<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body dir="auto">
<div dir="ltr"></div>
<div dir="ltr">Congrats to the WG and on the updated draft. I look forward to hearing at the OIDF hybrid workshop 10/20 about the current path to final! </div>
<div dir="ltr"><br>
</div>
<div dir="ltr">A quick reminder that we seek funding for a refresh of the federation security analysis conducted last year. As many of you will recall that work led to a very timely Responsible Disclosure on this spec…and related specs. There have been a lot
of breaking changes on this spec since the interop, so ideally we would rerun the security analysis. </div>
<div dir="ltr"><br>
</div>
<div dir="ltr">At last estimate the cost was on the order of $100k for the rigorous work by Stuttgart…and this is not a covered expense in the OIDF budget. </div>
<div dir="ltr"><br>
</div>
<div dir="ltr">The foundation invested already in this spec substantially: </div>
<div dir="ltr">• the first round of security analysis</div>
<div dir="ltr">• the development of the open source tests for the interop, and now the work to finalize tests in line with final spec release </div>
<div dir="ltr">• organising and funding the interop, kindly hosted by SUNNET</div>
<div dir="ltr"><br>
</div>
<div dir="ltr">It would be good for the spec - and market adoption - to have a suite of partners visibly recognized for cofunding this security analysis on route to final. </div>
<div dir="ltr"><br>
</div>
<div dir="ltr">If your organisation might be persuaded to help in whole or in part, please let me and Gareth know (copied). We will be chasing you but it helps if you come to us first! We appreciate that education and research orgs are leading the charge here
and funding is tight, but I hope we can collectively find a way!</div>
<div dir="ltr"><br>
</div>
<div dir="ltr">Thanks in advance,</div>
<div dir="ltr"><br>
</div>
<div dir="ltr">Gail </div>
<div dir="ltr"> </div>
<div dir="ltr"><br>
<blockquote type="cite">On Oct 16, 2025, at 8:09 PM, Michael Jones via Openid-specs-ab <openid-specs-ab@lists.openid.net> wrote:<br>
<br>
</blockquote>
</div>
<blockquote type="cite">
<div dir="ltr">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style>@font-face { font-family: "Cambria Math"; }
@font-face { font-family: Aptos; }
p.MsoNormal, li.MsoNormal, div.MsoNormal { margin: 0in; font-size: 12pt; font-family: Aptos, sans-serif; }
a:link, span.MsoHyperlink { color: rgb(70, 120, 134); text-decoration: underline; }
span.EmailStyle17 { font-family: Aptos, sans-serif; color: windowtext; }
.MsoChpDefault { }
@page WordSection1 { size: 8.5in 11in; margin: 1in; }
div.WordSection1 { page: WordSection1; }</style>
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt"><a href="https://openid.net/specs/openid-federation-1_0-44.html">Draft 44 of the OpenID Federation specification</a> has been published. The draft contains improved descriptions of a number of features. The
one breaking change made is that Trust Mark Status responses are now signed.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Some of the changes made are intended to facilitate implementation of features needed for some Swedish government use cases. In particular, extension points were added to make it easier to use OpenID Federation
for trust establishment for systems where existing entities may already be deployed, and may not be able to be modified.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">The changes made in -44 are detailed in the <a href="https://openid.net/specs/openid-federation-1_0-44.html#name-document-history">Document History</a> section.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Thanks all for the continued progress towards finishing the specification!<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"> -- Mike<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">P.S. This was also posted at <a href="https://self-issued.info/?p=2756">
https://self-issued.info/?p=2756</a> and referenced from <a href="https://x.com/selfissued/status/1979021080271503406">
https://x.com/selfissued/status/1979021080271503406</a>.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<span>_______________________________________________</span><br>
<span>Openid-specs-ab mailing list</span><br>
<span>Openid-specs-ab@lists.openid.net</span><br>
<span>https://lists.openid.net/mailman/listinfo/openid-specs-ab</span><br>
</div>
</blockquote>
</body>
</html>