Minutes 2020-01-11

Hi,

Here are the notes I took during our call today; next meeting on the 25th.

# WebAuthn.How
JS validation library almost ready to be committed, need to be tweaked
to handle different request types - should come in later today or tomorrow
Nick: open to add support more libraries, bring suggestions in

# Conformance test suite
Alex: have worked a bit on this; Matt & I are planning to work on this
together
Matt: ramping back up on this in the near future; will focus on
authenticator in particular
Yuri: happy to help as needed
Matt: trickiest part is to generate wellformed answer for authenticators
Yuri: I can definitely help develop these - lots of intersections with
my work in FIDO. Is generating bad PKI certificates a hurddle? I have
ended up tools for that - Ken@@@ has a PKI library js-rsa-sign that
helps create certificates. I'll be happy to show some of this stuff
Nick: would love to join the conversations as well if you share it on Slack
Yuri: likewise

# WebAuthn MOOC
John: Yubico working on course material; Thursday, Yubico/W3C lawyers
are meeting on the legal aspects around the course; next will be timeline

# Market adoption metrics
  ACTION: Andrew to share more usable metrics on WebAuthn market
addressability

# Platform-specific implementations
ACTION: Dom to suggest a way forward on tracking platform-specific
implementations considerations
ACTION: Nick to ask John Bradley if he can share his documented
platform-specific authenticators oddities
ACTION: Dom to work with DavidT on granularity of MDN data on browser
support for WebAuthn

Nick: e.g. default states of creation options, capabilities of authenticator
Nick: Yubikeys / keychain tokens are pretty normative; but some other
authenticators don't respond as normatively - these needs to be documented
David: related issues in terms of what browsers do; MDN BCD doesn't
document options at enough granularity
Dom: there is support for finer granularity in MDN BCD - I'm happy to help
Yuri: re non-standard behavior, are there more details?
Nick: keys that don't have all extensions; keys that behave differently
on key recovery, key transitions; John Bradley has a better list e.g.
canonical id creations not responding properly
Yuri: would love to have a list to help with improving certification
Bill: would love to have that group document these oddities / corner cases
Matt: having documented options that get me in a given mode would be
really helpful; even more if it gets me data for specific browsers
Bill: happy to help get FIDO support for this
Yuri: would also want to make sure we're aware of these oddities in case
they show gaps in the certification
Matt: the expectation is that as these oddities get reported, they would
be reported upstream to the certification test suite

Received on Monday, 11 January 2021 18:34:23 UTC