[{"author": "Guy Fedorkow", "text": "<p>hi Nancy, sorry I couldn't be there!</p>", "time": "2023-07-26T16:30:38Z"}, {"author": "Kathleen Moriarty", "text": "<p>Good morning!</p>", "time": "2023-07-26T16:32:06Z"}, {"author": "Nancy Cam-Winget", "text": "<p>Hi Guy, welcome!</p>", "time": "2023-07-26T16:34:09Z"}, {"author": "Dave Thaler", "text": "<p>We pushed the ta-store doc to another WG and we just reference it.  Sounds good to me for this one too.</p>", "time": "2023-07-26T17:09:39Z"}, {"author": "Mike Ounsworth", "text": "<p>I just want to point out that Carl is not online for this meeting :(</p>", "time": "2023-07-26T17:12:21Z"}, {"author": "Carl Wallace", "text": "<p>I am listening, but am zulip and audio stream this time. sorry about that.</p>", "time": "2023-07-26T17:15:25Z"}, {"author": "Thomas Hardjono", "text": "<p>Is this the point to talk about device profiles?</p>", "time": "2023-07-26T17:26:49Z"}, {"author": "Thomas Hardjono", "text": "<p>So that a verifier knows that a HW vendor cannot make claims about Apps</p>", "time": "2023-07-26T17:27:23Z"}, {"author": "Nancy Cam-Winget", "text": "<p>I can see the device profile being a use case from the claim sets that this draft is about</p>", "time": "2023-07-26T17:30:14Z"}, {"author": "Carl Wallace", "text": "<p>trust anchor constraints are relevant to this topic as well</p>", "time": "2023-07-26T17:31:25Z"}, {"author": "Guy Fedorkow", "text": "<p>Laurence is right -- Identity and Attestation keys are quite distinct in some of our worlds</p>", "time": "2023-07-26T17:31:45Z"}, {"author": "Thomas Hardjono", "text": "<p>The profile file carries the information needed for the logic inside the Verifier to help the Verifier decide (if something is wrong).</p>", "time": "2023-07-26T17:31:51Z"}, {"author": "Thomas Hardjono", "text": "<p>Else, the Verifiefr will need to have a whole table/logic needed to separate the 4 layers (and sub components)</p>", "time": "2023-07-26T17:32:27Z"}, {"author": "Thomas Hardjono", "text": "<p>When talking about \"Identity\", could we be more precise on the usage. eg. qualify it.</p>", "time": "2023-07-26T17:34:14Z"}, {"author": "Thomas Hardjono", "text": "<p>e.g. Endorser identity; Endroser signer identity; etc. etc.</p>", "time": "2023-07-26T17:34:42Z"}, {"author": "Mike Ounsworth", "text": "<p>tls-attestation:<br>\nI have the same question as Ned: is the attestation engine providing a key for signing (authenticating) the TLS handshake?<br>\n--&gt; It seems from the next slide that the answer is yes.</p>", "time": "2023-07-26T17:48:56Z"}, {"author": "Mike Ounsworth", "text": "<p>How do you put evidence into a CMW into a cert? Isn't evidence dynamic, and isn't certs very much non-dynamic?</p>", "time": "2023-07-26T17:51:34Z"}, {"author": "Nancy Cam-Winget", "text": "<p>@Mike are you remote?  You can get in the queue to ask your question directly....if you can't let us know and we can relay your question</p>", "time": "2023-07-26T17:53:03Z"}, {"author": "Mike Ounsworth", "text": "<p><span class=\"user-mention\" data-user-id=\"416\">@Nancy Cam-Winget</span> sure</p>", "time": "2023-07-26T17:53:20Z"}, {"author": "Michael StJohns", "text": "<p>I think this only makes sense for the ephemeral keys of the exchange.   The identity key in the x509 cert would be attested when the cert was issued.</p>", "time": "2023-07-26T17:58:26Z"}, {"author": "Mike Ounsworth", "text": "<p><span class=\"user-mention silent\" data-user-id=\"435\">Michael StJohns</span> <a href=\"#narrow/stream/45-rats/topic/ietf-117/near/82816\">said</a>:</p>\n<blockquote>\n<p>I think this only makes sense for the ephemeral keys of the exchange.   The identity key in the x509 cert would be attested when the cert was issued.</p>\n</blockquote>\n<p>My understanding is that, for example, a network gateway would only allow devices to complete a TLS connection if the devices has an acceptable (platform?) attestation.<br>\nI think that makes the attestation (potentially) orthogonal to the identity.</p>", "time": "2023-07-26T18:02:07Z"}]