05/24/2016 WebAuthn Summary
- J.C. Jones (Friday, 27 May)
- Vijay Bharadwaj (Friday, 27 May)
- J.C. Jones (Friday, 27 May)
- Vijay Bharadwaj (Friday, 27 May)
- J.C. Jones (Friday, 27 May)
- Wendy Seltzer (Friday, 27 May)
- Vijay Bharadwaj (Friday, 27 May)
- J.C. Jones (Friday, 27 May)
- Mandyam, Giridhar (Friday, 27 May)
- Sampath Srinivas (Friday, 27 May)
- Mandyam, Giridhar (Friday, 27 May)
- Sampath Srinivas (Friday, 27 May)
- Anthony Nadalin (Friday, 27 May)
- Mandyam, Giridhar (Friday, 27 May)
- Anthony Nadalin (Thursday, 26 May)
05/25/2006 W3C WebAuthn WG Agenda
5/11 W3C Web Authentication Meeting
[minutes] 13 May F2F
[minutes] Re: 05/25/2006 W3C WebAuthn WG Agenda
[w3c/webauthn]
[w3c/webauthn] 061201: Merge remote-tracking branch 'refs/remotes/origin/...
[w3c/webauthn] 0950a1: Update reference to Secure-Contexts (from Powerful...
[w3c/webauthn] 09bc41: Update README.md
[w3c/webauthn] 15e1b9: Lots of FPWD issues (#83)
[w3c/webauthn] 16df16: address vijay's comments #3 - minor tweaks
[w3c/webauthn] 17efea: Script updating gh-pages. [ci skip]
[w3c/webauthn] 19f23b: Remove base64 from packed and TPM attestation form...
[w3c/webauthn] 1be2d8: Fix formatting in F2F meeting agenda
[w3c/webauthn] 212d61: Script updating gh-pages. [ci skip]
[w3c/webauthn] 32994f: Create 2016-05-13-Berlin-f2f.md
[w3c/webauthn] 46784e: Fix spec shortname to prep for FPWD (#110)
[w3c/webauthn] 49d6ba: Replace TPM hyperlinks with working ones (#82)
[w3c/webauthn] 4fbfa4: Clarify Android attestation procedure
[w3c/webauthn] 53d985: Pre-FWPD proofreading corrections (#81)
[w3c/webauthn] 58c350: add link to test repo
[w3c/webauthn] 5aa4d7: Incorporate feedback from JeffH, fix an incorrect ...
[w3c/webauthn] 5f6c59: Update README.md
[w3c/webauthn] 600b0b: remove Makefile dependency on biblio.json
[w3c/webauthn] 634c26: Represent binary data as ArrayBuffers instead of b...
[w3c/webauthn] 66372a: Script updating gh-pages. [ci skip]
[w3c/webauthn] 6a6014: address Vijay's comments
[w3c/webauthn] 79afe1: Script updating gh-pages. [ci skip]
[w3c/webauthn] 827a63: Use case: user can use WebAuthn credential when cr...
[w3c/webauthn] 8d3761: Script updating gh-pages. [ci skip]
[w3c/webauthn] 970210: Script updating gh-pages. [ci skip]
[w3c/webauthn] a38ee2: Clarify that RP ID is globally unique
[w3c/webauthn] a8a2d7: JsonWebKey is a dictionary not an interface
[w3c/webauthn] b073bf: fix spelling and reference
[w3c/webauthn] b5493f: Make method parameters consistent between API and ...
[w3c/webauthn] bd6264: Clarify that extensions are optional
[w3c/webauthn] bfe17b: Fix spec shortname to prep for FPWD
[w3c/webauthn] c112c9: Clarify security model and remove vestiges of "nat...
[w3c/webauthn] c56539: fix formatting
[w3c/webauthn] c5b321: Clarify attestation model vs. attestation type
[w3c/webauthn] c830a9: Script updating gh-pages. [ci skip]
[w3c/webauthn] cd4e78: Simplify attestation structure by moving details i...
[w3c/webauthn] cefc6f: Replace TPM hyperlinks with working ones
[w3c/webauthn] d14fec: Clarify credential type
[w3c/webauthn] d1fb5f: Simplify Android attestation by removing manipulat...
[w3c/webauthn] da3117: Rebasing to master after merge of PR#77
[w3c/webauthn] ef90dc: Script updating gh-pages. [ci skip]
[w3c/webauthn] f520b5: publishing diff
[w3c/webauthn] fe40b5: Script updating gh-pages. [ci skip]
[webauthn] [5 second review] Fix spec shortname to prep for FPWD
[webauthn] AAGUID extension underspecified
[webauthn] Add Android "N" attestation type.
[webauthn] Add opaque data extension
[webauthn] Add section describing verification of a WebAuthnAssertion
[webauthn] adopt consistent terms for RP server-side and client-side components
[webauthn] assertionChallenge recommendations
[webauthn] Authenticator Selection Extension - Client Processing - Clarification
[webauthn] biblio.json: TPM refs 404
[webauthn] clarify conveyance of attested public key
[webauthn] clarify returned values from authenticatorMakeCredential operation
[webauthn] Clarify when an extension may be ignored by user agent
[webauthn] Clarify which sign. algm.'s RP's must support (Sec. 4.3.2.1.2)
[webauthn] Create an Explainer document
[webauthn] Define AuthenticatorVersion extension
[webauthn] Document wide review
[webauthn] ED512 Support
[webauthn] Editorial polishing of abstract, intro material, terminology, etc.
[webauthn] encodedClientData should be clientDataJSON ?
[webauthn] Issue: Add Android "N" attestation type. marked as type:technical
[webauthn] Issue: Add opaque data extension marked as type:technical
[webauthn] Issue: Add section describing verification of a WebAuthnAssertion marked as type:technical
[webauthn] Issue: Authenticator Selection Extension - Client Processing - Clarification marked as stat:Discuss
[webauthn] Issue: biblio.json: TPM refs 404 marked as type:editorial
[webauthn] Issue: clarify conveyance of attested public key marked as stat:Discuss
[webauthn] Issue: clarify returned values from authenticatorMakeCredential operation marked as spec:web-api-sig-fmt-et-al
[webauthn] Issue: Clarify when an extension may be ignored by user agent marked as type:editorial
[webauthn] Issue: Clarify which sign. algm.'s RP's must support (Sec. 4.3.2.1.2) marked as type:editorial
[webauthn] Issue: Create an Explainer document marked as type:editorial
[webauthn] Issue: Credential.id currently assumed to be RP unique marked as stat:OKtoDo
[webauthn] Issue: Document wide review marked as type:process
[webauthn] Issue: move biblio.js into in-line <pre class=biblio> block marked as spec:web-api-sig-fmt-et-al
[webauthn] Issue: New research suggest using ED512 instead of ED256. marked as type:technical
[webauthn] Issue: normalizing term(s) for authenticator-generated RP-specific public key marked as type:editorial
[webauthn] Issue: Privacy across OS accounts marked as stat:Discuss
[webauthn] Issue: Remove attestation specification from spec marked as type:technical
[webauthn] Issue: Scoped credentials represent a relationship between user and RP marked as spec:web-api
[webauthn] Issue: Section 4.3: add reference to privacy marked as type:editorial
[webauthn] Issue: Section 4: Mention requirement for user to give consent for key to be used marked as type:editorial
[webauthn] Issue: Security: Signature format doesn't cover whole context marked as spec:signature-format
[webauthn] Issue: Underspecified error conditions marked as type:technical
[webauthn] Issue: WebAPI: need to propagate credential de-commissioning through the system marked as duplicate
[webauthn] Key-Attestation: no point compression in the Packed attestation
[webauthn] Lots of FPWD issues
[webauthn] move biblio.js into in-line <pre class=biblio> block
[webauthn] Move optional parameters and extensions into an "options" dictionary
[webauthn] new commits pushed by equalsJeffH
[webauthn] New research suggest using ED512 instead of ED256.
[webauthn] normalizing term(s) for authenticator-generated RP-specific public key
[webauthn] Pre-FWPD proofreading corrections
[webauthn] Privacy across OS accounts
[webauthn] Remove attestation specification from spec
[webauthn] Rename WebAuthnAssertion / getAssertion
[webauthn] Represent binary data as ArrayBuffers instead of base64-encoded DOMStrings
[webauthn] Scoped credentials represent a relationship between user and RP
[webauthn] ScopedCredentialInfo attestation
[webauthn] Section 4.3: add reference to privacy
[webauthn] Section 4: Mention requirement for user to give consent for key to be used
[webauthn] Security: Signature format doesn't cover whole context
[webauthn] Should a FIDOAssertion on an Android platform use AndroidAttestationClientData?
[webauthn] SigFormat: Clarification of assertion delivery in platform specific manner
[webauthn] Simplify attestation structure by moving details into authnr model
- Vijay Bharadwaj via GitHub (Friday, 6 May)
- Rolf Lindemann via GitHub (Friday, 6 May)
- James 'J.C.' Jones via GitHub (Thursday, 5 May)
- =JeffH via GitHub (Tuesday, 3 May)
- Hodges, Jeff (Tuesday, 3 May)
- Alexei Czeskis via GitHub (Tuesday, 3 May)
- Hodges, Jeff (Tuesday, 3 May)
- Vijay Bharadwaj (Tuesday, 3 May)
- =JeffH via GitHub (Tuesday, 3 May)
[webauthn] Spec should not mandate behavior of server
[webauthn] Structure of Credential ID
[webauthn] Terminology consistency
[webauthn] tgbbn
[webauthn] tgbbnccccccevjdnfkufcdnulgkllldgvjrltediuknnjejbj
[webauthn] The FIDO Metadata Service needs a non-FIDO analogous mechanism
[webauthn] Update reference to Secure-Contexts (from Powerful-Features)
[webauthn] Verification of publicKey missing in section 3.5 Verifying an Attestation Statement
[webauthn] web-api: is further language needed describing AppID (aka rpId) usage ?
[webauthn] WebAPI: add userID as input parameter in authenticatorGetAssertion
[webauthn] WebAPI: Authentication failure due to inactivity
[webauthn] WebAPI: need to propagate credential de-commissioning through the system
Blog post for FPWD announcement
Blog post for FWPD announcement
Call for Consensus: Publish FPWD
Call for Exclusions: Web Authentication: A Web API for accessing scoped credentials
Cancel call today?
Closed: [webauthn] Abstraction layer for attestations
Closed: [webauthn] authenticatorMakeCredential and authenticatorGetAssertion parameters not uniformly specified
Closed: [webauthn] biblio.json: TPM refs 404
Closed: [webauthn] Clarify that extensions are optional and may not be supported
Closed: [webauthn] Credential.id currently assumed to be RP unique
Closed: [webauthn] Define AuthenticatorVersion extension
Closed: [webauthn] ED512 Support
Closed: [webauthn] encodedClientData should be clientDataJSON ?
Closed: [webauthn] key-attestation: lacks explanation of "attestation"
Closed: [webauthn] Key-Attestation: no point compression in the Packed attestation
Closed: [webauthn] key-attestation: S 2.3 "attestation types" -- move into S 2.1 "attestation models" ?
Closed: [webauthn] Rename WebAuthnAssertion / getAssertion
Closed: [webauthn] Should a FIDOAssertion on an Android platform use AndroidAttestationClientData?
Closed: [webauthn] SigFormat: Clarification of assertion delivery in platform specific manner
Closed: [webauthn] SigFormat: clarification of FIDOWebAPI scope
Closed: [webauthn] SigFormat: Question on FIDO 2.0 layers
Closed: [webauthn] Structure of Credential ID
Closed: [webauthn] TAG review comments on eTLD+1
Closed: [webauthn] TAG review feedback: Should we be using array types instead of base64-encoded DOMStrings?
Closed: [webauthn] tgbbn
Closed: [webauthn] tgbbnccccccevjdnfkufcdnulgkllldgvjrltediuknnjejbj
Closed: [webauthn] Verification of publicKey missing in section 3.5 Verifying an Attestation Statement
Closed: [webauthn] WebAPI: add userID as input parameter in authenticatorGetAssertion
Closed: [webauthn] WebAPI: Authentication failure due to inactivity
Closed: [webauthn] WebAPI: Clarification Credential Type
Closed: [webauthn] WebAPI: Credential Identifier scope
Closed: [webauthn] WebAPI: need to propagate credential de-commissioning through the system
Closed: [webauthn] WebAPI: Registration (embedded authenticator mode) use cases assumptions
Diff of vijaybh/lots-of-fpwd-issues branch from master branch
Draft blog post for FWPD announcement - PLEASE REVIEW
Draft Webauthn registration figure -- review please
Extensions (was RE: [minutes] 13 May F2F)
- Anthony Nadalin (Tuesday, 24 May)
- Hodges, Jeff (Tuesday, 24 May)
- Vijay Bharadwaj (Tuesday, 24 May)
- Mike Jones (Monday, 23 May)
- Hodges, Jeff (Monday, 23 May)
- Adam Powers (Monday, 23 May)
- J.C. Jones (Monday, 23 May)
- Vijay Bharadwaj (Saturday, 21 May)
extensions, continued.. (was: 05/24/2016 WebAuthn Summary
FPWD & blog post staged for publication
Fwd: TPAC 2016 Registration Now Open -- Webauthn set to meet Tuesday, Sept. 20
github notifications setup for w3c/webauthn?
How to create an IANA registry and populate it from non-IETF specs
if you read mail via gmail, please check..
Issues #1 and #61
Lots of editorial fixes and issues coming
Notes from WebAuthn Review
of shortnames and the /TR namespace
PR#109: Editorial polishing of abstract, intro material, terminology, etc.
Proposed F2F agenda
reference for SECURE-CONTEXTS (nee POWERFUL-FEATURES) ?
regarding "opaque pass-thru extensions"
Register for next F2F after May 13th Berlin: Sept 20th at TPAC Lisbon
Simplifying Android attestation
Test Plan Development
Thanks very much to Tony and Microsoft...
Three possibilities for discussion
updating milestone labels
use cases
user authn public key duplicated in ScopedCredentialInfo and AttestationStatement (rawData) ?
Web Authentication F2F meeting: Tomorrow, May 13, Berlin
Web Authentication Face to Face meeting in Berlin
Webauthn Tests
wrt client filtering of extensions (was: 05/24/2016 WebAuthn Summary
Last message date: Tuesday, 31 May 2016 22:24:19 UTC