Meeting minutes
phila: any other items for the agenda for today?
manu: there is a discussion over the last couple weeks around payments and digital credentials
… EMVCo did a presentation at the W3C
… some of us were there and noted that there are W3C VC community members doing payments work at other organizations
… some of those other orgs are also hoping to visit on August 27th to present some of that work
… I can't make that call
… but hopefully others here can
… there are some asks from FIDO and EMVCo
… and folks here could contribute review
… as they've been asked to support W3C Verifiable Credentials
… and it would be great for us to participate
phila: is that the FedID WG call on the 27th?
manu: yes.
<phila> The meeting Manu is talling about is https://
phila: I was under the wrong impression that it was only for chairs, but everyone is actually welcome
… I plan to be there and I hope others will join from this group as well
… there are other events this fall where various standards will be being discussed together
TallTed: that call is actually already on the VCWG calendar
<Zakim> brent, you wanted to say also at TPAC
brent: there is also a joint meeting on the Tuesday of TPAC
… if you've already registered, please consider attending that
… one of the bolded options for you should be that joint session
phila: It's 1:30 PM on Tuesday--Ireland time
… k. there's a list of things from manu for us to go through today
task Force updates
phila: anyone else have other task force things to discuss?
dmitriz: the Render Method Task Force agreed to ask the main group--this one--to do a resolution to start the horizontal review for our spec
<Zakim> manu, you wanted to note lots of work on threat models.
phila: dmitriz can you draft that?
manu: I actually have resolutions drafted
phila: great, let's use that/those
manu: this isn't usually how we do it, but doing one proposal would simplify things
wes-smith: that list should include VC Forgery Defense also
manu: k. adding that.
phila: so, some context for those who might be need
… wide review is a W3C distinguishing feature
… we have Accessibility, I18N (Internationalization), Security, Privacy, and the TAG (Technical Architecture Group) review every standard
… these things can take a bit, so we want to start them earlier than later
… these are valuable reviews since the Web is for Everyone (per Tim Berners-Lee)
wes-smith: we will need to link to these minutes as part of the request to the TAG (at least) when doing horizontal review
<manu> PROPOSAL: Request Horizontal Review for VC Rendering Methods, VC API for Lifecycle Management (VCALM), VC Barcodes, and VC Forgery Defense.
phila: manu please post the proposal--I think we're ready to vote
<TallTed> +1
<dlongley> +1
<bigbluehat> +1
<phila> +1
<wes-smith> +1
<manu> +1
<JennieM> +1
<dmitriz> +1
<pdl-ASU> +1
<michaelshea> +1
<brent> +1
<kezike> +1
<KevinDean> +1
phila: simple resolutions only come from far too few people doing far too much work
… thank you to those who have made this happen!
RESOLUTION: The VCWG requests Horizontal Review for VC Rendering Methods, VC API for Lifecycle Management (VCALM), VC Barcodes, and VC Forgery Defense.
<Zakim> manu, you wanted to note I have one more for the registration
phila: for wes-smith and anyone else who needs it, there is the direct link to the vote above
<Elaine> Post link again. Please. I was disconnected.
manu: it's good practice to register protocol and/or pseudo schemes at IANA
… we have one in VCALM called `interaction:`
… and it supports multiple protocols
<manu> https://
manu: this should actually help the ecosystem by building a bridges from user agents (Wallets, browsers) to various protocols
phila: this is what goes at the front of the URI?
manu: yes
<Elaine> Add me +1
phila: is this contentious?
manu: who knows?! We don't think so.
… the `web+interaction` URL is for web apps to be registered as Wallets
brent: as someone who is currently going through a failing URI attempt
… I am not seeing the description of the URI itself
… I see the scheme registration, but where is the description of what the URI actually looks like?
manu: are you asking about the ABNF?
… I thought that was not needed until the final registration, not a provisional one
<dlongley> https://
<manu> https://
manu: kezike may know more
kezike: we do have ABNF
manu: we could provide that. We do have it.
brent: all good. I just wasn't finding it.
manu: some registrations have very little info and others have pages...so who knows how this will go
kezike: we should probably put the full scheme names in the proposal
manu: we mention that the spec talks about what they are
… we could make it explicit
TallTed: yes, please do
<manu> PROPOSAL: Request the registration of protocol schemes listed in the IANA Considerations section, that is, interaction and web+interaction, of the Verifiable Credential API for Lifecycle Management (VCALM) specification via IANA.
<dlongley> +1
<dmitriz> +1
<brent> +1
<kezike> +1
<michaelshea> +1
phila: thank you, manu
<phila> +1
<bigbluehat> +1
<TallTed> +1
<manu> +1
<JennieM> +1
<pdl-ASU> +1
<Elaine> +1
RESOLUTION: The VCWG requests the registration of protocol schemes listed in the IANA Considerations section, that is, interaction and web+interaction, of the Verifiable Credential API for Lifecycle Management (VCALM) specification via IANA.
phila: whether you were part of the work or not, you are part of the group that approved this resolution
… I understand that folks can't be in all groups, but we do act as a group for significant actions such as this one.
test suites and implementations
phila: we're heading into a few upcoming months where test suites need expansion or creation
… with the number of things going on, it can be helpful to see who's actually using this stuff
… where can I see the W3C VC stack in the wild?
… if you have or you know of an implementation of W3C VCDM, I'd be very interested to hear about that
… so we can jot some of that down and talk about them at the conferences this fall
manu: I can't mention all of our rollouts, but one of them is the CA DMV
… all Driver's Licenses in CA are issued both as mDL and VCs
… they also issue Vehicle Titles as only W3C VCs
… there should be upcoming news about that
… there has also been educationally focused VCs getting traction in CA
… there are a number of pilots--such as the Career Passport pilot
… MOSIP has mentioned that they have 180 million _people_ using VCs--obviously even more VCs than people
… several US states are issuing VCs for a wide range of government and educationally related use cases
<dlongley> additional note on CA DMV: all new physical licenses include VCBs.
manu: CONEXSUS and NACS are releasing several VC ecosystem-based deployments
<wes-smith> and ID cards!
manu: I can't share all the timelines, but "soon"
… some of this surfaces on https://
… if you look at convenience.org's list of credentials, you'll find an entire retail store story there with VCs covering things such as gift cards, loyalty cards, etc.
… and many more announcements coming in the next 6-9 months
phila: that's great data.
… does anyone else have data they can share?
<pdl-ASU> I believe the California Career Passport also includes the Community Colleges and CA State University System, as well.
michaelshea: I believe the UNTP work is getting traction in Australia
… and is moving from pilot to production in the next 12-18 months
… that's obviously outside the person identity space
manu: thank you michaelshea, lots more going on at the UN and in the supply chain world as well
<pdl-ASU> ASU does issue W3C VC compliant OBv3 credentials as well
manu: I also meant to call out VC Barcodes specifically
… a VC Barcode is going on all physical Driver Licenses in CA
… so VCs are in people's hands--with a 5-to-1 ratio opposite mDL technology in CA
denkeni: as manu mentioned, MOSIP has lots of adoption
… we're going to propose a new task force under the CCG soon
… we're using much of this technology in our own countries
… and I'm hoping we can contribute to test suites, etc.
phila: I believe there's also work going on in Brazil?
hxavier: what I know is that there are biometric, non-VC-based private implementers
… but the government is working on a solution based on verifiable credentials
… I know VCs have been applied to giving credit to farmers, but not sure of the specifics
… and for age assurance they are using VCDM
… and also using the OID4* protocols
phila: anyone else have more to share?
… I and many others are going to be on the road talking about our work and pushing their own approaches
… it always helps to have real world use cases to present
<pdl-ASU> The Alabama Talent Triade is their statewide talent markplace has the W3C VC as a core pillar of its technology stack.
phila: it provides confidence
… and in this spirit, GS1 is indeed implementing W3C VCs
… we are a federated organization, so we have to work out governance next
… also, for the Recognized Entity folks, we are planning to get our docs up to date to share with that task force
… so, GS1 is certainly on board
… which is a big deal for cross-border trade, etc.
michaelshea: there is a great deal of activity going on with UNTP
… especially around mines
… and pilots around fashion and textiles
… and another around responsible businesses
… there's also a seafood traceability group forming
… and all these groups are bringing lots of attention to UNTP
… and UNTP is 100% W3C VC based technology
<pdl-ASU> The Tennessee Board of Regents (TBR) through its CRED System (Comprehensive Record for Every Learner) uses VCDMs (via OBv3 and CLRv2s)to represent verified skills, course competencies, co-curricilar achievements and credit-for-prior-learning.
CID
Elaine: just an FYI, I'm also in the ISO groups related to this work
phila: great. I have nothing but respect for anyone working in standards
Elaine: and just so you know, folks often think I'm the liaison for the W3C--which I am not
phila: yes...similar confusions about around GS1 here
<brent> +1 Elaine should feel free to give ISO folks an update on what we're doing
phila: michaelshea you wanted to discuss some specific things here
<pdl-ASU> The State of North Dakota issues W3C VCs to all K12 students (focused on middle and high school) and a few technical schools have joined into project managed through the State Longitudinal Data Service.
CID Issue 170 w3c/cid#170
michaelshea: this particular one probably needs Joe to be here
brent: this one is actually done
CID issue 167 w3c/cid#167
CID issue 165 w3c/cid#165
CID issue 166 w3c/cid#166
<phila> bigbluehat: It's bc we're using content-based hashes, line endings and so on can change the hash. We have to look through until we find a match...
<phila> michaelshea: That's outside my expertise - can you help please?
<phila> bigbluehat: Has anyone gone through and checked all these? We may need to change how we share hashes so they don't get messed up.
phila: there are a couple of instances where it really matters where the hash in the spec matches
… I'm thinking the JSON-LD context file in the VCDM
… in that case, it really matters
… in the examples, I think I've seen text that says we make no cryptographic promises around examples
<phila> bigbluehat: This is a topic in itself. Do we need non-normative hashes to be accurate?
<Zakim> brent, you wanted to give context
brent: to give some context here...no pun intended
… as we were preparing the last round of specs
<dmitriz> @bigbluehat -- we really need to add a canonicalization attribute to digestMultibase..
brent: we wanted to be able to normatively reference the context
… I don't think removing the hashes is an option
… we need to fix this one way or the other
<dlongley> dmitriz: i think that already exists, the group just didn't have consensus to use canonicalization for these hashes in the past.
phila: this maybe just needs a quick call with bigbluehat and pchampin
<dmitriz> @dlogley -- what's the mechanism? multihash?
michaelshea: I'm happy to try and set one up
phila: I know pchampin is on holiday
… but basically, it's a bit of engineering to get it right
michaelshea: I will setup a separate call around 166
<dlongley> dmitriz: https://
<dmitriz> @dlongley -- I'm familiar with multicodec mechanism in general, I'm more asking -- does digestMultibase support that notation
<dlongley> dmitriz: yup, just use that header :) ... it's in the same namespace
<dlongley> (that's my understanding)
Issue 161 w3c/cid#161
<dmitriz> @dlongley -- ahaa that's good. so we should bring up the issue to the group again. I suspect we can arrive at consensus now
michaelshea: does this look closable?
phila: michaelshea I would add the key people for CID as reviewers
<dmitriz> oh FANTASTIC news
<phila> bigbluehat: The JSON-LD WG, which is meeting at TPAC, is having a very similar discussion about hashes
phila: thank you everyone and bigbluehat for scribing
… JennieM is up next for scribing
… thanks all, bye
<Peter> quit