12:53:25 RRSAgent has joined #wot-sp 12:53:25 logging to http://www.w3.org/2015/12/10-wot-sp-irc 12:54:02 trackbot has joined #wot-sp 12:54:28 Zakim has joined #wot-sp 12:58:27 Oliver has joined #wot-sp 13:07:18 chair: Oliver 13:07:23 scribe: Yingying 13:07:40 Oliver: today's agenda: 13:08:01 ...1. Proposal for security-enabling the Plugfest@Eurecom F2F: overview of security-related deliverables and their status, hands-on session with Postman/Copper 13:08:14 2. Security and privacy artifacts in Github (https://github.com/w3c/wot) 13:08:26 ...3. Status of SP work items, next steps 13:08:34 ...4. AOB 13:08:44 ...any comments on the agenda. 13:09:19 Carsten: could you post the presentation showed yesterday? 13:09:51 Oliver: I will use the same slides in yesterday meeting. I can post it in the afternoon. 13:10:12 Oliver shows the presentation slides. 13:10:45 Oliver: the Plugfest in Sapporo is successful. we would like to continue and carry out the security aspects. 13:11:02 ...We would like include more people. 13:11:16 ...we have only 8 weeks left before Christmas. 13:11:48 So We could not do the detail demands of security domain knowledge. 13:12:02 ...We need to do what is possible. 13:12:21 ...we would like to have security communications. 13:12:51 ...We don't want to finish the security. 13:13:18 ...We would add component to instruct where to get instructions on security aspects. 13:13:50 ... the trick is to rely on existing standards as much as possible. 13:14:13 ...here is a layout of components showed in Sapporo. 13:14:35 ...we would introduce additional components. 13:16:04 ...there would be supporting components. communication protection and security token could be included. 13:16:49 ...The servient component has a security token processing. 13:17:49 ...C and RS implementations like in Sapporo. 13:18:47 ...Siemens volunteers to provide AM and AS. And we also welcome other companies to join it. 13:19:31 ...We need to avoid that AM and AS are implemented by different companies. 13:19:51 ...here is the list of materials we would be able to provide. 13:20:41 ...overview, howto and cheatsheet are already existed. 13:21:11 ...Cheatsheet includes some code snippets. 13:21:33 ...we are willing to give handson help. 13:21:55 Oliver shows the howto document, a 10 pages doc. 13:22:28 Oliver: there is "protected interaction" chapter. 13:23:06 ...We need to do some shortcut. 13:23:48 ...there 10-15 footnotes along the doc. 13:24:03 ...we are working with PostMan from Google. 13:24:49 ...there are some code examples and text. 13:25:41 Oliver uses the Postman to show some example. 13:25:58 J_Lynn has joined #wot-sp 13:26:02 ...Postman is a google chrome plugin. 13:26:20 ...I will show you the registration. 13:27:17 ...in example, we need to give the client_name and grant_types. 13:27:55 ...you can select Curl, or Java as the language you prefer. 13:28:14 ...then you get 201 for the response. 13:28:42 ...it is very straightforward to use. 13:29:38 ...the only dynamic is the authentication header. 13:29:48 ...which is a piece of client code to do. 13:30:04 ...you get the 200 response. and you get the access token. 13:30:12 ...it's not a tricky part. 13:31:12 Oliver shows the JWT. 13:31:50 Oliver: we have the type of the token. 13:32:17 ...there is something like as_token. 13:32:45 toru has joined #wot-sp 13:33:35 Oliver explains the minimum data in the payload. 13:34:09 Oliver: this is about the proposal for the plugfest. 13:35:34 ...there is a list of libs. We use the ES256 as default but we could also select others. 13:36:26 Carsten: the communication between C and AS are protected by other methods not covered here. 13:36:33 ...? 13:36:53 Oliver: the server has some authentication. 13:37:14 ...there is some instructions in the howto. 13:39:41 [some discussions on the protection of communication between client, AM and AS] 13:40:38 Carsten: is there any way that we don't need to care the certificaiton is on-going? 13:42:25 Oliver: It can be done. 13:43:42 [some discussion about DTLS/TLS underneath] 13:50:30 Carsten: the slides should be in the wiki this afternoon. I will fine tune the howto document and deliver it in the mid of next week. 13:50:46 s/Carsten/Oliver 13:51:25 Oliver: I can send it to you by end of next week. 13:51:52 Topic: Security and privacy artifacts in Github 13:52:20 Oliver shows the wiki landing page. 13:52:55 Oliver: I started moving the wiki page content into wot github. 13:53:11 ...here you can see some subfolders. 13:53:33 ...I created the IG-SP folder. 13:53:47 ...it is the same content as in wiki. 13:54:51 ...I will not move all. For the advanced concept stuff in brainstorming, I would like to keep them in wiki 13:56:02 Oliver explains the security privacy challenges in github. 13:56:38 Oliver: I would invite people to make the move as well. 13:57:13 ...the requirements were moved to github as well. 13:57:40 ...I also moved the glossary and references to github. 13:58:52 ...I will remove the wiki pages that were moved to github. 13:59:02 ...is that ok? 13:59:35 ...I will remove the payload in wiki and add the link to github. 14:01:09 present+ 14:01:11 ...next call will be in 4 weeks. It should be Jan 17th. 14:02:09 Topic: Status of SP work items, next steps 14:02:21 Oliver: no content changes 14:02:33 ...since 2 weeks. 14:02:50 ...everybody is busy with plugfest. 14:03:46 ...no further works until end of Jan. 14:04:03 ...comments? 14:04:09 [no] 14:04:34 Merry Christmas and Happy New year! 14:05:00 [adjourned] 14:06:14 present: Oliver_Pfaff, Yingying_Chen, Carsten_Bormann, James_Lynn, Tibor_Z_Pardi, Toru_Kawaguchi 14:06:21 rrsagent, make minutes 14:06:21 I have made the request to generate http://www.w3.org/2015/12/10-wot-sp-minutes.html Yingying 14:07:10 rrsagent, make minutes 14:07:10 I have made the request to generate http://www.w3.org/2015/12/10-wot-sp-minutes.html Yingying 14:07:19 rrsagent, make log public 15:11:41 yingying has joined #wot-sp 16:31:00 Zakim has left #wot-sp 16:51:02 Yingying has joined #wot-sp 17:19:45 tzp has joined #wot-sp