W3C

- DRAFT -

Web Authentication Working Group Teleconference

13 Dec 2017

Agenda

Attendees

Present
weiler, elundberg, wseltzer, nadalin, akshay, battre, gmandyam, agl, Rolf, jfontana, John_Bradley, jeffh, selfissued, jyasskin, apowers, angelo
Regrets
Chair
nadalin, jfontana
Scribe
weiler

Contents


<scribe> scribenick: weiler

tony: we put a call for consensus on the list, for using wd07 + issues marked for CR as the CR version.
... would appreciate responses
... There's a publishing milestone of 13 Dec (today), because of W3C holiday publication blackout. We won't meet that. The timeline I have in mind is a transition request on 2 Jan.
... That assumes we have consensus.

jfontana: working on transition doc. We're waiting for reviews.
... I sent emails again seeking those.

weiler: we may need to wait re: reviews - we didn't ask for those earlier in the process, and we may need to wait for them now.

https://github.com/w3c/webauthn/pull/476

nadalin: Rolf has this. I think we're still waiting for jyasskin and alexei.

https://github.com/w3c/webauthn/pull/510 - biometric

giri: I need jeff and emil's approvals.

jeff: next week

https://github.com/w3c/webauthn/pull/263

nadalin: jyasskin not here today. Rolf had issues... Jeff had issues...

<jyasskin> I can join. One second.

https://github.com/w3c/webauthn/pull/653

nadalin: not sure if we need this for CR or not

giri: it's an .md file change - i don't think it's a CR issue

nadalin: possible PR issue; needs to be done by then

https://github.com/w3c/webauthn/pull/664

nadalin: this is angelo's.... Jeff & Jyasskin asking for changes.

https://github.com/w3c/webauthn/pull/623

jyasskin: I've gotten pulled off of webauthn in favor of web packaging. anyone else to take this?

nadalin: [explains timeline again]

jeffh: happy to take it, but I think Jan 2 is highly aspirational. (3 weeks away) I'm gone week after Xmas.
... I'd prioritize doing other PRs first and getting those merged before this new work.

nadalin: trying to set some goals to get progress.

akshay: I can take this; I want someone to review after I make the changes.

nadalin: jeffrey, will you review?

jyasskin: yes.
... push it to my branch.

https://github.com/w3c/webauthn/pull/664

nadalin: angelo, would you review comments?

angelo: later this week

https://github.com/w3c/webauthn/pull/666

jeffh: early next week

emil: you recommended copying a passage... can we just do that?

<elundberg> https://github.com/w3c/webauthn/pull/666#discussion_r155356806

weiler: copy it.

wseltzer: copyright not an issue. good practice to give attribution, since it's not mere fact.

jeffh: +1

emil: will do.

https://github.com/w3c/webauthn/pull/686

jeffh: looks good to me.

nadalin: go for it.

https://github.com/w3c/webauthn/pull/687

emil: we said we'd wiat for 705, since they touch same things.

nadalin: it has a branch conflict....

https://github.com/w3c/webauthn/pull/688

nadalin: johan is gone for rest of year....

jeffh: this could wait.

nadalin: yes, could wait for PR. also still have IPR outstanding.

Rolf: it's just half a sentence. what if I just create a PR on the same

wseltzer: this is a patent issue, not copyright. which is why we're being diligent.

nadalin: wendy, why is it set up so someone not in group can create PR?

wseltzer: would we rather not hear from them, or hear from them and ask f/u q's? we can always reject PR. Our thought is that it's more helpful to get input from broader public and check IPR later.

nadalin: I don't like this route...

wseltzer: WRT this one specifically, we've been following up with them. we had email issues. we've gotten past that.

nadalin: johan has others in here - it's good to get him in the system.

https://github.com/w3c/webauthn/pull/705

jeffh: i need to look at emil's comments. friday.

https://github.com/w3c/webauthn/pull/708

nadalin: christiaan is away... agl, maybe?

agl: sure.

<jeffh> others are also invited to review #705 :)

akshay: me too

https://github.com/w3c/webauthn/pull/709

jeffh: looks good to me.

nadalin: angelo?

angelo: I think it's okay. will double-check.

https://github.com/w3c/webauthn/pull/710

nadalin: no issues?

agl: will merge.

https://github.com/w3c/webauthn/pull/721

nadalin: i think this is ok. jeffrey?
... anyone else available?

jeffh: looking now.

jyasskin: looks fine.

agl: two word change....

emil: i'll merge this and f/u on comments in another pr.

https://github.com/w3c/webauthn/pull/717

giri: why is this not flagged as CR?

jeffh: we have not-triaged issues and someone should triage.

nadalin: I'll go back through this list.

jeffh: can we do them on the call?

editors/acknowledgements

nadalin: some people should add themselves to the proper lists.

selfissued: I plan to incorporate jeff's feedback. if anyone wants different credit, put a comment on the issue.

nadalin: I think many have contributed to text and I'd like to see them as editors, also.

unclassified issues

https://github.com/w3c/webauthn/pull/[various]

agl: this is a result of addressing issue 599

and 723 addresses an issue tagged CR

so 723 should be tagged CR.

giri: 724 same story.... except issue is 679 ... better sooner than later because people care about interop.

nadalin: tag as CR, but OK to push it to PR

https://github.com/w3c/webauthn/pull/718

nadalin: this is also a CR....
... 717 should be CR
... I think all PRs have milestones marked.

Issues w/o milestones

<jeffh> https://github.com/w3c/webauthn/issues/725

nadalin: issue 725.... https://github.com/w3c/webauthn/issues/725

giri: predefined ext's not consistent w/ each other
... this is fixable but defn is not sufficient for an authenticator developer. some ext defs may not conform w/ requirements in previous section. both sections need fixing.
... need to more tightly define ext in section 9.
... e.g. what should ext defn's say re: client ext input et al
... only problem is that I didn't write those ext's. and we've been letting proponents edit their own ext's.
... are folks willing to let me edit this?
... e.g diff between CBOR text string v. CBOR map.
... whoever wrote this was conforming to req of section9, which is why I think section 9 should change.

nadalin: I put you and mike on this.

selfissued: I know certain indiv ext's need polishing, but I worked on general language. if changes needed to general language, give me specific suggestions.

giri: just wanted to ask, since these would be last-minute changes

nadalin: could these wait to PR?

giri: either way. but we will get comments on this. inconsistent ....

nadalin: I'll tag it as CR

https://github.com/w3c/webauthn/issues/712

Consider using "parse JSON from bytes"

emil: nice but not necessary

nadalin: I'm assigning this to PR. if we get nothing, we let it go.
... this leaves all issued as classified. TDB if we got it right. :-)
... so about 30 open issues for CR.
... How many of these can we get done before people disappear?

call schedule

nadalin: no call on 27th.
... will have a call on Dec 20th and Jan 3rd

weiler: there was an agenda item of interop; anything to say about that?

nadalin: we had talked about week of Jan 26th, w/ FIDO, in bay area. people are free to do online testing before that. we left it as Fri, Jan 26th at Google, I think....
... will settle that when Christiaan is back. but jc, angelo, and christiaan seemed happy with that. wd07 as basis.

Summary of Action Items

Summary of Resolutions

[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.152 (CVS log)
$Date: 2017/12/13 18:56:28 $

Scribe.perl diagnostic output

[Delete this section before finalizing the minutes.]
This is scribe.perl Revision: 1.152  of Date: 2017/02/06 11:04:15  
Check for newer version at http://dev.w3.org/cvsweb/~checkout~/2002/scribe/

Guessing input format: Irssi_ISO8601_Log_Text_Format (score 1.00)

Succeeded: s/717/[various]/
Succeeded: s/also/all/
Succeeded: s/he had/we had/
Present: weiler elundberg wseltzer nadalin akshay battre gmandyam agl Rolf jfontana John_Bradley jeffh selfissued jyasskin apowers angelo
Found ScribeNick: weiler
Inferring Scribes: weiler
Agenda: https://lists.w3.org/Archives/Public/public-webauthn/2017Dec/0162.html
Found Date: 13 Dec 2017
People with action items: 

WARNING: IRC log location not specified!  (You can ignore this 
warning if you do not want the generated minutes to contain 
a link to the original IRC log.)


[End of scribe.perl diagnostic output]