Agenda: Distributed meeting 2009-02-03

Agenda: W3C XML Security WG (XMLSec)
Teleconference 3 February 2009
Distributed Meeting #18

10-12:00 am Eastern Time
Information on meeting times in various time zones:
http://www.w3.org/2008/xmlsec/Group/Overview.html#phone

Zakim Bridge:
+1.617.761.6200 conference code 965732# ('XMLSEC')
IRC Chat:
irc.w3.org (port 6665), #xmlsec
Web-based IRC (member-only):
<http://cgi.w3.org/member-bin/irc/irc.cgi>

Please note that attendance of XMLSEC WG teleconferences is restricted  
to registered WG participants and persons invited by the chair.

Chair: Frederick Hirsch

Regrets:  Konrad Lanz

see http://www.w3.org/2008/xmlsec/Group/Overview.html#upcoming-meetings

1) Administrivia: scribe confirmation, next meeting, other

1a)  Sean Mullan  is scheduled to scribe

The current scribe list is at the end of this message, will rotate  
through this list.

Scribe Instructions:
http://www.w3.org/2007/xmlsec/Group/Scribe-Instructions.html

1b)   Meeting planning: weekly meetings

This WG meets weekly on Tuesdays 10-12 Eastern unless a meeting is  
cancelled.

Upcoming meeting information is available on the WG Administrative page:
http://www.w3.org/2008/xmlsec/Group/Overview.html#upcoming-meetings

Next meeting 10 Feb - Konrad Lanz to scribe,
17 Feb, Juan Carlos Cruellas scheduled to scribe.

1c) Liaisons and Coordination

See status at members page
http://www.w3.org/2008/xmlsec/Group/Overview.html#coordination

No new updates.

1d) Announcements

FIPS-186-3 (DSAwithSHA256) status:
http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0076.html

W3C 3rd Party Licensing Commitments material
http://www.w3.org/2004/01/pp-impl/42458/nmlc

2) Minutes Approval

2a) Minutes from F2F, 13-14 January, for approval:

http://www.w3.org/2009/01/13-xmlsec-minutes.html

http://www.w3.org/2009/01/14-xmlsec-minutes.html

2b) Minutes from 27 January 2009, for approval:

http://www.w3.org/2009/01/27-xmlsec-minutes.html

3) Issues
ISSUE-95: add as recommended algorithms "XPATH 2 Filter" and  
"Exclusive Canonicalization" to the list in section 6.0 of XML  
Signature 1.1
4) Document status

4a) Requirements

http://www.w3.org/2008/xmlsec/Drafts/xmlsec-reqs/Overview.html

Updated with algorithms section
http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0075.html  
(Frederick)

5) XML Signature 1.1

http://www.w3.org/2008/xmlsec/Drafts/xmldsig-core-11/Overview.htm

5a) Add RetrievalMethod text

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0055.html  
(Scott)

5b) Update examples use of algorithms

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0067.html  
(Sean)

5c) Schema cleanup

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0080.html  
(Thomas)

5d) ECC Algorithms Schema update

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0068.html  
(Magnus)

consistency of style of XML Signature schema?

5e) ECKeyValue namespace issue?

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0078.html  
(Thomas)

5f) Collisions discussion

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0070.html  
(Brad)

5g) insignificant whitespace in the ds:SignedInfo

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0071.html  
(Konrad)

5h) add as recommended algorithms "XPATH 2 Filter" and "Exclusive  
Canonicalization" to the list in section 6.0

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0072.html  
(Chris)

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0073.html  
(Sean, +1)

5i) Transform warning text to best practices (Scott ACTION-176)?

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0074.html  
(Sean)

5j) MUST ECC with editorial note?

5k) Open actions?

5l) Ready to publish?

6) XML Encryption 1.1

http://www.w3.org/2008/xmlsec/Drafts/xmlenc-core-11/

6a) Corrected spelling errors carried forward from XML Encryption 1.0

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0036.html

Errata item for 1.0 XML Encryption?

6b) Key Wrapping IETF duplication rationale?

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0042.html  
(Thomas)

6c) updated AES key warpping mechanism with padding

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0077.html  
(Thomas)

6d) Suite B reference?

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0050.html  
(Gerald)

6e) Open actions?

6f) Ready to publish?

REQUIRED Elliptic Curve Diffie-Hellman (Ephemeral-Static mode)

http://www.w3.org/2008/xmlsec/Drafts/xmlenc-core-11/#sec-AlgID

7) Algorithms Draft

7a) Updating formatting - status?

http://www.w3.org/2008/xmlsec/Drafts/xmlsec-algorithms/Overview.html  
(Thomas)

7b) Ready to publish?

8) XML Signature Transform Simplification: Requirements and Design

8a) Editorial updates and review

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0065.html  
(Pratik)

8b) Ready to publish?

9) XML Security Use Cases and Requirements

9a) Review of new algorithms section?

9b) Signing HTTP messages

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0040.html  
(Scott)

9c) Revising Canonicalization Requirements

http://lists.w3.org/Archives/Public/public-xmlsec/2008Nov/0006.html  
(Juan Carlos)

9d) Ready to publish?

10) Best Practices

http://www.w3.org/2007/xmlsec/Drafts/xmldsig-bestpractices/

10a) updated for timestamp, additional proposed changes

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0038.html  
(Frederick)

10b) additional best practice - Schema Normalization

http://lists.w3.org/Archives/Public/public-xmlsec/2009Jan/0054.html  
(Scott)

10c) Earlier comments from Juan Carlos

http://www.w3.org/2008/xmlsec/Drafts/best-practices/comments-bhill-jcc.html 
  (Edited document)

http://lists.w3.org/Archives/Public/public-xmlsec/2008Oct/0020.html  
(Frederick)

http://lists.w3.org/Archives/Public/public-xmlsec/2008Oct/0030.html  
(Juan Carlos)

10d) Ready to publish?

11) Derived Keys

11a) Review of Revised Draft
http://www.w3.org/2008/xmlsec/Drafts/derived-key/derived-keys.html  
(Magnus)

11b) Ready to publish with 1.1?

12) Action Item and Issue Review

12a) Close Pending actions
[pending review] ACTION-131: Thomas Roessler to Ping Tim Polk about  
likely 186-3 timing expectations - due 2009-01-13 [on ]
http://www.w3.org/2008/xmlsec/track/actions/131

[pending review] ACTION-151: Thomas Roessler to Propose changes - due  
2009-01-20 [on ]
http://www.w3.org/2008/xmlsec/track/actions/151

[pending review] ACTION-160: Thomas Roessler to Check on possibility  
for external RF commitments under patent policy - due 2009-02-04 [on ]
http://www.w3.org/2008/xmlsec/track/actions/160

[pending review] ACTION-168: Scott Cantor to Contribute additional  
text for transform note, to make clear what this document gets at -  
due 2009-01-21 [on C14N (Design for Canonicalization V Next)]
http://www.w3.org/2008/xmlsec/track/actions/168

[pending review] ACTION-195: Frederick Hirsch to Update requirements  
document with algorithms proposal - due 2009-02-03 [on ]
http://www.w3.org/2008/xmlsec/track/actions/195

12b) Open Action Review

Open actions are listed in Tracker at http://www.w3.org/2008/xmlsec/track/actions/open

Procedure for closing actions: http://www.w3.org/2007/xmlsec/Group/Overview.html#closing-actions

Please review open action list and update your actions appropriately:

http://www.w3.org/2008/xmlsec/actions-open.html

13) Other Business

14) Adjourn

Scribing  list
----------------
Konrad Lanz, IAIK (16 July F2F am)
Sean Mullan, Sun (12 August 2008)
Juan Carlos Cruellas, Universitat Politècnica de Catalunya (16  
September 2008)
Chris Solc, Adobe (20 October 2008 F2F am)
Robert Miller, MITRE (20 October 2008 F2F pm)
Bruce Rich, IBM (17 July F2F am, 21 October 2008 F2F am)
Kelvin Yiu, Microsoft (21 October 2008 F2F, pm)
Magnus Nyström, EMC (11 November 2008)
Ed Simon, Invited Expert (18 November 2008)
Scott Cantor, invited expert (29 July 2008, 2 December 2008)
Hal Lockhart, Oracle (9 December 2008)
John Wray, IBM (16 December 2008)
Phillip Hallam-Baker, Verisign (F2F 13 January 2009, am)
Gerald Edgar, Boeing (F2F 13 January 2009, pm)
Shivaram Mysore, Invited Expert ( F2F 14 January 2009, pm)
Pratik Datta, Oracle ( F2F 14 January 2009, pm)
Brian LaMacchia, Microsoft ( F2F 14 January 2009, pm)
Bradley Hill, Invited Expert (27 January 2009)

regards, Frederick

Frederick Hirsch, Nokia
Chair XML Security WG

Received on Friday, 30 January 2009 15:56:04 UTC