1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
|
Internet Engineering Task Force (IETF) S. Martin
Request for Comments: 7853 S. Tuecke
Category: Informational B. McCollam
ISSN: 2070-1721 M. Lidman
University of Chicago
May 2016
A URN Namespace for Globus
Abstract
This document describes a URN (Uniform Resource Name) namespace to be
used by Globus for naming persistent resources.
Status of This Memo
This document is not an Internet Standards Track specification; it is
published for informational purposes.
This document is a product of the Internet Engineering Task Force
(IETF). It represents the consensus of the IETF community. It has
received public review and has been approved for publication by the
Internet Engineering Steering Group (IESG). Not all documents
approved by the IESG are a candidate for any level of Internet
Standard; see Section 2 of RFC 5741.
Information about the current status of this document, any errata,
and how to provide feedback on it may be obtained at
http://www.rfc-editor.org/info/rfc7853.
Copyright Notice
Copyright (c) 2016 IETF Trust and the persons identified as the
document authors. All rights reserved.
This document is subject to BCP 78 and the IETF Trust's Legal
Provisions Relating to IETF Documents
(http://trustee.ietf.org/license-info) in effect on the date of
publication of this document. Please review these documents
carefully, as they describe your rights and restrictions with respect
to this document. Code Components extracted from this document must
include Simplified BSD License text as described in Section 4.e of
the Trust Legal Provisions and are provided without warranty as
described in the Simplified BSD License.
Martin, et al. Informational [Page 1]
^L
RFC 7853 A URN Namespace for Globus May 2016
Table of Contents
1. Introduction .................................................. 2
2. Specification Template ........................................ 3
3. Examples (Informative) ........................................ 5
4. Namespace Considerations ...................................... 5
5. Community Considerations ...................................... 6
6. Security Considerations ....................................... 6
7. IANA Considerations ........................................... 6
8. Normative References .......................................... 6
Acknowledgments .................................................. 7
Authors' Addresses ............................................... 7
1. Introduction
Globus (https://www.globus.org) is a software-as-a-service provider
that develops and operates services and tools for the global research
and education community.
Globus provides multiple services for users across many institutions,
primarily for research driven by high-performance computing. Globus
creates unique identifiers that will persist in external systems and
must be identifiable as references to Globus entities.
To address this need, this document requests that a formal URN space
type be assigned as described in Section 4.3 of [RFC3406].
Martin, et al. Informational [Page 2]
^L
RFC 7853 A URN Namespace for Globus May 2016
2. Specification Template
Namespace ID:
globus
Registration Information:
Version 1
Date: 2016-03-18
Declared Registrant of the Namespace:
Globus Project Lead
401 N Michigan Ave
Suite 900
Chicago, Illinois 60611
USA
Email: tuecke@globus.org
The position of Globus Project Lead is currently filled by Steve
Tuecke.
Declaration of Syntactic Structure:
The Namespace Specific String (NSS) of all URNs that use the
"globus" NID shall have the following structure:
<URN> ::= "urn:" "globus" ":" <NSS>
<NSS> ::= <SNID> | <SNID> ":" <subnamespace-specific-string>
<SNID> ::= 1*<non-colon-chars>
<subnamespace-specific-string> ::= 1*<URN chars>
<non-colon-chars> ::= <non-colon-trans> | "%" <hex> <hex>
<non-colon-trans> ::= <upper> | <lower> | <number> |
<non-colon-other>
<non-colon-other> ::= "(" | ")" | "+" | "," | "-" | "." | "=" |
"@" | ";" | "$" | "_" | "!" | "*" | "'"
The "SNID" is the top-level segment of the NSS. It is a required
US-ASCII string, subject to the above syntax, that conforms to the
URN syntax requirements (see [RFC2141]). It identifies a category
Martin, et al. Informational [Page 3]
^L
RFC 7853 A URN Namespace for Globus May 2016
of Globus entities, often associated with a particular Globus
service. For example "auth" could be used as an SNID for
identifiers generated by the Globus authentication and
authorization service (Globus Auth).
The "subnamespace-specific-string" is an optional US-ASCII string
and second-level segment of the NSS, belonging to the "SNID"
context, subject to the above syntax and conformant to the URN
syntax requirements (see [RFC2141]). "subnamespace-specific-
string" identifies a category of thing within that Globus service,
such as "scope:transfer.api.globus.org:all"
Relevant Ancillary Documentation:
None.
Identifier Uniqueness Considerations:
Identifier uniqueness will be enforced by the Globus Project Lead.
The Globus Project Lead may sub-delegate part of the namespace to
third parties. It will not be permissible, neither by the Globus
Project Lead nor any third party, to reassign previously assigned
URNs. A practical consequence is that a previously assigned
subnamespace cannot be reassigned, unless additional arrangements
are made to prevent identifier reassignments.
Identifier Persistence Considerations:
Identifiers will never be reassigned, but in some circumstances
they may be invalidated by the Globus Project Lead or by a third
party.
Process of Identifier Assignment:
Assignment of subnamespace identifiers is limited to the Globus
Project Lead and those authorities that are specifically
designated by the Globus Project Lead. The Globus Project Lead
may assign portions of the globus namespace (specifically, those
under designated subnamespace identifiers) for assignment by third
parties.
Process of Identifier Resolution:
None currently.
Future versions of this document may define resources that can be
used to resolve Globus identifiers.
Martin, et al. Informational [Page 4]
^L
RFC 7853 A URN Namespace for Globus May 2016
Rules for Lexical Equivalence:
No additional rules beyond those specified in RFC 2141.
Conformance with URN Syntax:
No special considerations.
Validation Mechanism:
None currently.
Future versions of this document may define resources that can be
used to validate Globus identifiers.
Scope:
Global.
3. Examples (Informative)
The following examples are based on plans for the Globus URN. They
are therefore not guaranteed to be valid.
The Globus Auth service defines the "auth" SNID and contains the
following URNs:
o urn:globus:auth:scope:transfer.api.globus.org:all
o urn:globus:auth:grants:dependent_token
A hypothetical service, the Globus Groups service, would have a
distinct SNID. If that SNID were "groups", it might have URNs such
as the following:
o urn:globus:groups:group:669b572e-9de4-11e5-966e-3c970e0c9cc4
o urn:globus:groups:memberships:72e1c6c6-9de4-11e5-966e-3c970e0c9cc4
4. Namespace Considerations
The current set of existing IANA namespaces are insufficient because
Globus will be creating unique identifiers that will persist in the
external system; these identifiers must be identifiable as references
to Globus entities.
Martin, et al. Informational [Page 5]
^L
RFC 7853 A URN Namespace for Globus May 2016
The use of the Globus namespace is expected to be broad, including
but not limited to usage for:
o OAuth2 scopes (see [RFC6749])
o OAuth2 custom extension grants
o Entity identification for Globus Services
5. Community Considerations
Members of the Globus community will benefit from persistent and
globally unique identifiers for use in software and in conformance
with protocols developed and used by Globus and third-party
collaborators.
6. Security Considerations
There are no special meanings for characters in the NSS. Thus, there
are no additional security considerations other than those normally
associated with the use and resolution of URNs in general, which are
described in [RFC1737] and [RFC2141].
7. IANA Considerations
IANA has registered the "globus" namespace identifier (NID) in the
"Formal URN Namespaces" registry located at
<http://www.iana.org/assignments/urn-namespaces>.
8. Normative References
[RFC1737] Sollins, K. and L. Masinter, "Functional Requirements for
Uniform Resource Names", RFC 1737, DOI 10.17487/RFC1737,
December 1994, <http://www.rfc-editor.org/info/rfc1737>.
[RFC2141] Moats, R., "URN Syntax", RFC 2141, DOI 10.17487/RFC2141,
May 1997, <http://www.rfc-editor.org/info/rfc2141>.
[RFC3406] Daigle, L., van Gulik, D., Iannella, R., and P. Faltstrom,
"Uniform Resource Names (URN) Namespace Definition
Mechanisms", BCP 66, RFC 3406, DOI 10.17487/RFC3406,
October 2002, <http://www.rfc-editor.org/info/rfc3406>.
[RFC6749] Hardt, D., Ed., "The OAuth 2.0 Authorization Framework",
RFC 6749, DOI 10.17487/RFC6749, October 2012,
<http://www.rfc-editor.org/info/rfc6749>.
Martin, et al. Informational [Page 6]
^L
RFC 7853 A URN Namespace for Globus May 2016
Acknowledgments
The authors would like to thank Stephen Rosen and Vas Vasiliadis for
proofreading this document and providing valuable feedback.
Authors' Addresses
Stuart Martin
University of Chicago
401 N Michigan Ave
Suite 900
Chicago, Illinois 60611
United States
Email: sjmartin@uchicago.edu
Steve Tuecke
University of Chicago
401 N Michigan Ave
Suite 900
Chicago, Illinois 60611
United States
Email: tuecke@globus.org
Brendan McCollam
University of Chicago
401 N Michigan Ave
Suite 900
Chicago, Illinois 60611
United States
Email: bmccollam@uchicago.edu
Mattias Lidman
University of Chicago
401 N Michigan Ave
Suite 900
Chicago, Illinois 60611
United States
Email: mattias@uchicago.edu
Martin, et al. Informational [Page 7]
^L
|