<div dir="ltr"><div dir="ltr">Hi all,<br><div>Thanks for your participation in today's call. Here are the notes. They are also stored here.</div><div><br></div><div>Atul</div><div><br></div></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><span><div dir="ltr" style="margin-left:0pt" align="left"><table style="border:none;border-collapse:collapse"><colgroup><col width="165"><col width="160"></colgroup><tbody><tr style="height:74.5pt"><td style="vertical-align:middle;padding:5pt;overflow:hidden"><p dir="ltr" style="line-height:1.44;margin-top:0pt;margin-bottom:0pt"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline"><span style="border:none;display:inline-block;overflow:hidden;width:137px;height:68px"><img src="https://lh7-us.googleusercontent.com/OubMXEaSzW6cz-Rt9RyUGsuX2z_G2pbaWOSLNAI_1YuZEk9lVaehxLoZgJt6AbxshlaXTZ4HHvQjpxPRVTWVxlwCl-fPKhGsbSTcgVVvejMX1rS_DaeeX4yOVQyvp2y3cFkC6XMBihqiTrDY3qBYwq8" width="137" height="68" style="margin-left:0px;margin-top:0px"></span></span></p></td><td style="vertical-align:top;padding:5pt;overflow:hidden"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-size:11pt;font-family:Poppins,sans-serif;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline"> Atul Tulshibagwale</span></p><p dir="ltr" style="line-height:1.5;margin-top:0pt;margin-bottom:0pt"><span style="font-size:11pt;font-family:Poppins,sans-serif;color:rgb(102,102,102);background-color:transparent;vertical-align:baseline"> CTO</span></p><p dir="ltr" style="line-height:1.44;margin-top:0pt;margin-bottom:0pt"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(136,136,136);background-color:transparent;vertical-align:baseline"> </span><a href="https://www.linkedin.com/in/tulshi/" target="_blank"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(17,85,204);background-color:transparent;vertical-align:baseline"><span style="border:none;display:inline-block;overflow:hidden;width:24px;height:24px"><img src="https://lh7-us.googleusercontent.com/nf4RO594hvFNyujzHdKSn1RCJcOIC1-Mk2-_S2GLH4LUi6Prxj4bL0tyguJ-6XH50k_fHPq6nynNBdkJwAzgGdYlImXDDKv07yQuj5PcskVaBqf9vL1Z2esDwZsb5Z9J4tvDcPiiZdQSuyzywRbH3Fs" width="24" height="24" style="margin-left:0px;margin-top:0px"></span></span></a><a href="mailto:atul@sgnl.ai" target="_blank"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(17,85,204);background-color:transparent;vertical-align:baseline"><span style="border:none;display:inline-block;overflow:hidden;width:24px;height:24px"><img src="https://lh7-us.googleusercontent.com/jy9xWqMUZyDKsa5W_-BxVILzsnbgKHSkJVzdCeCWVVSvhJbGal-I_Ja-qTTnA1SpYE65RrEcWMMLNPfbrp9HXjBOKdeXNIVuhOBg-vZe-Ed8e0rCV8BMjih-COWlyljD_Hfqg2SzCuqKASIsPk1O6_w" width="24" height="24" style="margin-left:0px;margin-top:0px"></span></span></a><a href="https://x.com/zirotrust" target="_blank"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(17,85,204);background-color:transparent;vertical-align:baseline"><span style="border:none;display:inline-block;overflow:hidden;width:24px;height:24px"><img src="https://lh7-us.googleusercontent.com/N98NNhPOiQxQunuxKbv5L50QKM2TRayIDZDsOkFpZBpnxX7DATMDAj6a1zNXbjWfqluWTHt6BLNE9WbRSEYForDpaWWxtEd63NkpNqVY_9xAKyidyaSrYvOdHmKaijtXcPetATtR_eUKqs21wuYLq5w" width="24" height="24" style="margin-left:0px;margin-top:0px"></span></span></a></p></td></tr></tbody></table><br></div><div dir="ltr" style="margin-left:0pt" align="left"><h1 id="gmail-WG-Meeting-2024-11-05" style="box-sizing:border-box;margin:0px 0px 16px;font-family:"Readex Pro",-apple-system,BlinkMacSystemFont,"Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";line-height:1.25;color:rgb(51,51,51);max-width:100%;border-bottom:1px solid;padding-bottom:0.3em;letter-spacing:0.35px"><span style="box-sizing:border-box">WG Meeting: 2024-11-05</span></h1><h2 id="gmail-Agenda" style="box-sizing:border-box;font-family:"Readex Pro",-apple-system,BlinkMacSystemFont,"Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";line-height:1.25;color:rgb(51,51,51);margin-top:24px;margin-bottom:16px;max-width:100%;border-bottom:1px solid;padding-bottom:0.3em;letter-spacing:0.35px"><a class="gmail-anchor gmail-hidden-xs" href="#Agenda" title="Agenda" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none;float:left;line-height:1;padding-right:4px"><span class="gmail-octicon gmail-octicon-link gmail-ph gmail-ph-link-simple-horizontal" style="box-sizing:border-box;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-weight:normal;font-stretch:normal;font-size:16px;line-height:1;font-family:octicons;display:inline-block;color:rgb(0,0,0);vertical-align:middle"></span></a><span style="box-sizing:border-box">Agenda</span></h2><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:16px;max-width:100%;padding-left:2em;color:rgb(51,51,51);font-family:Inter,-apple-system,"system-ui","Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,system-ui,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:16px;letter-spacing:0.35px"><li style="box-sizing:border-box"><span style="box-sizing:border-box">Review the new proposed </span><a href="https://github.com/openid/sharedsignals/pull/205" target="_blank" rel="noopener" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none"><span style="box-sizing:border-box">CAEP event</span></a><span style="box-sizing:border-box">: "Risk level change"</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Reviews issues that should be included SSF-final</span></li></ul><h2 id="gmail-Attendees" style="box-sizing:border-box;font-family:"Readex Pro",-apple-system,BlinkMacSystemFont,"Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";line-height:1.25;color:rgb(51,51,51);margin-top:24px;margin-bottom:16px;max-width:100%;border-bottom:1px solid;padding-bottom:0.3em;letter-spacing:0.35px"><a class="gmail-anchor gmail-hidden-xs" href="#Attendees" title="Attendees" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none;float:left;line-height:1;padding-right:4px"><span class="gmail-octicon gmail-octicon-link gmail-ph gmail-ph-link-simple-horizontal" style="box-sizing:border-box;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-weight:normal;font-stretch:normal;font-size:16px;line-height:1;font-family:octicons;display:inline-block;color:rgb(0,0,0);vertical-align:middle"></span></a><span style="box-sizing:border-box">Attendees</span></h2><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:16px;max-width:100%;padding-left:2em;color:rgb(51,51,51);font-family:Inter,-apple-system,"system-ui","Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,system-ui,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:16px;letter-spacing:0.35px"><li style="box-sizing:border-box"><span style="box-sizing:border-box">Atul Tulshibagwale (SGNL)</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Apoorva Deshpande (Okta)</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Thomas Darimont (OIDF)</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Yair Sarig (Omnissa)</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Stan Bounev (VeriClouds)</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Martin Gallo (Individual)</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Sean O'Neill (EasyDynamics)</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Tushar Raibhandare (Google)</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Sean O'Dell (Disney)</span></li></ul><h2 id="gmail-Notes" style="box-sizing:border-box;font-family:"Readex Pro",-apple-system,BlinkMacSystemFont,"Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";line-height:1.25;color:rgb(51,51,51);margin-top:24px;margin-bottom:16px;max-width:100%;border-bottom:1px solid;padding-bottom:0.3em;letter-spacing:0.35px"><a class="gmail-anchor gmail-hidden-xs" href="#Notes" title="Notes" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none;float:left;line-height:1;padding-right:4px"><span class="gmail-octicon gmail-octicon-link gmail-ph gmail-ph-link-simple-horizontal" style="box-sizing:border-box;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-weight:normal;font-stretch:normal;font-size:16px;line-height:1;font-family:octicons;display:inline-block;color:rgb(0,0,0);vertical-align:middle"></span></a><span style="box-sizing:border-box">Notes</span></h2><h3 id="gmail-Risk-level-change-event" style="box-sizing:border-box;font-family:"Readex Pro",-apple-system,BlinkMacSystemFont,"Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";line-height:1.25;color:rgb(51,51,51);margin-top:24px;margin-bottom:16px;font-size:1.25em;max-width:100%;letter-spacing:0.35px"><a class="gmail-anchor gmail-hidden-xs" href="#Risk-level-change-event" title="Risk-level-change-event" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none;float:left;line-height:1;padding-right:4px"><span class="gmail-octicon gmail-octicon-link gmail-ph gmail-ph-link-simple-horizontal" style="box-sizing:border-box;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-weight:normal;font-stretch:normal;font-size:16px;line-height:1;font-family:octicons;display:inline-block;color:rgb(0,0,0);vertical-align:middle"></span></a><span style="box-sizing:border-box">Risk level change event</span></h3><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:16px;max-width:100%;padding-left:2em;color:rgb(51,51,51);font-family:Inter,-apple-system,"system-ui","Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,system-ui,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:16px;letter-spacing:0.35px"><li style="box-sizing:border-box"><a href="https://github.com/openid/sharedsignals/pull/205" target="_blank" rel="noopener" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none"><span style="box-sizing:border-box">https://github.com/openid/sharedsignals/pull/205</span></a></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Atul) Can we call this something else to avoid confusion with RISC</span><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:0px;padding-left:2em"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Apoorva) I was thinking of Threat Level Change, but open to other suggestions.</span></li></ul></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Atul) How is this different from "assurance level change"?</span><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:0px;padding-left:2em"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Apoorva) Assurance level change is about policy, this is about risk, so this could be an event that leads to generating an "Assurance Level Change" event.</span></li></ul></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">Everyone please review this event and add your comments.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Yair) Can we be more flexible than saying "low/medium/high"? This is common, but there could be other ways in which we can express this.</span><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:0px;padding-left:2em"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Apoorva) We could have a numeric "risk score" if needed.</span></li></ul></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Stan) How can this event provide consistency between different vendors in what they mean by "low/medium/high"</span><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:0px;padding-left:2em"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Apoorva) We could incorporate a classification from MITRE, or it could be an offline agreement between the parties</span></li></ul></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Yair) Maybe adding an optional "risk type" can help in this regard? The "risk type" can provide the same classification</span><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:0px;padding-left:2em"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Apoorva) There is an existing comment along these lines that Shayne has made.</span></li></ul></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) The thought behind this PR was that having a singular scale</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) We could distinguish the type based on the subject claim</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Yair) How does one know what the other party means by "low/medium/high"</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) We can do that, but it will be hard to standardize, because each organization can perceive risk differently.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Thomas) Perhaps we can calculate score based on </span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator" target="_blank" rel="noopener" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none"><span style="box-sizing:border-box">NIST vulnerability score</span></a></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Thomas) Perhaps something like this already exists</span><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:0px;padding-left:2em"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Apoorva) CVSS may not directly apply here. These may not be vulnerabilities.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Thomas) Perhaps something similar (not the same) can work</span></li></ul></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Stan) Everytime there is a risk level change, the Tx will send this event. The Tx can send this event based on any event that we have already in CAEP. All other events could be made obsolete by this. Is this correct?</span><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:0px;padding-left:2em"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Apoorva) It's not, because each Tx may define risk differently. E.g., "session revoked" can be a completely different thing. Or "assurance level change". This will go hand-in-hand with the other events</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Stan) So if I implement both "risk lc" and "assurance lc", then how will I determine which one to use?</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) Assurance level change could just be normal behavior (e.g. user has used MFA), whereas the risk level change could indicate something completely different such as a session token being stolen.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Stan) So say if an Rx receives two events: "credential revoked", and "risk lc" (medium). The question is, are those two about the same thing, or are they describing something else that is going on. As an implementer it will be difficult to go to the bottom of things if there is a "risk lc" event, which doesn't actually say what the risk is, and other events that may be specific.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) You are asking for a prescriptive way of doing things, whereas CAEP is descriptive</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) The Tx also could insert a message in the event to say why, which could help reconcile.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Atul) We could use "txn" to correlate events</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Sean O'Dell) raises thumbs up paddle</span></li></ul></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Thomas) Does the “risk” level combines multiple facets? E.g. “impact” and “urgency”? Or is this about the outcome, e.g. what is affected? E.g. authentication level is “weaker” or “higher” because of the event.</span><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:0px;padding-left:2em"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Apoorva) It will be transmitters prerogative to determine the risk</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Thomas) It's not clear to me if a one-dimensional 3-level scale can capture the risk adequately</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) This will be based on the maturity of the ITDR of the transmitter, but each Transmitter will be different</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Sean O'Dell) This could be an additive signal, not a prescriptive signal.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) We can learn as we start implementing, but we can start here.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) Going back to Yair's point, the same thing could be said about the numeric scale</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Yair) That's why we need to indicate the scale we are using in the event.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Atul) We did something similar in the "Assurace LC" event, we added the "namespace" field to capture the scale we are using in the event.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Yair) The scale could default to "low/medium/high", so if the scale indicator doesn't exist, it is that. If it is specified, the value is from that scale.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) The processing of the event will be difficult if the scale is not the same from each transmitter (interoperability will be harder)</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Yair) It's upto the Receiver to determine what it can support.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) Please add examples of requiring different scales</span></li></ul></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Atul) One other concern is whether it is sufficient to determine what the event is about based on the subject format.</span><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:0px;padding-left:2em"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Yair) Agree with this concern. What happens when the subject is a complex subject and has say, an email and a device identifier. What is the event about?</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) So you're saying we need to pinpoint what the risk is about (device, user).</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) We can consider the risk to be about everything the subject indicates.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Atul) Please provide this language in PR</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) Will think about this</span></li></ul></li></ul><h3 id="gmail-What-issues-to-include-in-SSF-final" style="box-sizing:border-box;font-family:"Readex Pro",-apple-system,BlinkMacSystemFont,"Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";line-height:1.25;color:rgb(51,51,51);margin-top:24px;margin-bottom:16px;font-size:1.25em;max-width:100%;letter-spacing:0.35px"><a class="gmail-anchor gmail-hidden-xs" href="#What-issues-to-include-in-SSF-final" title="What-issues-to-include-in-SSF-final" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none;float:left;line-height:1;padding-right:4px"><span class="gmail-octicon gmail-octicon-link gmail-ph gmail-ph-link-simple-horizontal" style="box-sizing:border-box;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-weight:normal;font-stretch:normal;font-size:16px;line-height:1;font-family:octicons;display:inline-block;color:rgb(0,0,0);vertical-align:middle"></span></a><span style="box-sizing:border-box">What issues to include in SSF-final</span></h3><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:16px;max-width:100%;padding-left:2em;color:rgb(51,51,51);font-family:Inter,-apple-system,"system-ui","Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,system-ui,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:16px;letter-spacing:0.35px"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Atul) We do not need to go to ID-4 in order to call a revised spec final. We can propose a revised spec as the "final" proposed spec and vote on that.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) Can we verify that?</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Apoorva) My suggestion is to not take up anything unless it is urgently required. i.e. Let's take ID-3 to final.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Yair) What is the criteria for calling an issue to be in "v1Final"?</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Tushar) I have a question about v1Final vs vFuture. There are some quality of life changes that could be included.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">(Atul) Call to action: Please review the issues, and if you believe something needs to be in "v1Final", tag it and comment on the issue as to why you believe it should be so.</span></li></ul><h3 id="gmail-SSF-conformance-testing-Thomas" style="box-sizing:border-box;font-family:"Readex Pro",-apple-system,BlinkMacSystemFont,"Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";line-height:1.25;color:rgb(51,51,51);margin-top:24px;margin-bottom:16px;font-size:1.25em;max-width:100%;letter-spacing:0.35px"><a class="gmail-anchor gmail-hidden-xs" href="#SSF-conformance-testing-Thomas" title="SSF-conformance-testing-Thomas" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none;float:left;line-height:1;padding-right:4px"><span class="gmail-octicon gmail-octicon-link gmail-ph gmail-ph-link-simple-horizontal" style="box-sizing:border-box;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-weight:normal;font-stretch:normal;font-size:16px;line-height:1;font-family:octicons;display:inline-block;color:rgb(0,0,0);vertical-align:middle"></span></a><span style="box-sizing:border-box">SSF conformance testing (Thomas)</span></h3><p style="box-sizing:border-box;margin:0px 0px 16px;max-width:100%;color:rgb(51,51,51);font-family:Inter,-apple-system,"system-ui","Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,system-ui,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:16px;letter-spacing:0.35px"><span style="box-sizing:border-box">I wanted to take a moment to say “thank you” for providing the SSF Enabled environments to the OIDF to support SSF conformance test development. This has already been a great help!</span><br style="box-sizing:border-box"><span style="box-sizing:border-box">Thanks Atul (<a href="http://caep.dev">caep.dev</a>), Thanks Yair (Omnissa), Thanks Apoorva (Okta)</span></p><ul style="box-sizing:border-box;margin-top:0px;margin-bottom:16px;max-width:100%;padding-left:2em;color:rgb(51,51,51);font-family:Inter,-apple-system,"system-ui","Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,system-ui,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:16px;letter-spacing:0.35px"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(Thomas) It's a Java Spring Boot project that you can run to test your implementation. It should be ready in a few weeks.</span></li><li style="box-sizing:border-box;padding-top:0.25em"><span style="box-sizing:border-box">You can find the current (working) version </span><a href="https://gitlab.com/openid/conformance-suite" target="_blank" rel="noopener" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none"><span style="box-sizing:border-box">here</span></a><span style="box-sizing:border-box">.</span></li></ul><h2 id="gmail-Action-Items" style="box-sizing:border-box;font-family:"Readex Pro",-apple-system,BlinkMacSystemFont,"Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";line-height:1.25;color:rgb(51,51,51);margin-top:24px;margin-bottom:16px;max-width:100%;border-bottom:1px solid;padding-bottom:0.3em;letter-spacing:0.35px"><a class="gmail-anchor gmail-hidden-xs" href="#Action-Items" title="Action-Items" style="box-sizing:border-box;background-color:transparent;text-decoration-line:none;float:left;line-height:1;padding-right:4px"><span class="gmail-octicon gmail-octicon-link gmail-ph gmail-ph-link-simple-horizontal" style="box-sizing:border-box;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-weight:normal;font-stretch:normal;font-size:16px;line-height:1;font-family:octicons;display:inline-block;color:rgb(0,0,0);vertical-align:middle"></span></a><span style="box-sizing:border-box">Action Items</span></h2><ul style="box-sizing:border-box;margin-top:0px;max-width:100%;padding-left:2em;color:rgb(51,51,51);font-family:Inter,-apple-system,"system-ui","Segoe UI","Helvetica Neue",Helvetica,Roboto,Arial,system-ui,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:16px;letter-spacing:0.35px;margin-bottom:0px"><li style="box-sizing:border-box"><span style="box-sizing:border-box">(All) Call to action: Please review the issues, and if you believe something needs to be in "v1Final", tag it and comment on the issue as to why you believe it should be so.</span></li></ul></div></span></div></div></div>