W3C

XML Security Working Group Teleconference

13 Nov 2012

Agenda

See also: IRC log

Attendees

Present
Frederick_Hirsch, Gerald_Edgar, Scott_Cantor, Bruce_Rich, Pratik_Datta
Regrets
Chair
Frederick_Hirsch
Scribe
fjh

Contents


<trackbot> Date: 13 November 2012

<scribe> ScribeNick: fjh

Administrative: Agenda review, Announcements

RIM/Certicom official response to PAG report: http://lists.w3.org/Archives/Public/public-xmlsec/2012Nov/0005.html

Reminder, no call next week. Next call is scheduled for 27 November 2012.

Minutes Approval

Approve minutes from 23 October 2012

http://lists.w3.org/Archives/Public/public-xmlsec/2012Oct/att-0015/minutes-2012-10-23.html

RESOLUTION: Minutes from 23 October 2012 are approved.

Last Call of XML Signature 1.1 and XML Encryption 1.1

fjh: Last Call ended 8 November
... two comments, one on here() and one on separation of keys for signing and encryption (off-list)

Comment on XML Signature 1.1 and here() function, added this as Last Call comment LC-2721, see https://www.w3.org/2006/02/lc-comments-tracker/42458/WD-xmldsig-core1-20121018/2721 in tracker

fjh: proposed resolution - http://lists.w3.org/Archives/Public/public-xmlsec/2012Nov/0009.html
... proposed resolution is to clarify bullet as noted in link to make clear that not namespaced, and to be treated as if part of the library

scantor: may not be an issue since now XPath filter is used anyway
... ok with the proposed resolution

Proposed RESOLUTION: change bullet referring to here() or clarity, as noted in http://lists.w3.org/Archives/Public/public-xmlsec/2012Nov/0009.html, closing LC-2721

fjh: Ken noted acceptance of this resolution: http://lists.w3.org/Archives/Public/public-xmlsec/2012Nov/0010.html

RESOLUTION: change bullet referring to here() or clarity, as noted in http://lists.w3.org/Archives/Public/public-xmlsec/2012Nov/0009.html, closing LC-2721

<scribe> ACTION: fjh to update XML Signature 1.1 to address LC-2721 [recorded in http://www.w3.org/2012/11/13-xmlsec-minutes.html#action01]

<trackbot> Created ACTION-921 - Update XML Signature 1.1 to address LC-2721 [on Frederick Hirsch - due 2012-11-20].

fjh: this should not require another Last Call, just an editorial clarification
... key separation should be noted in XML Encryption 1.1, a security consideration, again should not require another Last Call

scantor: agree

<scribe> ACTION: fjh to propose additional security consideration for XML Encryption 1.1 key separation and update draft [recorded in http://www.w3.org/2012/11/13-xmlsec-minutes.html#action02]

<trackbot> Created ACTION-922 - Propose additional security consideration for XML Encryption 1.1 key separation and update draft [on Frederick Hirsch - due 2012-11-20].

fjh: Last call completed, will make corresponding editorial changes, need to wait for exclusion period before going to PR in mid-December

Interop Test Report publication

fjh: No objection to Call for Consensus on list to publish "XML Encryption 1.1 Interop Test Report" and "XML Signature 1.1 Interop Test Report" as W3C Notes.

http://lists.w3.org/Archives/Public/public-xmlsec/2012Oct/0016.html

fjh: I have prepared the documents for publication and submitted transition request (approved) and publication request. They should be published today.

XML Security 2.0

fjh: we need to determine our plans with XML Security 2.0

pdatta: we had one person express interest in implementing 2.0

fjh: can you please contact them again?

pdatta: yes

fjh: this could help, also need to see about progressing XPath work independently
... will need to decide in January whether to go to Note or not

Roadmap

<scribe> ACTION: fjh to update Roadmap page to reflect current status [recorded in http://www.w3.org/2012/11/13-xmlsec-minutes.html#action03]

<trackbot> Created ACTION-923 - Update Roadmap page to reflect current status [on Frederick Hirsch - due 2012-11-20].

fjh: next steps for 1.1 - editorial updates to reflect the two comments received during Last Call period, PR transition request 17 December

Action review

ISSUE-236?

<trackbot> ISSUE-236 -- Update all references in all Notes and Recs when publishing final REC? -- open

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/236

fjh: checked with thomas, we can update references at the end of the process

close ACTION-920

<trackbot> ACTION-920 Check with W3C team on ISSUE-236 closed

ACTION-883?

<trackbot> ACTION-883 -- Frederick Hirsch to review C14N 20 test cases document -- due 2012-04-10 -- OPEN

<trackbot> http://www.w3.org/2008/xmlsec/track/actions/883

Issue review

ISSUE-122?

<trackbot> ISSUE-122 -- Explain peformance improvements and rationale, relationship to earlier work, document, benchmarks -- open

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/122

fjh: do not expect work on ISSUE-122 unless we have additional interest in 2.0 implementation

pdatta: correct, do not plan on working on this now unless there is a change

ISSUE-234?

<trackbot> ISSUE-234 -- Reference SP800-56A later in publication process if the latest version is no longer a draft -- open

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/234

ISSUE-236?

<trackbot> ISSUE-236 -- Update all references in all Notes and Recs when publishing final REC? -- open

<trackbot> http://www.w3.org/2008/xmlsec/track/issues/236

fjh: both these issues are for reference updates upon final publication

Other business

fjh: any other business?
... none

Adjourn

Summary of Action Items

[NEW] ACTION: fjh to propose additional security consideration for XML Encryption 1.1 key separation and update draft [recorded in http://www.w3.org/2012/11/13-xmlsec-minutes.html#action02]
[NEW] ACTION: fjh to update Roadmap page to reflect current status [recorded in http://www.w3.org/2012/11/13-xmlsec-minutes.html#action03]
[NEW] ACTION: fjh to update XML Signature 1.1 to address LC-2721 [recorded in http://www.w3.org/2012/11/13-xmlsec-minutes.html#action01]
 
[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.135 (CVS log)
$Date: 2009-03-02 03:52:20 $