[Openid-specs-ab] Spec Call Notes 24-Oct-22
Mike Jones
Michael.Jones at microsoft.com
Tue Oct 25 07:27:30 UTC 2022
Spec Call Notes 24-Oct-22
Mike Jones
Vittorio Bertocci
George Fletcher
Kristina Yasuda
Dima Postnikov
Tom Jones
David Waite (DW)
Errata Updates
Mike created 7 errata PRs
They have [Errata] at the beginning of the subject line
He plans to merge them in a week after they were created unless comments are received
He noted that in the past, he simply pushed errata updates to master
Because the working group had already decided how to address them
Given the WG's increasing use of PRs, he created PRs this time to enable people to comment before merging
Addressing the open errata issues is part of preparing for ISO PAS submission
See the open errata issues at
https://bitbucket.org/openid/connect/issues?status=new&status=open&milestone=Errata
Pull Requests
https://bitbucket.org/openid/connect/pull-requests/
PR #335: chore: [Federation] disambiguations on the federation entity role
We need to address Roland's comments
PR #327: clarified the definition of response mode post - Issue #1626
Kristina requested that George review
We discussed the naming suggestions from the 13-Oct-22 SIOP special topic call
George is good with Joseph's name direct_post
This is different from other response modes because it can cross devices, rather than use a redirect
George said that direct_post is the only mode that makes sense cross-device
George said that direct_post with a cloud wallet is an interesting context
Vittorio asked whether there are any other response types or response modes that result in cross-device flows
He's not sure why we're trying to reuse an existing parameter rather than defining a new one
He said that using a client as an authorization server is confusing
Kristina said that it's well-defined for a native application to be able to do both
He doesn't see a security issue - he just finds it to be unnatural
Kristina said that these differences are why the introduction to OpenID4VP is long
The PR is an attempt to describe this better
Kristina said that developers have successfully built and deployed the specification
The form_post response mode is defined at https://openid.net/specs/oauth-v2-form-post-response-mode-1_0.html#FormPostResponseMode
The response_mode parameter is registered with IANA
The response mode values are not
George suggested adding more context about the roles that are being played by different parties
George agreed to make a comment on the PR
Issues
https://bitbucket.org/openid/connect/issues?status=new&status=open
#1681: [Federation] FAPI prohibits RS256
Mike reported that the Federation editors agreed to the following resolution:
"Implementations SHOULD support signature verification with RS256 because OpenID Connect Core requires support for RS256;
Federations MAY also specify different mandatory-to-implement algorithms."
Next Call
The next call is the SIOP Special Topic on Thursday, October 27th at 7am Pacific Time
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20221025/6de8d4d7/attachment-0001.html>
More information about the Openid-specs-ab
mailing list