W3C

XML Security Working Group Teleconference
28 Jul 2009

Agenda

See also: IRC log

Attendees

Present
Frederick Hirsch, Thomas Roessler, Scott Cantor, Cynthia Martin, Sean Mullan, Brian LaMacchia, Magnus Nystrom, Ed Simon, Brad Hill, Hal Lockhart, Gerald Edgar, Bruce Rich
Regrets
Pratik Datta, Kelvin Yui
Chair
Frederick Hirsch
Scribe
Scott Cantor

Contents


 

 

<trackbot> Date: 28 July 2009

<fjh> Agenda: http://lists.w3.org/Archives/Public/public-xmlsec/2009Jul/0054.html

Administrivia

<fjh> TPAC Overview: http://www.w3.org/2009/11/TPAC/overview.html

<fjh> Please register: http://www.w3.org/2002/09/wbs/35125/TPAC09/

fjh: no call next week, next call Aug 11

<fjh> 4 August 2009 Teleconference Cancelled

<hlockhar> NIST Announces Third Smart Grid Public Workshop, Aug. 3-4

<hlockhar> http://www.nist.gov/public_affairs/releases/smartgrid_wkshp_072409.html

<hlockhar> CyberSecurity Coordination Task Group http://collaborate.nist.gov/twiki-sggrid/bin/view/SmartGrid/CyberSecurityCTG

Minutes Approval

<fjh> http://www.w3.org/2009/07/21-xmlsec-minutes.html

RESOLUTION: minutes from July 21 approved

Editorial Update Status

<fjh> XML Signature 1.1 References update, ACTION-336

<fjh> http://lists.w3.org/Archives/Public/public-xmlsec/2009Jul/0050.html

<fjh> Review and update of explain documents for XML Signature 1.1 and XML Encryption 1.

<fjh> http://lists.w3.org/Archives/Public/public-xmlsec/2009Jul/0048.html

<fjh> Update Generic Hybrid Cipher

<tlr> mh. Perhaps the explain documents should be linked from the SOTDs...

<fjh> http://lists.w3.org/Archives/Member/member-xmlsec-commits/2009Jul/0039.html

<fjh> Update of Roadmap and Publications wikis

<fjh> http://lists.w3.org/Archives/Member/member-xmlsec/2009Jul/0010.html

1.1 Publication Status

<fjh> Transition request for Generic Hybrid Ciphers completed

<fjh> http://lists.w3.org/Archives/Member/member-xmlsec/2009Jul/0009.html

<fjh> publication planned for 30th July

<fjh> xml signature 1.1 and xml encryption 1.1 need to link to explain documents

tlr: sent email regarding possibly extraneous namespace

magnus: go ahead and pull it

tlr: for PKCS5, using RFC instead of RSA reference
... until I send publication request, not safe to edit specs
... so don't edit for next couple of hours

Issue Review

fjh: proposal to close various issues: http://lists.w3.org/Archives/Public/public-xmlsec/2009Jul/0053.html

<fjh> http://lists.w3.org/Archives/Public/public-xmlsec/2009Jul/0053.html

<fjh> ISSUE-105?

<trackbot> ISSUE-105 -- HMAC output length is defined on bits base64 on octets -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/105

<fjh> issue-67?

<trackbot> ISSUE-67 -- Revise XSLT transform; it's currently octet-stream to node-set. -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/67

<fjh> issue-128?

<trackbot> ISSUE-128 -- Add clarification in XML Signature regarding serialization impact with issue:: add clarification in XML Signature regarding serialization impact with -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/128

<fjh> issue-126?

<trackbot> ISSUE-126 -- Clarify XMLENC Section 5.8 (Message Authentication) -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/126

<fjh> issue-133?

<trackbot> ISSUE-133 -- Update Exclusive C14N Schema -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/133

<tlr> indeed

<fjh> issue-110?

<trackbot> ISSUE-110 -- Need better definition for "visibly utilizes" in Exc-C14N -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/110

<tlr> ISSUE-110 closed

<trackbot> ISSUE-110 Need better definition for "visibly utilizes" in Exc-C14N closed

agreement to close all issues in fjh's email

<fjh> issue-99?

<trackbot> ISSUE-99 -- Key Wrapping intro in XML Encryption needs Example -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/99

magnus: thinks it's closed

<fjh> issue-92?

<trackbot> ISSUE-92 -- Include the \"implicitCA\" option for ECKeyValueType and separate ECDomainParameterType type -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/92

<fjh> no more work required on this one

<tlr> ISSUE-92 closed

<trackbot> ISSUE-92 Include the \"implicitCA\" option for ECKeyValueType and separate ECDomainParameterType type closed

<tlr> ISSUE-99 closed

<trackbot> ISSUE-99 Key Wrapping intro in XML Encryption needs Example closed

<fjh> http://lists.w3.org/Archives/Public/public-xmlsec/2009Jul/0062.html

<fjh> issue-27?

<trackbot> ISSUE-27 -- Profile XML Signature spec to disallow removal of used namespace nodes from nodesets -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/27

<fjh> issue-29?

<trackbot> ISSUE-29 -- Able to run transforms in parallel (in general parallelism related to pipelining) -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/29

<fjh> issue-30?

<trackbot> ISSUE-30 -- Limit XPath Filter transform to be first transform or to not use parent axis -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/30

<fjh> these have been dealt with transform simplification, issue-29 is moot

<fjh> issue-30 closed

<trackbot> ISSUE-30 Limit XPath Filter transform to be first transform or to not use parent axis closed

<fjh> issue-29 closed

<trackbot> ISSUE-29 Able to run transforms in parallel (in general parallelism related to pipelining) closed

<fjh> issue-27 closed

<trackbot> ISSUE-27 Profile XML Signature spec to disallow removal of used namespace nodes from nodesets closed

<fjh> issue-60?

<trackbot> ISSUE-60 -- Define requirements for XML Security and EXI usage -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/60

<fjh> need to be clear in requirements document before closing this issue

<fjh> issue-27 closed

<trackbot> ISSUE-27 Profile XML Signature spec to disallow removal of used namespace nodes from nodesets closed

<fjh> issue-62?

<trackbot> ISSUE-62 -- Clarify best practice related to order of schema validation and xml security processing for 2nd Edition -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/62

<fjh> issue-62 closed

<trackbot> ISSUE-62 Clarify best practice related to order of schema validation and xml security processing for 2nd Edition closed

<fjh> issue-51 closed

<trackbot> ISSUE-51 Effects of schema normalization on signature verification closed

scantor: close issues related to schema validation dealt with in best practices

Errata

<fjh> C14N 1.1

<fjh> http://lists.w3.org/Archives/Public/public-xmlsec/2009Apr/0041.html

<fjh> scott notes that this may not be an errata but a desired change

I think it's part of the overall effort to fix c14n

<fjh> Signature 1.0

<tlr> http://www.w3.org/2001/10/xmldsig-errata

<tlr> Note: All errata listed on this page have been taken into account in the preparation of XML Signature, 2nd Edition. See the documentation of Changes in XML Signature Syntax and Processing (Second Edition) for details, and Errata for XML Signature 2nd Edition for Errata against the Second edition.

fjh: would prefer older docs be explicitly obsoleted

tlr: new web site changes will help make this clearer

Action Item Review

<fjh> http://www.w3.org/2008/xmlsec/track/actions/open

fjh: will close pending actions
... please review open actions
... will follow up with Konrad on some of his older actions

<fjh> issue-30?

<trackbot> ISSUE-30 -- Limit XPath Filter transform to be first transform or to not use parent axis -- CLOSED

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/30

<fjh> ed asks do not discuss canonicalization of output of xpath, how do toolkits handle this?

<fjh> scott suggests part of implicit processing

<fjh> ed suggests removing this inconsistency

esimon2: suggests we align text for XSLT and XPath on how to deal with results in node set form

<scribe> ACTION: esimon2 to propose text to align node set result treatment for XSLT and XPath in 1.1 spec [recorded in http://www.w3.org/2009/07/28-xmlsec-minutes.html#action01]

<trackbot> Created ACTION-350 - Propose text to align node set result treatment for XSLT and XPath in 1.1 spec [on Ed Simon - due 2009-08-04].

2.0 Discussion

prateek not here, no discussion at this time

Other Business

bal: asking for specifics on schedule during TPAC

<fjh> tlr m tue, exi, processing model

<tlr> can't think of any right now

questions regarding formats to use for reviewing...

<tlr> http://www.w3.org/2008/xmlsec/Drafts/xmldsig-core-20/Overview.xml

<fjh> info on xmlspec http://lists.w3.org/Archives/Member/member-xmlsec/2009Jun/0013.html

Summary of Action Items

[NEW] ACTION: esimon2 to propose text to align node set result treatment for XSLT and XPath in 1.1 spec [recorded in http://www.w3.org/2009/07/28-xmlsec-minutes.html#action01]
 
[End of minutes]


Minutes formatted by David Booth's scribe.perl version 1.135 (CVS log)
$Date: 2009/08/11 16:03:19 $