W3C

- DRAFT -

WoT Security

04 Dec 2017

Agenda

Attendees

Present
Kaz_Ashimura, Michael_McCool, Elena_Reshetova, Michael_Koster, Zoltan_Kis, Tomoaki_Mizushima, Barry_Leiba
Regrets
Chair
McCool
Scribe
mjkoster

Contents


<kaz> scribenick: mjkoster

previous minutes

<kaz> prev minutes

mccool: any objections to accepting the minutes?

minutes accepted

schedule for 2nd draft W3C note

second draft mid-january

NDSS paper deadline

mccool: submitted and updated the abstract
... will continue to update until the deadline
... there is a review version

https://github.com/mmccool/ndss-wot-sec/blob/submission-1/ndss-wot-sec.pdf

the submission-1 branch contains the review draft

mccool: removed examples in order to get the length under the limit
... added local links as a fifth issue
... does the structure of five issues make sense?
... the five things are a mixed bag, but we can't restructure the document massively at this point
... maybe we can fix up the wording
... need to have someone to do a critical review of the paper

<McCool> https://github.com/mmccool/ndss-wot-sec/blob/submission-1/ndss-wot-sec.pdf

Barry Leiba volunteered

mccool: review from the POV of a conference reviewer for this wprkshop
... schedule one more meeting before the Friday deadline

publication of the W3C note

mccool: what is the status of the publication?

kaz: working on the process of publication
... for example, a static rendered HTML version is needed

mccool: this is needed for github.io hosting also
... W3C moratorium on publication starts on December 18th

kaz: we could set December 7th as the publication date

<kaz> [kaz will let Michael McCool know about the publication version URL for the NDSS paper]

<kaz> ACTION: kaz to set up gh-pages setting for wot-security repo so that we can use github.io URL

issues review

https://github.com/w3c/wot-security/issues

mccool: get oauth2 and webtoken stuff sorted ASAP
... current issues won't affect the current version of the document

https local

<kaz> issue 55

mccool: network reachability
... attended the https in local network W3C CG meeting at TPAC

<kaz> HTTP in Local Network CG

mccool: depends on globally visible URLs
... Plex solution based on certificates based on IP address

<kaz> Certificate.md

<kaz> How Plex is doing

<McCool> see here for various ways to do https local: https://github.com/httpslocal/usecases/blob/master/Certificates.md

mccool: these are based on "wildcard certificates"

<McCool> https://github.com/httpslocal/usecases

<kaz> HTTP in Local Network CG's Use Cases above

Next steps for next publication

mccool: any other issues?
... what should be done by January 16th?
... what priorities and how can we split up the work?
... what about municipal or industrial sections?

elena: section 4.2
... scripting considerations

<kaz> section 4.2

elena: we also need work on the validation section

mccool: cite some existing IoT related approaches to security validation

<kaz> section 6 - Security Validation

mccool: reviewing assignments to the issues
... asking Zoltan to provide scripting input

<kaz> Issue 22

mccool: any more issues, AOB?
... next week will be cleaning up the paper submission
... no more business, adjourned

Summary of Action Items

[NEW] ACTION: kaz to set up gh-pages setting for wot-security repo so that we can use github.io URL
 

Summary of Resolutions

[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.152 (CVS log)
$Date: 2017/12/04 17:57:25 $