[Openid-specs-risc] [External] Re: Proposing final vote on the CAEP Interoperability spec

Atul Tulshibagwale atul.tulshibagwale at crowdstrike.com
Tue Jun 23 18:34:39 UTC 2026


Hi all,
All open issues related to the interoperability spec have now been
addressed.

Does anyone on this list object to proposing the updated interop spec
<https://openid.github.io/sharedsignals/openid-caep-interoperability-profile-1_0.html>
as the final specification? Please provide your responses by July 8th, 2026.

Thanks,
Atul

On Sat, May 16, 2026 at 3:08 AM Thomas Darimont <thomas.darimont at oidf.org>
wrote:

> Hello Atul et al.,
>
> Following Joseph, here is my list of currently open issues. Some of them
> can be closed due to the latest changes.
> Others might need a small adjustment to the CAEP Interop profile.
>
> #327 Clarify how a Receiver discovers the Authorization Server from a
> Transmitter URL
> https://github.com/openid/sharedsignals/issues/327 [github.com]
> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/issues/327__;!!BmdzS3_lV9HdKG8!0T8r2Oo9Lz4psHz4q_KRCa1SKxUoWmW5Y9qnzOZwTZVJ5Nrka3KSz-f6UKnaYCzlN2hczwOaYnevZem8cit9LMr558qPLFIxeFKIWA$>
> I think this still needs some clarification in the CAEP Interop profile
> document.
> E.g., if it is expected that the OAuth Authorization Server issuer
> information is provided to a receiver out-of-band.
>
> #319 Clarify status code usage for malformed stream configurations sent to
> the configuration endpoint
> https://github.com/openid/sharedsignals/issues/319 [github.com]
> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/issues/319__;!!BmdzS3_lV9HdKG8!0T8r2Oo9Lz4psHz4q_KRCa1SKxUoWmW5Y9qnzOZwTZVJ5Nrka3KSz-f6UKnaYCzlN2hczwOaYnevZem8cit9LMr558qPLFLoBpy3NA$>
> Here, it was agreed in an SSF WG call that stream configuration endpoint
> requests with a malformed request body (e.g. ;{ broken" should result in a
> status code of 400 Bad Request.
>
> If you think the spec is clear enough already, we can close this issue.
> Otherwise, we should adjust the CAEP Iterop profile.
>
> #318 Status endpoint requirements for CAEP interop profile
> https://github.com/openid/sharedsignals/issues/318 [github.com]
> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/issues/318__;!!BmdzS3_lV9HdKG8!0T8r2Oo9Lz4psHz4q_KRCa1SKxUoWmW5Y9qnzOZwTZVJ5Nrka3KSz-f6UKnaYCzlN2hczwOaYnevZem8cit9LMr558qPLFI2du8hIw$>
>
> It was agreed to keep support for "Reading the stream status" in the CAEP
> interoperability profile.
> I think this issue can be closed, as the changes are now in the CAEP
> Interop profile document.
>
> #294 CAEP interop spec should define features and behaviors expected from
> SSF Receivers
> https://github.com/openid/sharedsignals/issues/294 [github.com]
> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/issues/294__;!!BmdzS3_lV9HdKG8!0T8r2Oo9Lz4psHz4q_KRCa1SKxUoWmW5Y9qnzOZwTZVJ5Nrka3KSz-f6UKnaYCzlN2hczwOaYnevZem8cit9LMr558qPLFLnRt_riw$>
>
> I think this issue can be closed, as the changes are now in the CAEP
> Interop profile document.
>
> Kind regards,
> Thomas
> ---------------------
> *Thomas Darimont*
> Certification Specialist | Certification Team
> OpenID Foundation
> ------------------------------
> *From:* Openid-specs-risc <openid-specs-risc-bounces at lists.openid.net> on
> behalf of Atul Tulshibagwale via Openid-specs-risc <
> openid-specs-risc at lists.openid.net>
> *Sent:* Friday, May 15, 2026 9:13 PM
> *To:* Joseph Heenan <joseph.heenan at oidf.org>
> *Cc:* OpenID RISC List <openid-specs-risc at lists.openid.net>; Sean
> O'Dentity <iam at seanodentity.com>
> *Subject:* Re: [Openid-specs-risc] [External] Re: Proposing final vote on
> the CAEP Interoperability spec
>
> Hi Joseph,
>
> Thanks for looking this over and raising these points.
>
> I suppose we need one more iteration before proposing this as final.
>
> Atul
>
> On Fri, May 15, 2026 at 10:44 AM Joseph Heenan <joseph.heenan at oidf.org>
> wrote:
>
> Hi Atul
>
> I had a read through the spec and noticed a few things - I raised:
>
> https://github.com/openid/sharedsignals/issues/332 [github.com]
> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/issues/332__;!!BmdzS3_lV9HdKG8!zvVIODoUPKFlxUVukVraTtc-3N-_zbL5FUvFlcPGwusTiHvrZ_YRoHabuOYU5m9ct-C6jMuvcvNmlDUcEW20RHLXg3o9bXTc9fo$>
>
>
> And there were also some things I noticed that are hopefully uncontentious
> so I opened a PR for them, hope that’s okay:
>
> https://github.com/openid/sharedsignals/pull/333 [github.com]
> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/pull/333__;!!BmdzS3_lV9HdKG8!zvVIODoUPKFlxUVukVraTtc-3N-_zbL5FUvFlcPGwusTiHvrZ_YRoHabuOYU5m9ct-C6jMuvcvNmlDUcEW20RHLXg3o9c3HGWlw$>
>
> I think this issue should also have a clear conclusion and be fixed/closed
> before the spec proceeds to the next stage:
>
> https://github.com/openid/sharedsignals/issues/308 [github.com]
> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/issues/308__;!!BmdzS3_lV9HdKG8!zvVIODoUPKFlxUVukVraTtc-3N-_zbL5FUvFlcPGwusTiHvrZ_YRoHabuOYU5m9ct-C6jMuvcvNmlDUcEW20RHLXg3o9KTKfDmE$>
>
> Let me know if you have any questions!
>
> Thanks
>
> Joseph
>
>
> On 15 May 2026, at 00:41, Atul Tulshibagwale via Openid-specs-risc <
> openid-specs-risc at lists.openid.net> wrote:
>
> Hi all,
> We recently updated the draft CAEP interoperability [openid.github.io]
> <https://urldefense.com/v3/__https://openid.github.io/sharedsignals/openid-caep-interoperability-profile-1_0.html__;!!BmdzS3_lV9HdKG8!zvVIODoUPKFlxUVukVraTtc-3N-_zbL5FUvFlcPGwusTiHvrZ_YRoHabuOYU5m9ct-C6jMuvcvNmlDUcEW20RHLXg3o9E-qeyOQ$>
> spec to add receiver features and clarify existing ones.
> One PR is pending [github.com]
> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/pull/331__;!!BmdzS3_lV9HdKG8!zvVIODoUPKFlxUVukVraTtc-3N-_zbL5FUvFlcPGwusTiHvrZ_YRoHabuOYU5m9ct-C6jMuvcvNmlDUcEW20RHLXg3o9ZbEKbfQ$>;
> it only updates the non-normative Document History section. That will be
> merged soon.
>
> Does anyone on this list object to proposing the updated interop spec,
> including PR #331 [github.com]
> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/pull/331__;!!BmdzS3_lV9HdKG8!zvVIODoUPKFlxUVukVraTtc-3N-_zbL5FUvFlcPGwusTiHvrZ_YRoHabuOYU5m9ct-C6jMuvcvNmlDUcEW20RHLXg3o9ZbEKbfQ$>,
> as the final specification? Please provide your responses by May 28, 2026.
>
> Thanks,
> Atul
> _______________________________________________
> Openid-specs-risc mailing list
> Openid-specs-risc at lists.openid.net
> https://lists.openid.net/mailman/listinfo/openid-specs-risc
> [lists.openid.net]
> <https://urldefense.com/v3/__https://lists.openid.net/mailman/listinfo/openid-specs-risc__;!!BmdzS3_lV9HdKG8!zvVIODoUPKFlxUVukVraTtc-3N-_zbL5FUvFlcPGwusTiHvrZ_YRoHabuOYU5m9ct-C6jMuvcvNmlDUcEW20RHLXg3o913YZNCc$>
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260623/23cceb6e/attachment-0001.htm>


More information about the Openid-specs-risc mailing list