<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.29 (Ruby 3.4.4) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-spice-glue-id-02" category="std" consensus="true" submissionType="IETF" xml:lang="en" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.31.0 -->
  <front>
    <title abbrev="SPICE GLUE">GLobal Unique Enterprise (GLUE) Identifiers</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-spice-glue-id-02"/>
    <author fullname="Brent W. Zundel">
      <organization/>
      <address>
        <postal>
          <country>United States</country>
        </postal>
        <email>brent.zundel@gmail.com</email>
      </address>
    </author>
    <author fullname="Pamela Dingle">
      <organization>Microsoft Corporation</organization>
      <address>
        <postal>
          <country>United States</country>
        </postal>
        <email>pamela.dingle@microsoft.com</email>
      </address>
    </author>
    <author initials="M. B." surname="Jones" fullname="Michael B. Jones">
      <organization>Self-Issued Consulting</organization>
      <address>
        <postal>
          <country>United States</country>
        </postal>
        <email>michael_b_jones@hotmail.com</email>
        <uri>https://self-issued.info/</uri>
      </address>
    </author>
    <date year="2025" month="October" day="20"/>
    <area>Security</area>
    <workgroup>Secure Patterns for Internet CrEdentials</workgroup>
    <keyword>URI</keyword>
    <keyword>URN</keyword>
    <keyword>Enterprise</keyword>
    <keyword>Entity Identifiers</keyword>
    <abstract>
      <?line 56?>

<t>This specification establishes an IETF URN namespace for
GLobal Unique Enterprise (GLUE) Identifiers.
It also establishes an IETF URN namespace for identifiers addressing the
requirements identified by the IETF Secure Patterns for Internet CrEdentials
(SPICE) working group.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://ietf-wg-spice.github.io/draft-ietf-spice-glue-id/draft-ietf-spice-glue-id.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-spice-glue-id/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Secure Patterns for Internet CrEdentials Working Group mailing list (<eref target="mailto:spice@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/spice/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/spice/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/ietf-wg-spice/draft-ietf-spice-glue-id"/>.</t>
    </note>
  </front>
  <middle>
    <?line 65?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>There are a myriad of entity identifier types for businesses and organizations.
With the increasing use of digital credentials, there is a need for a common
methodology for expressing these identifiers such that claims about and by such
entities can be made in a consistent and interoperable manner.</t>
      <t>This specification establishes an IETF URN namespace that standardizes the expression of
existing organizational entity identifiers by providing a common representation format.
It also establishes a registry for managing how existing organizational entity
identification mechanisms relate to this namespace.</t>
      <t>Any organizational entity identifier whose identification mechanism has been registered
as an Authority Identifier in the registry may be represented as a GLUE URI.</t>
      <section anchor="requirements-notation-and-conventions">
        <name>Requirements Notation and Conventions</name>
        <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
        <?line -18?>

</section>
      <section anchor="terminology">
        <name>Terminology</name>
        <t>This specification uses the following terms:</t>
        <dl>
          <dt>GLUE URI:</dt>
          <dd>
            <t>a URI that uses the GLUE URN namespace established in this specification.</t>
          </dd>
          <dt>External Authority:</dt>
          <dd>
            <t>an organization that allocates External Identifiers for GLUE URIs using the Authority Identifier(s) over which they have jurisdiction.</t>
          </dd>
          <dt>Authority Identifier:</dt>
          <dd>
            <t>identifier for the External Authority responsible for assigning the External Identifier used in GLUE URIs.</t>
          </dd>
          <dt>External Identifier:</dt>
          <dd>
            <t>identifier assigned by an External Authority to identify a particular organization within GLUE URNs over which it has jurisdiction.</t>
          </dd>
        </dl>
      </section>
    </section>
    <section anchor="core-concepts">
      <name>Core Concepts</name>
      <t>Every GLUE URI <bcp14>MUST</bcp14>
contain the following components:</t>
      <ul spacing="normal">
        <li>
          <t>The Authority Identifier</t>
        </li>
        <li>
          <t>The External Identifier</t>
        </li>
      </ul>
      <section anchor="uniqueness-and-namespacing">
        <name>Uniqueness and Namespacing</name>
        <t>Each GLUE URI <bcp14>MUST</bcp14> be globally unique.</t>
        <t>It is assumed that most registered organizational entity identification schemes
already handle any necessary namespacing as part of the External Identifier.
However, if collisions are possible within the set of possible external
identifiers for an Authority Identifier scheme, then further namespacing is
necessary at the GLUE URI level. Such namespacing <bcp14>MUST</bcp14> be done on the Authority
Identifier. The combination of the namespacing and the authority <bcp14>MUST</bcp14> result in
a unique Authority Identifier.</t>
        <t>For example, assume there is an External Authority FEA that provides identifiers
for organizations in Singapore and South Korea. The identifiers issued in
Singapore are unique within Singapore, and the identifiers issued in South Korea
are unique within South Korea, but there is no guarantee that an organization in
Singapore will not be assigned the same identifier as an organization in South
Korea. Upon registration of FEA as an Authority Identifier, it would be
necessary to separately register two different Authority Identifiers (e.g.,
FEA-SG and FEA-KR) to provide differentiation between the two sets of External
Identifiers.</t>
      </section>
    </section>
    <section anchor="glue-uris">
      <name>GLUE URIs</name>
      <t>All GLUE URIs comply with <xref target="RFC3986"/>.
They begin with <tt>urn:ietf:spice:glue:</tt> and are followed by an Authority Identifier,
a colon character (":"), and the External Identifier allocated by the authority.</t>
      <t>Authority Identifiers consist of a sequence of characters beginning with a letter and
followed by any combination of letters, digits, plus ("+"), period ("."), or hyphen ("-").
Although Authority Identifiers are case-insensitive, the canonical form is lowercase
and documents that specify Authority Identifiers must do so with lowercase letters.
An implementation should accept uppercase letters as equivalent to lowercase
in Authority Identifier names (e.g., allow "EXAMPLE" as well as "example")
for the sake of robustness but should only produce
lowercase Authority Identifier names for consistency.
The ABNF [RFC5234] for Authority Identifiers is:</t>
      <t><tt>
authority-identifier = ALPHA *( ALPHA / DIGIT / "+" / "-" / "." )
</tt></t>
      <t>External Identifiers consist of a sequence of characters beginning with
a letter or digit or hyphen ("-") and
followed by any combination of letters, digits, plus ("+"), period ("."), or hyphen ("-").
A digit or hyphen is allowed as the first character to permit the case where
the External Identifier is the representation of a number.
It is specific to the Authority Identifier whether the
External Identifiers are case-insensitive or case-sensitive.
When they are case-insensitive, the canonical form is lowercase
and documents that specify External Identifiers must do so with lowercase letters.
The ABNF [RFC5234] for External Identifiers is:</t>
      <t><tt>
external-identifier = ( ALPHA / DIGIT / "-" ) *( ALPHA / DIGIT / "+" / "-" / "." )
</tt></t>
      <t>Combining these, the ABNF [RFC5234] for a GLUE URI is:</t>
      <t><tt>
glue-uri = "urn:ietf:spice:glue:" authority-identifier ":" external-identifier
</tt></t>
      <t>For example, the following is a GLUE URI using the Authority Identifier "example"
and the External Identifier "42":</t>
      <t><tt>
urn:ietf:spice:glue:example:42
</tt></t>
      <t>The Authority Identifier <bcp14>MUST</bcp14> be registered in the GLUE URI Authority Identifier registry
defined in <xref target="GLUE-URN"/>.
The External Identifier <bcp14>MUST</bcp14> be the identifier assigned to the organization
by the External Authority.</t>
    </section>
    <section anchor="authority-identifiers">
      <name>GLUE Authority Identifiers</name>
      <t>This section defines the following GLUE Authority Identifiers.</t>
      <table>
        <thead>
          <tr>
            <th align="left">Organization</th>
            <th align="left">Authority Identifier</th>
            <th align="left">External Authority Specification</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">GS1</td>
            <td align="left">gln</td>
            <td align="left">https://www.gs1.org/standards/id-keys/gln</td>
          </tr>
          <tr>
            <td align="left">GLEIF</td>
            <td align="left">lei</td>
            <td align="left">https://www.iso.org/standard/78829.html</td>
          </tr>
          <tr>
            <td align="left">Dun &amp; Bradstreet</td>
            <td align="left">duns</td>
            <td align="left">https://www.dnb.com/duns.html</td>
          </tr>
          <tr>
            <td align="left">Private Enterprise Numbers</td>
            <td align="left">pen</td>
            <td align="left">https://www.iana.org/assignments/enterprise-numbers/</td>
          </tr>
        </tbody>
      </table>
      <t>They are registered in the GLUE Authority Identifier URN Registry in <xref target="GLUE-URN"/>.</t>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>There are no additional security considerations beyond those already inherent to using URNs.
Security considerations for URNs can be found in <xref target="RFC2141"/>.</t>
    </section>
    <section anchor="privacy-considerations">
      <name>Privacy Considerations</name>
      <section anchor="private-identifiers-as-corporate-identifiers">
        <name>Private Identifiers as Corporate Identifiers</name>
        <t>There are some corporate identifiers that make use of personal identifiers. For
example, this is the case for some registered sole-proprietor businesses in the
United States, where the Tax ID may be the same as the Social Security Number
(SSN) of the business owner. Where the Tax ID uniquely identifies the business,
the SSN uniquely identifies an individual.</t>
        <t>It is possible for such business identifiers to be represented as GLUE URIs. An
identifier's expression as a GLUE URI does not change the privacy
characteristics of that identifier. The same cautions and concerns need to be
taken with the GLUE URI representation as with the original identifier.</t>
        <t>Implementers storing or evaluating GLUE URIs are encouraged to be aware the
privacy characteristics of each identification scheme represented by an
Authority Identifier and to appropriately handle any GLUE URI which violates
privacy policies.</t>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This section establishes two registries and populates them with their initial contents.
The following registration procedure is used for the
registries established by this specification.</t>
      <t>Values are registered on a Specification Required <xref target="RFC8126"/>
basis after a two-week review period on the spice-ext-review@ietf.org
mailing list, on the advice of one or more Designated Experts.
However, to allow for the allocation of values prior to publication
of the final version of a specification,
the Designated Experts may approve registration once they are satisfied
that the specification will be completed and published.
However, if the specification is not completed and published
in a timely manner, as determined by the Designated Experts,
the Designated Experts may request that IANA withdraw the registration.</t>
      <t>Registration requests sent to the mailing list for review should use
an appropriate subject
(e.g., "Request to register URN urn:ietf:spice:example" or
"Request to register URN urn:ietf:spice:glue:example").</t>
      <t>Within the review period, the Designated Experts will either approve or deny
the registration request, communicating this decision to the review list and IANA.
Denials should include an explanation and, if applicable,
suggestions as to how to make the request successful.
The IANA escalation process is followed when the Designated Experts
are not responsive within 14 days.</t>
      <t>Criteria that should be applied by the Designated Experts includes
determining whether the proposed registration duplicates existing functionality,
determining whether it is likely to be of general applicability
or whether it is useful only for a single application,
and whether the registration makes sense.</t>
      <t>IANA must only accept registry updates from the Designated Experts and should direct
all requests for registration to the review mailing list.</t>
      <t>It is suggested that multiple Designated Experts be appointed who are able to
represent the perspectives of different applications using this specification,
in order to enable broadly-informed review of registration decisions.
In cases where a registration decision could be perceived as
creating a conflict of interest for a particular Expert,
that Expert should defer to the judgment of the other Experts.</t>
      <t>The reason for the use of the mailing list is to enable
public review of registration requests, enabling both Designated Experts
and other interested parties to provide feedback on proposed registrations.
The reason to allow the Designated Experts to
allocate values prior to publication as a final specification is to enable
giving authors of specifications proposing registrations
the benefit of review by the Designated Experts
before the specification is completely done,
so that if problems are identified, the authors can iterate and fix them
before publication of the final specification.</t>
      <section anchor="SPICE-URN">
        <name>SPICE URN Registry</name>
        <t>This specification establishes the
IANA "SPICE URN" registry
creating a URN namespace for identifiers needed by
the IETF Secure Patterns for Internet CrEdentials (SPICE) working group.
The registry records the URN
and a reference to the specification that defines it.</t>
        <section anchor="registration-template">
          <name>Registration Template</name>
          <dl>
            <dt>URN:</dt>
            <dd>
              <t>The URN requested within the "urn:ietf:spice:" namespace.
The identifier following "urn:ietf:spice:"
and before any following colon (":") character
is not case sensitive and any letters <bcp14>MUST</bcp14> be expressed in lowercase characters.
This identifier <bcp14>MUST</bcp14> consist of a sequence of characters
beginning with a letter and followed by any combination of
letters, digits, plus ("+"), period ("."), or hyphen ("-").</t>
            </dd>
            <dt>Description:</dt>
            <dd>
              <t>Brief description of the purpose of the SPICE URN.</t>
            </dd>
            <dt>Change Controller:</dt>
            <dd>
              <t>For IETF stream RFCs, use "IETF".
For others, give the name of the responsible party.
Other details (e.g., postal address, e-mail address, home page URI) may also be included.</t>
            </dd>
            <dt>Specification Document(s):</dt>
            <dd>
              <t>Reference to the document or documents that specify the URN to be registered,
preferably including URLs that can be used to retrieve the documents.
An indication of the relevant sections may also be included, but is not required.</t>
            </dd>
          </dl>
        </section>
        <section anchor="initial-registry-contents">
          <name>Initial Registry Contents</name>
          <section anchor="urnietfspiceglue">
            <name>urn:ietf:spice:glue</name>
            <ul spacing="normal">
              <li>
                <t>URN: urn:ietf:spice:glue</t>
              </li>
              <li>
                <t>Description: GLUE URN namespace</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="glue-uris"/> of this specification</t>
              </li>
            </ul>
          </section>
        </section>
      </section>
      <section anchor="GLUE-URN">
        <name>GLUE Authority Identifier URN Registry</name>
        <t>This specification establishes the
IANA "GLUE Authority Identifier URN" registry
creating a URN namespace for Authority Identifiers for
GLobal Unique Enterprise (GLUE) Identifiers.</t>
        <t>Each entry registers the URN for an Authority Identifier within the
"urn:ietf:spice:glue:" namespace.
The organization responsible for the Authority Identifier is recorded.</t>
        <section anchor="registration-template-1">
          <name>Registration Template</name>
          <dl>
            <dt>Authority Identifier:</dt>
            <dd>
              <t>identifier for the External Authority responsible for assigning the External Identifier used in GLUE URIs.
This identifier
is not case sensitive and any letters <bcp14>MUST</bcp14> be expressed in lowercase characters.
It <bcp14>MUST</bcp14> consist of a sequence of characters
beginning with a letter and followed by any combination of
letters, digits, plus ("+"), period ("."), or hyphen ("-").</t>
            </dd>
            <dt>URN:</dt>
            <dd>
              <t>The URN within the "urn:ietf:spice:glue:" namespace
consisting of "urn:ietf:spice:glue:" followed by
the Authority Identifier.</t>
            </dd>
            <dt>Organization:</dt>
            <dd>
              <t>The organization responsible for the Authority Identifier.</t>
            </dd>
            <dt>Change Controller:</dt>
            <dd>
              <t>For IETF stream RFCs, use "IETF".
For others, give the name of the responsible party.
Other details (e.g., postal address, e-mail address, home page URI) may also be included.</t>
            </dd>
            <dt>Specification Document(s):</dt>
            <dd>
              <t>Reference to the document or documents that specify the Authority Identifier to be registered,
preferably including URLs that can be used to retrieve the documents.
An indication of the relevant sections may also be included, but is not required.</t>
            </dd>
          </dl>
        </section>
        <section anchor="initial-registry-contents-1">
          <name>Initial Registry Contents</name>
          <section anchor="gln">
            <name>gln</name>
            <ul spacing="normal">
              <li>
                <t>Authority Identifier: gln</t>
              </li>
              <li>
                <t>URN: urn:ietf:spice:glue:gln</t>
              </li>
              <li>
                <t>Organization: GS1</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="authority-identifiers"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="lei">
            <name>lei</name>
            <ul spacing="normal">
              <li>
                <t>Authority Identifier: lei</t>
              </li>
              <li>
                <t>URN: urn:ietf:spice:glue:lei</t>
              </li>
              <li>
                <t>Organization: GLEIF</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="authority-identifiers"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="duns">
            <name>duns</name>
            <ul spacing="normal">
              <li>
                <t>Authority Identifier: duns</t>
              </li>
              <li>
                <t>URN: urn:ietf:spice:glue:duns</t>
              </li>
              <li>
                <t>Organization: Dun &amp; Bradstreet</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="authority-identifiers"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="pen">
            <name>pen</name>
            <ul spacing="normal">
              <li>
                <t>Authority Identifier: pen</t>
              </li>
              <li>
                <t>URN: urn:ietf:spice:glue:pen</t>
              </li>
              <li>
                <t>Organization: Private Enterprise Numbers</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="authority-identifiers"/> of this specification</t>
              </li>
            </ul>
          </section>
        </section>
      </section>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC3986">
          <front>
            <title>Uniform Resource Identifier (URI): Generic Syntax</title>
            <author fullname="T. Berners-Lee" initials="T." surname="Berners-Lee"/>
            <author fullname="R. Fielding" initials="R." surname="Fielding"/>
            <author fullname="L. Masinter" initials="L." surname="Masinter"/>
            <date month="January" year="2005"/>
            <abstract>
              <t>A Uniform Resource Identifier (URI) is a compact sequence of characters that identifies an abstract or physical resource. This specification defines the generic URI syntax and a process for resolving URI references that might be in relative form, along with guidelines and security considerations for the use of URIs on the Internet. The URI syntax defines a grammar that is a superset of all valid URIs, allowing an implementation to parse the common components of a URI reference without knowing the scheme-specific requirements of every possible identifier. This specification does not define a generative grammar for URIs; that task is performed by the individual specifications of each URI scheme. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="66"/>
          <seriesInfo name="RFC" value="3986"/>
          <seriesInfo name="DOI" value="10.17487/RFC3986"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC2141">
          <front>
            <title>URN Syntax</title>
            <author fullname="R. Moats" initials="R." surname="Moats"/>
            <date month="May" year="1997"/>
            <abstract>
              <t>Uniform Resource Names (URNs) are intended to serve as persistent, location-independent, resource identifiers. This document sets forward the canonical syntax for URNs. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="2141"/>
          <seriesInfo name="DOI" value="10.17487/RFC2141"/>
        </reference>
        <reference anchor="RFC8126">
          <front>
            <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
            <author fullname="M. Cotton" initials="M." surname="Cotton"/>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <author fullname="T. Narten" initials="T." surname="Narten"/>
            <date month="June" year="2017"/>
            <abstract>
              <t>Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
              <t>To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed. This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
              <t>This is the third edition of this document; it obsoletes RFC 5226.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="26"/>
          <seriesInfo name="RFC" value="8126"/>
          <seriesInfo name="DOI" value="10.17487/RFC8126"/>
        </reference>
      </references>
    </references>
    <?line 413?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Alexander (A.J.) Stein
and
Martin Thomson
contributed to this specification.</t>
    </section>
    <section numbered="false" anchor="document-history">
      <name>Document History</name>
      <t>-02</t>
      <ul spacing="normal">
        <li>
          <t>Improved several descriptions in the specification.</t>
        </li>
      </ul>
      <t>-01</t>
      <ul spacing="normal">
        <li>
          <t>Updated Brent's affiliation.</t>
        </li>
      </ul>
      <t>-00</t>
      <ul spacing="normal">
        <li>
          <t>Initial working group draft, based on draft-zundel-spice-glue-id-02</t>
        </li>
      </ul>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+1b/XIbuZH/H0+Bo6ou0oakVl5f4mXlY2VLtpXIsk+Sz5dL
uWJwBiSxHg4mgxnRXNnvcs+SJ8uvG5gvcsi193JbqatTlS1yMAC6G92//oJG
o5EoTJHoiRw8u7RTlcjXqflrqeV5Wug8y43T8vDZ5evzI3kR67QwM6NzNxBq
Os31HWbdvLp4ci7pjYFIVDqfSJ2KSBV6bvP1RLoiFiK2UaqW2CPO1awYGV3M
Ri4zkR7Nk1KPTDz6+oFw5XRpnDM2LdYZ3r04v30q5YFUibPYx6SxznRKNAyG
cqBjU9jcqIS+XJw+xi+b49P17dOBSMvlVOcTEYOMiYhs6nTqSjeRRV5qAaq/
ESrXiqjXUZmbYj0QK5u/n+e2zKqnWr5SBWSQOjnD0hckj1QX8kl+zoIAXQPx
Xq8xMZ4IOZKvry/8ryv61cgvfMMubRGKO52WoE7KL99VSi+iwRsQbdK5fEZL
0POlMgmes3C/IzmPbT6nAZVHCwwsiiJzk+Njeo8emTs9rl47pgfH09yunD7m
FY5p5twUi3JKJ0DHtpr7kzvedZQ0JYHcXdHarjN17FccG7tzkZ0D40WxTAZC
qLJY2JzEju2knJVJ4jXscQ4pyTdj+V8ldCXhUe2lMqWh8Q/8/Ls5PRtHdslv
RLZMC1JXKH+hY3lTEAdie/lX+D9R8gxCTzSPQXAqNT+oAoo7kS9MlFtnZzgw
m2c258dtIjJeYBzzAt8tq9e/nBLstFA6kY/H8g82xSs0bFIo+Ytx51mXwBud
zEYXzpVY+wkMo0wKkNKmcOkX/sv0L9/TGt8tbNGRFexlIquDdbSc4eXGJp3Z
471MpDZfgo47Vvvrp0+++fbRryZC0MTuwIOThyfh46OTB3hnBJyi/6SauiJX
USHE7cI46TIdwZ4i5k5C6dQ0MW6hnVSpRxCYoySJuUxFmmxKfAHOjcVFwQD0
eUtL00yVKo5zDTyDeRYLLXL919LkeokXXPNeLKdrGvYLfi4CiENG3SO5CvbP
EDIWXkRLE8dQTnFAc3MblxErIQSmsbiif3K5BnbG0s6k9sjUUM7Y4veeliAf
PDDPcUeTIJo3MGOm3aQR0JQ5LSFGLBob2DhkjOcVzUN6FXvj0JRMNTinHRR0
ZbkEdUsNg45tYudrHtAfspb0sGpbtK6MaGdVyChRZokVp7YsmEaIk0YFs2VA
eITTmmoAY0yE8oapM64gmKAJhuRrM53jeOm1NNX5+CdqF5OEt9JY5bH5Ae+R
eCpWsISdCf0BmxNbbWlCVFvn4IiXLLd3hsCilpTMNS2HtzxV3nR2KCpenmO7
3MsUzKk5rbWwK7mfDlHREXhfaoBCahxknWuCd1lYMAcZ1dxDaKfp+kfZkquF
bR3n5vpyocC41mkgHSoTC8UCP2XM77pROlKScc3nUq3puGshQc9oNgco5KFB
5cGBvG4b45UNoiR1ACbe0eJQErYYCQ9PZhY7OXjx+uaWwg36La9e8ufr839/
fXF9fkafb56fXl7WH0R44+b5y9eXZ82nZuaTly9enF+d+cl4KjuPxODF6Z8w
QlQNXr66vXh5dXo58AxD7oipyiUrcc6HMdVelcG3Z1rE2kW5mWrScfn4yau/
/ffJQ3l//y+MryfffvoUvjw6+fVDfFktdOp3s2myDl8h27VQWaYVi1olsGmV
kW3DoCFYB1VKJRk2BPvVn0kybyfyN9MoO3n4u/CAGO48rGTWecgy236yNdkL
sedRzza1NDvPNyTdpff0T53vldxbD3/z+wSgKEcnj37/O8HadKvzpUkZu3qB
o3QBCWY2SeyKMQ1THFxfpZYTMYGS4oPHkHpGGG+DTGPgca0Mnf1wEucfyGnA
/Gqb4Q3SjnX6rXCklsJ1J+tJLQfIuFER6WRZAXKvMR66I2nv2MQNAzRMZ6Hu
tPweMYOLTRSo65tL9LVAgralbbYZgWm7jCCc4JpdCKB1nlZ09TBB0mRR1Xy0
JbSTBL+u99CQXA8lsLrwPt5AZJcXJioRVnelvIKbbDa/cm0RmYLxbkM+BxQ8
aoKiSGcFcOgcM9Y1+ZKMirKaQgX0a/QKPgLCIViDco3k7Y6TqsZ6pMAa7WMj
cv0MCFdB+ShSFOcKhHdoIeyZJxRUATdKngou4JDI1yM2XEKIrGtL64oWrv+I
rwjW46IFgNoJlSDIiEmjUoQ3oGuNMCICiQqySRsKCZboLCgO2aERY/HcrjSE
OpRmBpklMCdCfMbSzDqvXOHgaA2nebl6SIc1hdkwlV1uyjPBeAqXXeYUC3WI
Nk403EBULeO/kAloTcbyhsKe9qRK+DGOXNq0a5iixS8fNnRjalIv1CCbjtjS
mJ+pmn5eHuaGHAHmI1Q4214OceBPOWxTyyzRw3DurZiv14Kenp96zfBxjnbt
+EeQQDsxJxnxDWhVGdkHEXyDuG8h/4ivyjPZPhCflxDprUn4F9gI51uPDWsR
9C7S3kv0LNOMDhE4Fw3rqZXzUuUK3jmEiJtA3KFwZeBkU1vQwdYYxEqIw+oC
VM9Cng4RJPI6s1UgldcHT0LfHVENCZRWtkwAfLqlkwA7p2FXcBXJujZiWaws
ov3ZTHPe3begk4dI+cdDgX1HN89YyPTxj9dHtGg4+WYR4wmd6mJFYSBxTpvA
BB1RX2lRS70dY2bjpe4PuFpAoPoJ3gbibMYIICm6odzlzyEFfTumSI/iRkTH
fuhdmacTKj9MuPwwoQUn75h2OnoPuLVv6JWjoIg9ASeIbCljhbAOB5PBUaNm
fb6qcsd1Ylib4w7H6aqEhoSjICYC7oizsHpj51ljJ8nsKUAK5ZhEiugys97E
Cf8mwj1O6vA7S0qc6eCXxAryJmNjfBvTN9jrYp0RxB0ORoOjMWQPgsv5Yodi
kCgj5fTIcIXOUAWAMZKyNpvCAySc35AVEYk5vSxIfFX060LOxfHPesc2yxLS
iaFC1nNfL1XxBkJhOwRcyzqvQmRLNqAi8sGyRAjcmUIWREnEnUpI8aHIDYFm
hxNgtA3WwAe9koPz/zx98eryfEDrrTRUFb8HAUUHR6KKg5x6z0eaW+TkBTtm
wphAJAfsGaf6WjTc7SGC1q0T4WjNBiBPH189ZaP4twffPHzL7/QL1FB08e7d
O1Er56iFS7+Vp5evnp/Krw7Dh2N5dvHs4ha/oTT0/4j/Hw/kEa/SF4z9FLUW
tVqDctbWTY38X9f3rW3J9YXtVEgCTA6uGlAgDKQEogiKj4NbkesQuyDCuJDy
duoALCZf+B6H2KvKCnyuvkMfsBcHI1Sj6j2HPiMlBvlZ/WQs3iw8Wq//8Wbd
S9dnWPUOpe5drtbpKrbrqnSPLkOLj75AyZ+wmtUFLS+QHuqaWkVDU+XPQMig
zzMNZK8lwt3IHnY8PZ1wrZtFmHbF5EeSvgatxD6/Nnj4YBCY6WMgrDF5+MAT
tytxqUPeVhYRYvSa3t55VYFIxHpmUj/r/p7mjJCUffrklaWP8mrHbmDYCs28
cbXjMBF893bE20Qq/ch6f9B3kBTG+LqC5hxReiY2iwq718W2H+XLdqRIPx/7
RfWxL1K/6VQ0PoqPk9HmT/2oZ2znD1aSz25OZOfno0Q+mfKHqtGwWq3Gc3fC
faqqwuqOTTx6r9fumN7mlS7PL55urJRos7WScbaz0vGvHz168C03l+hdrHRW
pvJf5eNcxdAajfQPK8UlUpCNleJ0Sp2RYxqr5re2x0qvcgQJRafRcMUw7bBU
BszcIE2lynfjWMEYDY91PXfkId4dY20ftRLa7rCG3uOlatJ1VS7dsgKoZ9UT
5f4QlNBnDq7dQEBKo+LYhLzdVROizgQYzdoyJFDBt0rfTbrwuQLsxiMLFUXG
4mbHIgSJXDYJhfyZLblqz6hJfaK3TDRLOdqm+eCgPoCOU3N1g64z0GbS2SUl
zdVb7aTQVzMoJgsND3hwx7JovTWWgFjRgljjKt/Nboo44z1ap+dsokeI5HDW
uuh2YPzBik5LbehDBV7zVn2QF2dVAbxOGEPUcWMjA/JqKXsVFIc3N1dHVTWg
2kzaFTVB5JvNtX3Gm7TK+a4zccgxC5bsfVNRfhobZHulSuoCUV1TYXFQhaMm
oyNx21PWbwp68jRt1WJ+4dpNl079HxGDdpxeU8Nh7tnLvPKIOiij1kjkvFxw
0s3KvsjAgo2A1L5oBH2MqFZHLTvubDGxooB+hHSy4582AjcK/Kt3YKwIaDtq
RIKqMhPufdG1B27bSI3ko1RFDf2c4JLmIlK2Za7mFSlSrZQ/SRFYlT2sairs
9RbfOnLnqLk3FfWJLaAh8xrsSwWtel0tAl/9vDOWbwrURGU2MRFUhS364vTq
tAeCWl6w3eqiEkHw8Sa0KzOblbw+Mb6shWyok2GoJ0mnRn3AECk2jrRTMQEv
kY5LX8vhUnJIykRrv3ZRnp1/T1H+P3Ba2m3iNWnAhncN3amYIY7632/FVDkK
ymacsxOzo5XW77HOndGrKisJFUB/YQJx38gP1/dABPXxiT8QWgyr11V8Z3xi
xVXEXC6pCnWmyftwIeL8A9YnIdVFUzpjTl+r9DRULUIecucZxalan96UEI0f
FgFqZqzlWMzVuUtHXB5JtolgeGP9utMbha2UG7DBITo8dNRfF2zAXixtGXOV
bap9Pch3zEhlynCI3Qrx9nQTMKR/tuBGc2GWpP++pczdslgX3CpqqjvbHO7l
nC4RQNU8KrGBkFbHuVq1u6CVwl235ROmkvV450sT2grBhxkUKtQVSk7L2vYM
hJ5+D/MToYoxuK4osk1NkCKMjSC/yhGgX+Jz57QTA0qu+cJB3e9tKf5whyj9
IWvD+W2lNFQa0OlabMqrEtCQ++xlyifNeQ81W3H2rKlBbmF7FhudPB3FWJzp
lG46VNIzaZSUMSEfeaNEpXWXmZUKBJFVwPUNhSvnc+zt3Qk7O2rR4xfHGH5H
LzN4SKrIzsrEgxYrgXZIqVto5TjQqOscq5CZ94hI+GiuqLtqd3VB++ShjNWa
sPgJcB6CViEpX4TisOdgny5XIqBetNd8LtU0FQciFwEAZnSOIi5ZNATd9TWF
WZlGPt6E0xn2Lmg4oEjMezI77/iALHMN8wPYVPI2tICw+cY06DqE6ktpPg13
fEermudRiQ67TX+HbDosti/H/S86GS5S8JqhkFhfVCizmBmc5Xa5S3y0WxB3
DIcAs6MGfG3J3mBbBHS1s23cdbgVNK3uyNH9L9hX3+7+hK1hr79aWH91iEK1
woo6IvDHCCDPyCvfaefv/1QdgZb0mvbxpnMcEmDaPPbVMJ3yJtPcqjhBGsy3
w1hFmC2qgnaUJdgmXdZKObJ2ISpW/S/S9TSvwFTT1aCZr0vQHaaiummTzkA1
1x75UoUO8Njp8no5Db2H8V/q09IzzwsJ5/synvNNjeD7LGtP7VXZjOn+lL/M
w6+ErGILoo1rBCS8W90llkpLhv51WmKKnXsxgO58eFMIzGKQGdWu3aKZIbad
qui99DizbbghkArM1FHCDu2GFlXdjn0hg4/ffcCw5YQbacyRWNDhcVzKSth5
2QWKN8M7x45gCoyYmcILkcW5E9PEVM9sSIu2yKniAdg79WQB7DZkEDPaH3Qu
fQDYXAActro8PsklsCWZ0LHMzAeOXqtd23LphFKbwSbyXn8zu5Pu3x/wQ072
f/SOG4W4DGKDeqVBU0drmcv+e5CUEbGTYEl/0T1HueOe4237xhdwka9n0ep0
95p7dHjKABTpygq7fPKhVFU0U7DADmQnYLrVOEucgxBYle6G3PoNKssiUGwC
ks2y7KB9Ma7bmG4lGluzmPpw1pQxtW92UC+RO4hN8iaqOJTqCU11nkWA2VWv
qiphhqTYV4maennTUBl7nTAb1c/PaMWIPR1Gub/jIv4nHRcEXXTLLePbzYLu
fxsN/9M8rMwkK3MCrOprrdIU3/hKAHLNIgel/iYQlcdZWan+p5Z0FRmUETAP
6PFgzAV0hk08n5PYqxsV1R7tm0oEp+uxeMkwi+AFqF63AkEXXZYNF4YB2CMC
/eb7gopEGdJ5yp2PfApEVz35yh8HWMhXRDeHPAudlEN3RNxcb5pDfX2Q4uH+
rkswqLr0UqWsQ+TrtByAYh0I8GW8y7BAqNRxrswxPuXIQT71Xr7nmsYbaJbr
RN8p0BWSfNfLrr9hEZQ/3KyOgxFfhOS+Br0nIcvn4YO+LEOIr4jTSe/YV7Kt
Yj038vDGtgax7mBk96nI+/vmmsInz/8mHjOOf2Yp9/6gruN+AbTvXfxz4b6/
l/HFd+391TKdelT36lbj+t7rVQ0Qix39sQ007tya2bxRuLPVZVzwNrWy7fAY
/wQ3HDeA/B/vKZBP/NM7hw3Pvcdfb6qJCGxxqXW26/UW7WKX1oCMduetoucn
aeD/O6t9zqrXZv+Pea95kpK36gUYHtztySZ+uKOM1Hv96f6rv1e9x5eBgUSb
3QzQ4B4G/PAGA9Ty/XlZoF7vbh54dA8TYbzLxWa7+edlKNN7lIoG97Djh7vc
7G55/2x80R/CUa2COkmn0fvUrhLtyzBO3E98E13Hvx3MYJx6wNdE9Qe4I7ql
eTr+w/hI3hSaLj2nsXhBpRC4d0Cbw9rUNcoNTLi6/NHT6zmoyZfPDbXs1thV
9mxLf/kM1i+WXJ2OARx3XK1sZTBV63drk9HXJxy5ciUx9n/6+gvqEs1MYpqX
vuYNAq50Mmn/99iAI+V8J8r/2a3/E9ntv9D+Ownq7mMtPgAA

-->

</rfc>
