From nobody Thu Jul  7 11:05:06 2022
Return-Path: <Danny.Zollner@microsoft.com>
X-Original-To: scim@ietfa.amsl.com
Delivered-To: scim@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 37CEEC15A748
 for <scim@ietfa.amsl.com>; Thu,  7 Jul 2022 11:05:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.752
X-Spam-Level: 
X-Spam-Status: No, score=-2.752 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.745, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_MSPIKE_H2=-0.001,
 RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001,
 T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001,
 URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001]
 autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=microsoft.com
Received: from mail.ietf.org ([50.223.129.194])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id B4uYYrnlMMrv for <scim@ietfa.amsl.com>;
 Thu,  7 Jul 2022 11:05:01 -0700 (PDT)
Received: from NAM06-BL2-obe.outbound.protection.outlook.com
 (mail-bl2nam06on2111.outbound.protection.outlook.com [40.107.65.111])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 5A43DC15948B
 for <scim@ietf.org>; Thu,  7 Jul 2022 11:05:00 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
 b=MrlRYmmv0KmJ6K4Y782pM7KKhzciCQ8nirQZnXMIQBZ7TaFbJZRUOQ86hvzQpnV6qBeLqygzblyHWMJ503WnU71iZ55vg+5Hnuesny8yJryipNKurWnhzWkEeQCWYWE2TlTgSqxo8oqccBoGeObCXFsTTXHyORGrnBjWLYDK1hxbW6NSPZWSOrTxWUb20vCGPzR/ZHDzZ3nw682Efp3eeCswQvkMOB4CANRpAd7ODXmAisB85Q/H5joJa70GgGYR+vzMNKRMa0CIM7WzT7pZB06DdnFgBpH5K2j2u5lvhCyKWSpLW0J5H8t7DnNJKFJrAv0uRK9LnfIMQWYvK+f8fQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; 
 s=arcselector9901;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
 bh=NO0msA4XNmBECYG2FeIrnAbzdQgAkX8OlcfW337nYO8=;
 b=l8JM4U5Pw9ddMbvMVKS8hDhnV/4eEYk18Sv4b2/xOVqUmA2p1OmHOJhclMRGgy1WnGgOcezvIIYxfKUu7yUTyrdrPx8QI4T4bj9+aDGSy1UHzdndGWy4uIyGVQdZ80JcEqjfghOTiDWyO+kifIdKEPmo6uJxAeXJuLeoxNMF5EnDVA5BA1LNTcqax2teAyHFbDQl67ZMEtgaKAWJzFWGsfNfFb8x9gL/FXT6m9NioC4Hj9gxdCsMXXuvPhGE1/rqqku4+oCSC7BFnkqdCLhpQtPGOtMwmzT6DPbYKaLZoFgpSwnYyaxC1yVtScrREVUXoX5bMorOvQGMwWGiD8Qs1A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass
 smtp.mailfrom=microsoft.com; dmarc=pass action=none
 header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
 s=selector2;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
 bh=NO0msA4XNmBECYG2FeIrnAbzdQgAkX8OlcfW337nYO8=;
 b=d8mMA6GywK0FTPk7dFt27px/ym1mFBhi/imtFOkU1TOKH6mcj9Wc11BCza/5yVIxxOj1YNxoDNayfEfSiLtEkrMoHV0/SpGPKoUeeVP3fftAyCG0dBVevsRYwMU0QFdPdZS6/4VbQprhzYGK+lhTQHtiUFizHH56UHoH4fyGtqQ=
Received: from MN2PR00MB0720.namprd00.prod.outlook.com (2603:10b6:208:1d8::15)
 by DM6PR00MB0782.namprd00.prod.outlook.com (2603:10b6:5:1be::13) with
 Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5454.0; Thu, 7 Jul
 2022 18:04:56 +0000
Received: from MN2PR00MB0720.namprd00.prod.outlook.com
 ([fe80::b40e:4537:5ae8:2306]) by MN2PR00MB0720.namprd00.prod.outlook.com
 ([fe80::b40e:4537:5ae8:2306%8]) with mapi id 15.20.5457.000; Thu, 7 Jul 2022
 18:04:50 +0000
From: Danny Zollner <Danny.Zollner@microsoft.com>
To: Phillip Hunt <phil.hunt@independentid.com>, Julien Schneider
 <julien@audriga.com>
CC: "scim@ietf.org" <scim@ietf.org>
Thread-Topic: [scim] [EXTERNAL] Query on a specific known resource
Thread-Index: AQHYkdd8kWrSUoMLB0u6CRlCI7heSq1zLFiAgAACqTA=
Date: Thu, 7 Jul 2022 18:04:50 +0000
Message-ID: <MN2PR00MB0720FB58CB201915199826FDFF839@MN2PR00MB0720.namprd00.prod.outlook.com>
References: <bc9c53f8-82fd-57e9-8fe0-166e91048d6b@audriga.com>
 <MN2PR00MB07189D4A9DA54A11131E9896FF839@MN2PR00MB0718.namprd00.prod.outlook.com>
 <7792b174-48ad-181c-11e1-9adb5ff3bc54@audriga.com>
 <E034E806-F3BF-41B0-88BE-FC9C4E420561@independentid.com>
In-Reply-To: <E034E806-F3BF-41B0-88BE-FC9C4E420561@independentid.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true;
 MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2022-07-07T18:04:46Z; 
 MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard;
 MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal;
 MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;
 MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=d5d030a8-776b-4098-bee3-e82301d6b10f;
 MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0
authentication-results: dkim=none (message not signed)
 header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: d794c2ad-aa68-4045-8362-08da60432f6a
x-ms-traffictypediagnostic: DM6PR00MB0782:EE_
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: H3ogychQTcU6JyyfzBHpxxfza7vGTa7/fjwYGg8PNkqLuJbIhAkR/NKxGf1uIxba/NrMejgFrDxfOZmUAfbnvgOULgJPVpxhAQQmsxI3E87Rl0mJtFWa9hqTZz/o8FcxsSBqGTU0kfljUjYwrS8IFrTxVJTpWy58oohnuLXsu6qZam/eGkK4S7E4eiBxbGw2YV2Ewk6wSO09x+WTIIk0iC/T8fHnQUzi5AIcXCRClriau0lpXPIljHxbtYLA8fxHMfbuI3hqab/83wa/2lTaoZkmD/eCqNBVBIsIZcEf9rD5FMB/Lys5m8mhDzLGdaItSmwrnoLziE3QHSpaeHQokuVdSSEpXKkZlKJoItp/3EIEEOtw0SCKNA69OTnT7FCug+QChZCPc54gtftSaVNaaZKr3q0c7bKExcMKwJsM68yqv1Qaeu4tna5MCRtFsRPjT2pJ1mV8B2bt7xhYE9oqe+Mn/pJGPvzFFVi4NZS9AzJXaaCbf+6wN5B2mwpTzbhCG3KZ/sCYTPyk02Z9Wfi0i1RHYrKVI9zX+XxzWeTQkTLzrq1DwCS0Q61AHjNIvgEi8wo6i+7YO+DuEgsew2yRwS6QCCLbAD5GJ84FKwgC+VDkM2+bU0sl7H+HSoyfN4vHOGoX7KaukuUhTF4gtAqqlFoYqusWGlZqajwwzt/R4PlTQHIzQY/EKeFoOgNOMgIXzD4tNqIxdEhb3qNf3EHyn6OGITlYhbs4v0QFnJif2AUMuUVTd4IUQer/HYanTE8fOI/kwu3qshgVCV0nziZdJlcI9CH4WH5/Sj9WuBVA089oghOq6mZ3+JD224wJUQUXOZFuojhmsIbNPfmQle5eh/YS45LbL4vKK6S7/i9M5wqYOee922Ahmzr+63ARIU9K20yd7l/1Q7t7x+7hxBHLOJ4Zsxc+kpO9928pwDcoTww=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; 
 IPV:NLI; SFV:NSPM;
 H:MN2PR00MB0720.namprd00.prod.outlook.com; PTR:; CAT:NONE; 
 SFS:(13230016)(4636009)(376002)(346002)(136003)(396003)(366004)(39860400002)(451199009)(122000001)(53546011)(82960400001)(86362001)(55016003)(71200400001)(66446008)(66946007)(10290500003)(478600001)(966005)(2906002)(316002)(186003)(66476007)(64756008)(66556008)(76116006)(82950400001)(52536014)(38100700002)(166002)(4326008)(110136005)(6506007)(9326002)(8936002)(83380400001)(66574015)(5660300002)(33656002)(41300700001)(38070700005)(8990500004)(9686003)(7696005)(8676002);
 DIR:OUT; SFP:1102; 
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: =?iso-8859-1?Q?azYVloSrClo5tZ2trHXBJ5trOJH0QVTsvTP3KRb8qFu2F0OUJRg15yVRA8?=
 =?iso-8859-1?Q?lqnd/Pa3YH1uqWmI5NnpSFMHBBdYDqKlz1hiSSusnjd47RD6MzibRDGruP?=
 =?iso-8859-1?Q?okqXwuPf6mbZiC9zII/VNrJiYyJSoR7H+nA+by+ocP0YYahE7S71bb84Ht?=
 =?iso-8859-1?Q?fYodDUDH/JtWFRaGr7U56Btqq5O+y7+nl6rT2WCmAe5q+rPv8ySwKzltM+?=
 =?iso-8859-1?Q?2i64HUCkbEAVPYKTAg8/L2lvsZCX8AaWtsAO2ozQUEZ60wG2vjczeOjHsS?=
 =?iso-8859-1?Q?lVf74ERZwZBsM11kOAd8wQd01RdRjQ6LewoNIJLerL1aLoW7t5iDHsieSK?=
 =?iso-8859-1?Q?5/SyXeDJ/7rz5l+94JDLi/REdWV5M1d1SePhzJuYWJ8R8EKVXbNCqfcrf0?=
 =?iso-8859-1?Q?AM1tQaQppRPlekcU5soUW08jeCoH2Tna8JuzXkApoU1eYXUQFl41Un7bG4?=
 =?iso-8859-1?Q?50Y7INaJ8LpZYk3qHLc+GgRCOtAhkQ49+W0pykZFdNhzxVRhsEbX4kuVnY?=
 =?iso-8859-1?Q?lkXtzSfG3IKhuStOEM7a5IjdXaxBFGJ45w51y5gWW1b3/DAij5u3Bsufpe?=
 =?iso-8859-1?Q?zbTMsOBpvxGC3mmsqYxvSpHI4hXHNLm/rVgSRxnkEq30KsBBX9AgzlwzPQ?=
 =?iso-8859-1?Q?pKDU/L7UE9gPI65ELJ0lhwIYfsRjGnIGnPQtfDKppola7FKKdL+SHXkywo?=
 =?iso-8859-1?Q?64U7rjjdb4HD0YCcmusgRDBbQt8Mj+dX38T79Smr1xtl2Z28qSUZ59dJ2t?=
 =?iso-8859-1?Q?84Q/ysjXx5bCiULA2MF7XItTOBTyp8pQF2ag/eqDQb+bpSM8f+rCXDNpeh?=
 =?iso-8859-1?Q?5ImG7z5i4nKhq9jVEwCzxs9Cgax8NULxZS6plo0tVzXudckJEyHi27qEbP?=
 =?iso-8859-1?Q?+ho3XiHa+52DZuXnZvq7Q/jeHNgTpR+wTSihf/jGbW5Qfhl0EGvOmA9Erq?=
 =?iso-8859-1?Q?kIfyjkvzrWAJHKgcdfkK7/00UgrZQCORwHEB1LGY/oqNd1227ILe+B3uKC?=
 =?iso-8859-1?Q?r7VNnNSYVePxJevPeu9b3gn1iC99niGsH/Yxp+7yIbYDdfEHxFFLnGSFwU?=
 =?iso-8859-1?Q?+fZtQ/fRiZpYiix8bnRjm9nWgV7N/a3DhPLhtrfa4cMkU5xQJI8jot9Ch4?=
 =?iso-8859-1?Q?EifK/LlZTshDbwDe8Ijs3snPwnqaDnbt7w8HifM0wWtq5KUHPtLLgpV7h0?=
 =?iso-8859-1?Q?0+4mOsOxcKptLzvEjS0diGjNxlGTBurGBZpTpqfRGFUJwRxKrT4Dk8tisw?=
 =?iso-8859-1?Q?icZOvpfC0Bvg/gUK9fzG/p/i6c6jdoSPxeJ0cj0Ew/RDcMeI9Yp6x+SisB?=
 =?iso-8859-1?Q?QXzGmTJRfHtUbFC1Hz/cBS9vOKamy8ADp+dBn8cvhormk9KmpY81jo7YgY?=
 =?iso-8859-1?Q?XL0/BQSRw6ysRNxVvamYKxI8uAR0S55h6Y1obSY5oATwQBCsGBr5sYBVJX?=
 =?iso-8859-1?Q?kes9fq1Jnn5mQ956qs8zTYBqBAh7PPgpVku2oAF4mrffBxb0GNH6dcdE9q?=
 =?iso-8859-1?Q?k0sbuBPgcfqJ9vWNqsdcq1fuxgN29L4DBgb/JExmcJH+z7gIPkjQJw0Ulo?=
 =?iso-8859-1?Q?EM6XfQO9RkfbgZym4IF0k/eDCva3BiLi4lsfQOevoTJ95XY3lOh4MslY5q?=
 =?iso-8859-1?Q?ZMytsd2uNjDK473dkFLNqs5YlppdGLsUvIUfPoFGbrCVlFlZT1jcypKgRQ?=
 =?iso-8859-1?Q?+LsJgAGTn/ucP7hgxXOLpGsLy2GvVPj1iEQGESh9?=
Content-Type: multipart/alternative;
 boundary="_000_MN2PR00MB0720FB58CB201915199826FDFF839MN2PR00MB0720namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MN2PR00MB0720.namprd00.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d794c2ad-aa68-4045-8362-08da60432f6a
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jul 2022 18:04:50.0776 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: yg+cOVeToAyOxbLICoMSa1FquDlJ8W1ngAXKN6x5hMLPXAxJwDpXazvrF23X24UiLfO2up4vJE+hLawQNgGCaA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR00MB0782
Archived-At: <https://mailarchive.ietf.org/arch/msg/scim/xVF31HrWR5QQvniwXHffjh4UFqs>
Subject: Re: [scim] [EXTERNAL] Query on a specific known resource
X-BeenThere: scim@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Simple Cloud Identity Management BOF <scim.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/scim>,
 <mailto:scim-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scim/>
List-Post: <mailto:scim@ietf.org>
List-Help: <mailto:scim-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/scim>,
 <mailto:scim-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 07 Jul 2022 18:05:06 -0000

--_000_MN2PR00MB0720FB58CB201915199826FDFF839MN2PR00MB0720namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hi Phil,

I'm attempting to clarify what you've said here for both my own knowledge a=
nd others. Anything under a subsection of RFC 7644 3.4.2 counts as a query.=
 Query endpoints can be /Users/{id}, /Users, /Groups, and although not expl=
icitly listed - /AnyOtherResource/{id} as well.

Features that fall under the label of queries and therefore require a ListR=
esponse type response would be:

Filtering - i.e.: GET /x?filter=3DuserName eq "blah"
Sorting
Pagination
Attributes - both ?attributes=3D and ?excludedAttributes=3D

Looking at 3.4.2.1, where the query endpoints are listed, the following par=
ts of 3.4.2.x make sense and what you're saying is apparent. From my own ob=
servations, I think there may be hundreds of implementations out there that=
 implement ?attributes and ?excludedAttributes without a ListResponse wrapp=
er when the query URL is a known resource such as GET /Groups/456?excludedA=
ttributes=3Dmembers.

I think we're still a while away from attempting major changes to the proto=
col and schema RFCs, but in the future I'd be interested in having a discus=
sion on adding an exception to the ListResponse requirement for querying kn=
own resources. The attributes queries are a bit different from the others. =
For filter, sort and paginate you can only really use them against the root=
 of the server or the root of a resource (i.e.: /Users) as I understand it.=
 I can't think of a scenario where you'd do a filter like GET /Users/123?fi=
lter=3DuserName eq "x" - is there a use case there that I'm missing? Simila=
rly, I can't think of scenarios where you'd sort or paginate results for GE=
T /Users/123.

Thanks,

Danny

From: Phillip Hunt <phil.hunt@independentid.com>
Sent: Thursday, July 7, 2022 12:36 PM
To: Julien Schneider <julien@audriga.com>
Cc: Danny Zollner <Danny.Zollner@microsoft.com>; scim@ietf.org
Subject: Re: [scim] [EXTERNAL] Query on a specific known resource

Julien,

You are not wrong.  All queries regardless of path MUST have a ListResponse=
.

It may seem logical to make the jump to just returning a single resource fo=
r a query that can only return a single result, but this is not permitted i=
n the RFC. From a protocol point of view, allowing skipping ListResponse ma=
kes the protocol more complex because it creates "exceptions" which have to=
 be handled. For example, what happens if no filter match etc.

For the group:  For historical information, the issue is actually more comp=
lex than it seems.   For SCIM queries SCIM's profile of HTTP overrides both=
 HTTP GET (retrieves a resource) and HTTP POST (create a resource) to perfo=
rm a search function. In the case of GET, url based filters cause privacy c=
oncerns because of the leak of confidential information in URLs. The GET me=
thod does not allow request bodies. Because of thies, SCIM also supports ht=
tp POST queries. The HTTP definition suggests creation a resource.  Dual pu=
rposing these methods for search queries created necessary complexity. One =
of the basic rules of thumb is that whenever a "filter" shows up in a reque=
st, the request becomes a SCIM Query which mandates a ListResponse.

I discussed this at length with authors of the HTTP specifications and work=
ed with Julian Reschke (co-author of HTTP) to submit a proposal for a HTTP =
SEARCH method.  This would unburden GET and POST methods and simplify proto=
col overall.  Julian indicated to me at the time of finalizing SCIM (around=
 IETF93), that this issue comes up frequently for him as one of the HTTP au=
thors.  In the end, the HTTPbis WG chose not to create a new method because=
 there is too much water under the bridge.  See: https://httpwg.org/wg-mate=
rials/ietf93/ietf-93-httpbis-search.pdf<https://nam06.safelinks.protection.=
outlook.com/?url=3Dhttps%3A%2F%2Fhttpwg.org%2Fwg-materials%2Fietf93%2Fietf-=
93-httpbis-search.pdf&data=3D05%7C01%7CDanny.Zollner%40microsoft.com%7C61a3=
ef6cefda487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C6=
37928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luM=
zIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3DahU2tOHPGFEjoaXkz=
16HWA6W50waT9m5kcYXXIIpRzA%3D&reserved=3D0>

Phillip Hunt
@independentid
phil.hunt@independentid.com<mailto:phil.hunt@independentid.com>




On Jul 7, 2022, at 12:57 AM, Julien Schneider <julien@audriga.com<mailto:ju=
lien@audriga.com>> wrote:

Hi Danny, hi Phillip, hi everyone,

Thanks for your answers. I think the confusing part (for me at least) is "Q=
ueries MAY be made against a single resource or a resource type endpoint ..=
....." at the beginning of RFC7644 section 3.4.2., followed by "Responses M=
UST be identified using the following URI: "urn:ietf:params:scim:api:messag=
es:2.0:ListResponse" ".

My interpretation is that "GET /Users/2819c223-7f76-453a-919d-413861904646?=
attributes=3DuserName" is a query against a single resource, and should the=
n have a "ListResponse" response? Where am I wrong here?

Thanks



Julien Schneider

Tel: +49 721 170293 16

Fax: +49 721 170293 179



http://www.audriga.com<https://nam06.safelinks.protection.outlook.com/?url=
=3Dhttp%3A%2F%2Fwww.audriga.com%2F&data=3D05%7C01%7CDanny.Zollner%40microso=
ft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011db4=
7%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAi=
LCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3DugCO=
wiY5EXLH8EfrAacwK9%2FDCGnhMp3Sh7L%2Fo8WQNOA%3D&reserved=3D0> | http://www.t=
witter.com/audriga<https://nam06.safelinks.protection.outlook.com/?url=3Dht=
tp%3A%2F%2Fwww.twitter.com%2Faudriga&data=3D05%7C01%7CDanny.Zollner%40micro=
soft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011d=
b47%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMD=
AiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3De6=
nmZrdOJiUBA%2F31N1TwKLeeQTuwCVla%2FE4UuOds7AU%3D&reserved=3D0>



--------------------------------------------------------------------------

audriga GmbH |  Alter Schlachthof 57  | 76137 Karlsruhe

Sitz der Gesellschaft: Karlsruhe - Amtsgericht Mannheim - HRB 713034

Gesch=E4ftsf=FChrer: Dr. Frank Dengler, Dr.-Ing. Hans-J=F6rg Happel

--------------------------------------------------------------------------
On 07/07/2022 04:51, Danny Zollner wrote:
Hi Julien,

RFC 7644 section 3.4.2 specifically is talking about queries. Retrieving or=
 modifying known resources (i.e.: GET /Users/12345 ) does not require a Lis=
tResponse type response. A query of GET /Users?filter=3Ddisplayname contain=
s "contoso.com<https://nam06.safelinks.protection.outlook.com/?url=3Dhttp%3=
A%2F%2Fcontoso.com%2F&data=3D05%7C01%7CDanny.Zollner%40microsoft.com%7C61a3=
ef6cefda487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C6=
37928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luM=
zIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3D%2B7DoMHkSX3An6Cf=
G913vNi5zgP%2BAJY28kXSnR%2FgBr80%3D&reserved=3D0>" or GET /Users?attributes=
=3DuserName would require a ListResponse type response, as it does not iden=
tify a specific resource in the query URL via ID value (i.e.: "12345" in th=
e previous example). On the other hand, GET /Users/12345?attributes=3DuserN=
ame does not require the ListResponse type response as it does identify a s=
pecific resource.

To explicitly answer the final question in your email - the expected respon=
se to GET /Users/2819c223-7f76-453a-919d-413861904646?attributes=3DuserName=
would be the second example you provided.

Cheers,

Danny Zollner

From: scim <scim-bounces@ietf.org><mailto:scim-bounces@ietf.org> On Behalf =
Of Julien Schneider
Sent: Wednesday, July 6, 2022 3:41 AM
To: scim@ietf.org<mailto:scim@ietf.org>
Subject: [EXTERNAL] [scim] Query on a specific known resource

Some people who received this message don't often get email from julien@aud=
riga.com<mailto:julien@audriga.com>. Learn why this is important<https://ak=
a.ms/LearnAboutSenderIdentification>
Hi all,

I have a question about queries performed against a SCIM resource object (l=
ike "/Users/{id}").

The RFC (https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2<https:=
//nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fdatatracker.i=
etf.org%2Fdoc%2Fhtml%2Frfc7644%23section-3.4.2&data=3D05%7C01%7CDanny.Zolln=
er%40microsoft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f141af91a=
b2d7cd011db47%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoi=
MC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&=
sdata=3Djbbn1Y43e0GFmChjRVbpMnTKZEqlB5TzLgiJmhz7ZRY%3D&reserved=3D0>) state=
s:

Responses MUST be identified using the following URI:

   "urn:ietf:params:scim:api:messages:2.0:ListResponse"

If I understand correctly, that means the "schemas" parameter of the respon=
se to those queries must be set to:

"schemas":["urn:ietf:params:scim:api:messages:2.0:ListResponse"]

While I understand how that applies to queries on a resource type endpoint =
(like "/Users") or on the SCIM server root, I don't understand how that app=
lies to queries on a specific resource object.
If I understand correctly, queries on a specific resource object actually a=
re quite identical to "retrieving a known resource" (https://datatracker.ie=
tf.org/doc/html/rfc7644#section-3.4.1<https://nam06.safelinks.protection.ou=
tlook.com/?url=3Dhttps%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Frfc7644%=
23section-3.4.1&data=3D05%7C01%7CDanny.Zollner%40microsoft.com%7C61a3ef6cef=
da487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C6379281=
22539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJ=
BTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3DwbOMKvqD9T7hP5OFtruAwY2=
r26XrKdncriLPSapazGQ%3D&reserved=3D0>) which are a GET on a specific resour=
ce, like:

GET /Users/2819c223-7f76-453a-919d-413861904646
Responses to those requests should have the "schemas" parameter set to the =
resource schema(s):

{

     "schemas":["urn:ietf:params:scim:schemas:core:2.0:User"],

     "id":"2819c223-7f76-453a-919d-413861904646",

...

}

Now, how should the response to the following query should look like? And t=
o what value should the "schemas" parameter of the response be set?

GET /Users/2819c223-7f76-453a-919d-413861904646?attributes=3DuserName

Should it be:

   {

     "schemas":["urn:ietf:params:scim:api:messages:2.0:ListResponse"],

     "totalResults":1,

     "Resources":[

       {

         "id":"2819c223-7f76-453a-919d-413861904646",

         "userName":"bjensen"

       }

     ]

   }

Or something like:

   {

     "schemas":["urn:ietf:params:scim:schemas:core:2.0:User"],

     "id":"2819c223-7f76-453a-919d-413861904646",

     "meta":{

       "resourceType":"User",

       "created":"2011-08-01T18:29:49.793Z",

       "lastModified":"2011-08-01T18:29:49.793Z",

       "location":

   "https://example.com/v2/Users/2819c223-7f76-453a-919d-413861904646"<http=
s://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fexample.com=
%2Fv2%2FUsers%2F2819c223-7f76-453a-919d-413861904646&data=3D05%7C01%7CDanny=
.Zollner%40microsoft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f14=
1af91ab2d7cd011db47%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8ey=
JWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%=
7C%7C&sdata=3D1BDZsY%2B1DkxD3t2ZObBwf5UHRZlnoXdE9UFuuBZioS0%3D&reserved=3D0=
>,

       "version":"W\/\"f250dd84f0671c3\""

     },

     "userName":"bjensen"

   }

Thanks a lot in advance



--

Julien Schneider

Tel: +49 721 170293 16

Fax: +49 721 170293 179



http://www.audriga.com<https://nam06.safelinks.protection.outlook.com/?url=
=3Dhttp%3A%2F%2Fwww.audriga.com%2F&data=3D05%7C01%7CDanny.Zollner%40microso=
ft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011db4=
7%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAi=
LCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3DugCO=
wiY5EXLH8EfrAacwK9%2FDCGnhMp3Sh7L%2Fo8WQNOA%3D&reserved=3D0> | http://www.t=
witter.com/audriga<https://nam06.safelinks.protection.outlook.com/?url=3Dht=
tp%3A%2F%2Fwww.twitter.com%2Faudriga&data=3D05%7C01%7CDanny.Zollner%40micro=
soft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011d=
b47%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMD=
AiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3De6=
nmZrdOJiUBA%2F31N1TwKLeeQTuwCVla%2FE4UuOds7AU%3D&reserved=3D0>



--------------------------------------------------------------------------

audriga GmbH |  Alter Schlachthof 57  | 76137 Karlsruhe

Sitz der Gesellschaft: Karlsruhe - Amtsgericht Mannheim - HRB 713034

Gesch=E4ftsf=FChrer: Dr. Frank Dengler, Dr.-Ing. Hans-J=F6rg Happel

--------------------------------------------------------------------------

_______________________________________________
scim mailing list
scim@ietf.org<mailto:scim@ietf.org>
https://www.ietf.org/mailman/listinfo/scim<https://nam06.safelinks.protecti=
on.outlook.com/?url=3Dhttps%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fsci=
m&data=3D05%7C01%7CDanny.Zollner%40microsoft.com%7C61a3ef6cefda487b73ef08da=
603f27f4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637928122539415111%7C=
Unknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiL=
CJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3DlgmWfvOoa2uTk4zhZ2eC6txKydhzire0Hd85s=
Q4Ib5Y%3D&reserved=3D0>


--_000_MN2PR00MB0720FB58CB201915199826FDFF839MN2PR00MB0720namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Helvetica;
	panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:"Yu Gothic";
	panose-1:2 11 4 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
	{font-family:"\@Yu Gothic";
	panose-1:2 11 4 0 0 0 0 0 0 0;}
@font-face
	{font-family:wf_segoe-ui_normal;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
span.EmailStyle22
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:657881322;
	mso-list-type:hybrid;
	mso-list-template-ids:-1463644768 -2056125488 67698713 67698715 67698703 6=
7698713 67698715 67698703 67698713 67698715;}
@list l0:level1
	{mso-level-text:"%1\)";
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l1
	{mso-list-id:1895778014;
	mso-list-template-ids:-609423730;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea=
k-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Hi Phil,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I&#8217;m attempting to clarify what you&#8217;ve sa=
id here for both my own knowledge and others. Anything under a subsection o=
f RFC 7644 3.4.2 counts as a query. Query endpoints can be /Users/{id}, /Us=
ers, /Groups, and although not explicitly listed
 - /AnyOtherResource/{id} as well.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Features that fall under the label of queries and th=
erefore require a ListResponse type response would be:<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Filtering &#8211; i.e.: GET /x?filter=3DuserName eq =
&#8220;blah&#8221;<o:p></o:p></p>
<p class=3D"MsoNormal">Sorting<o:p></o:p></p>
<p class=3D"MsoNormal">Pagination<o:p></o:p></p>
<p class=3D"MsoNormal">Attributes &#8211; both ?attributes=3D and ?excluded=
Attributes=3D<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Looking at 3.4.2.1, where the query endpoints are li=
sted, the following parts of 3.4.2.x make sense and what you&#8217;re sayin=
g is apparent. From my own observations, I think there may be hundreds of i=
mplementations out there that implement
 ?attributes and ?excludedAttributes without a ListResponse wrapper when th=
e query URL is a known resource such as GET /Groups/456?excludedAttributes=
=3Dmembers.
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I think we&#8217;re still a while away from attempti=
ng major changes to the protocol and schema RFCs, but in the future I&#8217=
;d be interested in having a discussion on adding an exception to the ListR=
esponse requirement for querying known resources.
 The attributes queries are a bit different from the others. For filter, so=
rt and paginate you can only really use them against the root of the server=
 or the root of a resource (i.e.: /Users) as I understand it. I can&#8217;t=
 think of a scenario where you&#8217;d do a
 filter like GET /Users/123?filter=3DuserName eq &#8220;x&#8221; &#8211; is=
 there a use case there that I&#8217;m missing? Similarly, I can&#8217;t th=
ink of scenarios where you&#8217;d sort or paginate results for GET /Users/=
123.
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Thanks,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Danny<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b>From:</b> Phillip Hunt &lt;phil.hunt@independenti=
d.com&gt; <br>
<b>Sent:</b> Thursday, July 7, 2022 12:36 PM<br>
<b>To:</b> Julien Schneider &lt;julien@audriga.com&gt;<br>
<b>Cc:</b> Danny Zollner &lt;Danny.Zollner@microsoft.com&gt;; scim@ietf.org=
<br>
<b>Subject:</b> Re: [scim] [EXTERNAL] Query on a specific known resource<o:=
p></o:p></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Julien,<o:p></o:p></p>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">You are not wrong. &nbsp;All queries regardless of p=
ath MUST have a ListResponse.<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">It may seem logical to make the jump to just returni=
ng a single resource for a query that can only return a single result, but =
this is not permitted in the RFC. From a protocol point of view, allowing s=
kipping ListResponse makes the protocol
 more complex because it creates &#8220;exceptions&#8221; which have to be =
handled. For example, what happens if no filter match etc.<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">For the group: &nbsp;For historical information, the=
 issue is actually more complex than it seems. &nbsp; For SCIM queries SCIM=
&#8217;s profile of HTTP overrides both HTTP GET (retrieves a resource) and=
 HTTP POST (create a resource) to perform a search
 function. In the case of GET, url based filters cause privacy concerns bec=
ause of the leak of confidential information in URLs. The GET method does n=
ot allow request bodies. Because of thies, SCIM also supports http POST que=
ries. The HTTP definition suggests
 creation a resource. &nbsp;Dual purposing these methods for search queries=
 created necessary complexity. One of the basic rules of thumb is that when=
ever a &#8220;filter&#8221; shows up in a request, the request becomes a SC=
IM Query which mandates a ListResponse.<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">I discussed this at length with authors of the HTTP =
specifications and worked with Julian Reschke (co-author of HTTP) to submit=
 a proposal for a HTTP SEARCH method. &nbsp;This would unburden GET and POS=
T methods and simplify protocol overall.
 &nbsp;Julian indicated to me at the time of finalizing SCIM (around IETF93=
), that this issue comes up frequently for him as one of the HTTP authors. =
&nbsp;In the end, the HTTPbis WG chose not to create a new method because t=
here is too much water under the bridge. &nbsp;See:&nbsp;<a href=3D"https:/=
/nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fhttpwg.org%2Fw=
g-materials%2Fietf93%2Fietf-93-httpbis-search.pdf&amp;data=3D05%7C01%7CDann=
y.Zollner%40microsoft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f1=
41af91ab2d7cd011db47%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8e=
yJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C=
%7C%7C&amp;sdata=3DahU2tOHPGFEjoaXkz16HWA6W50waT9m5kcYXXIIpRzA%3D&amp;reser=
ved=3D0">https://httpwg.org/wg-materials/ietf93/ietf-93-httpbis-search.pdf<=
/a><o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<div>
<div>
<div>
<p class=3D"MsoNormal"><span style=3D"color:black">Phillip Hunt<o:p></o:p><=
/span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"color:black">@independentid<o:p></o:p=
></span></p>
</div>
<div>
<p class=3D"MsoNormal"><a href=3D"mailto:phil.hunt@independentid.com">phil.=
hunt@independentid.com</a><span style=3D"color:black"><o:p></o:p></span></p=
>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"color:black"><o:p>&nbsp;</o:p></span>=
</p>
</div>
</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class=3D"MsoNormal">On Jul 7, 2022, at 12:57 AM, Julien Schneider &lt;<a=
 href=3D"mailto:julien@audriga.com">julien@audriga.com</a>&gt; wrote:<o:p><=
/o:p></p>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:9.0pt;font-family:&quot;Hel=
vetica&quot;,sans-serif">Hi Danny, hi Phillip, hi everyone,<br>
<br>
Thanks for your answers. I think the confusing part (for me at least) is &q=
uot;Queries MAY be made<span class=3D"apple-converted-space">&nbsp;</span><=
b><u>against a single resource</u></b><span class=3D"apple-converted-space"=
>&nbsp;</span>or a resource type endpoint .......&quot;
 at the beginning of RFC7644 section 3.4.2., followed by &quot;Responses MU=
ST be identified using the following URI: &quot;urn:ietf:params:scim:api:me=
ssages:2.0:ListResponse&quot; &quot;.<br>
<br>
My interpretation is that &quot;<b>GET /Users/2819c223-7f76-453a-919d-41386=
1904646?attributes=3DuserName</b>&quot; is a query against a single resourc=
e, and should then have a &quot;ListResponse&quot; response? Where am I wro=
ng here?<br>
<br>
Thanks<br>
<br style=3D"caret-color: rgb(0, 0, 0);font-variant-caps: normal;text-align=
:start;-webkit-text-stroke-width: 0px;word-spacing:0px">
<br>
</span><o:p></o:p></p>
<pre>Julien Schneider<o:p></o:p></pre>
<pre>Tel: +49 721 170293 16<o:p></o:p></pre>
<pre>Fax: +49 721 170293 179<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><a href=3D"https://nam06.safelinks.protection.outlook.com/?url=3Dhttp%=
3A%2F%2Fwww.audriga.com%2F&amp;data=3D05%7C01%7CDanny.Zollner%40microsoft.c=
om%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011db47%7C=
1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQ=
IjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3DugCO=
wiY5EXLH8EfrAacwK9%2FDCGnhMp3Sh7L%2Fo8WQNOA%3D&amp;reserved=3D0">http://www=
.audriga.com</a> | <a href=3D"https://nam06.safelinks.protection.outlook.co=
m/?url=3Dhttp%3A%2F%2Fwww.twitter.com%2Faudriga&amp;data=3D05%7C01%7CDanny.=
Zollner%40microsoft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f141=
af91ab2d7cd011db47%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJ=
WIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7=
C%7C&amp;sdata=3De6nmZrdOJiUBA%2F31N1TwKLeeQTuwCVla%2FE4UuOds7AU%3D&amp;res=
erved=3D0">http://www.twitter.com/audriga</a><o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>----------------------------------------------------------------------=
----<o:p></o:p></pre>
<pre>audriga GmbH |&nbsp; Alter Schlachthof 57&nbsp; | 76137 Karlsruhe<o:p>=
</o:p></pre>
<pre>Sitz der Gesellschaft: Karlsruhe - Amtsgericht Mannheim - HRB 713034<o=
:p></o:p></pre>
<pre>Gesch=E4ftsf=FChrer: Dr. Frank Dengler, Dr.-Ing. Hans-J=F6rg Happel<o:=
p></o:p></pre>
<pre>----------------------------------------------------------------------=
----<o:p></o:p></pre>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:9.0pt;font-family:&quot;Hel=
vetica&quot;,sans-serif">On 07/07/2022 04:51, Danny Zollner wrote:<o:p></o:=
p></span></p>
</div>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt;font-variant-caps=
: normal;orphans: auto;text-align:start;widows: auto;-webkit-text-size-adju=
st: auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<div>
<p class=3D"MsoNormal">Hi Julien,<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal">RFC 7644 section 3.4.2 specifically is talking about=
 queries. Retrieving or modifying known resources (i.e.: GET /Users/12345 )=
 does not require a ListResponse type response. A query of<span class=3D"ap=
ple-converted-space">&nbsp;</span><b>GET
 /Users?filter=3Ddisplayname contains &#8220;</b><a href=3D"https://nam06.s=
afelinks.protection.outlook.com/?url=3Dhttp%3A%2F%2Fcontoso.com%2F&amp;data=
=3D05%7C01%7CDanny.Zollner%40microsoft.com%7C61a3ef6cefda487b73ef08da603f27=
f4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637928122539415111%7CUnknow=
n%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI=
6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3D%2B7DoMHkSX3An6CfG913vNi5zgP%2BAJY28kXS=
nR%2FgBr80%3D&amp;reserved=3D0"><b>contoso.com</b></a><b>&#8221;</b><span c=
lass=3D"apple-converted-space">&nbsp;</span>or<span class=3D"apple-converte=
d-space">&nbsp;</span><b>GET
 /Users?attributes=3DuserName</b><span class=3D"apple-converted-space">&nbs=
p;</span>would require a ListResponse type response, as it does not identif=
y a specific resource in the query URL via ID value (i.e.: &#8220;12345&#82=
21; in the previous example). On the other hand,<span class=3D"apple-conver=
ted-space">&nbsp;</span><b>GET
 /Users/12345?attributes=3DuserName<span class=3D"apple-converted-space">&n=
bsp;</span></b>does not require the ListResponse type response as it does i=
dentify a specific resource.<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal">To explicitly answer the final question in your emai=
l &#8211; the expected response to<span class=3D"apple-converted-space">&nb=
sp;</span><b>GET /Users/2819c223-7f76-453a-919d-413861904646?attributes=3Du=
serName</b>would be the second example you provided.<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal">Cheers,<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal">Danny Zollner<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
</div>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in">
<div>
<p class=3D"MsoNormal"><b>From:</b><span class=3D"apple-converted-space">&n=
bsp;</span>scim<span class=3D"apple-converted-space">&nbsp;</span><a href=
=3D"mailto:scim-bounces@ietf.org">&lt;scim-bounces@ietf.org&gt;</a><span cl=
ass=3D"apple-converted-space">&nbsp;</span><b>On Behalf Of<span class=3D"ap=
ple-converted-space">&nbsp;</span></b>Julien
 Schneider<br>
<b>Sent:</b><span class=3D"apple-converted-space">&nbsp;</span>Wednesday, J=
uly 6, 2022 3:41 AM<br>
<b>To:</b><span class=3D"apple-converted-space">&nbsp;</span><a href=3D"mai=
lto:scim@ietf.org">scim@ietf.org</a><br>
<b>Subject:</b><span class=3D"apple-converted-space">&nbsp;</span>[EXTERNAL=
] [scim] Query on a specific known resource<o:p></o:p></p>
</div>
</div>
</div>
<div>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
</div>
<table class=3D"MsoNormalTable" border=3D"0" cellspacing=3D"0" cellpadding=
=3D"0" align=3D"left" width=3D"100%" style=3D"width:100.0%">
<tbody>
<tr>
<td style=3D"background:#A6A6A6;padding:5.25pt 1.5pt 5.25pt 1.5pt"></td>
<td width=3D"100%" style=3D"width:100.0%;background:#EAEAEA;padding:5.25pt =
3.75pt 5.25pt 11.25pt">
<div>
<div>
<p class=3D"MsoNormal" style=3D"mso-element:frame;mso-element-frame-hspace:=
2.25pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-el=
ement-anchor-horizontal:column;mso-height-rule:exactly">
<span style=3D"font-size:9.0pt;font-family:wf_segoe-ui_normal;color:#212121=
">Some people who received this message don't often get email from<span cla=
ss=3D"apple-converted-space">&nbsp;</span></span><span style=3D"color:black=
"><a href=3D"mailto:julien@audriga.com"><span style=3D"font-size:9.0pt;font=
-family:wf_segoe-ui_normal">julien@audriga.com</span></a></span><span style=
=3D"font-size:9.0pt;font-family:wf_segoe-ui_normal;color:#212121">.<span cl=
ass=3D"apple-converted-space">&nbsp;</span></span><span style=3D"color:blac=
k"><a href=3D"https://aka.ms/LearnAboutSenderIdentification"><span style=3D=
"font-size:9.0pt;font-family:wf_segoe-ui_normal">Learn
 why this is important</span></a></span><o:p></o:p></p>
</div>
</div>
</td>
<td width=3D"75" style=3D"width:56.25pt;background:#EAEAEA;padding:5.25pt 3=
.75pt 5.25pt 3.75pt">
</td>
</tr>
</tbody>
</table>
<div>
<div>
<p class=3D"MsoNormal">Hi all,<br>
<br>
I have a question about queries performed against a SCIM resource object (l=
ike &quot;/Users/{id}&quot;).<br>
<br>
The RFC (<a href=3D"https://nam06.safelinks.protection.outlook.com/?url=3Dh=
ttps%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Frfc7644%23section-3.4.2&am=
p;data=3D05%7C01%7CDanny.Zollner%40microsoft.com%7C61a3ef6cefda487b73ef08da=
603f27f4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637928122539415111%7C=
Unknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiL=
CJXVCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3Djbbn1Y43e0GFmChjRVbpMnTKZEqlB5TzL=
giJmhz7ZRY%3D&amp;reserved=3D0">https://datatracker.ietf.org/doc/html/rfc76=
44#section-3.4.2</a>)
 states:<span class=3D"apple-converted-space">&nbsp;</span><o:p></o:p></p>
</div>
<pre>Responses MUST be identified using the following URI:<o:p></o:p></pre>
<pre>&nbsp;&nbsp; &quot;urn:ietf:params:scim:api:messages:2.0:ListResponse&=
quot;<o:p></o:p></pre>
<div>
<p class=3D"MsoNormal"><br>
If I understand correctly, that means the &quot;schemas&quot; parameter of =
the response to those queries must be set to:<o:p></o:p></p>
</div>
<pre>&quot;schemas&quot;:[&quot;urn:ietf:params:scim:api:messages:2.0:ListR=
esponse&quot;]<o:p></o:p></pre>
<div>
<p class=3D"MsoNormal"><br>
While I understand how that applies to queries on a resource type endpoint =
(like &quot;/Users&quot;) or on the SCIM server root, I don't understand ho=
w that applies to queries on a specific resource object.<br>
If I understand correctly, queries on a specific resource object actually a=
re quite identical to &quot;retrieving a known resource&quot; (<a href=3D"h=
ttps://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fdatatrac=
ker.ietf.org%2Fdoc%2Fhtml%2Frfc7644%23section-3.4.1&amp;data=3D05%7C01%7CDa=
nny.Zollner%40microsoft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86=
f141af91ab2d7cd011db47%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d=
8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%=
7C%7C%7C&amp;sdata=3DwbOMKvqD9T7hP5OFtruAwY2r26XrKdncriLPSapazGQ%3D&amp;res=
erved=3D0">https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.1</a>)
 which are a GET on a specific resource, like:<o:p></o:p></p>
</div>
<pre>GET /Users/2819c223-7f76-453a-919d-413861904646<o:p></o:p></pre>
<div>
<p class=3D"MsoNormal">Responses to those requests should have the &quot;sc=
hemas&quot; parameter set to the resource schema(s):<o:p></o:p></p>
</div>
<pre>{<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; &quot;schemas&quot;:[&quot;urn:ietf:params:sc=
im:schemas:core:2.0:User&quot;],<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; &quot;id&quot;:&quot;2819c223-7f76-453a-919d-=
413861904646&quot;,<o:p></o:p></pre>
<pre>...<o:p></o:p></pre>
<pre>}<o:p></o:p></pre>
<div>
<p class=3D"MsoNormal"><br>
Now, how should the response to the following query should look like? And t=
o what value should the &quot;schemas&quot; parameter of the response be se=
t?<o:p></o:p></p>
</div>
<pre>GET /Users/2819c223-7f76-453a-919d-413861904646?attributes=3DuserName<=
o:p></o:p></pre>
<div>
<p class=3D"MsoNormal"><br>
Should it be:<o:p></o:p></p>
</div>
<pre>&nbsp;&nbsp; {<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; &quot;schemas&quot;:[&quot;urn:ietf:params:sc=
im:api:messages:2.0:ListResponse&quot;],<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; &quot;totalResults&quot;:1,<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; &quot;Resources&quot;:[<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;id&quot;:&quot;=
2819c223-7f76-453a-919d-413861904646&quot;,<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;userName&quot;:=
&quot;bjensen&quot;<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; ]<o:p></o:p></pre>
<pre>&nbsp;&nbsp; }<o:p></o:p></pre>
<div>
<p class=3D"MsoNormal"><br>
Or something like:<o:p></o:p></p>
</div>
<pre>&nbsp;&nbsp; {<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; &quot;schemas&quot;:[&quot;urn:ietf:params:sc=
im:schemas:core:2.0:User&quot;],<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; &quot;id&quot;:&quot;2819c223-7f76-453a-919d-=
413861904646&quot;,<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; &quot;meta&quot;:{<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;resourceType&quot;:&quot;Us=
er&quot;,<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;created&quot;:&quot;2011-08=
-01T18:29:49.793Z&quot;,<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;lastModified&quot;:&quot;20=
11-08-01T18:29:49.793Z&quot;,<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;location&quot;:<o:p></o:p><=
/pre>
<pre>&nbsp;&nbsp; <a href=3D"https://nam06.safelinks.protection.outlook.com=
/?url=3Dhttps%3A%2F%2Fexample.com%2Fv2%2FUsers%2F2819c223-7f76-453a-919d-41=
3861904646&amp;data=3D05%7C01%7CDanny.Zollner%40microsoft.com%7C61a3ef6cefd=
a487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C63792812=
2539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJB=
TiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3D1BDZsY%2B1DkxD3t2ZOb=
Bwf5UHRZlnoXdE9UFuuBZioS0%3D&amp;reserved=3D0">&quot;https://example.com/v2=
/Users/2819c223-7f76-453a-919d-413861904646&quot;</a>,<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;version&quot;:&quot;W\/\&qu=
ot;f250dd84f0671c3\&quot;&quot;<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; },<o:p></o:p></pre>
<pre>&nbsp;&nbsp;&nbsp;&nbsp; &quot;userName&quot;:&quot;bjensen&quot;<o:p>=
</o:p></pre>
<pre>&nbsp;&nbsp; }<o:p></o:p></pre>
<div>
<p class=3D"MsoNormal"><br>
Thanks a lot in advance<br>
<br>
<br>
<o:p></o:p></p>
</div>
<pre>-- <o:p></o:p></pre>
<pre>Julien Schneider<o:p></o:p></pre>
<pre>Tel: +49 721 170293 16<o:p></o:p></pre>
<pre>Fax: +49 721 170293 179<o:p></o:p></pre>
<pre>&nbsp;<o:p></o:p></pre>
<pre><a href=3D"https://nam06.safelinks.protection.outlook.com/?url=3Dhttp%=
3A%2F%2Fwww.audriga.com%2F&amp;data=3D05%7C01%7CDanny.Zollner%40microsoft.c=
om%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f141af91ab2d7cd011db47%7C=
1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQ=
IjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3DugCO=
wiY5EXLH8EfrAacwK9%2FDCGnhMp3Sh7L%2Fo8WQNOA%3D&amp;reserved=3D0">http://www=
.audriga.com</a> | <a href=3D"https://nam06.safelinks.protection.outlook.co=
m/?url=3Dhttp%3A%2F%2Fwww.twitter.com%2Faudriga&amp;data=3D05%7C01%7CDanny.=
Zollner%40microsoft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86f141=
af91ab2d7cd011db47%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d8eyJ=
WIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7=
C%7C&amp;sdata=3De6nmZrdOJiUBA%2F31N1TwKLeeQTuwCVla%2FE4UuOds7AU%3D&amp;res=
erved=3D0">http://www.twitter.com/audriga</a><o:p></o:p></pre>
<pre>&nbsp;<o:p></o:p></pre>
<pre>----------------------------------------------------------------------=
----<o:p></o:p></pre>
<pre>audriga GmbH |&nbsp; Alter Schlachthof 57&nbsp; | 76137 Karlsruhe<o:p>=
</o:p></pre>
<pre>Sitz der Gesellschaft: Karlsruhe - Amtsgericht Mannheim - HRB 713034<o=
:p></o:p></pre>
<pre>Gesch=E4ftsf=FChrer: Dr. Frank Dengler, Dr.-Ing. Hans-J=F6rg Happel<o:=
p></o:p></pre>
<pre>----------------------------------------------------------------------=
----<o:p></o:p></pre>
</div>
</blockquote>
<p class=3D"MsoNormal"><span style=3D"font-size:9.0pt;font-family:&quot;Hel=
vetica&quot;,sans-serif"><br>
_______________________________________________<br>
scim mailing list<br>
</span><a href=3D"mailto:scim@ietf.org"><span style=3D"font-size:9.0pt;font=
-family:&quot;Helvetica&quot;,sans-serif">scim@ietf.org</span></a><span sty=
le=3D"font-size:9.0pt;font-family:&quot;Helvetica&quot;,sans-serif"><br>
</span><a href=3D"https://nam06.safelinks.protection.outlook.com/?url=3Dhtt=
ps%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fscim&amp;data=3D05%7C01%7CDa=
nny.Zollner%40microsoft.com%7C61a3ef6cefda487b73ef08da603f27f4%7C72f988bf86=
f141af91ab2d7cd011db47%7C1%7C0%7C637928122539415111%7CUnknown%7CTWFpbGZsb3d=
8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%=
7C%7C%7C&amp;sdata=3DlgmWfvOoa2uTk4zhZ2eC6txKydhzire0Hd85sQ4Ib5Y%3D&amp;res=
erved=3D0"><span style=3D"font-size:9.0pt;font-family:&quot;Helvetica&quot;=
,sans-serif">https://www.ietf.org/mailman/listinfo/scim</span></a><o:p></o:=
p></p>
</div>
</blockquote>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</div>
</body>
</html>

--_000_MN2PR00MB0720FB58CB201915199826FDFF839MN2PR00MB0720namp_--

