[Openid-specs-igov] FW: Action required: WGLC - Seeking WG consensus on iGov OAuth 2.0 profile readiness to begin Implementers Draft review process S: Jan 12, 2026

Giuseppe De Marco demarcog83 at gmail.com
Wed Jan 7 08:21:24 UTC 2026


Hi and good year!

Below my comments:

1. Considering this specification for the purpose of Govs implementing
OAuth 2.0, I suggest to mention Wallet ecosystems and therefore OpenID4VC,
eIDAS 2.0 and its trust framework too. The most of the Govs are going to
implement that.
2. Client Registration Section and Section 4.1 (Connection with Clients)
should mention OpenID Federation 1.0
3. Signed Access Token in JWT format should comply with
https://datatracker.ietf.org/doc/rfc9068/
4. iss in the token response should be recommended (SHOULD?). The **iss**
parameter in the authorization response (as defined in :rfc:`9207`)
mitigates mix-up attacks (I remember an bitbucket issue on this.. probably
on the openid specs)

congrats for the work made so far,
hope to hear you back soon
G

Il giorno lun 5 gen 2026 alle ore 20:51 Tom Clancy via Openid-specs-igov <
openid-specs-igov at lists.openid.net> ha scritto:

> Dear Working Group members and contributors,
>
> This is a reminder to respond with whether you believe the current draft
> should proceed or not by January 12, 2026.
>
> Next iGov WG meeting was moved to January 13, 2026 to provide additional
> WG review time. No WG meeting Tuesday, Jan 06, 2026.
>
> Kindest regards,
> Editors & Chairs
>
> ----<original message with errata>---
> From: Tom Clancy
> Sent: Thursday, December 18, 2025 5:21 PM
> To: iGov List (openid-specs-igov) <openid-specs-igov at lists.openid.net>
> Subject: Action required: WGLC - Seeking WG consensus on iGov OAuth 2.0
> profile readiness to begin Implementers Draft review process S: Jan 12, 2026
>
> Dear Working Group members and contributors,
>
> We would like to get WG consensus that the current International
> Government Assurance Profile (iGov) for OAuth 2.0 - draft (09) - is ready
> to start the Implementer's Draft approval process.
>
> ACTION: Please respond to this email within the next 25 days, by January
> 12, 2026, end of business hours in PST, whether you believe the current
> draft should proceed or not.
>
> At the December 9 iGov WG meeting, after resolving remaining issues and
> pull requests, we determined consensus to CHANGE the next scheduled iGov WG
> meeting from Jan 6 to Jan 13 to afford members ample time to thoroughly
> review the specification without compromising any holiday plans.
>
> The iGov OAuth 2.0 profile document to be reviewed can be found here:
> https://openid.bitbucket.io/iGov/openid-igov-oauth2-1_0.html
> The iGov WG repository is here:
> https://bitbucket.org/openid/igov/src/master/
> The details of the Implementer's Draft approval process can be found here:
> https://openid.net/wg/resources/approving-specifications/
> This email is about the first bullet point on this list, which is
> sometimes called Working Group Last Call (WGLC).
>
> Following WG consensus, next steps are to start a 45-day Foundation-wide
> review, followed by the 7-day voting period (the poll itself will open 7
> days before the end of the Foundation-wide review ends). Foundation-wide
> review could end on or about March 1, 2026.
>
> Kindest regards,
> Editors & Chairs
>
> _______________________________________________
> Openid-specs-igov mailing list
> Openid-specs-igov at lists.openid.net
> https://lists.openid.net/mailman/listinfo/openid-specs-igov
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-igov/attachments/20260107/a4195c9f/attachment.htm>


More information about the Openid-specs-igov mailing list