[regext] Discussion Topics for draft-ietf-regext-rdap-openid

"Hollenbeck, Scott" <shollenbeck@verisign.com> Tue, 12 March 2019 01:17 UTC

Return-Path: <shollenbeck@verisign.com>
X-Original-To: regext@ietfa.amsl.com
Delivered-To: regext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5DEC3131209 for <regext@ietfa.amsl.com>; Mon, 11 Mar 2019 18:17:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verisign.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dxBdy-2El2Js for <regext@ietfa.amsl.com>; Mon, 11 Mar 2019 18:17:48 -0700 (PDT)
Received: from mail5.verisign.com (mail5.verisign.com [69.58.187.31]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 851CB130DCD for <regext@ietf.org>; Mon, 11 Mar 2019 18:17:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=verisign.com; l=945; q=dns/txt; s=VRSN; t=1552353470; h=from:to:subject:date:message-id: content-transfer-encoding:mime-version; bh=TKLHG37SKRKdjUnTcYA0moTbzjegtAUDX/+Njp9u8xM=; b=ltKD0jndvNc3t5ZRLidBJWg4ZiJvfb1Y0nV180bG1u99R1GT0bhgQ1tO FlLtqaaCQ8nJaMvL3n/dlPJEbDVrim1CHMtUfhEz9vNX3SLzuE+daC4g1 6Bir/WePB7ikFgEbVSENOwU2cLngPjYy48KM1QP66E07l+LB6Fg/2reJh +TmkDMnLgEgc0TsHxlApjuxdYMV1TF+ZG/H/+a7p6lMn4g5SQuA+PlSia 0quIIrdWZ4Y7PsHPtigdgq3s57X6MzLJ+1eEfGjnjsrrc3RYLkTSgN2ag Ji0BjFTphaAvTamO5P/Vjbq49Wzr5i5yXOLbuU6bDmY1rA8H0w8hGM8nT g==;
X-IronPort-AV: E=Sophos;i="5.58,468,1544504400"; d="scan'208";a="7084723"
IronPort-PHdr: 9a23:X9TpfBKz9xDY2Cwdm9mcpTZWNBhigK39O0sv0rFitYgeI/7xwZ3uMQTl6Ol3ixeRBMOHsqoC07OempujcFRI2YyGvnEGfc4EfD4+ouJSoTYdBtWYA1bwNv/gYn9yNs1DUFh44yPzahANS47xaFLIv3K98yMZFAnhOgppPOT1HZPZg9iq2+yo9JDffhlEiCChbb9vMR67sRjfus4KjIV4N60/0AHJonxGe+RXwWNnO1eelAvi68mz4ZBu7T1et+ou+MBcX6r6eb84TaFDAzQ9L281/szrugLdQgaJ+3ART38ZkhtMAwjC8RH6QpL8uTb0u+ZhxCWXO9D9QLYpUjqg8qhrUgflhicZOTAk7GHZhM9+jKNHrxyuqBNy2JLUYJiXNPZiYq/RYc0WSGxcVchRTSxBBYa8YpMBA+QDOuZYq439qEUIrRSlGwajGODvxidVjXHrwaI61PghER3I0Ac9GN8Oq3TUrNLxNKcWT++1yrLHwivfYPNVwjr99pbHcgogofGXXLJwfszRxVMzGAPCi1WdsIroNC6b2OQKtmiU9etgVeS3hmE5pAB+uD2vxt8oiobXnI4a1lfE9SB/zY0oJtO4UFZ2bcO4HJdKqi2XNYV7Ttk/T2xotis20LILtJ2jcCQX1Jgr3QPTZv6bf4SS/x7uW+WcLS1liH9mYL6/iQi9/Eu8xuD5U8S50kpFojZfndTJq3wCywDc582HR/Rg4Eih1zOC2gTO5e5ZP085k7fQJYQ7zb4qjJUTtFzOHirxmErrkqCbbl4k+u206+T/ZbXmu4OcO5d0ig7gNqQundSyDPkkPAYWQmSU+fyy2rLi8kHlXblGlOM2nbXesJDAPcQXvLS2DBJP3oY98Ra/FDGm3M4EknkAKVJJYBOHj473NFHSOP30EOuzj06xnDppyf3KJKDtD5XDI3TZn7rsfq5x60tGxwoyydBf6YhUCrYEIP/rQU/xtNvYDhs9MwOqxeboE8ty2Z8dWW+UHK+WLrnSsV6T5uIuLOmMYpUZtyr6K/gg//Lul2M2mUcBfam12psacGq4EeppI0qHbnvsnswMEWYUsQoiQuzmklqCUSRcZyX6Y6VprCs2B4+2Ea/CS5yjxrub023zSodbaW1WFniNHGvmMYKeVKFfRjiVJ5orsjsAUbWnQYIq1lXmjwT916YtZr7P+iocsZ/l3tV+5MXNmAsz7j17CYKW1GTbHDI8pX8BWzJjhPM3mkd60FrWiaU=
X-IPAS-Result: A2HeBAC8B4dc/zCZrQpkHgEGBwaBZYJ4gTSzfQwBE4k4OBIBAQMBAQEIAQMCAQECgQYLgjoigzBRAT5CJgEEG4MbtAqFRYR/gS+LRIFBPo8FA6QhAwYCkwIhkzmKeJJHAgQCBAUCFYFegXhwUIJtkEqQE4EfAQE
Received: from BRN1WNEX02.vcorp.ad.vrsn.com (10.173.153.49) by BRN1WNEX01.vcorp.ad.vrsn.com (10.173.153.48) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1713.5; Mon, 11 Mar 2019 21:17:46 -0400
Received: from BRN1WNEX02.vcorp.ad.vrsn.com ([fe80::7c0a:1cc:5def:9dde]) by BRN1WNEX02.vcorp.ad.vrsn.com ([fe80::7c0a:1cc:5def:9dde%4]) with mapi id 15.01.1713.004; Mon, 11 Mar 2019 21:17:46 -0400
From: "Hollenbeck, Scott" <shollenbeck@verisign.com>
To: "regext@ietf.org" <regext@ietf.org>
Thread-Topic: Discussion Topics for draft-ietf-regext-rdap-openid
Thread-Index: AdTYcJG67wSosl3ySsOmF0LBg60saA==
Date: Tue, 12 Mar 2019 01:17:46 +0000
Message-ID: <9dae8cfbf532426d815855f8345158d3@verisign.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.170.148.18]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/regext/GzcIw-SLLxyoABU2TEXfMkuCTBM>
Subject: [regext] Discussion Topics for draft-ietf-regext-rdap-openid
X-BeenThere: regext@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Registration Protocols Extensions <regext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/regext>, <mailto:regext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/regext/>
List-Post: <mailto:regext@ietf.org>
List-Help: <mailto:regext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/regext>, <mailto:regext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Mar 2019 01:17:50 -0000

There's a chance that my slides won't be through my internal review process prior to the start of our WG session in Prague. That being the case, I wanted to tee up what I have on my list for discussion topics:

Ongoing policy development in the  ICANN context in particular. What happens here can have a direct impact on needed claims.

Non-browser clients: is the OAuth device flow needed?

Are the currently specified path segments "correct"? Are more needed?

Should custom claims returned in an ID token or via the UserInfo endpoint? OpenID Connect allows for both possibilities.

I think I need to change the way the draft describes sending tokens. It currently does this:

.../domain/example.com?id_token=eyJ0...EjXk&access_token=eyJ0...NiJ9

It should probably do this instead:

.../domain/example.com?id_token=eyJ0...EjXk along with an HTTP header (Authorization: Bearer <access_token>)

Scott