<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Spec Call Notes 19-Apr-21<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Mike Jones<o:p></o:p></p>
<p class="MsoNormal">Tom Jones<o:p></o:p></p>
<p class="MsoNormal">Nat Sakimura<o:p></o:p></p>
<p class="MsoNormal">Vittorio Bertocci<o:p></o:p></p>
<p class="MsoNormal">Dmitri Zagidulin<o:p></o:p></p>
<p class="MsoNormal">Kristina Yasuda<o:p></o:p></p>
<p class="MsoNormal">Tim Cappalli<o:p></o:p></p>
<p class="MsoNormal">Adam Lemmon<o:p></o:p></p>
<p class="MsoNormal">Edmund Jay<o:p></o:p></p>
<p class="MsoNormal">John Bradley<o:p></o:p></p>
<p class="MsoNormal">Tobias Looker<o:p></o:p></p>
<p class="MsoNormal">Tony Nadalin<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Internet Identity Workshop (IIW)<o:p></o:p></p>
<p class="MsoNormal"> IIW is the next three days. Here's some possible sessions to look for...<o:p></o:p></p>
<p class="MsoNormal"> Introduction to OpenID Connect - Mike Jones, Session 1<o:p></o:p></p>
<p class="MsoNormal"> Options for including W3C VC objects in OpenID Connect flows (Kristina)<o:p></o:p></p>
<p class="MsoNormal"> SIOP Use Cases - Kristina<o:p></o:p></p>
<p class="MsoNormal"> Credential Provider draft - Tobias and Adam<o:p></o:p></p>
<p class="MsoNormal"> SIOP Chooser - Jeremy and DW and Tom<o:p></o:p></p>
<p class="MsoNormal"> Using BB+ with JOSE and JWTs - Jeremy and DW<o:p></o:p></p>
<p class="MsoNormal"> Claims Aggregation draft - Nat and Edmund<o:p></o:p></p>
<p class="MsoNormal"> Logout Options in the face of Browser Changes - John suggested asking DW to do it<o:p></o:p></p>
<p class="MsoNormal"> Tim asked whether to also talk about what users understand about Web logout<o:p></o:p></p>
<p class="MsoNormal"> Authentic Data Economy series - David Huseby and Mike Lodder<o:p></o:p></p>
<p class="MsoNormal"> <a href="https://dwhuseby.medium.com/dont-use-dids-58759823378c">
https://dwhuseby.medium.com/dont-use-dids-58759823378c</a><o:p></o:p></p>
<p class="MsoNormal"> <a href="https://github.com/TrustFrame/authentic-data-specifications">
https://github.com/TrustFrame/authentic-data-specifications</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Mobile Driver's License<o:p></o:p></p>
<p class="MsoNormal"> mDL is ISO/IEC 18013-5 in SC17 WG10<o:p></o:p></p>
<p class="MsoNormal"> Tom told us about a request for comments by DHS on Mobile Driver's Licenses<o:p></o:p></p>
<p class="MsoNormal"> <a href="https://www.govinfo.gov/content/pkg/FR-2021-04-19/pdf/2021-07957.pdf">
https://www.govinfo.gov/content/pkg/FR-2021-04-19/pdf/2021-07957.pdf</a><o:p></o:p></p>
<p class="MsoNormal"> [Docket No. DHS–2020–0028]<o:p></o:p></p>
<p class="MsoNormal"> Minimum Standards for Driver’s Licenses and Identification Cards Acceptable by Federal Agencies for Official Purposes; Mobile Driver’s Licenses<o:p></o:p></p>
<p class="MsoNormal"> Kristina said that the ISO specs don't use VCs or DIDs<o:p></o:p></p>
<p class="MsoNormal"> John talked about needing not only standards, but also regulations and issuers to get a working ecosystem<o:p></o:p></p>
<p class="MsoNormal"> Tony reported that Nat is working on a liaison agreement between SC17 WG4 and WG10 and the OpenID Foundation<o:p></o:p></p>
<p class="MsoNormal"> Nat said that this would be a Category 3 liaison<o:p></o:p></p>
<p class="MsoNormal"> Tony suggested that we comment supporting use of the SIOP protocol for Mobile Driver's Licenses<o:p></o:p></p>
<p class="MsoNormal"> Tobias asked if there is an issuance protocol<o:p></o:p></p>
<p class="MsoNormal"> Tony said that there is a protocol for retrieval but not issuance<o:p></o:p></p>
<p class="MsoNormal"> Tony suggested that he and Kristina take ownership of drafting a response to DHS<o:p></o:p></p>
<p class="MsoNormal"> Tom said that Kantara will be drafting a response mostly about privacy<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Modified SIOP Special Call Schedule<o:p></o:p></p>
<p class="MsoNormal"> We will be alternating Pacific-friendly and Europe-friendly calls every two weeks<o:p></o:p></p>
<p class="MsoNormal"> The next Europe-Friendly call will be Tuesday, April 27 at 7am Pacific Time<o:p></o:p></p>
<p class="MsoNormal"> The next Pacific-Friendly call will be Tuesday, May 11th at 3pm Pacific Time<o:p></o:p></p>
<p class="MsoNormal"> Kristina will work with Mike Leszcz on updating the Foundation calendar<o:p></o:p></p>
<p class="MsoNormal"> We'll reconfirm the preferred call schedule during the next special call<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Claims Aggregation Draft<o:p></o:p></p>
<p class="MsoNormal"> Nat asked Tobias and Adam about their progress on the Claims Aggregation Draft<o:p></o:p></p>
<p class="MsoNormal"> Tobias reported that they're working on addressing issues on their Credential Provider draft<o:p></o:p></p>
<p class="MsoNormal"> Tobias said that they've defined a new endpoint for indirect presentation of end-user claims<o:p></o:p></p>
<p class="MsoNormal"> It can use different claims formats, including VCs, MDL, JWTs<o:p></o:p></p>
<p class="MsoNormal"> Tobias reported that Mike suggested using access tokens with single audiences<o:p></o:p></p>
<p class="MsoNormal"> He said that both Edmund's draft and theirs use new endpoints<o:p></o:p></p>
<p class="MsoNormal"> Edmund said that the UserInfo Endpoint doesn't support request parameters to request subsets of claims<o:p></o:p></p>
<p class="MsoNormal"> Nat told Tom that we're talking about claims issuance and aggregation - not claims presentation<o:p></o:p></p>
<p class="MsoNormal"> Mike asserted that Edmund's and Nat's draft is an interface between the OP and Claims Providers<o:p></o:p></p>
<p class="MsoNormal"> He asked whether the Credential Provider draft describes a different kind of interface<o:p></o:p></p>
<p class="MsoNormal"> Tobias said that the intent of the two is similar<o:p></o:p></p>
<p class="MsoNormal"> Tobias said that their credential notion is suitable for indirect presentation<o:p></o:p></p>
<p class="MsoNormal"> There was a digression about the confusion caused by having multiple meanings for the work "credential"<o:p></o:p></p>
<p class="MsoNormal"> To many, credentials are things like passwords, OTPs, biometrics, etc.<o:p></o:p></p>
<p class="MsoNormal"> To others, they're things like medical degrees, law degrees, proof of vaccination, etc.<o:p></o:p></p>
<p class="MsoNormal"> Hence the confusion<o:p></o:p></p>
<p class="MsoNormal"> Nat said that his primary interest was when Tobias and Adam could bring their work into the working group<o:p></o:p></p>
<p class="MsoNormal"> They said they want to address a few more issues before sending a draft for public review<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Open Issues<o:p></o:p></p>
<p class="MsoNormal"> <a href="https://bitbucket.org/openid/connect/issues?status=new&status=open">
https://bitbucket.org/openid/connect/issues?status=new&status=open</a><o:p></o:p></p>
<p class="MsoNormal"> We ran out of time to get to this<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Next Calls<o:p></o:p></p>
<p class="MsoNormal"> The next regular Connect call is scheduled for Thursday, April 22nd, 2021 at 7am Pacific Time<o:p></o:p></p>
<p class="MsoNormal"> However this conflicts with IIW Day 3 agenda creation<o:p></o:p></p>
<p class="MsoNormal"> I'll send a separate note asking if we should cancel for this week<o:p></o:p></p>
</div>
</body>
</html>