[Openid-specs-risc] Meeting notes

Atul Tulshibagwale atul.tulshibagwale at crowdstrike.com
Tue Aug 4 17:56:57 UTC 2026


Hi all,
The notes for today's meeting are stored here
<https://github.com/openid/sharedsignals/wiki/WG-Meeting:-2026%E2%80%9008-03>.
They are pasted below for convenience.

Thanks to those who participated,
Atul
---
Agenda

   - Gail's update on the certification launch
   - WISE adoption - final call
   - Issue with interop spec: We agreed
   <https://hackmd.io/@oidf-wg-sse/wg-meeting-20260407#Certification-testing>
   not to mention subject types, but we still do.
   - Use of SSF in AIMS
   <https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/>
   - AOB

<#Attendees>Attendees

   - Atul Tulshibagwale (CrowdStrike)
   - Gail Hodges (OIDF)
   - Matt Topper (UberEther )
   - Ashmita Chakraborty (Independent)
   - Sahil Mukhija (CVS Health)
   - Tom Sato (MyAuberge)
   - Debayan Basu (Independent)
   - Sean O'Dell (CVS Health)
   - Vatsal Gupta
   - Thomas Darimont (OIDF)
   - Jack Zaldivar (Databricks)
   - John O'Leary (WinMagic)
   - George Fletcher (Practical Identity LLC)

<#Notes>Notes <#Certification-launch>Certification launch

   - Gail: Since interop profile is scheduled to move to final Oct 10th,
   then we could target launch of test suite shortly after.
   - (Thomas) Some have sent preliminary test results, looking forward to
   receiving more.
   - (Thomas) We need 3 transmitters and 3 receivers. We need at least one
   more receiver. But more is always better.
   - (Thomas) Just one of the receiver submissions used poll delivery,
   others were using push, so we need get more receivers with poll delivery.
   - (Sahil) CVS implementation can also submit one for push delivery (poll
   already submitted)
   - (Thomas) We usually go with the "rule of three", so we need 12 tests
   in all (receivers, transmitters, push, poll)
   - (Gail) The board approved the fees in 2024:
      - $3500 per spec per stream type for non-members
      - $700 per spec per stream type for members.
   - (Gail) This might be a good reason to become members.
   - (Gail) Comms incentive, we will probably “soft launch” the test suite
   to the WG shortly after interop profile goes to Final giving a two week
   window for first wave of implementers to pass conformance and be recognised
   with quotes and entity names etc in blog post, with a subset in a press
   release. That comm announcement would then be the public, formal launch,
   including the clear industry support for the test suite and transparency on
   implementer conformance on OIDF website as per usual
   -

<#Interop-spec-issue>Interop spec issue:

   - (Atul) Re: Yair's message on Slack.
   - (Atul) I believe we should not change the spec at this time, because
   the WG agreed to propose this as the final spec after a 15 day review.
   - (Sean) This is a basic requirement, we can live with it.
   - (Thomas) We can always expand later to include other types, such as
   "complex"
   - (Gail) It will be wise to leverage the interop work done to date, and
   go with it.

<#WISE-Adoption>WISE Adoption

   - (Sean) Yes please
   - (Atul) No response to email soliciting objections, and no objections
   mentioned in the call.
   - (Tom) I second the adoption of WISE
   - (Atul) So the proposal stands adopted.

<#SSF-use-in-AIMS>SSF use in AIMS

   - IDPro Blog Post: Assembly Required: How we Stopped Reinventing and
   Started Composing Standards for Agentic Identity
   <https://idpro.org/how-we-stopped-reinventing-and-started-composing-standards-for-agentic-identity/>
   - AIMS Link
   <https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-00.html>
   - (Sean) SSF is the data plane that hits on all aspects of AIMS
   - (Sean) AIMS is getting very popular in the 4 months it has been around.
   - (Sean) The idea is to include WISE events in the AIMS draft, but to
   run it as a subgroup in OpenID
   - (Sean) We would develop the WISE events in OpenID, and then refer to
   those in the IETF spec.
   - (Sean, in chat) WISE in OIDF Profile of SSF. Use of WISE Events in AIMS
   - (Thomas) For the WISE profile, there are a bunch of events listed. How
   can we possibly do conformance testing for so many events.
      - (Thomas) Should there be a set of "core" events? Should we plan to
      test all of them?
      - (Thomas) Which are the basic ones?
      - (Sean) That is something that the co-authors (Sean, Jeff, and
      Pieter) will have to discuss and determine.
   - (Thomas) Instead of refering to specific WISE events in AIMS, would it
   make sense to let the events be in the respective specs?
   - (Thomas, in chat) Quick remark: Instead of listing each and every
   event in an OpenID WISE Profile - wouldn’t it make more sense to add an SSF
   Events section to the respective specs like “Workload Identity in a Multi
   System Environment (WIMSE) Architecture” and “OAuth Transaction
   Authorization Challenge” …
   - (Sean/Atul) They're only going to refer to the events, not define them
   (again) there.

<#Action-Receipts-update>Action Receipts update

   - (Sean) We are planning to discuss this next week in IPSIE
   - (George) They are skipping a week, so the next one is going to be the
   25th. You need to reach out to Aaron and Dick to get on the agenda.

<#Action-Items>Action Items

   - Atul to check with implementers about poll receivers.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260804/db4efad5/attachment-0001.htm>


More information about the Openid-specs-risc mailing list