OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Agenda for SSTC Con-Call, March 2, 2004






Agenda for SSTC Con-Call, March 2, 2004
---------------------------------------

1. Change of dial-in numbers:

The dial-in number for all teleconferences is +1 865 673 6950. The access code is 389-1508#. 
(Please note that these numbers have changed as of March 1!) 
Commands are *6 (mute), *7 (unmute), and ** (menu).

2. Accept minutes from previous conference call

http://lists.oasis-open.org/archives/security-services/200402/msg00146.html


3. March 30 F2F Planning

- Next F2F Mar 30 - April 1 
(Mike McIntosh to confirm hotel details etc.)

- March 16 absolute cutoff date of text for proposed specification 
text (no "new" text or documents after that date)

4. Work Item Review

The following work items do
not have solution proposals at this time and are at risk:

W-5b: SOAP Client Profile (Mike McIntosh, Tony Nadalin)
W-9: XML Encryption (Hal Lockhart)
W-15: Delegation and Intermediaries (bob Morgan, Scott Cantor, Ron Monzillo)
W-25: Kerberos Support (John Hughes, Tim Alsop)
W-21a: Document describing instances of "baselines attribute namespaces" (John Hughes, Prateek Mishra)

5. Recent document postings:

sstc-saml-schema-metadata-2.0.xsd

http://www.oasis-open.org/apps/org/workgroup/security/download.php/5725/sstc-saml-schema-metadata-2.0.xsd

bindings document

http://www.oasis-open.org/apps/org/workgroup/security/download.php/5727/sstc-saml-bindings-2.0-draft-06-diff.pdf

profiles document

http://www.oasis-open.org/apps/org/workgroup/security/download.php/5511/sstc-saml-profiles-2.0-draft-01.pdf

core draft

http://www.oasis-open.org/apps/org/workgroup/security/download.php/5600/sstc-saml-core-2.0-draft-06-diff.pdf


6. Close on Assertion-level subject discussion (vote if needed)

Eve's summary of the issue (and many other valuable e-mails on this thread)

http://lists.oasis-open.org/archives/security-services/200403/msg00005.html

7. Close on Ron Monzillo's proposed update of SubjectConfirmation and HoK

http://lists.oasis-open.org/archives/security-services/200402/msg00090.html

8. Close on Scott AuthNRequest/Response proposal (vote if needed)

http://lists.oasis-open.org/archives/security-services/200402/msg00102.html


9. Open action item review

#0129: Add W-28b material to core specification 
Owner: Eve Maler 
Status: Open 
Assigned: 01 Mar 2004 
Due: --- 
Comments:
 

--------------------------------------------------------------------------------
 
#0128: Liason with XRI Data Interchange 
Owner: Hal Lockhart 
Status: Open 
Assigned: 01 Mar 2004 
Due: --- 
Comments:
Prateek Mishra 2004-03-02 04:33 GMT
Hal will generate a posting on possible need to liaison. 

--------------------------------------------------------------------------------
 
#0127: Remove short-lived assertion restriction from SSO Profiles 
Owner: Scott Cantor 
Status: Open 
Assigned: 16 Feb 2004 
Due: --- 
Comments:
Prateek Mishra 2004-02-16 14:57 GMT
I can give a hand with this (prateek) 

--------------------------------------------------------------------------------
 
#0126: Modify Trust Model Submission and re-cast into SAML 
Owner: Jeff Hodges 
Status: Open 
Assigned: 16 Feb 2004 
Due: --- 
Comments:
 

--------------------------------------------------------------------------------
 
#0125: Propose language to explain that AuthNResponse may contain attribute statements 
Owner: Prateek Mishra 
Status: Open 
Assigned: 16 Feb 2004 
Due: --- 
Comments:
Prateek Mishra 2004-02-16 14:46 GMT
Easy to do but needs proposal on validity of assertion life-times as well. 

--------------------------------------------------------------------------------
 
#0124: Update meta-data specification with identifiers for SAML entities 
Owner: Jahan Moreh 
Status: Open 
Assigned: 13 Feb 2004 
Due: --- 
Comments:
 

--------------------------------------------------------------------------------
 
#0123: Obtain MIME type registration for HTTP lookup of SAML 
Owner: Jeff Hodges 
Status: Open 
Assigned: 13 Feb 2004 
Due: --- 
Comments:
 

--------------------------------------------------------------------------------
 
#0122: Arrangements for Austin F2F 
Owner: Michael McIntosh 
Status: Open 
Assigned: 13 Feb 2004 
Due: --- 
Comments:
 

--------------------------------------------------------------------------------
 
#0119: Extension of AuthNRequest - AuthNResponse protocol 
Owner: Scott Cantor 
Status: Open 
Assigned: 11 Feb 2004 
Due: --- 
Comments:
Prateek Mishra 2004-02-11 22:35 GMT
Scott: Proposes to change AuthnRequest to handle some of this.
Ron: would like to help

PROPOSAL: get basic integration of AuthnRequest/Response and then look at the various use cases to see how they can be integrated in. (Scott) 

--------------------------------------------------------------------------------
 
#0118: Solution proposal for encryption use-cases 
Owner: Hal Lockhart 
Status: Open 
Assigned: 11 Feb 2004 
Due: --- 
Comments:
Prateek Mishra 2004-02-11 22:33 GMT



ACTION: Hal to produce text to describe 3 use cases for SSTC to consider. 

--------------------------------------------------------------------------------
 
#0117: Describe use-cases for attribute-based SSO in relationship to ID-FF 1.2 NameIdPolicy 
Owner: Prateek Mishra 
Status: Open 
Assigned: 11 Feb 2004 
Due: --- 
Comments:
 

--------------------------------------------------------------------------------
 
#0116: Investigate removal of NotBefore/NotOnOrAfter from BaseNameIdentifier 
Owner: Scott Cantor 
Status: Open 
Assigned: 11 Feb 2004 
Due: --- 
Comments:
Prateek Mishra 2004-02-11 22:17 GMT

ISSUE: Consider removing NotBefore/NotOnorAfter based on sessions 
discussion. Sync up validity period (Scott)

ACTION: Scott to think about this more 

--------------------------------------------------------------------------------
 
#0115: Update metadata drafts with ID-FF 1.2 materials 
Owner: Jahan Moreh 
Status: Open 
Assigned: 19 Jan 2004 
Due: --- 
Comments:
Prateek Mishra 2004-01-20 03:27 GMT
Jahan:
ACTION: Update the metadata draft if necessary according to the
latest ID-FF V1.2 materials. (Scott will also review for this
purpose.)



http://lists.oasis-open.org/archives/security-services/200312/msg00064.html 

--------------------------------------------------------------------------------
 
#0114: Propose language to address attribute-based federation 
Owner: Prateek Mishra 
Status: Open 
Assigned: 19 Jan 2004 
Due: --- 
Comments:
Prateek Mishra 2004-01-20 03:22 GMT


http://lists.oasis-open.org/archives/security-services/200312/msg00064.html 

--------------------------------------------------------------------------------
 
#0112: Update (W-7) discovery protocol solution proposal 
Owner: Scott Cantor 
Status: Open 
Assigned: 19 Jan 2004 
Due: --- 
Comments:
Prateek Mishra 2004-01-20 03:17 GMT
ACTION: (SC) Update based on replacement of hash of succint id by literal provider id. 

--------------------------------------------------------------------------------
 
#0110: Feedback from LECP profile interop 
Owner: Frederick Hirsch 
Status: Open 
Assigned: 19 Jan 2004 
Due: --- 
Comments:
Prateek Mishra 2004-01-20 03:14 GMT
ACTION: (FH) Check with Liberty Interop for any problems that may have arisen with 

actual use of LECP profile. 

--------------------------------------------------------------------------------
 
#0109: Security concerns with LECP profile 
Owner: Anthony Nadalin 
Status: Open 
Assigned: 19 Jan 2004 
Due: --- 
Comments:
Prateek Mishra 2004-01-20 03:12 GMT
ACTION: (FH) update to respond to Tony's security questions but we need to ask Tony for the 

specific problem he had in mind. 

--------------------------------------------------------------------------------
 
#0105: Respond to IBM Analysis Paper 
Owner:  
Status: Open 
Assigned: 19 Jan 2004 
Due: --- 
Comments:
Prateek Mishra 2004-01-19 23:09 GMT
- [ACTION] Scott & Tony to make recommendations based on IBM security
analysis paper 

--------------------------------------------------------------------------------
 
#0086: Non-HTTP use-cases related to the LECP profile 
Owner: Bob Morgan 
Status: Open 
Assigned: 23 Nov 2003 
Due: --- 
Comments:
Prateek Mishra 2003-11-24 03:27 GMT
ACTION: Bob Morgan - more use cases. More generic use cases, may be not involving HTTP. May involve web dav. 



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]