[Openid-specs-ab] Spec Call Notes 25-Nov-24

Michael Jones michael_b_jones at hotmail.com
Tue Nov 26 01:18:04 UTC 2024


Spec Call Notes 25-Nov-24

Nat Sakimura
Mike Jones
Aaron Parecki
Tim Cappalli
Tom Jones

Policy on AI Note Takers
                Mike rejected multiple AI note takers that tried to join the call
                We don't have a foundation-wide policy on bots joining our calls
                Mike rejected them so that we could potentially have private discussions with the recording turned off
                One of the AI note takers was Tom's
                                He had no problem with us not admitting it to the calls

OpenID Connect RP Metadata Choices
                https://github.com/openid/rp-metadata-choices/
                https://github.com/openid/rp-metadata-choices/pull/1 Multi-valued parameters are for requests and not responses
                                Incorporates pre-adoption feedback from Filip and Joseph
                                Mike will merge and publish after the call

Native SSO spec
                https://bitbucket.org/openid/connect/pull-requests/742 was merged last week
                                George will close the issues 2167, 2166, and 2164 which were addressed by it
                Vladimir told George that they're not leveraging the ID Token
                                They're putting the needed state in the device secret
                George will send an e-mail to the list asking about not relying on state in the ID Token

Bitbucket Issues
             https://bitbucket.org/openid/connect/issues?status=new&status=open&status=submitted&is_spam=!spam
                No new issues, No PRs

OpenID Federation
            https://github.com/openid/federation/pull/141 Federation Entity Keys MUST NOT appear in metadata
                                Resolves a potential ambiguity
                                Mike will merge after the call
            https://github.com/openid/federation/pull/142 Clarify description of using request objects
                                Clarifies that Request Objects can be used at both the authorization endpoint and the PAR endpoint
                                Mike will merge after the call
      https://github.com/openid/federation/issues/147 Client cannot know what client authentication method a server has registered it for
                                Joseph suggests possibly only doing automatic registration at the PAR endpoint
                                Feedback is requested
      https://github.com/openid/federation/issues/148 Guidance / Strategie on how to deal with conflicting metadata due to trust chain selection
                                Feedback is requested

OpenID Federation Wallet Profile
                https://github.com/openid/federation-wallet/
                No new issues, no PRs
                People are encouraged to review the issues

OpenID Federation Extended Subordinate Listing
                https://github.com/openid/federation-extended-listing
                No issues or PRs

Tom's OpenID4VP issue about consent
   https://github.com/openid/OpenID4VP/issues/333 Verifiable Presentation does not meet the minimum requirements for holder informed consent
                He also stated in an e-mail that ACM Ethics document with respect to holder's informed consent.
                Discussion in the issue is welcomed
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20241126/7a8757f4/attachment.htm>


More information about the Openid-specs-ab mailing list