[scim] unknown attribute type in attribute selection parameter

Dale Olds <olds@vmware.com> Wed, 09 May 2018 21:52 UTC

Return-Path: <olds@vmware.com>
X-Original-To: scim@ietfa.amsl.com
Delivered-To: scim@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 90BCC12DB6E for <scim@ietfa.amsl.com>; Wed, 9 May 2018 14:52:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level:
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, T_DKIMWL_WL_MED=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=onevmw.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ciABgVaUW5me for <scim@ietfa.amsl.com>; Wed, 9 May 2018 14:52:16 -0700 (PDT)
Received: from NAM01-BN3-obe.outbound.protection.outlook.com (mail-bn3nam01on0078.outbound.protection.outlook.com [104.47.33.78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 574D0129C6B for <scim@ietf.org>; Wed, 9 May 2018 14:52:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=onevmw.onmicrosoft.com; s=selector1-vmware-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=9vtS72tqGnUEBC08G/Z27lNl4k6hgS6t5NMKnWvc/DA=; b=ATNFsR5fuJZ4RHP9zj9/xT+TVvgEMGII2U1bm240M7TVOMyp/71VjzPF4bQGC4fTc7HCQX+mmn/b8MV9Ew2YwcLzOssrsILBbQuzSzRjVC54Oba89UnsYFvRkPMo9lSKzicYA/OzjGjTFwmvz0VnqjnwZtHOP0cD5y3uC2bpuV4=
Received: from [10.33.98.142] (66.170.99.1) by DM5PR05MB3657.namprd05.prod.outlook.com (2603:10b6:4:3d::26) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.755.15; Wed, 9 May 2018 21:52:14 +0000
To: scim@ietf.org
From: Dale Olds <olds@vmware.com>
Message-ID: <546bd659-175a-f036-4fa2-0d2575091336@vmware.com>
Date: Wed, 09 May 2018 14:52:09 -0700
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.7.0
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="------------5AE0E3DCF2A2ED63E7D18D68"
Content-Language: en-US
X-Originating-IP: [66.170.99.1]
X-ClientProxiedBy: CO1PR15CA0090.namprd15.prod.outlook.com (2603:10b6:101:20::34) To DM5PR05MB3657.namprd05.prod.outlook.com (2603:10b6:4:3d::26)
X-MS-PublicTrafficType: Email
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(5600026)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7153060)(7193020); SRVR:DM5PR05MB3657;
X-Microsoft-Exchange-Diagnostics: 1; DM5PR05MB3657; 3:x49GWQFLM5JNSIekNsW5VaYeS6ie7oZqgNP/YlrGzPG87kyeQ7SPRBpuEKmM0M5pkDWL/h/6eyapBqYxzMjblDHhqyVWMDgVttnL7qxlUJwRD88rRMQLDdU0fwc/4L5eQnETEZZapigouiMhD/VQvOObUGW8+YTFaU+lE18unzZo1nsCXqnd1iJKbryatWyy/Epmgbgq9YMUqYNvaV041a3m+Mk9jXVOTZjxVLsK9Ddvp36CVaq90T2wi0vSG9sZ; 25:XX3WTKA6d6TsraWfjqhQzudAWFSzIcTxj8rDRZbgzMDHCyI8cLabJ3ukYnLz7rzKItQTQeX/2J9MaDLogSAEFXYmWLzNbbFfrwO4X7JmAag5HrmvmGYZtAowWDHJP9OzgIciK+FLF+8lTx98LwxeVOBFmQanW0jkXxwqE8mSII59G54qP34cjKDP6J9KOdyecTd3w/FE5SI1D13EwYhzg4NS6P1FDGtQCW5Hf1aOQHwb7SUtp2JfnD0Hg0wW7bvZpGIjQ/DqtGli426Y6M0ohGev+CeEX4BzxnTwBp6LuljXCE/f9UNB51BlNnW5cW0s8QBwN5j4ZVLIIcg5CpuvRA==; 31:uFHfTkbR2n4SvEjGrzkSzKikWD16uPJjVg6prJs1TPulaTAh0vc0z6IaxLW0v8y641uxWU18PdoRgjT91zyyXdzRD54n1D7ms2+WBBdQf+v5bsiMvR1E8HTxMbHhK/KS2eoRDeKP4HjtDZLCwr744GcuLtz0czqrQadPTDN5whTIatSWZzgOv7NihgCu/gwdpMz9/cUHdHfihgTTS+aUTz15On/gMWKgQazcd8yy5BM=
X-MS-TrafficTypeDiagnostic: DM5PR05MB3657:
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=olds@vmware.com;
X-Microsoft-Exchange-Diagnostics: 1; DM5PR05MB3657; 20:9jwlY2oANxrFgrLsK5+O1pWdI/jQQpHhQyFORQUXXaFAddW2QJEA58Tay8zZX+4uLotPOmJZnfXade5jnpOy9Nmd2GnBSoJ58zXx+SqOncxeYCL+lO3NOQrsP7O8LCmUo3jrli6Yh4H4fewSECsvB5nN92QSW+GeT3TBH2+sm1ujMrjfs68PWHdUFw5gitUQUn43lyYdQy47mVGN0zzLO5XrNozKSjwteBl8jLq5/3CMrCsId67RwPDd5nuPqLyxXiz7ULCz4aVfqTh7OzUu85qEnWu7vedbaJDxWaLDhmgSqxr8328oWAc/WzB9dzq2TncOwb5jvNcYOvxf7ZY8ZdMFsV5QDv4/VrAz0B7HqYZ6eIhseSUUPqZzFY/d035fMu8TR63YjcbgPqDvGUGidrZdg1Qf0UscinnjuzMUQ1nXo+L464eWT1WQ0VNDxlZyDzgTvaoqXz6MZMKysDjD4my52n8iEVD9o/ftI1Ib6/E6IzFeXD+Ym0LqhxJ3kzZj; 4:w2YSWffuKYdeeEU/2+rlKtp0/Bo8jFt+n+wEVl/fuV7UCE2ee4MQKmzEeqm8K+Fo8vqSpVJrGmXvl1W1EZbd+afDHjhgnsgTn6cGoogyrI53aAUbCotOTa3MzCdfoBtE9wZcPHhsBODusrvz7H4VRSEd+F2zzSGZrxM5M8j8gJQcX7o8AJ2438fgkEjhUP4ZuQXlf7Vc+Y+Bk4Q0bid9XhntZNrvYAyT0ujsNIByQjnWwgeTS0ytohcC2CJu5gLMOmSceGvKR8M6KZXsmSSkSLIvrv/+fWm0DHyz5ZyvR6737ivfI8L6C8Totk0FeiMI
X-Microsoft-Antispam-PRVS: <DM5PR05MB365708F6B72D5CC7D219C7E0BB990@DM5PR05MB3657.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(158342451672863);
X-MS-Exchange-SenderADCheck: 1
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(5005006)(8121501046)(93006095)(93001095)(3231254)(944501410)(52105095)(10201501046)(3002001)(149027)(150027)(6041310)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123560045)(20161123564045)(20161123562045)(20161123558120)(6072148)(201708071742011); SRVR:DM5PR05MB3657; BCL:0; PCL:0; RULEID:; SRVR:DM5PR05MB3657;
X-Forefront-PRVS: 0667289FF8
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10009020)(6049001)(396003)(366004)(39860400002)(39380400002)(346002)(376002)(199004)(189003)(2351001)(25786009)(16526019)(77096007)(68736007)(2361001)(8936002)(186003)(37036004)(65956001)(386003)(316002)(66066001)(65806001)(270700001)(26005)(105586002)(33964004)(54896002)(16576012)(59450400001)(58126008)(52116002)(16586007)(84326002)(81156014)(106356001)(81166006)(31686004)(65826007)(8676002)(64126003)(6116002)(2906002)(7736002)(6486002)(956004)(6916009)(97736004)(86362001)(6666003)(478600001)(5660300001)(2616005)(486006)(31696002)(476003)(36756003)(53936002)(3846002); DIR:OUT; SFP:1101; SCL:1; SRVR:DM5PR05MB3657; H:[10.33.98.142]; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
Received-SPF: None (protection.outlook.com: vmware.com does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1; DM5PR05MB3657; 23:ZLBCL6eZKVmEee/9IBHjPI35v2QJT/pu1kIu5x2K3xQiSTUo/npyu/Yo7HEwUdGM1KuNc6RZpIJbOf2vod4+q/VLxTOBpHj43iYp4tjEzhTrgPPMYTTewwJ69ZIw+YG7tBtTXiNyav5Us2yzW9DBsE++YaSiCHhg8RGEQNsxNwCqFxHEMrHvUyQKdQQvzFFjfl6OzhuJxIqasJgm/yYiMawLWH13W962Ab0TS1Rr+mEk0nOzZcsySbEOliQsvmbdAusE+K7yqZlwV8PO+qT3DXT7E3ilS3AUXeN/BQZiK5iFp59YxjGNx+qJ6zfWNQNdupkLTxl0oAbbqXbjKgYmV0wadoKAaEzjBXdlDV96o7/bCtsuZ5b+nZXmkBjsrlzi8j5K5Se0R2OjMKgYuF3Qo7/DsfCYD0UFnzDH0GON2CpuUL2d6N9+GEcqXXN4CpV398sWteeKQocvkLcck4Aeq3iP0AlvlDRQHLeGYzhtnZ7ASZZ5sWh88u8rA/zZ6p8IldoyR2nTAV+Ptk/+xAezyIy0N+EpHEEPijYZU1OVllYaLbMYBqe/YKRzsk+2Xcda20xZro9VXYdgcUk6oXgS+hfqXqThxFd/Nc+XZIHx47DAX527/3ZtKdt+Wp5JVpJbb7vjCz0j5p4L85TI6LISDV/TG0oNAUOKE4d/YvaC9JHMHo0Z4qXfW1Us2SmZ0U4fZEvaZkYhKs6VeERvCJdtfXnE6u2fuNfG0zK7OdxQ3xUaoP/I7cifzEGYKQFlPpZ5SmgxxKwRxpn+qR6/zxOUJFJSdJT+Ysn6pQovkW67jBR+46gTq6IyYsCsnqq8ZsEUou4d6SgfUs5GUIHcFPDtxZHSjjhWK52hFWL+CD83LNrUFMPup8N5dN4nLkCNL/u2voJEUUGSxcsYzQd3k7sENr8baD9aiodx3u5iTdyoP5DCAccuFVY+rSz4A/mr3OCEFExkwxdeoHIAr3HLcSAm4rw9Y5MAj1V9vrqsD//FqgwtyyJFljMxrplzUdQUH4bf326LKBprIp45pySnNgd3XafLKBl9ttXaUoxjKYS6182WO/TRK7aoVXddbgMqLoGHi+DN58s83FkiDhzKkUz4uwtsQwF+CO8E9/nuKaWxjgBY/jnUkWZYclPs9LnfzPSOq4mHNvEz+DWE9S7RlgXo7NWNvi8KGlqiymyKznzWktpFUnjJlIaDlMMpWwta9nKFOLFQbjjkfR6FeH/AvLv1dvDmt6Q/45ZZzcdGkC1PDpUYgV1jWyRDJKZNMpk5H76t4/5o0NMjl2pOk8ca2CwGDgs3ahzpZ0lEIJHtc+REUCk=
X-Microsoft-Antispam-Message-Info: pUt46TBJV9qvknKQUmuh7C1/vr+rKXbg6FNWxUk3Nn+S63gyapg0dNdkqUJXCznF1nNvl4OO8NCFdP/Kjn1SWBSTZqy7mpYZM7IgTfe2EMPGWZSbkGjrMVSWLdxIoeSdHngmTl7GwA+A5o/qfv+yCfr+rLUjssJfJZDDMbjOiOhnY1xUVHKllFQLaq3TS19S
X-Microsoft-Exchange-Diagnostics: 1; DM5PR05MB3657; 6:8jHX18Xrz0yKqWmISqjUPl4Tk6hNgV+0Ns+TWy7P4CS4r1D7rftWCGo+4gtdrmdKIp/xGPpsUkYDfgpbWGLfnVZA1C40UBlf8ywMsHFvnfRzdadFJL/nHRNX3frSq2GaXKQZ7EkS4r1wsDa2zzAzWL9LccgM2AjJ9AiXQUPPP1tO6bxwhUst/zH7PohTSmhR73ImkgClZproRNEMvNezUypeVWemZR4Y3cvCAjsaD0BNYajSc0x3Wgua22IrflbtjorAVHywGOytWoVtG3MJdzBXjJg4DWpbPjTvZA7TxLa8EoK8KdFRQNNJkxF/Jsx+2Tswx3BEiZEfrbJnxYeNIGSVDP6GqGItFYO0J/ZzDA7J8nQstn5JYGtJsNCqrIIM6Pot7MjsUPUB+p23QdKTuVbjTnn8BF4hL6V/GNLlzsd6U4c0OM7H9uDTA7S6QtmqWes4/LlsN+AGQoETljj+Lw==; 5:KafUkzLzRJF4F01Ac0vHyqctwuKqDcU76b/1009IUQq3XOM1NyUCxsTraitjz5iivnrYEQqu0r0oDF2GsCP0wka/6NzN/7fBFsLI7dbeKXusjoN7zE0mh95XhlPPd7xmMuZURW3D3GIe6rKbz/zsIhbHRRlPBaXVGI8LsiIszbY=; 24:ubu241tslw3pXVVfeEs11N293tPmj4t9W+HeRaU/n/JK+TgPOGAXZK5LzGKmPuz3kEMysEUeNeqMA7vVyvC9Tu/dzruG+LU0EZ4rHoLhcXw=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; DM5PR05MB3657; 7:hmXSuyByjQzrhR3j7v0salZJL6Jzg1+IkbI5HsOCObY8Q0nqD66LNFQz8ieok0wDPSqE6kiIhRBJ8gXGhFyVFd9qGtL6zlrOScfqxrtaN1jMcVY7AVyuBdp51M0saf4es0z/MUiGD7SW9GmJz+bcyn8dBpJLVu0EHgwVMQ7X3PtJXT5LwIsLq1Hn/dA9alXmUeIvaerAuciV/VND9Zu3tBJRvYEwUu2WN+LdQL2v2WcOaJgjQsV5d9alicGnC4Ec; 20:EwbnQlIEjylSu+PSlUKf7QmU0rRTPKDSfcQyj1298We4JM9+IVI07wM99PvcE49DwmUMOjM7ijGyKHMIdNqHflL4rcvjzqOuXp0LE4m3p+P+U8wF5LoFDStVqjf8iCNGOPRI+tCnBV+ac4QccfigX3rAH2o4WWgPMSAI+T6VVE4=
X-MS-Office365-Filtering-Correlation-Id: 7b5f8c2f-93c3-4a31-411e-08d5b5f7201f
X-OriginatorOrg: vmware.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 May 2018 21:52:14.1190 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 7b5f8c2f-93c3-4a31-411e-08d5b5f7201f
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: b39138ca-3cee-4b4a-a4d6-cd83d9dd62f0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR05MB3657
Archived-At: <https://mailarchive.ietf.org/arch/msg/scim/8cn3t7Ub9WpUFngL2ZTFVFku_qg>
Subject: [scim] unknown attribute type in attribute selection parameter
X-BeenThere: scim@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Simple Cloud Identity Management BOF <scim.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/scim>, <mailto:scim-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scim/>
List-Post: <mailto:scim@ietf.org>
List-Help: <mailto:scim-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/scim>, <mailto:scim-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 May 2018 21:52:18 -0000

I have a question regarding how a SCIM server should handle unknown 
attribute names in an attribute selection parameter. The SCIM 2.0 spec, 
section 3.9, defines the "attributes" parameter. We're seeing an 
implementation that returns an error if one of the given attribute types 
is unknown to that server.

 From previous experience working with directory services it was very 
important that servers not return an error, but simply ignore that 
attribute since resources will not contain a value for it. This allowed 
for requests to be coded in a more portable fashion. If an app really 
needed to know what schema was supported, it could query the schema.

However, in looking over the SCIM 2.0 spec, I can't find anything that 
would directly address this case. It is somewhat indirectly addressed in 
that I can't find an error defined for invalid or undefined attribute type.

Is there an expected behavior for this situation or is it up to the 
server implementation?

--Dale Olds