[Openid-specs-mobile-profile] OIDC Mobile profile call Sept 24th: final notes

philippe.clement at orange.com philippe.clement at orange.com
Fri Sep 26 17:24:48 UTC 2014


Dear all,

Please find below the final notes of our call "OpenID Connect profile for mobile" on Sept 24th.
Thank you to people who provide me with remarks/suggestions


Participants:

Nat Sakimura, NRI

John Bradley, Ping Identity

Torsten Lodderstedt, Deutsche Telekom

Gonzalo Fernandez, Telefonica

Bjorn Hjelm, Verizon

Gautam Hazari, GSMA

Sebastian Ebling, Deutsche Telekom

Tim Bray, independent

Jörg Connotte, Deutsche Telekom

Philippe Clément, Orange


Agenda:


1-      Comments to initial submission

2-      Questions raised by Gonzalo

3-      Meeting frequency

Decisions:


-          3 documents will be managed from initial proposal: Discovery - registration - Authentication

-           Jorg, Bjorn, John volunteered for editor roles, KDDI is in the final stages of the IPR process and is willing to support with editing

-          Stories or user journey to sketch to fix the scope of the WG (TIM volunteered, Jörg Connotte to do an initial draft)

-          Discussions to continue on the mailing list



Discussion:



1-      Comments to initial submission


DT submission is considered as a good starting point.

3 documents will be managed from initial proposal: Discovery - registration - Authentication

3 volunteers for editor roles: Jorg, Bjorn, John. The three of them will synchronize who edits which sub


2-      Questions raised by Gonzalo


a.       Keep the user identifier hidden from the RPs
MSISDN will probably be a major identifier in the mobile operator world. Different cases to have in mind: the RP already knows the MSISDN (in this case, it can push it to simplify user journey) or not.
we agreed to consider this concern and come up with proposals how to extend the discovery concept. There are proposals by Gonzalo (implicit), Torsten (see mailing list), and John (Account Chooser).


b.      Choosing Mobile Connect authentication on a SP page triggers an "internal" discovery process
Questions about number and/or account portability and considering multiple MNOs (OP) raised, and if the discovery service internal working is in the scope of the WG


c.       Implicit discovery in the middle of an OIDC auth request

We mainly discussed about MNOs as a single, virtual IDP and mobile phone number portability. The WG has to come up with a common understanding and meet a decision.

è Discussions to go on the mailing list

è Stories or user journey to sketch to fix the scope of the WG (TIM volunteered, Jörg Connotte to do an initial draft)


3-      Meeting frequency
Meetings will occur bi-weekly on Wednesday (same time)


Kind regards,
Philippe


De : CLEMENT Philippe IMT TECHNO
Envoyé : jeudi 25 septembre 2014 14:35
À : 'openid-specs-mobile-profile at lists.openid.net'
Cc : Lodderstedt, Torsten (t.lodderstedt at telekom.de); Connotte, Joerg
Objet : OIDC Mobile profile call Sept 24th: preliminary notes

Dear all,

Please find below the preliminary notes of our call "OpenID Connect profile for mobile"
If you have any remark on these notes, please let me know before Friday Sep 26th EOB. Final notes will then follow with potential modifications

_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-mobile-profile/attachments/20140926/c6145260/attachment-0001.html>


More information about the Openid-specs-mobile-profile mailing list