[Openid-specs-ab] Spec call notes 18-Mar-13

Mike Jones Michael.Jones at microsoft.com
Tue Mar 19 00:19:12 UTC 2013


Spec call notes 18-Mar-13

John Bradley
Mike Jones
Brian Campbell
Edmund Jay
Nat Sakimura

Agenda:
                McGrew Algorithm
                PKCS #1 1.5 Security Considerations
                Implementer's Drafts
                Open Issues

McGrew Algorithm:
                Dave McGrew seems like he is willing to refactor draft-mcgrew-aead-aes-cbc-hmac-sha2 to make it easier to use in JOSE
                                Discussions are ongoing
                John pointed out that we probably don't need to include the base64url encoded IV value in the additional associated data
                                Mike said that we should probably be consistent between GCM and McGrew, should we adopt McGrew

PKCS #1 1.5 Security Considerations
                We need to beef up the security considerations and reference documents
                John will take a crack at this, per issue #813

JOSE and Implementer's Drafts
                Mike thinks he can apply the edits for the current Connect issues within about a day
                Optimistically, he can then apply the edits for the resolved JOSE issues in about a week
                                If the McGrew change can happen and be agreed to quickly, we could incorporate that as well
                We will publish our Implementer's Drafts after the Connect and JOSE edits

JOSE Status:
                We need Karen and Jim to post their take on what issues were resolved
                We're also waiting to hear when the regular calls and interim meeting will be

Open Issues:
                We went through several issues about language tags and determined resolutions
                                In these, we're following RFC 5646 more closely
                Mike sent email to Vladimir about us closing #809 - Common UserInfo "verified_claims" claim?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20130319/ec698639/attachment.html>


More information about the Openid-specs-ab mailing list