W3C

- DRAFT -

Web Authentication Working Group Teleconference

02 May 2018

Agenda

Attendees

Present
wseltzer, weiler, jeffh, elundberg, agl, Christiaan, selfissued, jfontana, akshay, jbradley, nadalin, rolf
Regrets
Chair
nadalin, jfontana
Scribe
jeffh

Contents


<scribe> scribenick: elundberg

<jfontana> I'm in

<jfontana> emil I will start

nadalin: there are no un-triaged Pull Requests except #653

<jfontana> https://github.com/w3c/webauthn/pull/653

nadalin: we have 3 un-triaged issues

<jfontana> tony: we have two new un-triaged issues. 981 and....

https://github.com/w3c/webauthn/issues/891

<jfontana> 891

<jfontana> https://github.com/w3c/webauthn/issues/891

<jfontana> tony: anything to talk about her

<jfontana> here

<jfontana> elungberg: can talk in PR

<jfontana> jeffH: akshay says it is ok can we merge?

<jfontana> tonry: we should be OK

<jfontana> https://github.com/w3c/webauthn/issues/894

<jfontana> elungberg: some discussion in the comments.

<jfontana> ...I need to catch up on comments

<jfontana> tony: looks mainly editorial

<jfontana> elungberg: if htis is someting we wnat to do lets put it in PR

<jfontana> seflissue: we should put in PR milestone

<jfontana> elungberg: I can do that

<jfontana> https://github.com/w3c/webauthn/pull/829

<jfontana> tonny: changes are still pending

<jfontana> elungberg: maybe, need jeffH to review.

<jfontana> JeffH: I am in process of reveiw

<jfontana> rolf is on IRC

<jfontana> tony: JeffH merger

<jfontana> jeffH: yes.

<jfontana> https://github.com/w3c/webauthn/pull/836

<jfontana> tony: waiting to merge

<jfontana> selfissue: is it case this isi single cert and not a chain

<jfontana> agl: yes

<jfontana> tony: who can merge

<jfontana> agl: I can do it.

<jfontana> https://github.com/w3c/webauthn/pull/842

<jfontana> work in progress

<jfontana> https://github.com/w3c/webauthn/pull/878

<jfontana> jeffH: this is a start

<jeffh> scribe: jeffh

https://github.com/w3c/webauthn/pull/884

that's WIP

https://github.com/w3c/webauthn/pull/887 -- merge this now

https://github.com/w3c/webauthn/pull/888 waiting on @herrejeremiand

https://github.com/w3c/webauthn/pull/893 merge now

https://github.com/w3c/webauthn/issues?q=is%3Aopen+is%3Aissue+milestone%3APR

<jfontana> can the IRC group see this question?

<jfontana> thank you

<jfontana> I will scribe.

<jfontana> https://github.com/w3c/webauthn/issues/303

<jfontana> selfissue: I think it should be closed. we have IANA registry and that should be well defined.

<jfontana> https://github.com/w3c/webauthn/issues/334

<jfontana> elungberg: resolved with taxonomy stuff?

<jfontana> jeffH: I was going to add to this the on-going discussion and further review of authenticator taxonomy in that light

<jfontana> ...and the pull request

<jfontana> https://github.com/w3c/webauthn/issues/349

<jfontana> akshay: what is this saying

<jfontana> jeffH: add another api method to web authN api to get authenticator ino

<jfontana> ...RP would call that

<jfontana> ...RP gets information

<jfontana> akshay: i will read

<jfontana> https://github.com/w3c/webauthn/issues/360

<jfontana> jeffH: work in progress

<jfontana> https://github.com/w3c/webauthn/issues/364

<jfontana> tony: i thought this one was already considered

<jfontana> selfissue: who should we assign this to?

<jfontana> jeffH: this is not done. we vaguely talk time out value. begs issue for having examples. so jcjones said in other issues..

<jfontana> tony: this could be recommendation.

<jfontana> jeffH: could be

<jfontana> JeffH assigned.

<jfontana> https://github.com/w3c/webauthn/issues/382

<jfontana> elundberg: I can take this

<jfontana> jeffH: we have gone halfway with privacy considerations section

<jfontana> https://github.com/w3c/webauthn/issues/403

<jfontana> jeffH: this references issue 403 related with 334

<jfontana> https://github.com/w3c/webauthn/issues/405

<jfontana> jeffH. editorial

<jfontana> https://github.com/w3c/webauthn/issues/422

<jfontana> jeffH: PR open for that. I will add label

<jfontana> https://github.com/w3c/webauthn/issues/454

<jfontana> tony: elundberg can you reference and change that

<jfontana> elundberg: yes.

<jfontana> agl: can probably be closed. chrome has an answer here

<jfontana> tony: agl can you update and close

<jfontana> agl: yes.

<jfontana> https://github.com/w3c/webauthn/issues/462

<jfontana> ongoing

<jfontana> 553, 519 ongoing

<jfontana> https://github.com/w3c/webauthn/issues/575

<jfontana> christiaan:

<jfontana> ..we decided we will not do this stuff. return is immediate.

<jfontana> jeffH: then we need to submit an issue on the spec.

<jfontana> ..see section 5.1.7

<jfontana> christiaan: should I clarify in issue

<jfontana> jeffH: sure.

<jfontana> https://github.com/w3c/webauthn/issues/576

<jfontana> agl: we have a PR about what to do if you don't check attestation. I think this answers this.

<jfontana> tony: was supppose to be closed.

<jfontana> ...I guessed he re-opened.

<jfontana> agl: looks like it will be closed by the PR elundberg is working on.

<jfontana> https://github.com/w3c/webauthn/issues/578

<jfontana> tony: thought we ran this one around.

<jfontana> ...akshay?

<jfontana> akshay: I can look at it. the privacy aspects.

<jfontana> https://github.com/w3c/webauthn/issues/585

<jfontana> tony: ongoing

<jfontana> jeffH: PR open I will add label

<jfontana> https://github.com/w3c/webauthn/issues/593

<jfontana> jeffH: this is related to PR ....jeff will do this and add number

<jfontana> https://github.com/w3c/webauthn/issues/613

<jfontana> tony: just some clean-up in text.

<jfontana> elundberg: I can take stab.

<jfontana> tony: k

<jfontana> https://github.com/w3c/webauthn/issues/621

<jfontana> elundberg: looks like we agreed to do this and assigned akshay

<jfontana> tony: Ok

<jfontana> tony: 704 in progress, JeffH:

<jfontana> jeffH: yes.

<jfontana> ....close more issues before we muck with this.

<jfontana> https://github.com/w3c/webauthn/issues/712

<jfontana> jeffH: I have been working on that.

<jfontana> ...we have what we can do in spec, at this point done. and I am submitting issues to other specs

<jfontana> https://github.com/w3c/webauthn/issues/733

<jfontana> jeffH: working on it. needs review.

<jfontana> https://github.com/w3c/webauthn/issues/743

<jfontana> elundberg: I can take this

<jfontana> https://github.com/w3c/webauthn/issues/750

<jfontana> jeffH: I have to look at it

<jfontana> https://github.com/w3c/webauthn/issues/764

<jfontana> elundberg: i will take a look at this.

<jfontana> https://github.com/w3c/webauthn/issues/796

<jfontana> elundberg: ongoing

<jfontana> https://github.com/w3c/webauthn/issues/831

<jfontana> jeffH: I thought we fixed this

<jfontana> elundberg: wait two points not resolved.

<jfontana> ... i think we can close this. I will do that.

<jfontana> https://github.com/w3c/webauthn/issues/833

<jfontana> tony: editorial

<jfontana> https://github.com/w3c/webauthn/issues/851

<jfontana> agl: I may have PR open that might relate to thils

<jfontana> akshay: adam opened a PR

<jfontana> ...this is transports and how they work, get assertion, may need help

<jfontana> ...figure this is issue, it is not common scenario. need to discuss.

<jfontana> ...had three different parallel parcel going on.

<jfontana> ...third thing is the transport.

<jfontana> ...adam, christiaan may know better, guide user to better transport.

<jfontana> ...we need more detail

<jfontana> jeffH: basically an authenticator that does three different transports.

<jfontana> agl: i can talk 822 now.

<jfontana> agl: three points. One covers nfc , usb b.tooth.

<jfontana> akshay, you saying internal is ???bus?

<jfontana> in step one of this change. internal is we need somthign to express this case.

<jfontana> agl: two . FIDO did hack. we should have more principled way to do that.

<jfontana> ...step 3. is solving the issue referenced. wants to know in authenticator is internal

<jfontana> ...make new internal mean platform authenticator, then we know it is platform

<jfontana> christiaan: I think face to face this makes more sense.

<jfontana> ..we need to sit down how co. will implement these things

<jfontana> ...as we implement these flows, number of things here importnat

<jfontana> ...one. when creating cred. an RP can say how they want credential exposed.

<jfontana> ...it does not exlude cred if that platform supports it.

<jfontana> ...we can say in the transports, direct or attached. ..same credential could be used remotey if you want to mr. RP

<jfontana> ...this gives RPs more info. to make decisions. if RP has to challenge used they can ask how to sign, say direct only

<jfontana> ...despite transport, RP can ask for other creds. it might sound complicated now, but we can explain later, we need an hour to wlak through this. can do in FIDO Amsterdam.

<jfontana> aksay: think we should talk about this. thought this covered user name.

<jfontana> ...i want to show the journey google is doing and how msft is doing that

<jfontana> christiaan: grat.

<jfontana> great

<jfontana> aksay: I will build some UI

<jfontana> tony: will leave to plenary

<jfontana> https://github.com/w3c/webauthn/issues/864

<jfontana> agl: I don't understand what this is saying

<jfontana> tony: I thought we agreed to have this mis-match.

<jfontana> ...we went through this

<jfontana> ...suggest we close.

<jfontana> jeffH: is adding note.

<jfontana> tony: we are out of time. meeting next two week and following those weeks we will not have one. that is FIDO Plenary week. so we skip week of the 22nd May

<jfontana> ...bye

Summary of Action Items

Summary of Resolutions

[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.152 (CVS log)
$Date: 2018/05/02 18:03:44 $

Scribe.perl diagnostic output

[Delete this section before finalizing the minutes.]
This is scribe.perl Revision: 1.152  of Date: 2017/02/06 11:04:15  
Check for newer version at http://dev.w3.org/cvsweb/~checkout~/2002/scribe/

Guessing input format: Irssi_ISO8601_Log_Text_Format (score 1.00)

Succeeded: s/PR/PR milestone/
Present: wseltzer weiler jeffh elundberg agl Christiaan selfissued jfontana akshay jbradley nadalin rolf
Found ScribeNick: elundberg
Found Scribe: jeffh
Inferring ScribeNick: jeffh
ScribeNicks: elundberg, jeffh
Agenda: https://lists.w3.org/Archives/Public/public-webauthn/2018May/0045.html
Found Date: 02 May 2018
People with action items: 

WARNING: Input appears to use implicit continuation lines.
You may need the "-implicitContinuations" option.


WARNING: IRC log location not specified!  (You can ignore this 
warning if you do not want the generated minutes to contain 
a link to the original IRC log.)


[End of scribe.perl diagnostic output]