JTEKHCS1IxB+NwMtiAFqIVrxi1LLax KjdXjV7bY+Mg5DJk86n7tf0Xp5Qo11fOeTV/yA5zoRDDfZwkGwpfnfFmN2hKZmDc/b FPtasF4Qn8sGbxcY1sDN/kpCOKEwRXMnGg7kN5sE=
Message-Id: <6.2.5.6.2.20260408113842.0a50c9b0@elandnews.com>
X-Mailer: QUALCOMM Windows Eudora Version 6.2.5.6
Date: Wed, 08 Apr 2026 11:44:54 -0700
To: Will Bartlett <wibartle@microsoft.com>, dnsop@ietf.org
From: S Moonesamy <sm+ietf@elandsys.com>
In-Reply-To: <PH0PR00MB287470B5624C4161156CB2E6D35DA@PH0PR00MB2874.nampr d00.prod.outlook.com>
References: <PH0PR00MB287470B5624C4161156CB2E6D35DA@PH0PR00MB2874.namprd00.prod.outlook.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"; format="flowed"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: Z2X3DPDGGNQJDOJH357RRMJ4WI4AXA3Y
X-Message-ID-Hash: Z2X3DPDGGNQJDOJH357RRMJ4WI4AXA3Y
X-MailFrom: sm@elandsys.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Advice sought: DNS record type for FedCM well-known file delegation
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/8X14s6GKq8KxV13-mrxha0ib-Os>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
Hi Will, At 05:03 PM 06-04-2026, Will Bartlett wrote: >The W3C Federated Identity CG/WG is working on >FedCM (Federated Credential Management), a >browser API for federated authentication. The >spec currently requires Identity Providers to >host a .well-known/web-identity file at the >registrable domain (apex). This requirement is >privacy driven - in order to ensure Identity >Providers are unaware of Relying Parties until >user consent is granted, Identity Providers must >not be permitted to use per-Relying Party >configuration files. In other words, each >registrable domain must have a single >configuration file. Hosting a file at the apex >is operationally problematic when the apex is >operated by a different service than the >authentication service a common setup where >login.example.com CNAMEs to a white-label auth >provider while the apex serves a marketing site, storefront, etc. >We're considering using DNS to let IDPs indicate >where the well-known data lives. We have four >candidate approaches and would appreciate >guidance on which is most appropriate, or if another pattern is appropriate: I took a quick look at the web API. It uses "well-known locations" (RFC 8615). I suggest starting from that RFC. Regards, S. Moonesamy
- [DNSOP] Advice sought: DNS record type for FedCM … Will Bartlett
- [DNSOP] Re: Advice sought: DNS record type for Fe… Jim Reid
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: Advice sought: DNS record type for Fe… John Levine
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Matthew Pounsett
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… John R Levine
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: Advice sought: DNS record type for Fe… S Moonesamy
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… S Moonesamy
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… S Moonesamy
- [DNSOP] Re: Advice sought: DNS record type for Fe… John Levine
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: Advice sought: DNS record type for Fe… Matthew Pounsett
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… John R. Levine
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: Advice sought: DNS record type for Fe… Matthew Pounsett
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: Advice sought: DNS record type for Fe… Ben Schwartz
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Ben Schwartz
- [DNSOP] Re: [EXTERNAL] Re: Advice sought: DNS rec… Will Bartlett