<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Spec Call Notes 13-Dec-21<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Mike Jones<o:p></o:p></p>
<p class="MsoNormal">Nat Sakimura<o:p></o:p></p>
<p class="MsoNormal">Kristina Yasuda<o:p></o:p></p>
<p class="MsoNormal">Tom Jones<o:p></o:p></p>
<p class="MsoNormal">Vittorio Bertocci<o:p></o:p></p>
<p class="MsoNormal">Edmund Jay<o:p></o:p></p>
<p class="MsoNormal">John Bradley<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Proposed Implementer's Drafts<o:p></o:p></p>
<p class="MsoNormal"> Several PRs implementing review comments have been created and some merged<o:p></o:p></p>
<p class="MsoNormal"> Mike, Edmund, David Chadwick, and DW have reviewed one or both specs<o:p></o:p></p>
<p class="MsoNormal"> Issue #1372 by DW has 35 comments<o:p></o:p></p>
<p class="MsoNormal"> Kristina has created PRs for David's and DW's comments<o:p></o:p></p>
<p class="MsoNormal"> She continues processing the comments received via e-mail<o:p></o:p></p>
<p class="MsoNormal"> The review comments have resulted in substantial improvements. Thanks all!<o:p></o:p></p>
<p class="MsoNormal"> Editor's drafts of both specs have been published for both specs recently<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">OpenID Connect for Verifiable Credential Issuance<o:p></o:p></p>
<p class="MsoNormal"> An editor's draft of -02 has been published<o:p></o:p></p>
<p class="MsoNormal"> <a href="https://openid.bitbucket.io/connect/openid-connect-4-verifiable-credential-issuance-1_0.html">
https://openid.bitbucket.io/connect/openid-connect-4-verifiable-credential-issuance-1_0.html</a><o:p></o:p></p>
<p class="MsoNormal"> Mike will look into it being published as WG draft<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Errata Status<o:p></o:p></p>
<p class="MsoNormal"> The errata 2 edits are about 80% done<o:p></o:p></p>
<p class="MsoNormal"> Possible PAS submission to ITU and/or ISO is a reason to finish them soon<o:p></o:p></p>
<p class="MsoNormal"> Mike plans to try to finish them during the next month<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Logout Status<o:p></o:p></p>
<p class="MsoNormal"> We still need to logout_hint to RP-Initiated Logout<o:p></o:p></p>
<p class="MsoNormal"> Mike said that we should take these to final status soon after that<o:p></o:p></p>
<p class="MsoNormal"> In part, to have a stable description of how the current mechanisms work<o:p></o:p></p>
<p class="MsoNormal"> Vittorio questioned whether we should do this or not, given present browser realities<o:p></o:p></p>
<p class="MsoNormal"> Mike wants to document how these have worked for years<o:p></o:p></p>
<p class="MsoNormal"> We agreed that if there are new logout mechanisms, they should be in new specs<o:p></o:p></p>
<p class="MsoNormal"> We'll take this discussion to the list<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Open Pull Requests<o:p></o:p></p>
<p class="MsoNormal"> <a href="https://bitbucket.org/openid/connect/pull-requests/">
https://bitbucket.org/openid/connect/pull-requests/</a><o:p></o:p></p>
<p class="MsoNormal"> PR #89: David Chadwick comments sent by email<o:p></o:p></p>
<p class="MsoNormal"> Kristina to merge after resolving conflicts<o:p></o:p></p>
<p class="MsoNormal"> PR #90: addressing DW's comments in Issue 1372<o:p></o:p></p>
<p class="MsoNormal"> Kristina still updating<o:p></o:p></p>
<p class="MsoNormal"> PR #57: Further specify how to use encrypted id_token_hint values<o:p></o:p></p>
<p class="MsoNormal"> Still an ongoing discussion<o:p></o:p></p>
<p class="MsoNormal"> PR #50: Response-as-Push<o:p></o:p></p>
<p class="MsoNormal"> Jeremie may close this and do it as an IETF spec instead<o:p></o:p></p>
<p class="MsoNormal"> Mike agrees with this plan<o:p></o:p></p>
<p class="MsoNormal"> All the other PRs are for the Claims Aggregation spec, and were discussed with their issues below<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Open Issues<o:p></o:p></p>
<p class="MsoNormal"> <a href="https://bitbucket.org/openid/connect/issues?status=new&status=open">
https://bitbucket.org/openid/connect/issues?status=new&status=open</a><o:p></o:p></p>
<p class="MsoNormal"> #1311: Require refresh tokens<o:p></o:p></p>
<p class="MsoNormal"> We didn't find a compelling case to make this required when it's normally optional<o:p></o:p></p>
<p class="MsoNormal"> Edmund will add a note to PR #60 saying that some profiles and Trust Frameworks could require it<o:p></o:p></p>
<p class="MsoNormal"> #1284: Section 3 - Require Sender Constrained Tokens<o:p></o:p></p>
<p class="MsoNormal"> There wasn't consensus to require this here<o:p></o:p></p>
<p class="MsoNormal"> If anything, once DPoP is a standard, we could create a Connect 1.1 including it<o:p></o:p></p>
<p class="MsoNormal"> PR #63 was intended to do this, so it will be closed with no action<o:p></o:p></p>
<p class="MsoNormal"> #1276: Section 2.2. - Missing parameter to determine the credential type.<o:p></o:p></p>
<p class="MsoNormal"> PR #74 was intended to do this<o:p></o:p></p>
<p class="MsoNormal"> Edmund said that this was waiting for the Credential Issuance draft<o:p></o:p></p>
<p class="MsoNormal"> Edmund will compare this request to what's in the Credential Issuance draft now<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Next Call<o:p></o:p></p>
<p class="MsoNormal"> The next call is on Thursday, December 16th at 7am Pacific Time<o:p></o:p></p>
</div>
</body>
</html>