[{"author": "Dick Brooks", "text": "<p>BRB</p>", "time": "2023-01-09T16:04:14Z"}, {"author": "Roy Williams", "text": "<p>Have you started working on a work back schedule yet Hannes?</p>", "time": "2023-01-09T16:04:26Z"}, {"author": "Hannes Tschofenig", "text": "<p><a href=\"https://github.com/ietf-scitt/draft-birkholz-scitt-software-supply-chain-use-cases\">https://github.com/ietf-scitt/draft-birkholz-scitt-software-supply-chain-use-cases</a></p>", "time": "2023-01-09T16:06:55Z"}, {"author": "Dick Brooks", "text": "<p>Back again</p>", "time": "2023-01-09T16:08:44Z"}, {"author": "Zachary Newman", "text": "<p>having audio issues but i think joshua lock is on the call</p>", "time": "2023-01-09T16:11:25Z"}, {"author": "Zachary Newman", "text": "<p>he hopes to add some content to the existing use cases</p>", "time": "2023-01-09T16:11:36Z"}, {"author": "Zachary Newman", "text": "<p>and possibly add a new one</p>", "time": "2023-01-09T16:11:45Z"}, {"author": "Hannes Tschofenig", "text": "<p><a href=\"https://github.com/ietf-scitt/draft-birkholz-scitt-software-supply-chain-use-cases/pull/4\">https://github.com/ietf-scitt/draft-birkholz-scitt-software-supply-chain-use-cases/pull/4</a></p>", "time": "2023-01-09T16:14:01Z"}, {"author": "Henk Birkholz", "text": "<p>No audio issues here</p>", "time": "2023-01-09T16:14:42Z"}, {"author": "Jon Geater", "text": "<p>Yes sorry I was late, had trouble getting into Datatracker</p>", "time": "2023-01-09T16:15:00Z"}, {"author": "Dick Brooks", "text": "<p>The new proposed use case is based on the NIST Consumer Software Label concept and Microsoft's comment filing with NIST: <a href=\"https://www.nist.gov/document/cybersecurity-labeling-position-paper-microsoft-corporation\">https://www.nist.gov/document/cybersecurity-labeling-position-paper-microsoft-corporation</a></p>", "time": "2023-01-09T16:20:32Z"}, {"author": "Dick Brooks", "text": "<p>NIST's consumer labeling recommendation is here: <a href=\"https://doi.org/10.6028/NIST.CSWP.02042022-1\">https://doi.org/10.6028/NIST.CSWP.02042022-1</a></p>", "time": "2023-01-09T16:21:33Z"}, {"author": "Roy Williams", "text": "<p>Labeling is going to be a deep deep topic.</p>", "time": "2023-01-09T16:27:04Z"}, {"author": "Roy Williams", "text": "<p>It will vary based on audience and who the auditors.</p>", "time": "2023-01-09T16:27:25Z"}, {"author": "Jon Geater", "text": "<p>Audio all good for me</p>", "time": "2023-01-09T16:28:46Z"}, {"author": "Dick Brooks", "text": "<p>I agree Roy. Here again it's really just about identifying possible use cases where SCITT may be the answer.</p>", "time": "2023-01-09T16:28:47Z"}, {"author": "Yogesh Deshpande", "text": "<p>Here is the open issue on Terminology: <a href=\"https://github.com/ietf-scitt/draft-birkholz-scitt-architecture/issues/37\">https://github.com/ietf-scitt/draft-birkholz-scitt-architecture/issues/37</a></p>", "time": "2023-01-09T16:37:41Z"}, {"author": "Steve Lasker", "text": "<p>@ray, it's a great example of disclosure information.</p>", "time": "2023-01-09T16:43:36Z"}, {"author": "Hannes Tschofenig", "text": "<p><a href=\"https://www.rfc-editor.org/rfc/rfc4949\">https://www.rfc-editor.org/rfc/rfc4949</a></p>", "time": "2023-01-09T16:46:38Z"}, {"author": "Hannes Tschofenig", "text": "<p>(Terminology)</p>", "time": "2023-01-09T16:46:44Z"}, {"author": "Henk Birkholz", "text": "<p>+1 to Definition first!</p>", "time": "2023-01-09T16:51:23Z"}, {"author": "Dick Brooks", "text": "<p>possible alternatives re: trust bond replacement: trust relationship, verified trusting parties, authoritative entities, Totally willing to withdraw use of \"trust bond\" with a more acceptable option to describe the concept in which \"trust bond\" was first applied.</p>", "time": "2023-01-09T16:52:30Z"}, {"author": "Raymond Lutz", "text": "<p>@steve yes, definitely the election data use case has a component where the data exists and needs to be locked down, and potentially can be pubic later. Except for more robust remote references, I think the current architecture is fine. I am working on that remote refs document now, and we worked on a E2E election security doc in a prior technical meeting, which I will revise based on that meeting and then submit to the WG.</p>", "time": "2023-01-09T16:53:15Z"}, {"author": "Henk Birkholz", "text": "<p>use case description are intended to use colloquial language / layman's terms</p>", "time": "2023-01-09T16:53:43Z"}, {"author": "Hannes Tschofenig", "text": "<p>Here is the document to review: <a href=\"https://github.com/ietf-scitt/draft-birkholz-scitt-software-supply-chain-use-cases/blob/main/draft-birkholz-scitt-software-use-cases.md\">https://github.com/ietf-scitt/draft-birkholz-scitt-software-supply-chain-use-cases/blob/main/draft-birkholz-scitt-software-use-cases.md</a> (move to \"Trust Bond between Package Supplier and the Signing Authority\")</p>", "time": "2023-01-09T16:53:57Z"}, {"author": "Hannes Tschofenig", "text": "<p><a href=\"https://mailarchive.ietf.org/arch/msg/scitt/KzuJj5xCEfSDRGg7UuyPM3gycdg/\">https://mailarchive.ietf.org/arch/msg/scitt/KzuJj5xCEfSDRGg7UuyPM3gycdg/</a></p>", "time": "2023-01-09T16:54:46Z"}, {"author": "Henk Birkholz", "text": "<p>Yes, I checked the case studies</p>", "time": "2023-01-09T16:55:27Z"}, {"author": "Zachary Newman", "text": "<p>Thank you Hannes! We're hoping to fold some of the important aspects of the case studies into the existing use case documents.</p>", "time": "2023-01-09T16:56:59Z"}, {"author": "Dick Brooks", "text": "<p>Proposed replacement: Trust Relationship between Package Supplier and the Signing Authority</p>", "time": "2023-01-09T16:57:01Z"}, {"author": "Dick Brooks", "text": "<p>Henk, what do you think about the proposed language?</p>", "time": "2023-01-09T16:58:09Z"}, {"author": "Zachary Newman", "text": "<p>Exactly :)</p>", "time": "2023-01-09T16:58:13Z"}, {"author": "Charles Hart", "text": "<p>Gotta run gang. +1 on just the 1 call weekly for now. Thanks!</p>", "time": "2023-01-09T17:01:37Z"}, {"author": "Joshua Lock", "text": "<p>gtg, look forward to engaging on the use-cases</p>", "time": "2023-01-09T17:02:20Z"}, {"author": "Steve Lasker", "text": "<p>Thanks folks, welcome to the new year...</p>", "time": "2023-01-09T17:03:52Z"}]