W3C

- DRAFT -

Web Authentication Working Group Teleconference

04 Oct 2017

See also: IRC log

Attendees

Present
jcj_moz, jeffh, elundberg, jfontana, apowers, Rolf, jyasskin, kpaulh, WD07, weiler, AkshayKumar, battre, John_Bradley, nadalin
Regrets
Chair
nadalin, jfontana
Scribe
jfontana

Contents


<apowers> sec, getting a GTM

are we restricted from using a GTM channel?

<apowers> https://global.gotomeeting.com/join/171358933

can everyone get into the GTM?

we are moving to this URL https://global.gotomeeting.com/join/171358933

<Rolf> .. since webex didn't work properly today

<jeffh> am waiting for Rae Hayward's screen....

<John_Bradley> on the goto meeting;

<jeffh> cannot hear anything as yet tho my local audio works

<jeffh> "connecting to audio......"

audio restored

Tony: At FIDO meeting last week. Some things were moved along at FIDO, CTAP to RD3
...

if somebody objects to an off-cycle meeting we can't hold it as a W3C meeting. it will have to be private.

Tony: does anyone object to another meeting in a week and having it be official W3C

dial in services provided by Christiaan/Google

Tony: are there any objections?

Tony not hearing any. No objections for face-to-face and phone in. I will put it on mailing list and ask again for objections

Christiaan: I will send the details to the group

thanks jeffh

Tony: we will have a normal call on Wed. also

<apowers> sorry, what's the date / time / location for the off-cycle meeting?

lost audio

back with audio

can someone enter the issue being discussed.

<akshayku> https://github.com/w3c/webauthn/pull/498

thank you

539:

https://github.com/w3c/webauthn/pull/539

PR will be reviewed by JeffH, others.

544: https://github.com/w3c/webauthn/pull/544

Tony: complete the part in FIDO land...where do we stand with changes that M.Jones requested

<elundberg> weren't we on 558?

Christiaan I made changes a few days ago

https://github.com/w3c/webauthn/pull/558

tony: jeffH you want to review

Christiaan: I am picking userhandle people love it

JeffH: sounds good to me.

Christiaan: I am merging

582: https://github.com/w3c/webauthn/pull/582

tony: restore the name back to normal

christiaan: Dirk will work on the mapping

Tony: this will be in RD04 CTAP
... can we close this

jeffH: fine by me.

Christiaan: can we keep it open until we have PR in CTAP land

Tony: OK

597: https://github.com/w3c/webauthn/pull/597

Tony: this is rolf's

Rolf: allows the sig counter or signature generated nonce
... I think it is ready.
... if I get all the conflicts I am done

tony: we moving it?

<Rolf> I think it is ready to go

rolf: 597 was a FIDO decision, I think most would prefer this one
... give the green light and I will merge

tony: any objections

rolf: 597 is better than alternative

<Rolf> 597 was preferred over 539

close 539?

JeffH: fine by me, if everyone is comfortable.

Akshay: lets close 539

tony: rolf can you do that and fix 597 issues
... and let jeffH review

JeffH: happy to look at it.

tony some issues for wd07, about 30 open issues.

scribe: still tremendous issue on cancel
... do we have a conclusion on cancel

jeffH: you are referring to PR 544?

toney: yes
... we need to wait for angelo on this
... we have issue 316
... stil an issue JC?

<jeffh> https://github.com/w3c/webauthn/issues/316

jcjone: we still need to solve it.

tony: it is not a breaking choice

jcjones: I don't think we need to hold wd07 hostage for it

tony: i am moving it off.

akshay: can we move to the breakage first

tony: breaking change , a couple 547 and 584...do 584 first
... there is desireccccccegihhntgcrbguhbgrgijdvngngvibtnjrlcrun

sorry about that :-(

rolf: this would be a new attestation type in the end
... we have to think that through

akshay: what he is saying just have two different signatures.
... we do not have agreement what this thing should look like

christiaan: what are we breaking here?

akshay: we can do it here, my concern is we can look at it and have discussion.
... on ething is prvacy, onthing is how sig comes up.
... I want this privacy CA
...

jbradley: if we change privacy of attestation we might have unintended consequences
... it probably needs its own security analysis

jeffH: i tend ot agree with that

tony: hearing we should open a new issues for new attestation format and not changing the format we have

akshay: yes.

tony: Christiaan, do you object?

Christiaan: I will see if there are any, i can't think of any right now
... an issues

akshay: thanks

thanks for clarification jeffH

don't do anything with 584 open up a new issue

tony: 547 , where does dirk or google stand on this

https://github.com/w3c/webauthn/issues/547

jcjones: I'm not an expert, but I think this is OK.

tony: christiaan can you check with dirk and close this issue?

Christiaan: yes

tony: I think these are the two issues that are potentially breaking
... looks like we can close one, and a new format may mean the other is not breaking

akshay: OK

tony: we are out of tiem.

apowers: first..... second, maybe interop in Nov. (CTAP)

missed the first, can anyone add.

tony: maybe host in Seattle
... i would like to see wd08 interop so shortly after TPAC we can have some wd08 implementations that interop.
... Christiaan can you think about hosting a second interop.

apowers. FIDO approved CTAP for publication. We will do that.

tony: i should be in a public spot. make sure everyone can get at it.
... apowers can you post a link on the W3C WebAuthN mailing list

apowers: will do.

tony: we need to make a reference to it in the WebAuthN spec

cse

close

Summary of Action Items

Summary of Resolutions

[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.152 (CVS log)
$Date: 2017/10/04 18:07:27 $

Scribe.perl diagnostic output

[Delete this section before finalizing the minutes.]
This is scribe.perl Revision: 1.152  of Date: 2017/02/06 11:04:15  
Check for newer version at http://dev.w3.org/cvsweb/~checkout~/2002/scribe/

Guessing input format: Irssi_ISO8601_Log_Text_Format (score 1.00)

Present: jcj_moz jeffh elundberg jfontana apowers Rolf jyasskin kpaulh WD07 weiler AkshayKumar battre John_Bradley nadalin
No ScribeNick specified.  Guessing ScribeNick: jfontana
Inferring Scribes: jfontana

WARNING: No "Topic:" lines found.

Found Date: 04 Oct 2017
Guessing minutes URL: http://www.w3.org/2017/10/04-webauthn-minutes.html
People with action items: 

WARNING: No "Topic: ..." lines found!  
Resulting HTML may have an empty (invalid) <ol>...</ol>.

Explanation: "Topic: ..." lines are used to indicate the start of 
new discussion topics or agenda items, such as:
<dbooth> Topic: Review of Amy's report


[End of scribe.perl diagnostic output]