12:03:14 RRSAgent has joined #wot-sec 12:03:14 logging to https://www.w3.org/2022/06/13-wot-sec-irc 12:03:49 meeting: WoT Security 12:04:06 jiye has joined #wot-sec 12:04:06 present+ Kaz_Ashimura, Michael_McCool 12:05:07 present+ Jiye_Park 12:07:31 present+ Tomoaki_Mizushima 12:12:14 scribenick: kaz 12:12:16 topic: Minutes 12:12:24 -> https://www.w3.org/2022/05/30-wot-sec-minutes.html May-30 12:12:40 mm: (goes through the minutes) 12:14:18 approved 12:14:31 topic: Discovery and TLS/DTLS 12:15:34 -> https://w3c.github.io/wot-discovery/#exploration-server WoT Discovery draft - 7.2 Thing Description Server 12:17:32 mm: (shows section "7.2 Thing Description Server") 12:17:57 ... would remove the redundant assertions on TLS and authentication 12:19:09 ... current text there is a pair of assertions 12:19:44 ... i.e. 12:19:46 ... An HTTP-based TD Server providing a TD SHOULD use TLS when serving requests. 12:20:00 ... An HTTP-based TD Server providing a TD SHOULD provide the resource only after performing necessary authentication and authorization. 12:20:48 ... instead, we could just add another text 12:22:41 ... e.g., use of secure transport is subject to further assertions given in the Security Considerations sections of the WoT Architecture and the WoT Thing Description specifications, including scenarios where secure is mandatory and mutual authentication is recommended. 12:23:07 s/secure/secure transport/ 12:23:38 s/instead, // 12:23:59 kaz: adding clarification would be good 12:24:22 mm: there is a similar issue around the other sections too 12:25:51 kaz: referring to the other specs like Architecture and TD is fine 12:26:30 ... but that would mean the features are not really the ones of Discovery, and the Discovery spec itself doesn't need to test those features 12:26:35 ... is that correct? 12:26:38 mm: yeah 12:27:18 ... the point here is moving the description to those existing specs 12:27:31 jp/kaz: ok 12:28:07 mm: (creates a PR for that purpose) 12:28:25 ... this change, we can remove the Editor's Note too 12:28:40 s/PR/Issue/ 12:29:04 -> https://github.com/w3c/wot-discovery/issues/335 Issue 335 - Fix TLS Assertions 12:29:14 mm: will create a PR for that purpose too 12:29:29 s/Issue for that purpose/Issue about this/ 12:29:35 rrsagent, make log public 12:29:40 rrsagent, draft minutes 12:29:40 I have made the request to generate https://www.w3.org/2022/06/13-wot-sec-minutes.html kaz 12:30:43 topic: Discovery Issue 303 12:31:06 -> https://github.com/w3c/wot-discovery/issues/303 wot-discovery Issue 303 - Personal devices and public/private TDDs 12:32:27 -> https://github.com/w3c/wot-thing-description/issues/1497 related wot-thing-description Issue 1497 - Identifiers don't seem to rotate enough 12:32:59 mm: (add a comment to wot-discovery Issue 303 about wot-thing-description Issue 1497) 12:39:51 ... (also adds some more comments) 12:45:12 -> https://github.com/w3c/wot-discovery/issues/303#issuecomment-1153869121 McCool's comments 12:48:30 mm: (also adds comments to the wot-thing-description Issue 1497 too) 12:53:13 -> https://github.com/w3c/wot-thing-description/issues/1497#issuecomment-1153876618 comments on wot-thing-description Issue 1497 12:55:24 q+ 12:57:16 kaz: the bigger question here is whether the WoT specs like TD and Discovery should define the algorithm for how to generate IDs and use them or not 12:57:17 mm: yeah 12:57:42 ... let's continue the discussion next week 13:00:15 kaz: fyi, I'm planning to organize a breakout session during TPAC about how to deal with IDs which requires further collaboration with the other related groups, e.g., DID and VC 13:00:41 ... we should handle that potential session separately from this discussion, though 13:00:46 mm: yeah 13:01:15 ... we should think about both (1) future version and the (2) current version 13:01:54 ... but should handle the future version discussion separately from the current specs 13:02:01 [adjourned] 13:02:05 rrsagent, make log public 13:02:08 rrsagent, draft 13:02:08 I'm logging. I don't understand 'draft', kaz. Try /msg RRSAgent help 14:00:36 kaz has joined #wot-sec 14:04:01 Mizushima has left #wot-sec 14:24:16 https://github.com/w3c/wot-discovery/issues/340 14:33:11 https://github.com/w3c/wot-discovery/issues/341 14:55:27 Zakim has left #wot-sec