Wiki

Clone wiki

connect / Connect_Meeting_Notes_2018-09-13

OpenID AB/Connect Call Note (2018-09-13)

Date: 2018-09-13 14:00 UTC

Location: GoToMeeting https://global.gotomeeting.com/join/181372694

The meeting was called to order at 14:07 UTC.

1.   Roll Call

  • Present: John, Nat, Bjorn, Brian, Roland, Torsten, Rich
  • Regret: Mike, George

2.   Commonalities and Differences Report on Fed Specs (Andreas/Roland)

Started to write the text, but far from being finished. It should be ready for review in the beginning of October.

Nordu Net meeting next week. TecEx before the IIW week.

3.   Issues

3.1.   #1029 - authentication_failed error response (Torsten)

https://bitbucket.org/openid/connect/issues/1029/authentication_failed-error-response

WG members are requested to review the draft and vote YES if you think this should be adopted as a WG work item.

3.3.   #1046 - Core 3.1.2.1. - id_token_hint (Torsten)

George proposed the text, which is contained in the ticket comment. If it looks good, please upvote.

3.4.   Federation Issues

It was agreed that they should be put on hold until Andreas and Roland come up with the comparison document.

4.   Oct. 9 Certification Meeting (Roland)

Present: Mike, Roland, Hans, Filip,

Presentation was made on Open Banking test tool. It was found out that the tests are for Open Banking that includes further restriction over FAPI and not FAPI itself.

There also was a re-certification discussion. Banks are required to re-certify every 6 months, but what would happen if the test tool had a bug fix in the meantime? How would it affect?

New test features like refresh token and the third party initiated requests were also being discussed.

No clear direction on whether to keep two versions, how they should be used in combination, etc. emerged.

6.   Token Binding (John)

The code was removed from Canary release already. Chrome cannot reach AAL3 because of it. People need to use other browsers, e.g., Edge. It undermines the work on WebAuthen.

7.   3. AOB

7.1.   Topics for the next call:

  1. Safari IPT2 and implicit flow
  2. Native SSO spec.

The call closed at 15:00 UTC

Updated