Hello Trey,
Yes, I'm considering SCIM for password changes too as our needs are,
well, simple.
Saying that it might be useful if a provider resource could express its
password policy (well, format rules). I'm not sure how much millage you
could get trying to achieve that with attributes alone (max/minLength,
mustContain...etc.). A regular expression would be great, parsing issues
not withstanding.
Maybe that is starting to creep into the NotSoSimpleCIM. If you provide
value validations for that attribute then where do you stop?
Cheers,
n