Internet Engineering Task Force (IETF) L. Johansson
Request for Comments: 6711 NORDUNet
Category: Informational August 2012
ISSN: 2070-1721
An IANA Registry for Level of Assurance (LoA) Profiles
Johansson Informational [Page 1]
RFC 6711 LoA Registry August 2012
Table of Contents
1. Introduction
This document establishes an IANA registry for Level of Assurance (LoA) Profiles.
Johansson Informational [Page 2]
RFC 6711 LoA Registry August 2012
For instance, OpenID Connect defines the standard claim 'acr' as a identifier that may reference a SAML Authentication Context Class even though OpenID Connect is not itself based on XML or SAML.
2. Name of Registry
The name of the registry shall be "Level of Assurance (LoA) Profile", in plural "Level of Assurance (LoA) Profiles".
3. Registration Template
The following information must be provided with each registration:
Johansson Informational [Page 3]
RFC 6711 LoA Registry August 2012
label = ( ALPHA / DIGIT ) name = label 1*( label / "-" / "." / "_" )
3.1. Example Registration
1. Name of requester: J. Random User
Johansson Informational [Page 4]
RFC 6711 LoA Registry August 2012
<xs:documentation>
3.2. Note on the Example
The example is borrowed (slightly modified) from [SAML]. The example should not be registered.
4. Registration Policy
The registry is to be operated under the "Expert Review" policy from RFC 5226 [RFC5226], employing a pool of experts. IANA will be kindly asked to do rough, randomized load-balancing among the experts and also to perform an initial review of each submission to ensure that the name and URI are unique within the registry. The review criteria are outlined below.
4.1. Reviewer Expectations
The expectation of the IANA LoA Registry is that it will contain registrations of bona fide Level of Assurance Profiles while not presenting a very high bar for entry. Expert reviewers are expected to verify that:
Johansson Informational [Page 5]
RFC 6711 LoA Registry August 2012
o the registration is consistent and that the provided XML fulfills the requirements of [SAML].
5. Registry Semantics
The intended use for this registry is to serve as a basis for discovery of LoA definitions that might, for instance, be used by protocol-specific (e.g., SAML 2.0 or OpenID Connect) management tools.
6. IANA Considerations
This document sets up a registry with IANA, making the whole document a set of considerations for IANA.
Johansson Informational [Page 6]
RFC 6711 LoA Registry August 2012 7. Security ConsiderationsThe registry is not a federation or trust framework. Consumers of the registry are strongly advised to review the information about an LoA before relying on it.
8. Acknowledgements
RL "Bob" Morgan, Scott Cantor, Lucy Lynch, and John Bradley were involved in the initial discussions around this idea and contributed to the semantics of the registry. The various versions of the document were socialized in the Kantara Federation Interoperability WG and in other parts of the identity community.9. References 9.1. Normative References[RFC5234] Crocker, D. and P. Overell, "Augmented BNF for Syntax
9.2. Informative References
[RFC4949] Shirey, R., "Internet Security Glossary, Version 2",