Minutes IETF122: scim: Wed 08:30
minutes-122-scim-202503190830-00
| Meeting Minutes | System for Cross-domain Identity Management (scim) WG | |
|---|---|---|
| Date and time | 2025-03-19 08:30 | |
| Title | Minutes IETF122: scim: Wed 08:30 | |
| State | Active | |
| Other versions | markdown | |
| Last updated | 2025-03-21 |
SCIM IETF 122
2025 03 19
(2569 BE)
Chairs Intro
welcome
note well
intro slides and how-tos
agenda review
Dean: any updates on Delta Queries?
Nancy: not adopted yet, ask on mailing list
SCIM Use Cases
Draft submitted to group last IETF
got some feedback, but lacking more.
This session will be an overview on what's in the draft.
Why is this needed? side conversations made it clear there needs to be
some common terms and concepts.
This will have generic and specialized use cases. Not exhaustive, but
sufficient.
Once the concepts from this document are agreed on, the drafts in
progress should be reviewed for consistency.
Terminology overview slide: data models, roles, actions, etc. This
terminology should be used in WG drafts.
Basic use cases slide: The goal is that these fit any of the flows
described today. resource subscriber, creator, and manager use cases.
Specific Use Cases slide: details of select use cases. Quick run through
of each one listed.
These are the use cases discussed in previous meetings.
Volunteers for review:
- Dean
- Anjali
Harvey wants the slides. They are available in the datatracker - meeting
materials.
SCIM Roles and Entitlements
Aaron presenting (chair hat off).
presenting on behalf of remote colleagues.
This was adopted and of 2022. Hasn't has much activity since, but is
being used.
Core schema defines roles and entitlements for users
This extension extends that, making the roles and entitelements managed
by the client.
Completes the half-picture drawn by the core vocabulary
Okta has implemented it and recommends some changes.
Summary of proposed changes slide: changes are currently sitting in a PR
on the repo
is adopted, but the original author has not pursued it. Folks at Okta
are looking to move it forward.
Has anyone reviewed this?
- 🦗🦗
Nancy: make the updates, do a rev, then post to the mailing list.
Update from the OpenID IPSIE Working Group
Aaron is now wearing a slightly different hat (Open-ID). Still not a
chair one though.
Group is concerned with enterprise identity problems.
interop and security are two main themes of the work.
a lot of times there are enterprise identity providers who have utilized
the optionality available to them in the standards, which means every
implementation differs.
Lots of new threats as well. SSO was previously sufficient, but not
longer is enough. New threats require new solutions.
IPSIE Charter scope slide: some of the things are not as related to SCIM
goal is to profile existing specs as much as possible, to reduce the
optionality and pick the more secure ones. Allow users to follow specs
not vendor docs
What has this to do with SCIM?
Two lifecycles: session and identity, each with three levels
SCIM can likely ignore the session lifecycle
Identity lifecycles have overlap wuth SCIM WG drafts
Don't want to see IPSIE go off and profile SCIM on its own island. The
work should be done in conjuntion with this core SCIM group
IPSIE is trying to reuse as much of the existing infrastructure as
possble.
Feedback requested from SCIM implementers on the identity lifecycles
IPSIE has described, particularly as IPSIE profiles SCIM work.
IPSIE goals slide: they want stable drafts of first lifecycles by Sept
2025, demonstrate interop by Dec 2025. What does it actually look like
to use SCIM to achieve the goals of the first Identity Lifecycle
any comments or questions?
Dean: I co-chair this and would love to see folks in this room help. We
could use active deployers of SCIM to help us move forward. SCIM work
should be defined here, so that it can be used in IPSIE.
Nancy: one thing that would help us: can we have on the SCIM mailing
list a sharing of the documents. Is this public?
Aaron: it is public
Nancy: put it on the mailing list, hack on this at the next IETF
Hackathon, get live review in interim SCIM meeting.
Dean: would it be better for me to do this than Aaron?
Nancy: yes
Aaron: IPSIE is exclusively focused on enterprise use cases, SCIM is
not. This can serve to differentiate where the work happens. Want to
avoid OpenID defining the extensions.
Ali Hussein: what does enterprise cover?
Aaron: we have word-smithed our definition of enterprise
Dean: the way we defined enterprise is - if you consider yourself an
enterprise, you are. Government, small business, etc.
Aaron: if you want to control your overall application usage from a
single control point, you are an enterprise (i.e., in scope of IPSIE).
Dean: eduroam/internet 2 space are also involved.
Nancy: Please keep us up to date
Dean: we will
Justin: do we have a formal liasion relationship with OpenID and IETF?
Mike: No
Aaron: is that okay?
Nancy: it's pretty much the same people
Justin: our relationship with CNCF is also informal.
Nancy: deliberate, but informal
Mike Jones: There is a very long history of cooperation between OpenID
and IETF. OAuth, JOSE, etc. This works because people are inb both
places deliberately.
Nancy: I don't see the need for formality
AOB
Nancy: any other business?
No