W3C

XML Security Working Group Teleconference

30 Aug 2011

Agenda

See also: IRC log

Attendees

Present
Bruce_Rich, Cynthia_Martin, Ed_Simon, Frederick_Hirsch, Hal_Lockhart, Pratik_Datta, Scott_Cantor, Thomas_Roessler
Regrets
Shivaram_Mysore, Chris_Solc
Chair
Frederick_Hirsch
Scribe
fjh

Contents


<trackbot> Date: 30 August 2011

Administrative

<scribe> ScribeNick: fjh

No new news

Minutes Approval

Approve minutes, 16 August 2011

http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/att-0047/minutes-2011-08-16.html

RESOLUTION: Minutes from 16 August are approved.

RELAX NG Schemas publication

Publication request sent, http://lists.w3.org/Archives/Member/member-xmlsec/2011Aug/0008.html

proposed RESOLUTION: The WG agrees to publish an updated working draft of XML Security RELAX NG Schemas on 30 August 2011, as prepared at http://www.w3.org/2008/xmlsec/Drafts/xmlsec-rngschema/2011-08-19-snapshot/Overview.html

RESOLUTION: The WG agrees to publish an updated working draft of XML Security RELAX NG Schemas on 30 August 2011, as prepared at http://www.w3.org/2008/xmlsec/Drafts/xmlsec-rngschema/2011-08-19-snapshot/Overview.html

XML Encryption 1.1 updates

schema, ACTION-824, LC-2543 http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0051.html

media type section, remove self-reference, LC-2541, http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0062.html

base64 clarity, LC-2542, http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0066.html

added timing attacks security consideration, http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0075.html

corrected the SHA-1 URI in enc-example.xml for XML Encryption 1.1, http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0085.html

updated xenc-schema-11.xsd for AlgorithmIdentifierType and PRFAlgorithmIdentifierType schema to add use="required" for the Algorithm attribute, http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0086.html

will make update based on magnus suggestion

http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0090.html

RESOLUTION: Accept change from magnus on security note

ACTION-814?

<trackbot> ACTION-814 -- Magnus Nystrom to make namespace ("&xenc;") related edits in XML Encryption 1.1 -- due 2011-07-05 -- PENDINGREVIEW

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/814

Additional open comment, http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0079.html

need to review this to see if there are additional errors

XML Encryption algorithms

http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0014.html

http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0048.html

scantor: notes an alternative is to use KEM vs OAEP, but no known issue with OAEP

<Zakim> tlr, you wanted to ask whether there's other information that we could gather that would help us decide?

fjh: general agreement to change algorithm requirement from pkcs 1.5
... this fall consider referencing additional papers

hal: argument against requiring new algorithms, as time required for attack to be known
... once attack is known, algorithm use will diminish over time

ACTION-829?

<trackbot> ACTION-829 -- Scott Cantor to provide additional proposal text regarding xml encryption changes for pkcs1.5 -- due 2011-08-23 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/829

XML Security 2.0

Update of XML Signature 2.0 to reference Best Practices in introduction, LC-2507

http://lists.w3.org/Archives/Public/public-xmlsec/2011Jul/0015.html

ACTION-717?

<trackbot> ACTION-717 -- Pratik Datta to document the Performance improvements with 2.0 -- due 2010-11-09 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/717

LC-4288, detailed comments from Paul Grosso

ACTION-802?

<trackbot> ACTION-802 -- Pratik Datta to review comments from XML Core WG and formulate response, http://lists.w3.org/Archives/Public/public-xmlsec/2011Jun/0005.html -- due 2011-06-14 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/802

ACTION-810?

<trackbot> ACTION-810 -- Pratik Datta to review and respond to additional XML Core WG comments http://lists.w3.org/Archives/Public/public-xmlsec/2011Jun/0005.html -- due 2011-06-21 -- CLOSED

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/810

http://lists.w3.org/Archives/Public/public-xmlsec/2011Jun/0005.html

http://lists.w3.org/Archives/Public/public-xmlsec/2011Jul/0018.html

<Cynthia1> ?

<scribe> ACTION: pdatta to compose draft response for LC-4288 and share on xmlsec list for review [recorded in http://www.w3.org/2011/08/30-xmlsec-minutes.html#action01]

<trackbot> Created ACTION-830 - Compose draft response for LC-4288 and share on xmlsec list for review [on Pratik Datta - due 2011-09-06].

pdatta: issue 3 noted in email, that section is wrong

<pdatta> Issue 1 - will not make a change

<pdatta> Issue 2 - will make the suggested change

<pdatta> Issue 3 - put that section in compatibility section, and make fixes to that section

<pdatta> Issue 4 - will make the change

RESOLUTION: make 2.0 changes as outlined in http://lists.w3.org/Archives/Public/public-xmlsec/2011Jul/0018.html for issue 2 and 4, move issue 3 section to compatibility section with changes, no change for issue 1

ACTION-809?

<trackbot> ACTION-809 -- Pratik Datta to fix examples in signature 2.0 -- due 2011-06-21 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/809

LC-2487, change name of attribute from type to Attribute

Interop

fjh: suggest we revisit interop plans in a week or two, after summer holiday returns

<tlr> yes

Updated suite b interop page, http://lists.w3.org/Archives/Public/public-xmlsec/2011Aug/0091.html

tlr: need to focus on test suite and implementations to bring this work forward

<scantor> +1

Adjourn

Summary of Action Items

[NEW] ACTION: pdatta to compose draft response for LC-4288 and share on xmlsec list for review [recorded in http://www.w3.org/2011/08/30-xmlsec-minutes.html#action01]
 
[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.135 (CVS log)
$Date: 2009-03-02 03:52:20 $