W3C

- DRAFT -

WoT Security

05 Feb 2018

Agenda

Attendees

Present
Kaz_Ashimura, Michael_McCool, Elena_Reshetova, Michael_Lagally, Tomoaki_Mizushima
Regrets
Chair
McCool
Scribe
mlagally, mlagally__

Contents


<kaz> scribenick: mlagally__

Agenda

mccool: please review agenda and add missing things
... we have 2 more calls to prepare for the plugfest

Previous minutes

<kaz> prev minutes

kaz: we should update "Agenda" to "Plugfest template" in last call's minutes

elena: "security bootstrapping" should be called just "bootstrapping"

mccool: IETF draft for draft-garcia-core-security-06 not finalized
... alignment of terminology would be desirable
... having same state diagram will be better

minutes are accepted with above change

mccool: terminology should be clarified further, aligned with ietf, if possible

Security review

mccool: we missed deadline for 2nd draft, should target plugfest
... security review of other TF documents should be reviewed from security POV, presented at plugfest
... for next call I will work on template
... not too much feedback on template presentation to plugfest group
... merge of Michael Koster's template and our template should happen, Michael Koster has the AI
... if you have time to review security template, please work on that

elena: I take an AI to check Michael Kosters template to check what we're missing in the current template

mccool: Security checklist is under "checklists" under plugfest directory

<McCool> Need to convert to markdown, merge with Michael Koster's template

<kaz> Koster's slides

Lifecycle

elena: picture was updated terminology cleaned up
... "security bootstrapping" will be renamed after the call

<kaz> pullrequest 63 - initial text for lifecycle

mccool+elena: discussing details of the diagram
... reprovisioning of same device to a different context is possible. What happens for decommissioning?

mccool: we could use labels to show decommissioning

mccool+elena: discussion on diagram aspects for "decommissioning" continues
... we could have 2 parallel chains of operation states, I can draft a diagram
... I'll accept Elena's pr into the working draft, if all are ok

accepted with no objections

Planning

mccool: need concrete discussion around OAuth and Tokens, need to update thing description
... we don't have much time before the plugfest
... we could just do a minor document update for the plugfest, after that we can do concrete work based on the results of the plugfest
... around March 10th target a document update
... target content: finalize editorial comments, validation

elena: I should do part of section 4, forward proxy scenario in section 5

mccool: industrial use cases are missing, we're weak on that
... need to work on those too in the next month
... 1 month after plugfest we'll have another update including the practical results of the plugfest
... discussion planning details for Feb 12th call
... we should review doc from the other TF groups
... they are not final yet
... let's assume documents are final by this Friday (Feb 9th)

elena: I volunteer for scripting API

mccool: I'll look at TD
... just high level review of the doc - we only have 5 mins to discuss - what needs to be done has to be documented
... I'm unavailable for Feb 19th - reschedule or cancel ? - will do doodle poll

Review of F2F topics and agenda

mccool: need to flesh out use case section, I'm working on payment, validation needs to be added too to the document

<updating Prague F2F Wiki page>

mccool: will review F2F topics again next week

GitHub issues

elena: we should review github issues that we need to bring into the F2F discussion

<kaz> issue 61

elena: we can put labels on issues
... to mark affected group/document

<kaz> (McCool adds labels to some of the issues)

elena: I'll do that offline

meeting adjourned

Summary of Action Items

Summary of Resolutions

[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.152 (CVS log)
$Date: 2018/02/06 05:26:58 $