Chairs: Christopher Inacio, Jon Geater
Area Director: Deb Cooley
Notetakers: A.J. Stein
Orie Steele: I think Justin pointed this out in COSE, if you are
signing a hash then you better check the hash of the artifact. It's
not opaque.
Brendan Moran: It seems that the URI being in the unprotected header
is odd. What in the threat model declare this is ok or motivate this
decision?
Justin Richer: I should clarify a point germane to this discussion
in COSE re a detached hash. Typically Merkle trees are not. The
problem with that approach is that it is sitting there and doesn't
map back to whatever it is pointing to, that's the risk. This is a
data structure implementation/note concern. Not so familiar with
this draft, don't know if it belongs in
draft-ietf-scitt-architecture or another draft, but should be in
security considerations of relevant I-D.
Steve Lasker: location is a hint (it used to be call that)
Orie Steele: you still need to match hash in signature, agreed with
previous questions and impressions from others.
Roy Williams
Henk Birkholz: architecture is not done, profiling to be done and
not germane into the specifics of this document (but others).
Henk Birkholz: I want to address the PRs in the Hackathon primarily
from Hannes Tschofenig. All but four were approved and contentious.
Noteworthy open items:
Consolidating function names and role names
Please raise issues, or they are done or will soon to be
resolved
AJ: we need something for matching identifiers to invariant
definitions of an artifact that is pluggable in the API and that is
outside of the scope of this WG.
Jon Geater: constrain to issuer and subject for now (not other
things for now).