I think the first step would be finding the appropriate IETF group. I don't 
think this is in scope for OAuth-WG as this topic seems to be about account 
management and user credentials.
________________________________
From: Kevat Shah <kevats...@gmail.com>
Sent: Monday, August 9, 2021 16:14
To: mich...@palage.com <mich...@palage.com>
Cc: Tim Cappalli <tim.cappa...@microsoft.com>; oauth@ietf.org <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Specifications for Identity Providers

How would that work? Would we need to work with W3C to ensure conformity of 
standards?

On Mon, Aug 9, 2021, 4:11 PM <mich...@palage.com<mailto:mich...@palage.com>> 
wrote:

Although the IETF has been involved in Best Commercial Practices (BCP) (see 
https://www.ietf.org/rfc/bcp-index.txt<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Frfc%2Fbcp-index.txt&data=04%7C01%7CTim.Cappalli%40microsoft.com%7C41ce5aec4d7a4cf7efef08d95b726f93%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637641369333693489%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=cDC15G1s1n4JCY%2Fk5vFDDyCj6WF%2Bhd8Pd4Fq0JNEIzQ%3D&reserved=0>
 )  which I think was the subject of Kevat’s original email.



So perhaps this is a subject matter that could co-exist in both the IETF and 
W3C?







From: OAuth <oauth-boun...@ietf.org<mailto:oauth-boun...@ietf.org>> On Behalf 
Of Tim Cappalli
Sent: Monday, August 9, 2021 4:06 PM
To: kevats...@gmail.com<mailto:kevats...@gmail.com>
Cc: oauth@ietf.org<mailto:oauth@ietf.org>
Subject: Re: [OAUTH-WG] Specifications for Identity Providers



I don't think there is explicit ownership, but generally password and magic 
link type "stuff" happens in W3C.



There are existing work efforts around standardizing password reset endpoint 
discovery, password complexity schemas, etc.

________________________________

From: Kevat Shah <kevats...@gmail.com<mailto:kevats...@gmail.com>>
Sent: Monday, August 9, 2021 16:03
To: Tim Cappalli <tim.cappa...@microsoft.com<mailto:tim.cappa...@microsoft.com>>
Cc: oauth@ietf.org<mailto:oauth@ietf.org> 
<oauth@ietf.org<mailto:oauth@ietf.org>>
Subject: Re: [OAUTH-WG] Specifications for Identity Providers



You don't often get email from kevats...@gmail.com<mailto:kevats...@gmail.com>. 
Learn why this is important<http://aka.ms/LearnAboutSenderIdentification>

That's a good point. Is it fair to assume that W3C owns the standards for most 
(if not all) standards related to Identity Providers? Or does it make sense for 
IETF to start setting these standards in cases where W3C standards don't exist?



- Kevat

On Mon, Aug 9, 2021, 2:56 PM Tim Cappalli 
<tim.cappa...@microsoft.com<mailto:tim.cappa...@microsoft.com>> wrote:

I believe this topic would be more W3C scope, not IETF.



tim

________________________________

From: OAuth <oauth-boun...@ietf.org<mailto:oauth-boun...@ietf.org>> on behalf 
of Kevat Shah <kevats...@gmail.com<mailto:kevats...@gmail.com>>
Sent: Sunday, August 8, 2021 16:37
To: oauth@ietf.org<mailto:oauth@ietf.org> 
<oauth@ietf.org<mailto:oauth@ietf.org>>
Subject: [OAUTH-WG] Specifications for Identity Providers



Some people who received this message don't often get email from 
kevats...@gmail.com<mailto:kevats...@gmail.com>. Learn why this is 
important<http://aka.ms/LearnAboutSenderIdentification>

I propose that we expand upon specific functionality provided by Identity 
Providers (IdPs) and tasks handled by them.



To start with, there should be clear specifications for various functionalities 
that IdPs provide such as:



- Email verification on registration

- Specifications regarding "forgot password" functionality

- Specifications regarding "resest password" functionality for users that are 
logged in





These specifications only pertain to Identity Providers, and allow an 
industry-wide set of rules that each Identity Provider must follow. The purpose 
of doing so would be to standardize various frequently used and implemented 
flows that are secure and widely reusable.







Some problems that would be addressed by these specifications would be:



- How to securely implement functionality where a user is sent a link to verify 
their email address



- How to securely implement functionality where a user is sent a verification 
code to verify their email address



- How to securely implement functionality where a user is sent a link to reset 
their password



- How to securely implement functionality where a user is sent a verification 
code to reset their password






_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to