OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Minutes - SS TC Concall - Jan 29, 2008


========================================================================
====
sec svs concall  Tue Jan 29 09:09:56 PST 2008
------------------------------------------------------------------------
----

AI summary:

AI: hal to brief anil on secty duty particulars

AI: JeffH to make errata on orig spec wrt correct ref in place of 
draft-mealling-uuid-urn-05.txt

AI: scott to update his doc


------------------------------------------------------

attendance duly taken, have quorum

Voting Members

Hal Lockhart  	BEA Systems, Inc.
Rob Philpott 	EMC Corporation
Charles Knouse 	Hewlett-Packard
Scott Cantor 	Internet2
Bob Morgan 		Internet2
Eric Tiffany 	Liberty Alliance Project
Tom Scavo 		National Center for Supercomputing Applica...
Peter Davis 	Neustar, Inc.
Jeff Hodges 	Neustar, Inc.
Frederick Hirsch 	Nokia Corporation
Abbie Barbir 	Nortel
Paul Madsen 	NTT Corporation
Ari Kermaier 	Oracle Corporation
Brian Campbell 	Ping Identity Corporation
Anil Saldhana 	Red Hat
Eve Maler 		Sun Microsystems
Emily Xu 		Sun Microsystems
Kent Spaulding 	Tripod Technology Group, Inc.
David Staggs 	Veterans Health Administration

15-Jan-2008 minutes approved by unanimous consent

admin: steve anderson stepping down

  anil has volunteered to take on membership secty
  any objections challenges? nope.


Fredrick moves to make formal thankyou to SteveA for his svc as secty to
the 
SSTC, and to the SSTC in general (ammedment by Hal), Eve & Jeff 2nd.

chairs take action to notify steve once meeting ajourned.

AI: hal to brief anil on secty duty particulars

BrianC thanks Anil for quickly jumping in and helping out the SSTC




 > 2. Administrative
 >
 > 2.1 Steve Anderson is stepping down
 >
http://lists.oasis-open.org/archives/security-services/200801/msg00026.h
tml
 > There is open opportunity to assume the duties as membership
secretary
 > *Anil Saldhana (Red Hat) has Volunteered*
 >
 > 2.2 SAML XML.org Focus Area
 >
 > 2.2a Blogs
 >
http://lists.oasis-open.org/archives/security-services/200801/msg00024.h
tml

just pointing it out and encouraging folks to update as they can and/or
get info...

 >
 > 2.2b Wiki vs. Wiki
 >
http://lists.oasis-open.org/archives/security-services/200801/msg00031.h
tml


looking at carolG's note describing intent, BrianC believes it makes it
clear 
as to what goes where btwn the oasis wiki and the xml.org site. BrianC
(BC) has 
made some cross links.

are we in agreement wrt general usage of the two sites? does Carol need
to clarify?
<silence> i.e. agreement

ScottC (SC): someone migrate content from the "overburdened" TC homepage
to the 
wikis ?

BrianC (BC): that stuff would boto xml.org wiki...

SC: don't wait for approval, just do it....

BC: agree.


 > 3. Document Status


 >
 > 3.1 Public Review of Five specifications ends on February 9th
 >
http://lists.oasis-open.org/archives/security-services/200712/msg00040.h
tml



 > 3.3 Subject-based Profiles for SAML V1.1 Assertions
 >
http://lists.oasis-open.org/archives/security-services/200801/msg00003.h
tml
 > and definition of "strongly matches"
 >
http://lists.oasis-open.org/archives/security-services/200801/msg00025.h
tml

BC asking TomS to clarify need for guidance TomS has written up

tomS (TS): for migrating non-stdz'd SAMLv1.X profile to SAMLv2, so major
goal 
of the profile is the subject element, Subject is more relaxedly spec'd
in 
SAMLv1.x than in SAMLv2, so profile is to restrict SAMLv1.x usage such
that 
migration to SAMLv2 is eased.

BC: there's discussion on the list...

TS: want to wait and discuss on list for now, but if there's no disc,
will go 
forward

BC: so folks who have interest look at disc on the list, and get yer
0.02 in 
before TS revises doc...


 > 3.4 Tech Overview
 >
http://www.oasis-open.org/committees/download.php/20645/sstc-saml-tech-o
verv
 > iew-2%200-draft-10.pdf [linked from SSTC home page]
 >
http://www.oasis-open.org/committees/download.php/25411/sstc-saml-tech-o
verv
 > iew-2.0-draft-14.pdf [most recent?]
 > There was a CD-01 around April/May of last year


BC: various versions of SAML Tech Overview lying about... so wrt the
current 
-14 rev, do we want to move this doc to CD ?   wrt an informational doc
like 
this, public review isn't nec or perhaps appropriate,

Hal: we shud vote to CD, don't really feel one way or another wrt public

review, what do editors think?  is Paul Madsen the present editor?...

TS: yes Paul has done a fair amount of work on it....

BC: agrees with Hal,  So folks should read the -14 over next two weeks,
bring 
up issues on list if any, and we'll intend to vote to CD next mtg in two
weeks.



 > 4 Other business
 >
 > 4.1 The HL7 Clinical Context Object Workgroup (CCOW)
 > The HL7 Clinical Context Object Workgroup (CCOW) maintains an
 > international standard describing the implementation of the CCOW
 > infrastructure.  David Staggs is co-chair of the CCOW TC and they
 > have proposed a new project that would:
 >
 >   1. Provide a way to obtain SAML assertions about the user in
context,
 > &
 >   2. Establish the user into context using a SAML assertion.
 >
 > The SSTC might want to provide insights to the CCOW TC.

David Staggs (DS):

HL7 is a consortium, CCOW is a visual info system, useful in clinical
apps, 
helps dr not to mix up test results.... how might integrate this into
SAML.... 
Am in process of kicking off new proj in TC, that would be how to use
SAML "in 
the 'context'", and how to use this to ident the user



ASTM E-2995-07 -- Skaggs uses saml, "privilege management guidelines"


some discussion wrt adding a page on wiki for external-to-SSTC SAML
profiles




BC: any other biz?

none.



 > 5 Action Items (Report created 28 January 2008 01:22pm EST)
 >
 > #0321: Check with Mark Wahl on being included in Acknowledgments in
the SAML
 > V2.0 X.500/LDAP Attribute Profile
 > Owner: Hal Lockhart
 > Status: Open
 > Assigned: 2008-01-16
 > Due: 2008-01-29
 >
 > #0320: Determine correct reference in place of:
 > http://www.ietf.org/internet-drafts/draft-mealling-uuid-urn-05.txt in
SAML 2
 > Attribute Profiles.
 > Owner: Jeff Hodges
 > Status: Open
 > Assigned: 2008-01-16
 > Due: 2008-01-29

AI: JeffH to make errata on orig spec wrt correct ref in place of 
draft-mealling-uuid-urn-05.txt

AI: scott to update his doc


 > #0316: Take a look at the red line versions of erratum docs
 > Owner: Abbie Barbir
 > Status: Open
 > Assigned: 2007-12-18
 > Due: ---

done. closed.

 > #0311: Propose specific document changes required for PE-65
 > Owner: Scott Cantor
 > Status: Open
 > Assigned: 2007-10-23
 > Due: 2007-12-01

still open.


Minutes taken by Jeff Hodges
========================================================================
====


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]