From brent.zundel at yubico.com Mon Aug 10 21:00:21 2026 From: brent.zundel at yubico.com (Brent Zundel) Date: Mon, 10 Aug 2026 15:00:21 -0600 Subject: [Openid-dcp] DCP WG Americas call agenda (11 Aug 2026) Message-ID: Proposed agenda for today's call: 1. Code of conduct / Antitrust policy / IPR policy: https://openid.net/wp-content/uploads/2025/06/OIDF_Groups-Activities-Events-Note-Well_Final_2025-06-12.pdf 2. Note-taking 3. Introductions 4. Agenda bashing 5. Events 6. Issuance - Server2server issue triage: S2S Issues - Review open PRs: https://github.com/openid/OpenID4VCI/pulls - Review other open Issues https://github.com/openid/OpenID4VCI/issues 7. AOB -- Brent Zundel Standards Architect | Yubico -------------- next part -------------- An HTML attachment was scrubbed... URL: From brent.zundel at yubico.com Tue Aug 11 19:08:00 2026 From: brent.zundel at yubico.com (Brent Zundel) Date: Tue, 11 Aug 2026 13:08:00 -0600 Subject: [Openid-dcp] Minutes from 11-Aug-2026 Americas DCP WG call Message-ID: Not enough people came for us to have quorum. Ended the meeting early. -- Brent Zundel Standards Architect | Yubico -------------- next part -------------- An HTML attachment was scrubbed... URL: From dima at postnikov.net Wed Aug 12 07:37:54 2026 From: dima at postnikov.net (Dima Postnikov) Date: Wed, 12 Aug 2026 17:37:54 +1000 Subject: [Openid-dcp] DCP APAC WG call agenda Message-ID: Proposed agenda for today's call: 1. Code of conduct / Antitrust policy / IPR policy: https://openid.net/wp-content/uploads/2025/06/OIDF_Groups-Activities-Events-Note-Well_Final_2025-06-12.pdf 2. Note-taking 3. Introductions 4. Agenda bashing 5. Events 6. Standing topics for general updates 1. Test requirements document for the EU 2. Conformance test updates 7. Presentation 1. Towards 1.1 2. Review open PRs https://github.com/openid/OpenID4VP/pulls 3. Review open issues https://github.com/openid/OpenID4VP/issues 8. Issuance - Server2server - IAE / Building Interactive Authorisation on top of first-party apps draft. - Review other open PRs: https://github.com/openid/OpenID4VCI/pulls - Review open issues: https://github.com/openid/OpenID4VCI/issues 9. AOB -------------- next part -------------- An HTML attachment was scrubbed... URL: From frederik.krogsdal at idura.eu Wed Aug 12 09:03:30 2026 From: frederik.krogsdal at idura.eu (Frederik Krogsdal Jacobsen) Date: Wed, 12 Aug 2026 11:03:30 +0200 Subject: [Openid-dcp] Minutes from 12-Aug-2026 APAC DCP WG call Message-ID: - Participants: Dima Postnikov, Joseph Heenan, Frederik Krogsdal Jacobsen, Martijn Haring, Rachel O?Connell, Jan Veerecken - Certification program has been launched - It does not certify verifiers or VCI over DC API yet - There will be more announcements about certification soon, so if you want to be mentioned as a certified implementation, get your final certification in ASAP - Some issues are still open regarding clarifications and gaps. Since certifications are now open, we need to clarify those issues in a way that does not invalidate existing certifications if possible. - Interoperability event in Geneva before GDC - GDC interoperability will be with the certification suite as verifier and wallet - Test requirement document for the EU - They have started moving from spreadsheets to writing down end-to-end ?smoke? test descriptions, and these will be published soon. These are mostly targeted at certifying wallets and are much broader in scope than just OpenID4VC things. They also include ETSI specifications. - Argument: verifiers are the ones that are likely to need the most help to do things correctly. The EU is focusing on wallet certification because it is required by the regulation. On the other hand, many verifiers will purchase the capability as a service instead of developing it themselves, so this might be less of a problem than it initially appears. - OpenID4VP - https://github.com/openid/OpenID4VP/pull/775 - Fixes a wrong cross-reference. - https://github.com/openid/OpenID4VP/pull/776 - Fixes an incomplete renaming of a prefix. - https://github.com/openid/OpenID4VP/pull/761 - Discussion: should this be in the errata for 1.0 or not? Probably not necessary to put it in there, but no real consensus beyond general opinions on whether we should put them into errata. - https://github.com/openid/OpenID4VP/pull/745 - Joseph has asked for some trivial changes to formatting/punctuation, but otherwise looks fine. - Frederik to review. - https://github.com/openid/OpenID4VP/pull/744 - This has an interoperability impact, so should we do something in errata for this? It depends on whether we also update the reference to SD-JWT VC (see next PR). - It is already the case that a wallet must somehow know which credential inherits from which, so any wallet that accepts credentials without knowing about inheritance is already non-compliant. - Discussion: why do people actually use inheritance when they could use DCQL instead? Is anything missing in DCQL that would solve this use case? Also, do we have an example of a concrete DCQL query that would work for EU PIDs? - DCQL supports asking for specific issuers, so why does this need to exist, except for historical reasons? - https://github.com/openid/OpenID4VP/pull/726 - What exactly should we do in 1.1 and in 1.0? We need to make a decision on what to do to minimize breaking changes while moving to -18. -------------- next part -------------- An HTML attachment was scrubbed... URL: From brent.zundel at yubico.com Wed Aug 12 21:20:59 2026 From: brent.zundel at yubico.com (Brent Zundel) Date: Wed, 12 Aug 2026 15:20:59 -0600 Subject: [Openid-dcp] DCP WG Europe Agenda 2026 08 12 Message-ID: Proposed agenda for today's call: 1. Code of conduct / Antitrust policy / IPR policy: https://openid.net/wp-content/uploads/2025/06/OIDF_Groups-Activities-Events-Note-Well_Final_2025-06-12.pdf 2. Note-taking 3. Introductions 4. Agenda bashing 5. Events 6. Standing topics for general updates 1. Test requirements document for the EU 2. Conformance test updates 7. Presentation 1. Towards 1.1 2. Review open PRs https://github.com/openid/OpenID4VP/pulls 3. Review open issues https://github.com/openid/OpenID4VP/issues 8. Issuance - Server2server - IAE / Building Interactive Authorisation on top of first-party apps draft. - Review other open PRs: https://github.com/openid/OpenID4VCI/pulls - Review open issues: https://github.com/openid/OpenID4VCI/issues 9. AOB -- Brent Zundel Standards Architect | Yubico -------------- next part -------------- An HTML attachment was scrubbed... URL: From valentine.mazurov at dsr-corporation.com Fri Aug 14 05:28:10 2026 From: valentine.mazurov at dsr-corporation.com (Valentine Mazurov) Date: Fri, 14 Aug 2026 09:28:10 +0400 Subject: [Openid-dcp] [OpenID DCP] EU friendly call meeting notes Message-ID: Hi all, Please find meeting notes that occurred on August 13th below. Participants: * Brent Zundel * Gail Hodges * Bjorn Hjelm * Frederik Krogsdal Jacobsen * Michael Jones * Oliver Terbu * Ryan Galluzzo * Joseph Heenan * Valentine Mazurov Notes * Events: * Pre-GDC DCP meeting * Make sure you signed up if you are planning to participate * https://dcp-wg-pre-gdc * **Date: Monday 31st August 2026** * ? **Time:** **10:00 - 14:30 CEST** * ? **Location:** Hilton Geneva Hotel & Conference Centre, 34 route Fran?ois Peyrot, Le Grand Saconnex, 1218 Geneva, Switzerland * DCHP WG meeting * https://oidf-dchp-mtg-pre-gdc-31aug26.eventbrite.com/ * **Date:** **Monday 31st August 2026** * ? **Time:** **16:00 - 20:00 CEST** * ? **Location:** IATA Center, 33 Route de l'A?roport, PO Box 416,1215, Geneva, Switzerland * Conformance tests have been released * https://openid.net/openid4vp-and-openid4vci-conformance-tests-are-complete-and-open-for-self-certification/ * Oliver: * Also EUDI FCAF baseline tests published for review * https://conformance.eudi.dev/latest/fcaf/suts/wallet_solution/relying_party/baseline-tests/ * https://conformance.eudi.dev/latest/fcaf/suts/wallet_solution/attestation_provider/baseline-tests/ * OID4VCI * Please, review server-to-server related issues (: * Stuttgart 8: how does wallet determine which session if there are multiple? #702 * https://github.com/openid/OpenID4VCI/issues/702 * Frederik Krogsdal Jacobsen to write a PR * Stuttgart 2: auth_session security requirements * https://github.com/openid/OpenID4VCI/issues/689 * May be solved due to text in FPA spec * Stuttgart 1: specify more details on IAE request * https://github.com/openid/OpenID4VCI/issues/688 * May be solved due to text in FPA spec * Stuttgart 7: HTTP status code for IAE responses undefined * https://github.com/openid/OpenID4VCI/issues/694 * Closed * Make auth_session optional if other binding mechanism exists. * https://github.com/openid/OpenID4VCI/pull/706 * Basically, WG leans toward the Wallet to ignore an unexpected auth_session * OID4VP * Normative version inconsistency for SD-JWT VC in 1.0 final * a breaking change in this circumstance might be necessary, and allowable under the need to address errata. If WG goes down this route, it needs to be very explicit about the changes. There seemed to be general support for this approach. * Gail Hodges: SAML to OIDC (or OpenID4VC) General view emerging, that it will be timely to offer implementer guidance on SAML to OIDC Migration, and in some cases perhaps also SAML to OpenID4VC. Appetite confirmed from AB/Connect and IPSIE WG Cochairs for a set of coordinated actions, and progress towards a Best Current Practice guidance and potentially specifications to support implementers. Support in principle from OIDF Board (via Strategic Task Force in June), and topic will be revisited in September Strategic Task Force, with potential for any funding requirements or directed funding approvals in Board meeting end of Sep. Contributors to discussion so far include Nat Sakimura, Dick Hardt, Karl McGuiness, Aaron Parecki, and members of OIDF Task Force Open question on whether DCP WG wants to take up their own issues/actions in parallel Current plan of AB/Connect and IPSIE Cochairs. 1. IPSIE WG leads a short requirements and deployment workstream covering enterprise and SaaS migration patterns, operational constraints, identifier continuity, account linking, assurance mapping, coexistence, rollback, and legacy isolation 2. AB/ Connect WG evaluates Karl McGuiness?s three spec proposals (to AB/Connect and IPSIE WG lists) on this topic against those requirements (in 1 above) and takes responsibility for any normative SAML/OIDC protocol profiles 3. IPSIE WG develops the implementation guidance and decision tree, with AB/ Connect WG reviewing the protocol and security content 4. Certification Team work follows only for profiles that are adopted and have sufficient implementation commitment and business case. (Note: Migration tend to be a one time thing and may not create recurring revenue, so there are prioritization considerations by Foundation/Cert team) 5. DCP/DCHP- SAML-to-OpenID4VC should be treated as a separate exploratory track with the relevant Digital Credentials group. It is an architectural transition, not simply another SAML/OIDC mapping. Other notes On ownership, the migration and IdP-backed OP protocol profiles fit AB/ Connect. For the bridge proposal, IPSIE WG should define the enterprise use cases and deployment requirements, while AB/ Connect owns any normative protocol behavior. We probably want to consider the bridge lower priority because it introduces a new assertion-issuing security boundary. The initial Best Current Practice should clearly separate migration architecture from external drivers such as shorter certificate lifetimes and PQC. Those may motivate migration, but moving from SAML to OIDC does not by itself provide PQC readiness. Other guidance may be useful in conjunction with PQC readiness work happening in parallel (e.g. blog series for PQC readiness under consideration, in discussion by AB/Connect now and also for Strategic Task Force update in September with expectation of a ?program of work? to monitor progress) For September, we suggest approving a bounded requirements/BCP phase first, with named editors and SaaS implementer participation, followed by a go/no-go decision on each proposed specification. If DCP WG wants to take action on this topic as well, Please let Gail know your WG intent and direction Any associated Issues/PRs so staff can Monitor progress across WGs and staff deliverables (as per Task Force), and cross link with staff tracking in Asana/ GitLab Understand your priorities/timing for these items (e.g. you may have backlog on 1.1/1.2 you must prioritize first) Size any staff dependencies e.g. coordinate any directed funding to support the work (eg demonstration or test development) any public facing comms certification team requirements ecosystem or leading implementer briefs anything else. Best Regards, Valentine Valentine Mazurov | Software Engineer | DSR Corporation | E-mail: valentine.mazurov at dsr-corporation.com -------------- next part -------------- An HTML attachment was scrubbed... URL: