usnistgov / NISTIR-8112

Attribute Metadata Publication
4 stars 11 forks source link

Verifier may not be Origin nor AP, Provider versus Source. #50

Closed JaapFrancke closed 7 years ago

JaapFrancke commented 7 years ago

Organization: 2 Type:

Reference (Include section and paragraph number): 4.2

Comment (Include rationale for comment): The report distinguishes between the following parties:

The allowed/recommended values for the Verifier-attribute suggest it's either the Origin or the Provider that is verifying the attribute. It may however be the case that an attribute is verified by neither Origin nor AP. In this case the Pedigree could be "Sourced".

An IDP could act as a attribute 'proxy', acting as a RP towards one or more APs and acting as a AP to various RPs. Note that section recognizes sources other than Origin. In a similar fashion, it makes sense to recognize different Verifiers

Suggested Change: The report could suggest as possible values for Verfier:

Alternately, the report could explain that the "Provider" (Provenance), does NOT have to be the Attribute Provider itself. In the 2nd use case it says "Verifier: Provider: The clearance was verified by the IDP (also acting as the AP in this instance)", so that suggests that indeed the "Provider" does not have to be the AP. The example in section 4.2 could be improved to give an example value for the Provider attribute, indicating the relevant IDP.

Extending the previous remark, I would suggest


Organization: 1 = Federal, 2 = Industry, 3 = Other 
RGalluzzo commented 7 years ago

We opted to go with a clarifying statement RE:the "provider" does not have be the AP itself.