Nowhere in the specification do we directly say that an Entity Identifier must use the `https` scheme. I'm thinking that the best place to do this is in the Entity Identifier definition itself. Thoughts?