[Openid-specs-ab] Spec call notes 15-Aug-13
Mike Jones
Michael.Jones at microsoft.com
Thu Aug 15 15:15:11 UTC 2013
Spec call notes 15-Aug-13
John Bradley
Justin Richer
Edmund Jay
Mike Jones
William Kim
Agenda:
Open Issues
Next Call
Open Issues:
#867 - Use of "alg":"none" for ID Tokens
We will allow this when requested by the client
#868 - Use of "alg":"none" for request objects
We will clarify that "none" is allowed unless explicitly prohibited
#866 - Why are there two different ways to request acr?
We will say that the behavior is unspecified if both request methods are used
#863 - Stateless Registration Discovery/Messages
John described the means of doing this by encoding everything in the client_id
John will send a note to Naveen asking if that's what they want to do
#864 - Native Client code leakage
John added a comment that it is better to make this a proof of possession mechanism for code
People should do the homework of reading the draft at http://bit.ly/1chmIeG
John will try to get feedback from Naveen on it
#865 - Registration needs update capability too
The resolution of this may depend upon the outcome of the OAuth registration work
No decisions were made for now
Mike still needs to write proposed text about Torsten's MTI issues raised in Berlin
Next Call:
A JOSE call will be at our regularly scheduled Monday call time - 4pm Pacific on Monday, August 19th
People are encouraged to join the JOSE call
The next Connect call will be in a week
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20130815/96b14ad9/attachment.html>
More information about the Openid-specs-ab
mailing list