Please find enclosed the preliminary minutes of our MODRNA call on June 14th 2017
Participants :
Bjorn, Axel, Philippe, Charles, Gonzalo

Agenda :
1.      CPAS feedback post-Workshop meeting [Siva]
2.      Issue Tracker [All] #52 to #56
1.      CPAS feedback post-Workshop meeting [Siva]
Not addressed

2.      Issue Tracker [All]
*       #52<https://bitbucket.org/openid/mobile/issues/52/ciba-pairwise-identifiers-structuring-text>
signed request object: it seems to not be enough, keep 52 open until John comment.
==>     John to comment
*       #53<https://bitbucket.org/openid/mobile/issues/53/ciba-terminology-consumption-device>
*       CIBA terminology of consumption device on front channel. Axel changed it. Nobody disagrees, change approved.
*       #54<https://bitbucket.org/openid/mobile/issues/54/ciba-client-notification-endpoint>
CIBA BackChannel endpoint authentication.
The client sending an auth request with a bearer token, used to authenticate the ID Provider. Client endpoint must be able to authenticate the OP. This feature is in CIBA from the beginning. John mentioned that banks wouldn't use bearer tokens.
Could be interesting to allow other kinds of mechanism to authenticate the OP. One possibility is a bearer token, but other means could work too.
==>     Axel to ask to FAPI team what they think
*       #55<https://bitbucket.org/openid/mobile/issues/55/ciba-signed-result-objects>
*       CIBA sends the result object, in S2S communication. FAPI team wants non repudiation. Id Token must be signed, is it enough ? do we need and is there a way to sign the whole response ?
==>     Axel to ask to FAPI team what they think
*       #56<https://bitbucket.org/openid/mobile/issues/56/signed-request-object-authentication>
*       How to choose between OIDC spec or the JWT spec, as they seem to not be totally consistent ?
*       Email occurred on the list.
*       The signed request object should be OK, because we are in S2S exchanges. in the JWT, only the expiration param is mandatory.
*       --> Question for John.
3.      Closing old issues in Issue Tracker [Axel]
4.      Go through the old issues on the next call.
4.      AOB
   Axel: how to make categories on Bitbucket.

