Network Working Group | L. Johansson |
Internet-Draft | NORDUNet |
Intended status: Informational | April 02, 2011 |
Expires: October 04, 2011 |
An IANA registry for SAML 2.0 Level of Assurance Context Classes
draft-johansson-loa-registry-00
This document establishes an IANA registry for Level of Assurance Context Classes for SAML 2.0. The registry is intended to be used as an aid to discovering such LoA definitions.
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in RFC 2119 [RFC2119].
This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.
Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at http://datatracker.ietf.org/drafts/current/.
Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."
This Internet-Draft will expire on October 04, 2011.
Copyright (c) 2011 IETF Trust and the persons identified as the document authors. All rights reserved.
This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (http://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Simplified BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Simplified BSD License.
This document establishes an IANA registry for Level of Assurance Context Profiles for SAML 2.0. Such objects are XML schema definitions that fulfil the requirements of sstc-saml-loa-authncontext-profile-draft-01 [OASIS.sstc.saml-loa-authncontext-profile-draft-01]. Quoting from this specification we find the following definition of the concept of level of assurance:
Many existing (and potential) SAML federation deployments have adopted a “levels of assurance” (or LOA) model for categorizing the wide variety of authentication methods into a small number of levels, typically based on some notion of the strength of the authentication. Federation members (service providers or “relying parties”) then decide which level of assurance is required to access specific protected resources, based on some assessment of “value” or “risk”.
Several so called trust frameworks and identity federations now exist, some of which define one or more LoAs. The purpose of this specification is to create an IANA registry where such LoA definitions can be discovered.
The name of the registry shall be "SAML 2.0 LoA Context Class", in plural "SAML LoA Context Classes". The term LoA is an abbreviation of Level of Assurance.
The following information MUST be provided with each registration:
Note that it is not uncommon for a single XML Schema to contain definitions of multiple URIs. In that case the registration MUST be repeated for each URI. Since the registry key (the URI) is unique by design there is no need for namespace management for this registry.
The registry is to be operated under the "Designated Expert Review" policy from RFC5226 [RFC5226] employing a pool of experts. IANA is kindly asked to do rough randomized load-balancing among the experts. The initial pool of expert and the review criteria are outlined below.
The intent is that the IANA LoA Registry contain URIs that represent bona fide SAML 2.0 LoA Context Class definitions while not presenting a very high bar for entry. Expert reviewers SHOULD not place undue value in any percieved or actual quality of the associated trust framework or federation and SHOULD only exclude those registrations that in the view of the experts do not represent a bona fide attempt at defining an LoA.
The designated experts are also expected to verify that the registration is consistent and that the XML is schema valid and fulfills the requirements of sstc-saml-loa-authncontext-profile-draft-01 [OASIS.sstc.saml-loa-authncontext-profile-draft-01].
TBD
The intended use for this registry is to serve as a basis for discovery of LoA definitions for instance in SAML tools. Consumers of the registry MUST NOT treat it as a complete list of all LoA definitions and MUST provide a way for the user to provide additional LoA Context Class definitions by other means. It is not expected that all LoA definitions will want to be registered with IANA.
The presense of an entry in the registy MUST NOT be taken to imply any semantics beyond the review done by the expert reviewers as part of the registration process.
This document sets up a registry with IANA making the whole document a set of considerations for IANA.
An implementor of SAML MUST NOT treat the list of Level of Assurance URIs as a trust framework and MUST NOT make any assumptions about the quality or properties of any of the listed Level of Assurance URIs.
Bob 'RL' Morgan, Scott Cantor, Lucy Lynch and John Bradley were involved in the initial discussions around this idea and contributed to the semantics of the registry.
[RFC2119] | Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997. |
[RFC5226] | Narten, T. and H. Alvestrand, "Guidelines for Writing an IANA Considerations Section in RFCs", BCP 26, RFC 5226, May 2008. |
[OASIS.sstc.saml-loa-authncontext-profile-draft-01] | Tiffany, E., Madsen, P. and S. Cantor, "Level of Assurance Authentication Context Profiles for SAML 2.0", July 2008. |