GLobal Unique Enterprise (GLUE) Identifiers
Orie Steele: Is it possible for vendors to register their businesses
within another authority? Is it possible for me to do this?
Tim Geoghegan: Do i need to provide an identity to
Chose namespaces
Rohan: We should put ietf in the URN so people know where to find
additional information
urn:glueurn:glueWerner: I'm confused because we already have a namespace for LEIs,
and so if we're going to use a namespace for this let's use the
namespace that already exists. Also, the namespace should provide
information about what the URI is being used.
Beltran Maldant presents
Since Madrid...
#_verified claimsTwo questions for the WG on issue #26
How do we sync changes or additions to OIDC IANA registry?
How could we have a shared IANA registry for both JWT & CWT
claims
Mike Jones: You're right, OIDC is final and not going to change.
Also when we began building the CWT registry, we mentioned that they
should attempt to correlate with the JWT claims. As for a shared
registry, it shouldn't be the job of this draft to register those
claims
Questions around issue #25
If we recommend some values, and we're using CBOR,should we
assign numbers for genders?
Rohan: You're right to call out the semantics here and that's
the best way to approach this. This is insufficiently
complicated as a structure to convey the medical definitions of
biological sex and gender. The only thing that I can think of is
to say that it's up to the issuer to define what it is, and
people will know from specific issuer's (i.e. governments) what
their options/values are.
Mike Jones: The goal of this draft is to re-register specific
claims for JWTS and CWTs, and not just for this but i've said in
the past that we should make them exactly the same between JWTs
and CWTs. I have an open PR that reflects that. Rohan calls out
a good point that some of these are ambiguously open, and
slightly open for interpretation.
Wendy: it's important to give humans the choice
Justin: We shouldn't lean on decisions we've made in
specifications long ago to do something one way. We should be
allowed and able to get better. I do really like adding the text
that this is really only defined in the context of the issuer.
Also, it is very difficult to define the societal differences
between sex, genomic sex, gender, etc through.
Kathleen Moriarty: I think we should handle this the way we did
in the IETF previously, we used to be very clear that the IETF
is just defining something for technical implementation, and if
it gets construed as a legal or political statement, that's out
of scope.
Rohan Mahy discussing changes since IETF 123. THere have been 4
normative changes and 5 non-normative. Nothing major. Open issues but no
open PRs. Discussion around those open issues. Discussing CBOR encoding
restrictions such as forbidding indeterminate lengths, max depth,
preferred encoding.
Mike Jones: Trying to limit the time claims to integer values fly in
the face of how time values have generally be used. Having
fractional seconds is perfectly fine
Carsten Bormann: We get to decide about these encoding restrictions
and we need to be very thoughtful about what we restrict and allow
Rohan: Not hearing many objections around what was proposed moving
forward.
Status updates. No major normative changes needed only section missing
is the decoy digest section. We already have some implementations! There
are 1.5 Rust implementations alongside JS and Python implementations. If
you have your own implementation or would like to write one, please
reach out to Rohan.
Discussion led by Leif Johansson. We're re-writing a draft of this that
was originally written from IETF 124. We'd like reviewer sfor this new
draft.
Adjourn.