<div dir="ltr">Hey Mike -- I'm not sure it really matters, but I was on the phone for this meeting.  I didn't say anything because I was in the airport (and then onboard my aircraft), but was present for whole meeting, only missing the very beginning and a little bit of the meeting that went over the time at the end there.<div><br></div><div>Thanks!</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, May 9, 2016 at 3:01 AM, Mike Jones <span dir="ltr"><<a href="mailto:Michael.Jones@microsoft.com" target="_blank">Michael.Jones@microsoft.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="#0563C1" vlink="#954F72">
<div>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><b>April 27, 2016 OpenID Board Meeting Minutes<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><b>Present:<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Don Thibeau, Executive Director<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">John Bradley<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Mike Jones<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Nat Sakimura<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">George Fletcher<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Prateek Mishra<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Brian Berliner<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Dale Olds<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Adam Dawes<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><b>Present on the Phone:<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Bjorn Hjelm<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><b>Absent:<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Debbie Bucci<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Pamela Dingle<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Lydia Varmazis<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Tony Nadalin<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><b>Visitors:<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Tom Smedinghoff, Locke Lord LLP (on the phone)<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Mike Leszcz, OIDF (on the phone)<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Phil Hunt, Oracle<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.25in;margin-bottom:.0001pt">
<u></u><b><span>1.<span style="font:7.0pt "Times New Roman"">      
</span></span></b><u></u><b>New Board Member<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">We welcomed Oracle to the board.  Prateek Mishra and Phil Hunt are in attendance from Oracle.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Prateek said that Oracle is working to integrate an identity fabric with business services – both for external applications and within the company.  Phil Hunt said that SCIM is very important
 to Oracle and sees potential synergies between SCIM and OpenID Connect.  Phil talked about developing best deployment practices.  George and Brian and John affirmed Oracle’s goals.  Phil expressed a desire for us to evaluate the possibility of doing SCIM interop
 and possibly conformance work, which the IETF doesn’t do.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.25in;margin-bottom:.0001pt">
<u></u><b><span>2.<span style="font:7.0pt "Times New Roman"">      
</span></span></b><u></u><b>Legal and Policy Review<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Tom has been going through our mostly 7-year-old legal documents, addressing issues found.  One item was to create a software contribution agreement based upon the Google contribution agreement. 
 Some members and potential members had also identified issues.  We are explicitly not touching the IPR Policy and IPR Process documents.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Tom has sent revised copies to the EC for review and is awaiting comments.  Then they will be circulated to the full board.  The new versions separate policies from procedures.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Mike described that the IPR policy and process documents are, by design, difficult to update.  Nat pointed out that we did update them once, in 2009, to streamline the specifications council
 working group approval procedures.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.25in;margin-bottom:.0001pt">
<u></u><b><span>3.<span style="font:7.0pt "Times New Roman"">      
</span></span></b><u></u><b>Status of Trademarks<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">There is a deadline of May 6<sup>th</sup> for a response to a trademark registration refusal in Canada, which is related to SXIP’s registration of OpenID in Canada.  Mike Jones and Don Thibeau
 are in communication with Dick Hardt about assigning SXIP’s registration to the OpenID Foundation, which Dick has agreed to do.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><b><u></u> <u></u></b></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.25in;margin-bottom:.0001pt">
<u></u><b><span>4.<span style="font:7.0pt "Times New Roman"">      
</span></span></b><u></u><b>OpenID Certification<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Mike reported on the status of the certification program.  The number of registrations continues to grow.  Registrations are now being paid for by registrants.  OpenID Connect working group
 members and Don are working with Roland Hedberg on advancing the RP certification program during IIW.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><b><u></u> <u></u></b></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.25in;margin-bottom:.0001pt">
<u></u><b><span>5.<span style="font:7.0pt "Times New Roman"">      
</span></span></b><u></u><b>Website Update<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Mike reported that we are making substantial progress both towards deploying the revised membership Ruby code and towards transitioning from Darin Richardson, as our web site developer to
 Nov Matake, who has agreed to become our new web site developer.  Mike and Don have continued to work with both Darin and with OSUOSL and are happy to report that the new code is now running on a staging server and another server that will be put in production
 to replace the 7-year old Ruby deployment, after the new code has been evaluated and accepted.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.25in;margin-bottom:.0001pt">
<u></u><b><span>6.<span style="font:7.0pt "Times New Roman"">      
</span></span></b><u></u><b>Working Group Updates<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">There were substantive working group updates at the OpenID workshop on Monday, so we didn’t repeat most of that content here.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Adam reported that Google is working on opening up their Android password manager and Account Chooser experience to other platforms.  This would require a standard password manager API.  That
 work is happening in the W3C Web Credentials working group.  The Account Chooser working group may choose to utilize and build upon this functionality.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.25in;margin-bottom:.0001pt">
<u></u><b><span>7.<span style="font:7.0pt "Times New Roman"">      
</span></span></b><u></u><b>Financial Update<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">The foundation is in sound financial shape.  The legal efforts have been the primary cost driver but there are sufficient existing funds to cover that work without needing directed funding.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.25in;margin-bottom:.0001pt">
<u></u><b><span>8.<span style="font:7.0pt "Times New Roman"">      
</span></span></b><u></u><b>Recognizing Substantive Contributions to the Foundation and its Mission<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">In recognition of their substantive contributions towards the creation of the OpenID Foundation and their long-term technical contributions to OpenID Foundation specifications, the foundation
 elected to honor David Recordon, Dick Hardt, and Drummond Reed by offering them lifetime invited expert status and accompanying free lifetime individual OpenID Foundation memberships.  John made the motion and Adam seconded it.  The motion passed unanimously.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.25in;margin-bottom:.0001pt">
<u></u><b><span>9.<span style="font:7.0pt "Times New Roman"">      
</span></span></b><u></u><b>Communication about Security Best Practices<u></u><u></u></b></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">William Denniss led a productive discussion at IIW based on input from George Fletcher at the Monday OpenID workshop on OAuth mix-up attacks and related issues.  We gathered notes about vulnerabilities
 for purposes of possibly publishing them as an informative note on the OpenID blog.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">Don pointed out that our mission includes adoption.  He said that publishing advice to developers is a way of adding value to members, including internationally.  We might call it a “Deployment
 Advisory” in the title.  Mike said that it would be OK for the blog category to be “Security Advisory” but people thought that was too strong to use in the title.  Our communication needs to include information on cross-site request forgery and the mix-up
 attacks.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">We will ask William Denniss to be lead author on the text.  Mike, John, George, Phil, and Don will review the text.<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt">George moved that we publish information conveying the security and deployment guidance.  Brian seconded the motion.  John pointed out that we can coordinate with NIST, who has mechanisms
 for publishing security advisories, and that that might have a favorable side-effect of helping to deepen NISTs engagement with the OpenID Foundation.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>

<br>_______________________________________________<br>
board mailing list<br>
<a href="mailto:board@lists.openid.net">board@lists.openid.net</a><br>
<a href="http://lists.openid.net/mailman/listinfo/openid-board" rel="noreferrer" target="_blank">http://lists.openid.net/mailman/listinfo/openid-board</a><br>
<br></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr"><div><div style="padding:0px;margin:0">
        <table style="border-collapse:collapse;padding:0;margin:0" border="0">
                <tbody><tr>
                        <td style="vertical-align:top;width:75px">                                      
                                <a href="https://www.pingidentity.com/" target="_blank"><img src="http://4.pingidentity.com/rs/671-MGJ-570/images/EXP_PIC_square_logo_RGB_with_hard_drop.png" style="width:75px;height:79px;margin:0;border:none" alt="Ping Identity logo"></a>
                        </td>
                        <td style="vertical-align:top;padding-left:10px;padding-bottom:15px">

                        <div style="margin-bottom:7px">
                                <span style="color:#e61d3c;font-family:arial,helvetica,sans-serif;font-weight:bold;font-size:14px">Pam Dingle</span><br>
                                <span style="color:#000000;font-family:arial,helvetica,sans-serif;font-weight:normal;font-size:14px">Principal Technical Architect<br>Ping Identity</span>
                        </div>
                        <table style="border-collapse:collapse;border:none;padding:0;margin:0">
                                <tbody><tr>
                                        <td style="text-align:right;border-right:1px solid #e61d3c;padding:0 5px 0 0;height:26px"><span style="color:#e61d3c;font-family:arial,helvetica,sans-serif;font-weight:bold;font-size:14px;padding:0 2px 0 0">@</span></td>
                                        <td style="text-align:left;padding:3px 0 0 3px;vertical-align:top"><span style="text-decoration:none;color:#000000;font-family:arial,helvetica,sans-serif;font-weight:normal;font-size:14px;padding:0 0 0 3px"><a href="mailto:pdingle@pingidentity.com" target="_blank">pdingle@pingidentity.com</a></span></td>
                                </tr>
                                <tr>
                                        <td style="text-align:center;border-right:1px solid #e63c1d;padding:0;vertical-align:middle;height:26px;padding:0 2px 0 0"><img style="width:13px;height:16px" src="http://4.pingidentity.com/rs/pingidentity/images/EXP_phone_glyph.gif" alt="phone"></td>
                                        <td style="text-align:left;padding:3px 0 0 3px;vertical-align:top"><span style="color:#000000;font-family:arial,helvetica,sans-serif;font-weight:normal;font-size:14px;padding:0 0 0 3px">+1 303.999.5890</span></td>
                                </tr>
                                <tr>
                                        <td style="text-align:center;border-right:1px solid #e63c1d;padding:0;vertical-align:middle;height:26px;padding:0 2px 0 0"><img style="width:18px;height:16px" src="http://4.pingidentity.com/rs/pingidentity/images/twitter_logo.png" alt="twitter"></td>
                                        <td style="text-align:left;padding:1px 0 0 3px;vertical-align:top"><span style="color:#000000;font-family:arial,helvetica,sans-serif;font-weight:normal;font-size:14px;padding:0 0 0 3px">@pamelarosiedee</span></td>
                                </tr>
                        </tbody></table>
                        <table style="border-collapse:collapse;border:none;margin:15px 0 0 0;width:100%">
                                <tbody><tr>
                                        <td style="font-family:arial,helvetica,sans-serif;font-size:14px;font-weight:normal;color:#999999">Connect with us!</td>
                                </tr>
                                <tr>
                                        <td>
                                                <div style="display:block;float:left;padding-right:3px;margin-right:5px;border-right:1px solid #cccccc;height:23px"><a href="https://www.pingidentity.com/" style="text-decoration:none" title="pingidentity.com" target="_blank"><img src="http://4.pingidentity.com/rs/pingidentity/images/EXP_PIC_logo_bug.gif" style="width:23px;height:23px;border:none;margin:0" alt="pingidentity.com"></a></div>
                                                <a href="http://www.glassdoor.com/Overview/Working-at-Ping-Identity-EI_IE380907.11,24.htm" style="text-decoration:none" title="We're hiring!" target="_blank"><img src="https://4.pingidentity.com/rs/671-MGJ-570/images/glassdoor-grayscale.png" style="width:22px;height:23px;border:none;margin:0" alt="twitter logo"></a>
                                                <a href="https://twitter.com/pingidentity" style="text-decoration:none" title="Ping on Twitter" target="_blank"><img src="http://4.pingidentity.com/rs/pingidentity/images/twitter.gif" style="width:20px;height:23px;border:none;margin:0" alt="twitter logo"></a>
                                                <a href="https://www.youtube.com/user/PingIdentityTV" style="text-decoration:none" title="Ping on YouTube" target="_blank"><img src="http://4.pingidentity.com/rs/pingidentity/images/youtube.gif" style="width:23px;height:23px;border:none;margin:0" alt="youtube logo"></a>
                                                <a href="https://www.linkedin.com/company/21870" style="text-decoration:none" title="Ping on LinkedIn" target="_blank"><img src="http://4.pingidentity.com/rs/pingidentity/images/linkedin.gif" style="width:23px;height:23px;border:none;margin:0" alt="LinkedIn logo"></a>
                                                <a href="https://www.facebook.com/pingidentitypage" style="text-decoration:none" title="Ping on Facebook" target="_blank"><img src="http://4.pingidentity.com/rs/pingidentity/images/facebook.gif" style="width:23px;height:23px;border:none;margin:0" alt="Facebook logo"></a>
                                                <a href="https://plus.google.com/u/0/114266977739397708540" style="text-decoration:none" title="Ping on Google+" target="_blank"><img src="https://4.pingidentity.com/rs/671-MGJ-570/images/google_plus.png" style="width:22px;height:23px;border:none;margin:0" alt="Google+ logo"></a>
                                                <a href="http://www.slideshare.net/PingIdentity" style="text-decoration:none" title="Ping on SlideShare" target="_blank"><img src="http://4.pingidentity.com/rs/pingidentity/images/slideshare.gif" style="width:23px;height:23px;border:none;margin:0" alt="slideshare logo"></a>
                                                <a href="https://www.pingidentity.com/blogs/" style="text-decoration:none" title="Ping blogs" target="_blank"><img src="http://4.pingidentity.com/rs/pingidentity/images/rss.gif" style="width:23px;height:23px;border:none;margin:0" alt="rss feed icon"></a>
                                        </td>
                                </tr>
                        </tbody></table>
                </td>
        </tr>
        <tr>
                <td colspan="2" style="text-align:left">
                        <hr style="margin:0 0 1px 0;border-color:#f3f3f3">
                        <a href="https://www.cloudidentitysummit.com/en/index.html" target="_blank"><img src="https://www.pingidentity.com/content/dam/pic/images/misc/CIS2016_EmailSignature_v3.jpg" style="width:323px;height:111px;border:none;margin:0" alt="CIS 2016"></a>
                </td>
        </tr>
</tbody></table>
</div></div></div></div>
</div>