W3C

XML Security Working Group Teleconference
22 Jun 2010

Agenda

See also: IRC log

Attendees

Present
+1.301.448.aaaa, +1.408.347.aacc, +1.425.237.aadd, +1.613.940.aabb, +1.781.744.aaee, Ed_Simon, Gerald_E, bal, brich, csolc, cynthia, fjh, hal, mjensen, pdatta, Frederick_Hirsch, Cynthia_Martin, Chris_Solc, Meiko_Jensen, Pratik_Datta, Gerald_Edgar, Brian_LaMacchia, Bruce_Rich, Hal_Lockhart
Regrets
Magnus_Nystrom, Scott_Cantor, Thomas_Roessler
Chair
Frederick Hirsch
Scribe
Gerald_E

Contents


<trackbot> Date: 22 June 2010

Administrative

<fjh> http://lists.w3.org/Archives/Public/public-xmlsec/2010Jun/0013.html

<fjh> s;http://lists.w3.org/Archives/Public/public-xmlsec/2010Jun/0013.html;;

<scribe> scribe: Gerald_E

<fjh> ScribeNick: Gerald_E

<fjh> TPAC registration open (XML Security F2F 1-2 November 2010)

<fjh> http://lists.w3.org/Archives/Member/member-xmlsec/2010Jun/0004.html

<fjh> ACTION-592?

<trackbot> ACTION-592 -- Thomas Roessler to set up dial-in v attendance questionnaire for TPAC 2010 -- due 2010-06-22 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/592

Announcement: TPAC registration is now open, in Lyon, France

Minutes approval

<fjh> Approve 15 June 2010 minutes

<fjh> http://www.w3.org/2010/06/15-xmlsec-minutes.html

Resolution: 15 June 2010 minutes approved
... 15 June 2010 minutes approved

ECC

<fjh> No W3C Team update expected until 6 July meeting

fjh:

Last call issues

<fjh> LC-2387

<fjh> http://lists.w3.org/Archives/Public/public-xmlsec/2010Jun/0003.html

<fjh> awaiting review from Thomas, ACTION-585

fjh: defer this because we are waiting for Thomas's review

<fjh> ACTION-585?

<trackbot> ACTION-585 -- Thomas Roessler to review proposal for LC-2387 -- due 2010-07-07 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/585

Last call 2390

<fjh> completed resolution on list

C1L XML 2.0

<fjh> Curies discussion on list, please comment on list

<fjh> http://lists.w3.org/Archives/Public/public-xmlsec/2010Jun/0034.html

fjh:

<fjh> ACTION-576?

<trackbot> ACTION-576 -- Pratik Datta to add "high performance profile" to c14n2 -- due 2010-06-22 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/576

s/c1n/c14n

Pratik: we are having named subsets

fjh: we are planning to go to last call in the fall

<fjh> http://www.w3.org/2008/xmlsec/wiki/Roadmap#XML_Security_2.0

fjh: this would be in September

Pratik: to have this done by next week

fjh: to have a draft by mid July for review

<fjh> ACTION-579?

<trackbot> ACTION-579 -- Pratik Datta to update c14n2 with proposal from ACTION-574 -- due 2010-06-22 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/579

<fjh> ACTION-574?

<trackbot> ACTION-574 -- Scott Cantor to send his proposal on prefix rewriting to the list -- due 2010-05-11 -- CLOSED

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/574

<fjh> ACTION-580?

<trackbot> ACTION-580 -- Pratik Datta to review c14n 2.0 for parsing-related options; propose removal (or add octet-stream processing to 2.0) -- due 2010-06-01 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/580

<fjh> ACTION-594?

<trackbot> ACTION-594 -- Scott Cantor to write detailed proposal, not including xsi:type, based on http://lists.w3.org/Archives/Public/public-xmlsec/2010Jun/0020.html -- due 2010-06-22 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/594

<fjh> ACTION-596?

<trackbot> ACTION-596 -- Pratik Datta to add single xmlAncestors parameter that only supports inherit or none values to c14n2 -- due 2010-06-22 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/596

<fjh> ACTION-597?

<trackbot> ACTION-597 -- Pratik Datta to add proposed text to draft -- due 2010-06-22 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/597

fjh: if these are edits, we do not need to discuss this, but if there is something wrong we will need to talk about it

Pratik: for a high performance profile, he is having a hard time addressing the different kinds of profiles.

fjh: Some things are in the profile and some things are not
... you have to do what the profile says, but you can use what it specifies

so you do not have to specify everything, if it is in the profile

<fjh> issue: for c14n20 profile - clarify that conformance implies support, but also changes to xml or what must be explicitly specififed

<trackbot> Created ISSUE-206 - For c14n20 profile - clarify that conformance implies support, but also changes to xml or what must be explicitly specififed ; please complete additional details at http://www.w3.org/2008/xmlsec/track/issues/206/edit .

<fjh> need to think and review text for this issue

Signature 2.0

<fjh> http://lists.w3.org/Archives/Public/public-xmlsec/2010Jun/0013.html

fjh: we want to change the scema to address URIs

Hal: WSS takes the signature out

fjh: to fix the schema in 2.0
... not to change the current standard, but to fix it in 2.0

hal: to create a new schema
... I do not see any problems in creating a new schema

Pratik: a new file, but in the same namespace

Hal: the actual namespace would use a different URI
... 99% like the old one, but it is still a new namespace

fjh: we need a pratical proposal, to have something written down

<fjh> ACTION: tlr to draft proposal of how update to 1.0 schema will work practically for existing implementations [recorded in http://www.w3.org/2010/06/22-xmlsec-minutes.html#action01]

<trackbot> Created ACTION-600 - Draft proposal of how update to 1.0 schema will work practically for existing implementations [on Thomas Roessler - due 2010-06-29].

fjh: not to belabor this, but to be careful
... hal's concern is we have a new schema, but not a new namespace.

hal: there is a lot of W3C policy on this, we need to find out what the TAG said

<fjh> hal recommends need to review changes to schema and compatibility issues of it, see TAG findings

fjh: we need to determine how to roll this out

Pratik: we have 3 name spaces now 1.0, 1.1, 2.0
... using a long number has problems, we need to use a string

<fjh> pratik notes IssueSerial change to string so long enough, 1.0 change

fjh: What affect does changing a nubmer to a string have?

Gerald: how tightly bound are XML processors to data type number vrs string

fjh: we want to be clear in writing this

<fjh> ACTION-556?

<trackbot> ACTION-556 -- Pratik Datta to review text related to Object tag for consistency with 2.0 model -- due 2010-06-15 -- PENDINGREVIEW

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/556

<fjh> ACTION-590 ?

<trackbot> ACTION-590 -- Pratik Datta to create separate XPath profile document (from XML Signature 2.0) -- due 2010-06-08 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/590

<fjh> ACTION-589?

<trackbot> ACTION-589 -- Pratik Datta to create 2.0 schema with X509IssuerSerial change -- due 2010-06-08 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/589

<fjh> ACTION-599?

<trackbot> ACTION-599 -- Pratik Datta to incorporate Object tag proposal as per http://lists.w3.org/Archives/Public/public-xmlsec/2010Jun/0012.html -- due 2010-06-28 -- PENDINGREVIEW

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/599

Pratik: for the seperate XPath document, he is adding some sections, we need to have futher review on that

fjh: after all the changes we will have to have a more careful review

Best Practices

<fjh> ACTION-586?

<trackbot> ACTION-586 -- Meiko Jensen to draft text about XPath risks for BP document -- due 2010-06-08 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/586

fjh: what is the state?

mjensen: it is on his schedule for this week

Test cases and Interop

<fjh> ACTION-280?

<trackbot> ACTION-280 -- Magnus Nyström to produce test cases for derived keys -- due 2009-05-19 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/280

<fjh> ACTION-411?

<trackbot> ACTION-411 -- Pratik Datta to perform measurement related to transform octet conversion -- due 2010-06-30 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/411

fjh: Magnus said he would work on this if he has time

<Cynthia> These need to be documented

fjh: is there more we shold be doing? is there more we need to document?

<fjh> pratik notes that performance work might be possible in 2 months

fjh: Do Bruce or Brian have performance information? Is there something we can use?

<fjh> ACTION-540?

<trackbot> ACTION-540 -- Frederick Hirsch to ask Makoto regarding implementations and interop -- due 2010-03-09 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/540

<fjh> ACTION-552?

<trackbot> ACTION-552 -- Frederick Hirsch to ask on list about interop and implemention plans for 1.1 features, including encryption and also 2.0 -- due 2010-04-27 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/552

fjh: planning on what we will do at the face to face

open action review

<fjh> ACTION-456?

<trackbot> ACTION-456 -- Scott Cantor to review workshop papers regarding strengthening id based references with respect to wrapping attacks -- due 2010-06-15 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/456

<fjh> ACTION-538?

<trackbot> ACTION-538 -- Meiko Jensen to provide proposal related to namespace wrapping attacks -- due 2010-03-09 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/538

<fjh> action-456 closed

<trackbot> ACTION-456 Review workshop papers regarding strengthening id based references with respect to wrapping attacks closed

<fjh> action-538 will depend on QNames and XPath profile so need to resolve those first

<fjh> action-538: dependency on 2.0 decisions regards QNames and XPath profile

<trackbot> ACTION-538 Provide proposal related to namespace wrapping attacks notes added

<fjh> ACTION-553?

<trackbot> ACTION-553 -- Thomas Roessler to contact implementers known from hmac affair -- due 2010-06-30 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/553

<fjh> ACTION-568?

<trackbot> ACTION-568 -- Magnus Nystrom to and bal to review relationship between ghc and material in encryption -- due 2010-06-01 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/568

fjh: HMAC follow up

<fjh> action-568 closed

<trackbot> ACTION-568 And bal to review relationship between ghc and material in encryption closed

<fjh> ACTION-581?

<trackbot> ACTION-581 -- Scott Cantor to make proposal around IDness of attributes -- due 2010-06-15 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/581

fjh: is there anything else for this call?

<fjh> s;completed resolution on list;completed on list, see http://lists.w3.org/Archives/Public/public-xmlsec/2010Jun/0039.html;

<fjh> s;s/c1n/c14n;;

<fjh> s/gedgar: C1L XML 2.0/gedgar: C14N XML 2.0/

Summary of Action Items

[NEW] ACTION: tlr to draft proposal of how update to 1.0 schema will work practically for existing implementations [recorded in http://www.w3.org/2010/06/22-xmlsec-minutes.html#action01]
 
[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.135 (CVS log)
$Date: 2010/07/01 15:09:28 $