Internet-Draft | SCHAC URN Namespace | April 2021 |
Milinovic | Expires 22 October 2021 | [Page] |
This document describes a Uniform Resource Name (URN) namespace for the Schema for Academia (SCHAC).¶
The namespace described in this document is for naming persistent resources defined by the SCHAC participants internationally, their working groups, and other designated subordinates. The main use of this namespace will be for the creation of controlled vocabulary values for attributes in the SCHAC schema. These values will be associated with particular instances of persons or objects belonging to any of the SCHAC object classes.¶
This document obsoletes RFC 6338.¶
This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.¶
Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.¶
Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."¶
This Internet-Draft will expire on 22 October 2021.¶
Copyright (c) 2021 IETF Trust and the persons identified as the document authors. All rights reserved.¶
This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Simplified BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Simplified BSD License.¶
The Schema for Academia (SCHAC) international activity was born inside the Task Force on European Middleware Coordination and Collaboration (TF-EMC2) of the Trans-European Research and Education Networking Association (TERENA) ([7]). The initial aim of SCHAC was to harmonize the disjoint person schemas of the participating countries in order to have a common way for expressing data about persons, exchanged between educational organizations. SCHAC, as are other person schemas, is designed to ease the sharing of information about a given individual between parties, mostly, but not limited to, educational and research institutions. The main aims of this sharing are to provide resources to individuals and to allow said individuals to move, virtually and physically, between such institutions. Thus, the SCHAC schema [8] was defined with input from all participants' national person schemas.¶
SCHAC does not supplant other person schemas such as organizationalPerson [9], inetOrgPerson [10], or eduPerson [12]; it extends those where needed for the purposes of Higher Education outside the United States. This characteristic has made SCHAC, originally a European effort, useful for groups outside Europe.¶
TERENA joined forces with DANTE in 2014 to become the organization known as GEANT[20]. At the same time, TERENA delegated schema management to REFEDS[19]. This document changes the definition of the SCHAC URN namespace accordingly, and obsoletes RFC 6338 [11].¶
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 (RFC2119) [1] (RFC8174) [2].¶
Registration Version Number 2¶
Registration Date: 2019-10-30¶
REFEDS c/o GÉANT Hoekenrode 3 1102 BR Amsterdam The Netherlands Designated contacts: Contact: Schema Editorial Board Affiliation: REFEDS, GÉANT Hoekenrode 3 1102 BR Amsterdam The Netherlands EMail: schema-board@lists.refeds.org Syntactic structure:¶
SCHAC-NSS = 1*subStChar *( ":" 1*subStChar ) subStChar = trans / "%" HEXDIG HEXDIG trans = ALPHA / DIGIT / other / reserved other = "(" / ")" / "+" / "," / "-" / "." / "=" / "@" / ";" / "$" / "_" / "!" / "*" / "'" reserved = "/" / "?" / "#"¶
REFEDS will create an initial series of immediately subordinate naming authorities, and will define a process for adding to that list of authorities. Such a list, and the policy for adding to it, will be published at the root registry page. Each country with a representative in SCHAC will be invited to designate a naming authority. Country-specific namespaces based on the country Internet Top-Level Domain (TLD) [14] will then be assigned to the designated authority. The subordinated namespaces int and eu will remain under REFEDS authority, controlled by the SCHAC activity members, for entities of global, international, or European interest. There is also the possibility of granting subordinate namespaces to multi-country organizations; in this case, the organizational Internet Fully Qualified Domain Name (FQDN) will be used as the prefix.¶
As an example, a European-level interest entity would be any value related to information used in the Higher Education European Space, or the so-called Bologna process. Such entities will belong in the eu subordinate namespace.¶
Global international entities could encompass values related to the Grid community or values useful both for some European and for some Australian universities. Such entities would belong in the int subordinate namespace.¶
Examples of multi-country organizations include GEANT itself or an association like the Educational Policy Institute (EPI) (educationalpolicy.org) that has members from Australia, Canada, and the US.¶
URNs intended for values of SCHAC attributes will include the attribute name immediately after the NSS prefix, before any geographical namespace delegation, such that any string can convey information about the attribute for which it is a value. For example, values for schacUserStatus will be of the form:¶
urn:schac:userStatus:int urn:schac:userStatus:au or urn:schac:userStatus:terena.org¶
The namespace is not currently listed with a Resolution Discovery System (RDS), but nothing about the namespace prohibits the future definition of appropriate resolution methods or listing with an RDS.¶
REFEDS will maintain a registry of all SCHAC-assigned URN values, both final and for delegation, on its web site:¶
https://wiki.refeds.org/display/STAN/SCHAC+URN+Registry¶
Delegation entries will have a pointer to the registry of the subordinate naming authority. This SHOULD recurse down the delegation tree, but registries for several delegated namespaces MAY be maintained by a single naming authority.¶
All registries MUST publish their URNs over https links (RFC2818) [4]. The https links MUST be secured by sites offering credentials signed by a SCHAC-community recognized Certification Authority (CA) using the latest secure methods for accessing a web site (which at present is the latest version of Transport Layer Security (TLS) (RFC5246) [5]). Registries SHOULD consider the user interface implications of their choice of CA, taking into account issues like browser alerts and blind trust.¶
The following examples are not guaranteed to be real. They are listed for pedagogical reasons only.¶
There are no additional security considerations beyond those normally associated with the use and resolution of URNs in general.¶
In order to guarantee the validity and origin of SCHAC-NSS URN values, they MUST be published over https links (RFC2818) [4]. The https links MUST be secured by sites offering credentials signed by a SCHAC- community recognized Certification Authority (CA) using the latest secure methods for accessing a web site (which at present is the latest version of TLS (RFC5246) [5]).¶
Registration of a Namespace Identifier (NID) specific to SCHAC is reasonable given the following considerations:¶
Some of the already defined SCHAC attribute values have been assigned URNs under the urn:mace:terena.org namespace. These values will enter a deprecation cycle, with a clear indication that they will be replaced by values under the new namespace once it is assigned. In any case, RFC3406 [6] (which replaced RFC 2611) includes an explicit statement that two or more URNs may point to the same resource.¶
The assignment and use of identifiers within the namespace are open, and the related rule is established by the SCHAC activity members. Registration agencies (the next-level naming authorities) will be the National Research and Education Networks (NRENs) and established organizational cross-border organizations that participate in SCHAC.¶
It is expected that the majority of the European NRENs, their constituencies, participants in the Australian Access Federation, and some other international activities will make use of the SCHAC namespace.¶
After the establishment of the SCHAC namespace, TERENA established a registry service (analogously to other distributed pan-European services, such as eduroam, PerfSONAR, etc.) for the namespace clients. This registry is now maintained by REFEDS and available via: https://wiki.refeds.org/display/STAN/SCHAC+URN+Registry. The policy for registrations will be defined in documents available at the root page of the registry.¶
In accordance with BCP 66 (RFC3406) [6], IANA has registered the Formal URN Namespace 'schac' in the Registry of URN Namespaces, using the registration template presented in Section 2 of this document.¶
The original registration of SCHAC was done by Victoriano Giralt (University of Malaga) and Dr. Rodney McDuff (The University of Queensland) for their work on the original specification. Their work remains much appreciated.¶
SCHAC was the result of the TERENA TF-EMC2 task force and many others that have contributed ideas to the development of the schema.¶
Peter Saint-Andre has also provided comments that have improved the overall document quality, for which we herein thank him. We'd also like to thank Chris Lonvick for helping us express our security concerns in a better way. Finally, we thank other reviewers that have helped us to give the final touches to the text.¶
Special thanks should go to Dyonisius Visser from the TERENA technical team for taking the time and effort required to set up the root instance of the namespace registry.¶