20:06:34 RRSAgent has joined #webauthn 20:06:38 logging to https://www.w3.org/2024/11/13-webauthn-irc 20:06:55 Meeting: WebAuthn WG weekly meeting 20:07:44 Tony: we're going to cancel meetings on 12/04/2024 and 12/15/2024 20:08:57 > Tony: we're going to cancel meetings on 12/04/2024 and 12/15/2024 20:08:57 didn't he say 25th? the 15th is a Sunday. 20:10:17 Topic: Clarify use creating and verifying TPM attestation statements. by mwiseman-byid · Pull Request #2193 · w3c/webauthn 20:11:19 [Monty explained some concepts about migration] 20:12:13 Topic: 2194 20:13:54 Adam: fine for me 20:13:54 Tim: it is the status quo 20:14:37 Pascoe: fine to me 20:15:08 Tony: if anyone any issues, we can merge it 20:16:01 present+ Monty, Simone, Askshay, Sweeden, Tony, Nina, Adam, Matthew, John, Emil, Jaimin, David_Turner, Pascoe, Tim, David_Waite, Lanchlan 20:16:11 topic: 2193 20:16:45 Sweeden: ok for me 20:16:47 Emil: approved 20:17:54 Topic: Update Use Cases for L3 by timcappalli · Pull Request #2139 · w3c/webauthn (github.com) 20:18:11 Tony: it is editorial, we can prioritize before January 20:18:26 Topic: Cleanup: Manual References by timcappalli · Pull Request #2111 · w3c/webauthn (github.com) 20:18:58 Tim: this one is the same. It is editorial and to be done later 20:21:12 Adam: we're going to create the L3 branch, if it is ok 20:24:00 ... we need to check if all the PRs was applied to the correct branch 20:25:37 Emil: to solve it, I am going to merge main into L3 20:26:04 Topic: 2195 20:26:32 Tony: we agreed that this will be in L3 20:27:37 Topic: 2186 20:27:42 Tim: already merged 20:28:22 Topic: The authenticator may hide the credential even if the RP signals unknown credentials · Issue #2192 · w3c/webauthn 20:29:36 Nina: in general, the signal api cannot guarantee it. I can answer it but this will not change the spec 20:30:14 Tim: I agree with you. We should leave it as it is 20:30:43 Nina: ok I am going to comment, close and tag L3 20:30:54 Topic: Bit set by the SPC extension should backed up as part of the Public Key Credential Source · Issue #2153 · w3c/webauthn (github.com) 20:31:29 Tim: this is just a reminder to talk with SPC people, we can close it 20:31:36 Topic: Allow `platform`-based self attestation with non-zero AAGUID when `AttestationConveyancePreferenceOption` `"none"` is used · Issue #2146 · w3c/webauthn (github.com) 20:32:12 Tony: is this still valid? 20:33:56 Matthew: I am not aware of any authenticator that fills into this scenario 20:34:28 ... who wants to prive attestation when there is no attestation? 20:35:24 John: self-attestation don't have a GUID 20:36:05 Sweeden: for the purpose of RP trust, this has no meaning 20:36:27 present+ Michael_Jones 20:37:12 John: do we have somewhere that authentication cannot return it? 20:38:01 Matthew: Is the PR 2150, but it is in the future 20:38:40 akshay: move to the future is ok for me, with the PR mentioning it 20:39:03 ... are both platform authenticators and security keys allowed to do that? 20:39:22 Tim: we decided no, but desire to yes 20:40:34 John: default behaviour should be a AA GUID 20:42:33 Tim: going to create a new issue for that 20:42:44 ...but not committing on PR 20:43:23 John: can we say that AA GUID must be a 16 zero bytes? 20:43:41 Emil: removed for platform authentication specifically 20:43:56 .. it was 2058 20:44:01 s/../.../ 20:45:02 John: but it not says what is the default 20:45:39 Akshay: it is on the IDL 20:47:01 Tim: [sharing screen] looking at the editor's draft as it was merged 20:47:27 Nina: this is to avoid fingerprinting of the key vendor 20:48:37 Tim: This is also for spec match 20:48:54 s/ a GUID/AA GUID/ 20:50:50 John: the word is for the dialog, as discussed at TPAC 20:52:08 Tim: created issue 2198 to describe the results of the discussion in the call 20:52:55 Tony: we can approve today or last week 20:54:24 present+ Mike 20:54:35 Mike: ok I'll read it, approve and merge 20:55:35 Emil: I can do a quick PR to remove the sentence, to close 2146 or move to future? 20:55:46 Topic: 2106 20:56:14 tony: move to the future? 20:56:20 Emil: I can comment and close 20:56:31 Topic: 2059 20:56:57 Tim: future at this point 20:57:07 Topic: 2056 20:58:27 Sweeden: something for browser vendors 20:58:34 Tony: in the future 20:59:00 I'll close #2192 during the next meeting, to give OP some time to respond. 20:59:19 Tony: we are going to close all the technical PRs 21:00:36 Topic: any objection to go in create a WD, having the Wide Review, then going to Candidate Recommendation? 21:01:52 Tony: as we all agree and there are no objections, we can go! We'll work on the editorial, and for the technical part, we'll have on L4 21:02:37 RRSAgent, make logs public 21:02:45 RRSAgent, draft minutes 21:02:47 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:30:16 s/12/15/2024/12/25/2024/ 21:30:21 RRSAgent, draft minutes 21:30:23 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:31:15 s/tony/Tony/g 21:31:48 s/haveAA/have AA/ 21:33:16 s/Topic: 2186/Topic: Mozilla feedback: Related Origins #2186/ 21:33:20 RRSAgent, draft minutes 21:33:21 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:34:03 present+ Akshay 21:34:20 RRSAgent, draft minutes 21:34:22 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:35:22 present- Askshay 21:35:41 RRSAgent, draft minutes 21:35:42 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:36:11 s/akshay/Akshay/ 21:37:00 s|12/15/2024|12/25/2024| 21:37:06 RRSAgent, draft minutes 21:37:07 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:37:34 chair: Tony 21:37:37 RRSAgent, draft minutes 21:37:38 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:39:32 s/Topic: 2195/Drop outdated "Issue 1" from spec #2195/ 21:40:28 s/Topic: 2193/Topic: Clarify use creating and verifying TPM attestation statements. #2193/ 21:40:53 s/Topic: 2194/Topic: Delete authenticatorDisplayName #2194/ 21:41:46 s/Topic: Clarify use creating and verifying TPM attestation statements. by mwiseman-byid · Pull Request #2193/TPM discussion/ 21:42:17 s/TPM discussion/Topic: TPM Clarifications/ 21:42:29 RRSAgent, draft minutes 21:42:30 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:47:35 i|Tony: we're going to cancel meetings|Topic: Meetings plan| 21:47:49 RRSAgent, draft minutes 21:47:51 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:48:41 s/Topic: 2193/Topic: Clarify use creating and verifying TPM attestation statements. #2193 21:48:46 s/Topic: 2193/Topic: Clarify use creating and verifying TPM attestation statements. #2193/ 21:49:09 RRSAgent, draft minutes 21:49:11 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:50:40 s/Topic: 2056/Topic: CollectedClientData serialization is confusing WebIDL and/_r Infra values for ECMAScript values #2056/ 21:50:51 s/Topic: 2056/Topic: CollectedClientData serialization is confusing WebIDL and_or Infra values for ECMAScript values #2056/ 21:50:56 RRSAgent, draft minutes 21:50:57 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:52:02 s/Topic: 2059/Topic: Additional guidance or clarification on RP ID and origin validation #2059/ 21:52:39 s/Topic: 2106/Topic: Make AuthenticatorAttestationResponseJSON.publicKeyAlgorithm optional #2106/ 21:53:30 s/Topic: 2193/Topic: Clarify use creating and verifying TPM attestation statements. #2193/g 21:53:32 RRSAgent, draft minutes 21:53:34 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:58:24 s/topic: 2193/Topic: Clarify use creating and verifying TPM attestation statements. #2193/ 21:58:27 RRSAgent, draft minutes 21:58:29 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 21:58:54 s|Tony: we're going to cancel meetings on 12/04/2024 and 12/15/2024|Tony: we're going to cancel meetings on 12/04/2024 and 12/25/2024| 21:58:56 RRSAgent, draft minutes 21:58:58 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 22:00:50 i|Tony: we're going to cancel meetings on 12/04/2024 and 12/25/2024|Topic: Canceled Meetings| 22:00:55 RRSAgent, draft minutes 22:00:56 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 22:01:29 s/Topic: Meetings plan// 22:01:33 RRSAgent, draft minutes 22:01:34 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 22:02:48 s/any objection to go in create a/Any objection to/ 22:02:53 RRSAgent, draft minutes 22:02:55 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 22:03:36 s/Any objection to WD/Any objection to publish a Working Draft/ 22:03:39 RRSAgent, draft minutes 22:03:41 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone 22:04:50 s/having the Wide Review, then going to Candidate Recommendation?/ask the Wide Review, then go to Candidate Recommendation?/ 22:04:52 RRSAgent, draft minutes 22:04:54 I have made the request to generate https://www.w3.org/2024/11/13-webauthn-minutes.html simone