IRC log of wot-td on 2021-06-02

Timestamps are in UTC.

14:04:38 [kaz]
meeting: WoT-WG - TD-TF
14:05:24 [kaz]
present+ Kaz_Ashimura, Michael_McCool, Ege_Korkan, Michael_Koster
14:08:28 [kaz]
14:09:15 [mjk]
mjk has joined #wot-td
14:09:19 [kaz]
scribenick: mjk
14:09:53 [mjk]
topic: minutes review
14:10:30 [kaz]
present+ Tomoaki_Mizushima
14:10:47 [Ege]
I can take over minutes anytime now
14:12:25 [Ege]
14:12:47 [kaz]
scribenick: Ege
14:12:53 [zkis]
zkis has joined #wot-td
14:12:54 [Ege]
Topic: PRs
14:13:19 [kaz]
14:13:28 [kaz]
14:14:08 [kaz]
scribenick: mjk
14:14:37 [mjk]
PR #1156
14:15:05 [mjk]
ege: subprotocol is an enum of the possible protocols
14:15:46 [mjk]
14:17:24 [mjk]
(reviewing problems in PR)
14:18:14 [mjk]
mm: questions about use of "rel"
14:18:44 [mjk]
ege: link validation is complicated due to the icon link type
14:18:57 [mjk]
ege: it is correct
14:20:04 [mjk]
mm: try to reduce lines where the brackets can be on one line
14:20:42 [mjk]
mjk: processors seem to always expand the brackets
14:20:55 [Mizushima]
14:21:54 [mjk]
mm: (line by line review of the diff)
14:23:10 [mjk]
mizushima-san: there is a problem on line 2
14:23:10 [Mizushima]
14:23:22 [mjk]
mm: (fixed)
14:23:39 [mjk]
mm: any objections to merging?
14:24:26 [mjk]
mm: OK
14:24:43 [mjk]
mm: review other PRs
14:24:54 [mjk]
mm: signatures, PR #1151
14:25:16 [kaz]
14:25:19 [mjk]
mm: still some things yet to do
14:25:41 [kaz]
14:28:11 [mjk]
mm: added support for XML signatures that have signatures for sub-sections of the document
14:28:37 [mjk]
it creates a digest and signs individual items in the digest
14:28:55 [mjk]
s/it/mm: it
14:29:04 [kaz]
present+ Philipp_Blum
14:29:15 [kaz]
14:29:50 [citrullin]
citrullin has joined #wot-td
14:29:56 [kaz]
14:29:59 [mjk]
mm: there needs to be a way to support keys in the TD
14:30:23 [mjk]
... or it could be a URL that points to the keys
14:30:28 [kaz]
14:31:44 [mjk]
mm: there is a question of which curves to support beyond JWS
14:32:17 [mjk]
... testing could impose a practical limit on the number of curves we can support
14:33:16 [mjk]
mm: there is an issue with including the digest as a mandatory element in TD
14:33:35 [mjk]
mm: there could be 2-step validation, before and after
14:34:19 [mjk]
mm: another question about expanding references
14:34:33 [mjk]
... we can't validate a TD with expanded references
14:35:27 [mjk]
mm: we could build reference expansion into the processing
14:35:49 [mjk]
... the expanded form wouldn't be stored or validated
14:36:53 [mjk]
mm: with PKI, the signatures aren't compared directly but decrypted and the hash compared
14:37:27 [mjk]
mm: it introduces a dependency on signature type
14:38:52 [mjk]
philip: the curve selection is important; it's good to support a lot of curves, but maybe we don't need to test optional curves
14:39:40 [mjk]
mm: we can't use a curve that we can't test, so we will need a small set
14:40:30 [mjk]
philip: we have the same situation in other areas, for example CBOR + JSON issue in the profiles
14:42:06 [mjk]
mm: the testing doesn't need to include the mathematics of the curves
14:42:21 [mjk]
... we just use a library
14:42:33 [mjk]
kaz: the main consideration is 2 implementations
14:42:55 [mjk]
mm: the TD feature we are testing is the signature wrapper
14:44:56 [mjk]
mm: we should test the 3 reference types json pointer, json path, and xpath
14:45:12 [mjk]
philip: we should test the DID method
14:45:26 [mjk]
mm: we have a general need to test URI methods
14:45:53 [mjk]
mm: we get to a question of coverage vs. requirement
14:46:24 [mjk]
mm: would like to merge this PR but it could be TD 2.0
14:46:36 [mjk]
mm: any other PRs?
14:47:41 [mjk]
mm: canonicalization wrt prefixes is still a question
14:48:01 [mjk]
mm: any other topics?
14:48:06 [mjk]
... AOB?
14:48:12 [mjk]
... adjourn
14:48:37 [kaz]
