13:02:31 RRSAgent has joined #wot-sec 13:02:31 logging to https://www.w3.org/2021/11/15-wot-sec-irc 13:02:39 meeting: WoT Security 13:02:53 present+ Kaz_Ashimura, Michael_McCool, Jiye_Park 13:03:23 Jiye has joined #wot-sec 13:06:28 McCool has joined #wot-sec 13:07:21 present+ Tomoaki_Mizushima 13:08:56 topic: Minutes 13:09:12 -> https://www.w3.org/2021/11/08-wot-sec-minutes.html Nov-8 13:09:31 mm: think the requirements for the possible management API is for the next Charter period 13:09:35 kaz: agree 13:10:27 mm: (adds note on wot-scripting issue 298 to the wot-security-best-practices draft) 13:10:49 -> https://github.com/w3c/wot-scripting-api/issues/298 wot-scripting-api issue 298 13:11:31 jp: wondering about the draft 13:11:44 mm: need to create an actual Pullrequest later 13:12:55 ... think the minutes themselves are OK 13:13:02 (approved) 13:13:09 topic: PRs 13:13:28 https://github.com/w3c/wot-security-best-practices/pull/28 13:13:33 s/PRs/PR and Issue/ 13:14:01 mm: related to issue 27 and 13 13:14:19 s/28/28 PR 28 - Local transport and secure onboarding/ 13:14:22 s/https/-> https/ 13:14:33 ... issue 13 is about local transport 13:15:14 -> https://github.com/w3c/wot-security-best-practices/issues/13 issue 13 - Update Secure Local Transport 13:15:38 mm: the easiest to handle those two issues at once 13:16:03 ... give you a general idea and ask you for opinions 13:16:16 ... not directly merged today 13:16:54 -> https://pr-preview.s3.amazonaws.com/mmccool/wot-security-best-practices/pull/28.html#secure-transport Preview - 2. Secure Transport 13:17:03 mm: extended the section 2 13:17:30 ... we have to revisit the description, e.g., about TLS 1.3 13:17:42 ... then two sections 13:17:53 ... 2.1 Global Networks 13:17:56 ... and 13:18:02 ... 2.2 Offline and Local Networks 13:18:10 ... pretty straightforward 13:18:22 ... how to deal with offline networks is the question 13:18:43 ... no connection with the Internet 13:18:49 ... like a factory network 13:19:09 ... or partial connection like home networks 13:19:32 ... need to establish keys 13:19:41 ... missing part is onboarding process 13:20:00 ... then another paragraph here 13:20:21 ... about onboarding practice 13:20:40 ... then 2nd option 13:21:04 s/practice/practice as a first option/ 13:22:03 ... exposing a limited number of secure endpoints 13:22:12 ... 2nd option would be better, I think 13:22:21 ... then "3. Onboarding" 13:23:38 ... need to look into IETF draft on bootstrapping 13:24:45 ... the bottom line is that we need to know something about onboarding 13:25:17 jp: any kind of assumption for WoT devices? 13:25:37 mm: we don't have all the control 13:26:21 ... probably need to divide the spec into two pieces, brownfield devices and greenfield devices 13:27:15 ... e.g., we can't control devices conforming to the other standards like ECHONET 13:27:58 ... (adds references to the "3. Onboarding" section) 13:29:32 @@@links here 13:34:09 https://datatracker.ietf.org/doc/html/draft-sarikaya-t2trg-sbootstrapping-11 13:34:17 s/@@@links here// 13:34:25 https://datatracker.ietf.org/doc/draft-lear-brski-pop/ 13:34:43 https://datatracker.ietf.org/doc/html/rfc8572 13:35:52 https://datatracker.ietf.org/doc/html/rfc8995 13:36:55 https://datatracker.ietf.org/doc/html/draft-irtf-t2trg-secure-bootstrapping 13:37:31 mm: please make comments on the PR 13:38:08 -> https://github.com/w3c/wot-security-best-practices/pull/28 PR 28 - Local transport and secure onboarding 13:38:35 mm: we need to look into issue 13, 14 and 27 13:39:35 ... would start with 13 and 27 13:40:07 -> https://github.com/w3c/wot-security-best-practices/issues/13 issue 13 - Update Secure Local Transport 13:40:33 -> https://github.com/w3c/wot-security-best-practices/issues/27 issue 27 - Add Onboarding/Key Distribution Section 13:41:51 mm: (adds "BRSKI, DID/VC, Anima" as well) 13:42:31 ... regarding "4. Authentication and Access Control" 13:42:41 ... we only have OAuth 13:43:15 ... need to go through "psk, public, or cert security schemes" again 13:43:38 ... section "6. Object Security" has the same issue 13:43:48 jp: will go through the PR 13:44:04 mm: yes, please look at it in detail 13:44:29 ... will fix the style as well 13:44:32 [adjourned] 13:44:37 rrsagent, make log public 13:44:41 rrsagent, draft minutes 13:44:41 I have made the request to generate https://www.w3.org/2021/11/15-wot-sec-minutes.html kaz 15:08:07 Zakim has left #wot-sec