Skip to main content

IETF Last Call Review of draft-ietf-scim-events-10
review-ietf-scim-events-10-opsdir-lc-iannone-2025-09-26-00

Request Review of draft-ietf-scim-events
Requested revision No specific revision (document currently at 16)
Type IETF Last Call Review
Team Ops Directorate (opsdir)
Deadline 2025-10-01
Requested 2025-09-11
Requested by Mohamed Boucadair
Authors Phillip Hunt , Nancy Cam-Winget , Mike Kiser , Jen Schreiber
I-D last updated 2026-05-14 (Latest revision 2025-11-02)
Completed reviews Dnsdir IETF Last Call review of -09 by R. (Miek) Gieben (diff)
Genart IETF Last Call review of -10 by Elwyn B. Davies (diff)
Opsdir IETF Last Call review of -10 by Luigi Iannone (diff)
Artart IETF Last Call review of -09 by Shuping Peng (diff)
Assignment Reviewer Luigi Iannone
State Completed
Request IETF Last Call review on draft-ietf-scim-events by Ops Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/ops-dir/1xGqG6bUGqLCU7D9Wn-ZaLjMZWs
Reviewed revision 10 (document currently at 16)
Result Has nits
Completed 2025-09-26
review-ietf-scim-events-10-opsdir-lc-iannone-2025-09-26-00
Hi,

I have reviewed this document as part of the OPS area directorate's ongoing
effort to review all IETF documents being processed by the IESG.

To me the document is: Ready with Nits

This document defines a set of SCIM Security Events, as extension of what is
already defined in [RFC8417], and defines as well an asynchronous communication
model. It is well written and easy to follow.

Nits:

The abstract and introduction may be more clear about the fact that while
asynchronous communication is possible, it is not mandatory.

The documents contains a lot of non-ascii characters. I would invite the
authors to provide an markdown or xml source that generates ascii-only .txt
file and svg figures for the other formats.

The example figures in Section 2 are cited inconsistently in the text
(sometimes are cited sometimes not). I would suggest to put explicit references
in the text for all figures.

In Section 4 (Security Considerations), in the bullet:

- Avoid use of SCIM PUT (Section 3.5.1 [RFC7644]) operations on large groups as
this may require excessive locking in data store systems as well as large
Security Event payloads. Use SCIM PATCH (Section 3.5.2) to focus on updating
and notifying about changed information.

I wonder whether wouldn't be better to add RECOMMENDED for the use of SCIM
PATCH.

Section 6.4, in the reference column of the table add [This Document], to make
sure that IANA will add the RFC number of these specifications when published.