[{"author": "Orie Steele", "text": "<p>sry I am late</p>", "time": "2023-06-12T15:10:09Z"}, {"author": "Orie Steele", "text": "<p>I've been looking at registration policies related to domain verification recently</p>", "time": "2023-06-12T15:12:57Z"}, {"author": "Orie Steele", "text": "<p><a href=\"https://mailarchive.ietf.org/arch/msg/dance/XALzTQEO-3JnJDbhzyAVlPkXdvU/\">https://mailarchive.ietf.org/arch/msg/dance/XALzTQEO-3JnJDbhzyAVlPkXdvU/</a></p>", "time": "2023-06-12T15:12:59Z"}, {"author": "Orie Steele", "text": "<p>Yep Jon, thats correct, there were discussion about policy dependencies, and portability</p>", "time": "2023-06-12T15:14:19Z"}, {"author": "Orie Steele", "text": "<p>I'm que'ed to summarize some of what was discussed</p>", "time": "2023-06-12T15:15:13Z"}, {"author": "Orie Steele", "text": "<p>basically anytime you process a signed thing, you have to have a reason to trust the key.</p>", "time": "2023-06-12T15:18:08Z"}, {"author": "Orie Steele", "text": "<p>could be you have an allow list, could be a CA thing.... could be \"trusted domains\" with \"key discovery\", etc..</p>", "time": "2023-06-12T15:18:39Z"}, {"author": "Orie Steele", "text": "<p>if you have an <code>iss</code> field... you kinda need to discuss what its expected values are</p>", "time": "2023-06-12T15:19:55Z"}, {"author": "Orie Steele", "text": "<p>+1 Yogesh, the question is, if there are minimal requirements regarding understanding references to transparent statements.</p>", "time": "2023-06-12T15:25:08Z"}, {"author": "Orie Steele", "text": "<p>or not.</p>", "time": "2023-06-12T15:25:10Z"}, {"author": "Raymond Lutz", "text": "<p>Sure it is prudent to think of this now esp. with regard to SW use case, but perhaps only to ensure that they can be accommodated by the scitt mahine.</p>", "time": "2023-06-12T15:32:16Z"}, {"author": "Steve Lasker", "text": "<p>Please review notes, to assure we're capturing the thoughts, accurately</p>", "time": "2023-06-12T15:33:43Z"}, {"author": "Orie Steele", "text": "<p>saudio issues</p>", "time": "2023-06-12T15:35:07Z"}, {"author": "Jon Geater", "text": "<p>KISS @neil - +1</p>", "time": "2023-06-12T15:37:10Z"}, {"author": "Jon Geater", "text": "<p>We need to hear out the concerns and needs of the WG but my leaning is to shed as much complexity as possible for our initial publication</p>", "time": "2023-06-12T15:38:09Z"}, {"author": "Orie Steele", "text": "<p>its is because issuers are compromised, that you consider making transparent the registration policy that was applied when a signed statement is made transparent</p>", "time": "2023-06-12T15:38:44Z"}, {"author": "Orie Steele", "text": "<p>sounds like you are talking about witnessed identifiers?</p>", "time": "2023-06-12T15:43:23Z"}, {"author": "Orie Steele", "text": "<p>full circle... to my domain comment at the start : )</p>", "time": "2023-06-12T15:47:25Z"}, {"author": "Orie Steele", "text": "<p>great comments regarding domain verification, but that seems to be a \"service specific\" policy</p>", "time": "2023-06-12T15:48:38Z"}, {"author": "Orie Steele", "text": "<p>there could be lots of other policies related to assurance levels for the issuers.</p>", "time": "2023-06-12T15:49:09Z"}, {"author": "Orie Steele", "text": "<p>consider a transparency service policy for processing passkey authenticators... some services might only accept certain platform authenticators</p>", "time": "2023-06-12T15:51:56Z"}, {"author": "Raymond Lutz", "text": "<p>Maybe good to defer the policy issue by having a policy verifier -- akin to what RATS did to avoid the issue, yet provide the mechanism</p>", "time": "2023-06-12T15:52:07Z"}, {"author": "Raymond Lutz", "text": "<p>Such a verification would occur as it is submitted.</p>", "time": "2023-06-12T15:54:00Z"}, {"author": "Steve Lasker", "text": "<p>TIme Check</p>", "time": "2023-06-12T15:55:13Z"}, {"author": "Orie Steele", "text": "<p>payload structures are out of scope : /</p>", "time": "2023-06-12T15:56:12Z"}, {"author": "Orie Steele", "text": "<p>content types are the solution to that.</p>", "time": "2023-06-12T15:56:27Z"}, {"author": "Jon Geater", "text": "<p>I'm hearing overwhelming opinion leaning to the simple case</p>", "time": "2023-06-12T15:56:42Z"}]