W3C

- DRAFT -

Web Authentication Working Group Teleconference

28 Jun 2017

See also: IRC log

Attendees

Present
IbrahimDamlaj, Rolf, angelo, apowers, christiaan, jeffh, jfontana, jyasskin, nadalin, selfissued
Regrets
weiler
Chair
nadalin, jfontana
Scribe
selfissued

Contents


Reviewing WD-06 PRs

PR #379 isPlatformAuthenticatorReady - Angelo waiting for more feedback

PR #460 requireUserVerification option - assigned to Mike - expect to work on this week

PR #495 fixup algs cont 2 - JeffH says ready to merge

Tony asks whether we want to take this breaking change now or delay it

Rolf says that existing implementations can't work in this regard, so we wouldn't be breaking them

JeffH says that we should proceed

Tony: This will break WD-05
... If we want to keep server compatibility, with WD-06 being an incremental add-on, then we could delay this

JeffH: This doesn't affect the server side at all
... #498 won't affect the server either
... This is in the browser machinery. It doesn't affect the signature format.

Angelo: Edge will wait on this because it may take a long time for it to get done

JeffH: Implementer's should focus on the WD-05 Implementer's Draft

Angelo: It's reasonable to fix the algorithm here

JeffH: Responds to Tony saying that #495 is good to go

We will get another review recruited by Dominic Battre and then merge #495

JeffH: #498 builds on #495
... There is a bug in threading exposed by #498
... We can't do some of the things we're doing in the background. This must be fixed for CR.
... It would be great to get Mike West and Jeffrey Yasskin to look at #498

Tony: We should cancel the call for the week of IETF

PR #499 Rate Limiting definition - JeffH says ready to merge

Tony: Giridhar can merge this

JeffH: There would be an authenticator considerations section referencing others specs for security and certification information - plus SP 800-63

Angelo: Removing the "required" keyword doesn't change anything

JeffH: Removing "required" doesn't do what you want

Angelo: This isn't intended to impact any behaviors
... Replied to Tony that this is not an immediate issue

JeffH: We shoudl punt to CR

PR #501 Merge sample-scenarios with usecase section

JeffH: I would not do this the way you've done it
... Vijay was adamant that we don't need decommissioning in the protocol

Angelo: I want to address the TAG review to merge these together

JeffH: There is a separate issue
... There are multiple audiences for this and the use cases section is currently very high level
... The current Section 11 is developer oriented
... I would keep the current use cases section separate
... Vijay and I thought the roadmap would satisfy the TAG issue
... I would leave the current use cases section as-is
... If you deploy things, you need to think about decommissioning use cases
... Long discussion between Angelo and JeffH about decommissioning, with no clear conclusions

PR #502 requreResidentKey

JeffH: I have a comment on this
... We need to fix the ordering
... Why was authenticator selection added to ignored section?

Tony: This ends the open PRs for WD-06
... We many not get #379 closed for WD-06

#460 we don't have an answer for but will get one in the next few days - hopefully it can be merged

#495 is ready to go after review

#498 needs some additional review but JeffH is OK if it doesn't make WD-06

#499 is ready to go

#500, #501, and #502 are pushed off

Tony: On #379 there is still controversy. Are you OK pushing this off if you can't spend time on it?

Angelo: Let's wait a week and then decide

Tony: We will decide next week whether to push the button for WD-06 or not
... The call on July 12th is questionable due to travel

(Call ends)

Summary of Action Items

Summary of Resolutions

[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.152 (CVS log)
$Date: 2017/06/28 17:57:00 $

Scribe.perl diagnostic output

[Delete this section before finalizing the minutes.]
This is scribe.perl Revision: 1.152  of Date: 2017/02/06 11:04:15  
Check for newer version at http://dev.w3.org/cvsweb/~checkout~/2002/scribe/

Guessing input format: Irssi_ISO8601_Log_Text_Format (score 1.00)

Succeeded: s/deply/deploy/
Present: IbrahimDamlaj Rolf angelo apowers christiaan jeffh jfontana jyasskin nadalin selfissued
Regrets: weiler
No ScribeNick specified.  Guessing ScribeNick: selfissued
Inferring Scribes: selfissued

WARNING: No "Topic:" lines found.

Found Date: 28 Jun 2017
Guessing minutes URL: http://www.w3.org/2017/06/28-webauthn-minutes.html
People with action items: 

WARNING: No "Topic: ..." lines found!  
Resulting HTML may have an empty (invalid) <ol>...</ol>.

Explanation: "Topic: ..." lines are used to indicate the start of 
new discussion topics or agenda items, such as:
<dbooth> Topic: Review of Amy's report


[End of scribe.perl diagnostic output]