[scim] Re: [Technical Errata Reported] RFC7643 (8475)

Phil Hunt <phil.hunt@yahoo.com> Tue, 28 October 2025 00:02 UTC

Return-Path: <phil.hunt@yahoo.com>
X-Original-To: scim@mail2.ietf.org
Delivered-To: scim@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 905AE7D24AFA for <scim@mail2.ietf.org>; Mon, 27 Oct 2025 17:02:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=yahoo.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9KusxmYb5MLA for <scim@mail2.ietf.org>; Mon, 27 Oct 2025 17:02:31 -0700 (PDT)
Received: from sonic310-25.consmr.mail.ne1.yahoo.com (sonic310-25.consmr.mail.ne1.yahoo.com [66.163.186.206]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 8D2C67D24ACE for <scim@ietf.org>; Mon, 27 Oct 2025 17:02:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1761609744; bh=hJwc+lONXNjmem8aHDkt7LmeugPrThM9yrRQzFr2lSs=; h=From:Subject:Date:In-Reply-To:Cc:To:References:From:Subject:Reply-To; b=lEIYYYKzHrftOdqqp6uGY8eZ2/As4eXSPOiiGTqI45H/44pnU9gxiO/EzJkZvB2BtkofJEvm514R2UrhV/AJHVWwRqmuhbBXxiZXYDyE4wOEMma/cwry9opuckXPIzVrtoXSy3QRI4uRDv6dUHA75ZJA3sJ4/0YS7oFnV4WNbBRSltC3knHDxmWsXe32/dfkSnUDW+I5WZrz91bcyNw/49zzRFi9Ih4o5Bp6AKw7jr+ApNXBaW7GeE3AdOyrD+qkYh4UA0AJdjcXPcihupk0+sF9s1A9Jfh3JB+JUjab4W7tq/c0h+OQkhby325+/Q/SB0QN9wysJtF7vaNpJQX9XA==
X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1761609744; bh=grfFUEFtFlOKhomTX9VY6yw/vebAxHQzsEEj+WL51/z=; h=X-Sonic-MF:From:Subject:Date:To:From:Subject; b=XMwLVYx1RG1UAk6i0NdocnUZZcJaBq4cvyB0TYxDstHkRGEt+FoiMoMAlM0Veaq6ER7aAp7uEaS51FJLXN9TyVUKfI63kp4JnNRj6GSa49Rx2HRim9OCIiIcZHU6gBluGspC8RWfRBLp+l//Xoqae/KZ8zF2WAhTsm8zEX+cH3XXeTYG+wND4/DOV7aZTpX7DCXFjkCcmZ24FdmEHUAcXqoR9X/4DSW/3P1Ng2DHs2/Tpuoiyqu9sxHryL7dvK20qKEVwuaSjIZ8vdhp2qXQqRF0XrGviEmUZc1fQYKsN1HzMJvTZgZ9Cz2DEuk7l5cEadzE3NT9ZrZErVwYFxPBAQ==
X-YMail-OSG: r5y3AMIVM1mMb79qEgIhidhW_XoV.iHXSciNSYkwppqIhLmFSYK4EMt1ja9o51I VcgGngicx5zxPARqRXinzJz6v1KAHUAAqrVnlDS14mHCQnxKmIbP0sJcEAH34.qxPkpQrXxSg0eS wxmNruPfb8..UMK5Sg_Z_DoXCJACzVQE9x.XOBAvdLdqT7PMHk7ChKU2E93P63bgGctOk4Sqdro2 CYTlllWRYz7skdhZNiNvvlkOzGpb2yopxbQukEZ7eFPdWXaJS6Y50XvO1xYfgeeBfanbhne4AQP2 b15vBlUCUDU3YMeaU_H48ZWKva_0a0ga2UeNjJaQ57v4djzWxqnzVC.7hnHlMSZZjNb8Go1.612t h1M9Oz5ijdL6nOf4BtIaj8ddxRMsEYlw64cBkgM_Brhs1Lh8W8bB66Sqx4NMuAJCcK7si6Ue75d2 15Aj1TQ3Tsow.XokT7K6wpYG4ik1mw8HJ9NxuNIQhDcVRbbnP398eI2hCfwvAfjLICZnAzI8B3eL 7B.l_yZqPtHBK.yWIsu.1f5rKFSWytc8NW02PVizeEhGSwf19HKTIGWvIwG0arxZhTKONtiFcMWT WzmcGD5vbKVqGl_Oh.VTBwXIXwdJ0hQk8q1cvcgakb1WPifloekmkbolaora7HhCsCSF1A1gftp8 6gdSF4iGgtJWxAodK0qbs9oDWNK7oR.sBbR3j9Kd0yldkOllfSbyhcZdFPab1JrOzxjbmNOU8FyM KZaKB_LinrVid9Jb541guzkvvhVsnDF7VeT9qHFAqEOyESdShCvQlV_mRGy2xGYTJS4SPKzFKFb. Ym7eJCjof5LWkVCf0LlzY11CbAuhMl2XgPaDnE2Jw0UQrhmHgGcCPCphlLTM6lCO67Misk9yb5FY xXe2Isu9m2EMMqg9VF7i3OUeD8CvWuBOXw8ciz7oC2MRfqBAmVT1Kl6PrG7GojC5PzzH1EH5K3A1 _OflqTJllWsKyESKwpVy3awNDUxlZBv3iGixZH7WBuPZloMfm0D1PUXyqrAX.XRx8LKvXZZ9mR.a 76ZOzpPADEutu.5hlYgxkfO5O9elmSGo531X_oFNEaWzWCIeH6iNFL8E9wKHevPo_TN2kGbuxtCw cEEDayMxlm0v2a5KZMW4YiYgZFtzrUOr888T9bYF5jtlhAjsv8ztn1L.4BHHlgzw7_QVQhGzFfw. STWD6ik8IIEZuWOTzQWogdZHCObvzTrzn0uJAk69Dhh6n2a7s_lt0FGHTkycHALCerdb.R8g8BfF Vjb1yJMPos.vh4sNrREttx3V6IoTatl.8r26l9yCiWHFiINqzNfaLJY8HIDgDFAbuEy7MtI4wFth 26lQj4uWuUYk7W4BLAeUyHrbhRfAObrOw76imuI3FQL5W06nDRHBTTcNvhpl9B_kAcW2Bflt1B.X 2CnOCDVbjC31W2YxMhMtC1w8ljWNS9SWb3qRb5iCJLz_T1Oiw31EREb9Gkae7gBX2c2wRdmMRYWf wp5446KLn4p9uHyVBMjQXM8CjEtOj11hL8hlhMsFWhJT4DDyjASfxurtFhHSm_.BrMZif5i3wcDW cpIjJnv2hjPSUi72caUzepMBQohmuUtFST9AO3bZA9TuXm4IC7RHm5e9rDAk5QIzEx9cOQL3kqBq oFQ_tFkA8OqU5Oh8yBJukbFIdHM6evelZzwLWIR15xxKby4ysqz.QSr2BWJ9UN7MYRuKLaL8zI1b WXc907emqhgscShPO3mXfDCsGySp28h7OjvvF0hld5nRjCQvNhgJ9DkRk6yvSjSxfPSRoQ2xsTIj WB7lOsWiZZGCyoM.rNowX_DlW7FqndMS0q.hybpPH1ZOzJlSdeGwspnF64NyBG_ML8YdeDORYmC4 r5gM1WbDJT5NHm61GeK2JPhFJTXdqjb5pP_l9puxpjd_SNA7IYfb14P0LDUDU1YlTkxK1mxMtaqO vrbJ_oGtdBux.EaCmp4g5qQl75ZhjEL6Lbhfw58eHrMWUvcYK9fP5t3_hqmd5jwyVCeaQZ4CqcD8 qZmxTGMfV4JL3JSUGkxdCFc.eLyINFVgl0A8Cy9aXXhsaQ86kHVpKu0kNp58biVtToIe4VT1w.no mRrI1JRaPbnYRh1k1caX8O.MBZSmFhVGHLiNwnVLlPCj._69sJ81mZvKAMkIiRzoHI3VnY2bSmhk AVtnLDuCr_yWC00GceFfT4XwVjfaB.6g5CyDtaOReIPI6PevDRKCCEdPFHW7Ta8M8PRTb.aqOVD4 AiBqoUiSN3xE8FjyL4p4g8KXyL364zXrgSW_v00RcSlIAOB4i44wWC8iKyL.uyRaOPVlidhs641m 58UllLB6u.0PSI2Dk
X-Sonic-MF: <phil.hunt@yahoo.com>
X-Sonic-ID: 50a38ece-d79f-4350-8c4b-d7b5b150b9e8
Received: from sonic.gate.mail.ne1.yahoo.com by sonic310.consmr.mail.ne1.yahoo.com with HTTP; Tue, 28 Oct 2025 00:02:24 +0000
Received: by hermes--production-gq1-7cf9d58dc6-h69vv (Yahoo Inc. Hermes SMTP Server) with ESMTPA ID 5703a5fe0e50aa0c75a294c94df00ea7; Tue, 28 Oct 2025 00:02:19 +0000 (UTC)
From: Phil Hunt <phil.hunt@yahoo.com>
Message-Id: <9024514C-886E-443A-B142-B228182C4A2D@yahoo.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_A97B05D4-34E8-4914-A136-97FD8722F318"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81\))
Date: Mon, 27 Oct 2025 17:02:07 -0700
In-Reply-To: <20250620151135.192D626F45F@rfcpa.rfc-editor.org>
To: RFC Errata System <rfc-editor@rfc-editor.org>
References: <20250620151135.192D626F45F@rfcpa.rfc-editor.org>
X-Mailer: Apple Mail (2.3826.700.81)
Message-ID-Hash: ULHIKIT64A3KNPBMYTD6KAHCBSDB6BG7
X-Message-ID-Hash: ULHIKIT64A3KNPBMYTD6KAHCBSDB6BG7
X-MailFrom: phil.hunt@yahoo.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-scim.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Kelly Grizzle <kelly.grizzle@sailpoint.com>, erik.wahlstrom@nexusgroup.com, cmortimore@salesforce.com, scim-ads@ietf.org, Nancy Cam-Winget <ncamwing@cisco.com>, matthias.winter@betasystems.com, scim@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [scim] Re: [Technical Errata Reported] RFC7643 (8475)
List-Id: Simple Cloud Identity Management BOF <scim.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/scim/kR1JJdAtkSM_GXR-1pon6DkoAw4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scim>
List-Help: <mailto:scim-request@ietf.org?subject=help>
List-Owner: <mailto:scim-owner@ietf.org>
List-Post: <mailto:scim@ietf.org>
List-Subscribe: <mailto:scim-join@ietf.org>
List-Unsubscribe: <mailto:scim-leave@ietf.org>

I finally had time to look at this.  

VERIFIED.

Apologies for the delay.  


Phil Hunt
phil.hunt@yahoo.com



> On Jun 20, 2025, at 8:11 AM, RFC Errata System <rfc-editor@rfc-editor.org> wrote:
> 
> The following errata report has been submitted for RFC7643,
> "System for Cross-domain Identity Management: Core Schema".
> 
> --------------------------------------
> You may review the report below and at:
> https://www.rfc-editor.org/errata/eid8475
> 
> --------------------------------------
> Type: Technical
> Reported by: Matthias Winter <matthias.winter@betasystems.com>
> 
> Section: 6
> 
> Original Text
> -------------
> Section 6.  ResourceType Schema
> 
>   name
>      The resource type name.  When applicable, service providers MUST
>      specify the name, e.g., "User" or "Group".  This name is
>      referenced by the "meta.resourceType" attribute in all resources.
>      REQUIRED.
> 
> ...
> 
>   endpoint
>      The resource type's HTTP-addressable endpoint relative to the Base
>      URL of the service provider, e.g., "Users".  REQUIRED.
> 
> ---
> 
> Section 8.7.2.  Service Provider Schema Representation
> 
>  {
>    "id" : "urn:ietf:params:scim:schemas:core:2.0:ResourceType",
>    "name" : "ResourceType",
>    "description" : "Specifies the schema that describes a SCIM
>      resource type",
>    "attributes" : [
> ...
>      {
>        "name" : "name",
>        "type" : "string",
>        "multiValued" : false,
>        "description" : "The resource type name.  When applicable,
>          service providers MUST specify the name, e.g., 'User'.",
>        "required" : true,
>        "caseExact" : false,
>        "mutability" : "readOnly",
>        "returned" : "default",
>        "uniqueness" : "none"
>      },
> ...
>      {
>        "name" : "endpoint",
>        "type" : "reference",
>        "referenceTypes" : ["uri"],
>        "multiValued" : false,
>        "description" : "The resource type's HTTP-addressable
>          endpoint relative to the Base URL, e.g., '/Users'.",
>        "required" : true,
>        "caseExact" : false,
>        "mutability" : "readOnly",
>        "returned" : "default",
>        "uniqueness" : "none"
>      },
> 
> Corrected Text
> --------------
> Section 6.  ResourceType Schema
> 
>   name
>      The resource type name.  When applicable, service providers MUST
>      specify the name, e.g., "User" or "Group".  This name is
>      referenced by the "meta.resourceType" attribute in all resources.
>      This attribute has a "uniqueness" of "server" and is case-exact.
>      REQUIRED
> 
> ...
> 
>   endpoint
>      The resource type's HTTP-addressable endpoint relative to the Base
>      URL of the service provider, e.g., "Users".  This attribute has a
>      "uniqueness" of "server" and is case-exact.  REQUIRED
> 
> ---
> 
> Section 8.7.2.  Service Provider Schema Representation
> 
>  {
>    "id" : "urn:ietf:params:scim:schemas:core:2.0:ResourceType",
>    "name" : "ResourceType",
>    "description" : "Specifies the schema that describes a SCIM
>      resource type",
>    "attributes" : [
>      {
>        "name" : "name",
>        "type" : "string",
>        "multiValued" : false,
>        "description" : "The resource type name.  Service providers MUST
>          specify the name, e.g., "User" or "Group".",
>        "required" : true,
>        "caseExact" : true,
>        "mutability" : "readOnly",
>        "returned" : "default",
>        "uniqueness" : "server"
>      },
> ...
>      {
>        "name" : "endpoint",
>        "type" : "reference",
>        "referenceTypes" : ["uri"],
>        "multiValued" : false,
>        "description" : "The resource type's HTTP-addressable
>          endpoint relative to the Base URL, e.g., '/Users'.",
>        "required" : true,
>        "caseExact" : true,
>        "mutability" : "readOnly",
>        "returned" : "default",
>        "uniqueness" : "server"
>      },
> 
> Notes
> -----
> The attributes "name" and "endpoint" in the ResourceType schema must have a "uniqueness" of "server" and be case-exact.
> 
> Case-exact:
> The attributes "name" and "endpoint" are both used in references (e.g. "{base-url}/ResourceTypes/{name}" and "{base-url}/{endpoint}/{id}"). References are defined as case-exact in section 2.3.7. Therefore, both attributes must also be case-exact.
> This should also be reflected in section 8.7.2
> 
> Uniqueness:
> For the uniqueness of "name" see Errata ID: 8362.
> For "endpoint" the change makes it explicit that each endpoint should provide exactly one type of resource. I do not see any point in RFC 7644 or RFC 7643 that currently forbids using the same endpoint for several resource types, but this would not work when creating resources. Clients cannot specify which resource type they want to create; they can only specify the endpoint and schema.
> This should also be reflected in section 8.7.2 (see Errata ID: 8366)
> 
> Instructions:
> -------------
> This erratum is currently posted as "Reported". (If it is spam, it 
> will be removed shortly by the RFC Production Center.) Please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party  
> will log in to change the status and edit the report, if necessary.
> 
> --------------------------------------
> RFC7643 (draft-ietf-scim-core-schema-22)
> --------------------------------------
> Title               : System for Cross-domain Identity Management: Core Schema
> Publication Date    : September 2015
> Author(s)           : P. Hunt, Ed., K. Grizzle, E. Wahlstroem, C. Mortimore
> Category            : PROPOSED STANDARD
> Source              : System for Cross-domain Identity Management
> Stream              : IETF
> Verifying Party     : IESG