13:06:09 RRSAgent has joined #wot-sec 13:06:09 logging to http://www.w3.org/2017/10/30-wot-sec-irc 13:07:05 McCool has joined #wot-sec 13:07:16 everyone, webex link for meeting was missing from email 13:07:33 kaz, if you are on, can you please email it around ASAP? 13:07:48 https://mit.webex.com/mit/j.php?MTID=m07ff415438cb61e39f740c6ca81d2b5d 13:10:50 Meeting: WoT IG - Security 13:11:05 present+ Kaz_Ashimura, Michael_McCool, Michael_Koster 13:12:26 elena has joined #wot-sec 13:13:22 -> https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#Agenda Agenda 13:13:27 agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#Agenda 13:13:49 sorry I am trying to get audio working 13:14:08 present+ Elena_Reshetova 13:15:07 present+ Tomoaki_Mizushima 13:16:33 scribenick: kaz 13:16:56 topic: agenda 13:16:59 mjkoster has joined #wot-sec 13:17:22 mm: review of prev minutes, draft publication, schedule, issues, workshop 13:17:32 ... TPAC agenda and PlugFest objectives 13:17:44 er: next week? 13:17:47 mm: yes 13:18:06 ... so no meeting on Nov. 6 13:18:24 topic: minutes 13:18:36 -> https://www.w3.org/2017/10/23-wot-sec-minutes.html prev minutes 13:19:11 mm: goes through the minutes 13:19:14 ... various issues 13:19:21 ... one clarification 13:19:28 ... working branch was deleted 13:19:34 ... merged into the main master branch 13:19:52 er: and started new work on the working branch 13:19:54 mm: ok 13:20:18 ... master branch staying clean is important for TPAC discussion 13:20:31 ... goes through issues 13:20:46 ... I'm ok with the minutes 13:20:51 er: fine by me as well 13:20:58 resolution: prev minutes accepted 13:21:15 mm: working branch is not gone but merged 13:21:24 kaz: will fix that point 13:21:35 topic: schedule 13:21:50 -> https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#Schedule Schedule 13:22:58 mm: we've done the preparation 13:23:07 ... kaz, can you work for the publication? 13:23:20 kaz: will send a transition request to the project manager 13:23:32 ... and check the document using check tools 13:23:37 ... and then talk with the Webmaster 13:23:51 mm: possible pub date on Nov. 16? 13:23:57 kaz: yes, let's aim that 13:24:06 ... if there is any problem, I'll get back to you 13:24:26 mm: updates the schedule 13:25:05 topic: draft publication 13:25:05 Mizushima has joined #wot-sec 13:25:14 mm: master is updated version for TPAC 13:25:21 present+ Zoltan_Kis 13:25:31 ... feel free to provide pull requests but the master branch should be clean 13:25:41 er: Matthias's comments? 13:26:01 mm: he's busy so maybe difficult 13:26:08 ... during TPAC, there are three things 13:26:20 ... plugfest, security features as part of my contribution 13:26:33 ... trying to work with HTTPS 13:26:44 ... authentication using OAuth 13:26:58 ... in conjunction with Amazon Alexa as well 13:27:15 ... any prototype of implementations for TPAC? 13:27:44 er: thinking about practical implementations 13:27:55 ... example use cases for section 5 13:28:28 ... not sure how to collect information at the moment, though 13:28:52 mm: add topics for "TODO: Security Features" from his slides 13:29:05 ... (WoT0McCoolPOC(007).pptx 13:29:14 s/(W/W/ 13:29:23 er: now we have a very basic one 13:29:55 mm: Use Cases from PlugFest 13:30:17 ... additional lower-level "patterns" or "system configurations" 13:30:34 ... some information at: https://github.com/w3c/wot/tree/master/plugfest/2017-burlingame 13:30:50 ... we can discuss the document 13:31:05 ... you'd do a presentation on the current status? 13:31:23 ... you can add people about possible additional system configuration 13:31:35 er: section 5 is good to go 13:31:44 ... examples of security mechanisms 13:32:04 mm: want a document 13:32:57 ... e.g., Intel POC includes HTTPS, SSH tunnel for NAT traversal, OAuth, CoAPS locally 13:33:14 ... shows the current configuration 13:33:21 ... [1.5 Metadata Bridging] 13:33:32 ... metadata bridge 13:33:41 ... and HTTPS bridge 13:34:02 ... relays the NAT tunnel 13:34:25 ... good HTTPS access to the system here (at the local network) 13:34:39 ... correct setup for remote access 13:34:43 ... and also local access 13:35:08 ... HTTP connection is not so nice 13:35:17 ... would try HTTPS end point 13:35:33 ... thing directory is a SPARQL end point 13:35:55 ... global HTTP endpoint and local HTTP endpoint 13:36:25 ... that's my configuration 13:36:33 er: local HTTP 13:36:40 ... local network is not so secure 13:36:53 ... may be some acceptable scenario, though 13:37:01 mm: right 13:37:19 ... IP address not visible globally 13:37:37 ... how to set up a local HTTPS bridge? 13:38:16 ... now working with Edison 13:38:30 ... not fully OCF 1.1 compliant 13:38:45 ... may be able to use CoAPS, though 13:39:14 ... not fantastically secure yet 13:39:33 er: lack of setting up a local HTTPS server 13:39:52 ... question of protocols 13:40:16 mm: many possible ways 13:40:28 ... issues: local certs for HTTPS? 13:40:53 ... let's Encrypt/certbot does not work; cert renewal (need certibot) 13:41:04 ... there is a CG working on local HTTPS 13:41:41 kaz: we can talk with them during TPAC 13:41:45 mm: yeah 13:41:58 ... AVS server needs to talk with these guys 13:42:25 ... (showing [2. Semantic Voice Control]) 13:42:47 ... any other certificate issues? 13:43:04 ... look into "HTTPS Local CG" 13:43:31 ... authenticated, encrypted, securely identified endpoints 13:43:39 ... HTTPS + OAuth 13:44:09 ... the connection is encrypted 13:44:28 ... probably not locally... 13:45:17 topic: TPAC agenda 13:45:22 -> https://www.w3.org/WoT/IG/wiki/F2F_meeting,_4-10_November_2017,_Burlingame,_CA,_USA#Agenda TPAC Agenda wiki 13:45:39 mm: regarding security 13:45:47 ... should mention... 13:46:01 ... Wednesday, in addition to the regular topics 13:46:31 ... we'll have a joint session with Payments/Security 13:46:44 ... also joint meeting on Thursday with Web Commerce 13:47:18 er: wondering about the timezone 13:47:26 mm: California time 13:48:17 ... asking a speakerphone 13:48:24 ... morning should be better for you 13:49:08 er: Monday is fine 13:49:19 ... but something on Tuesday 13:49:41 mm: you're listed here on Monday in the morning (in California) 13:50:03 ... also summary of security work in the afternoon on Monday 13:50:09 ... feedback on section 5 13:50:31 ... I can do it if not good for you 13:51:05 ... Tuesday morning, 1.5 hours for security 13:53:35 please delete the above line before email is published 13:54:43 mm: and Wednesday 13:54:53 ... introduction to WoT for Security guys 13:55:16 ... will generate some short presentation for that purpose 13:55:43 topic: issues 13:55:45 skipping 13:55:52 topic: workshop 13:55:58 mm: busy with POC work 13:56:07 ... you input welcome 13:56:25 ... will write the paper after TPAC 13:56:34 topic: AOB 13:56:39 mm: anything else? 13:56:51 (none) 13:56:56 mm: no meeting on Nov. 6 13:57:18 but there will be one the week after that 13:57:27 Nov 13 13:57:40 mm: next meeting on Nov. 13 13:58:06 [adjourned] 13:58:14 rrsagent, make log public 13:58:17 rrsagent, draft minutes 13:58:17 I have made the request to generate http://www.w3.org/2017/10/30-wot-sec-minutes.html kaz 15:39:14 Zakim has left #wot-sec