Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Minutes

Roll call

Quorum was not? reached.

Approve minutes

Approve minutes of UMA telecon 2016-10-132016-11-03: ?APPROVED by unanimous consent.

Logistics

tbsWe ARE meeting next week, but Friday at 9am PT, not Thursday. That's right after the Legal call.

Work on UMA.next issues

...

Eve is concerned that not being able to fully replace the permissions structure in the token introspection response is a bridge too far in having removed the token profile scaffolding. OAuth has token profiling. There is a use case for just conveying RqP identity claims for achieving fine-grained authorization at the edge (along with a use case for conveying RqP identity claims on top of permissions). UMA permissions on their own only convey "scope-grained" permissions. Can we reuse the UMA profiling capability to allow third parties to replace the permissions structure if they need to? It's already possible to create these (so Gluu could consider doing this).

We have some outstanding questions around the token profiling question and the permissions structure. Eve will send an email outlining these with all the options she can think of and possibly making some proposals so we can decide by next week. (She'll include the Sec Consid point from 7.1.1.)

AI: Eve: Email about token profiling, as above.

Instructions for Core rev 08:

  • Sec 3.4: The RS has the option of using cached RPT status results, so include this in the options (has swimlane implications?). This is also an AS TTL strategy thing (including revocation and disconnected RS scenarios, e.g. IoT scenarios), which we should comment on if we haven't already.
    • Add companion security considerations around TTL for RPTs and permissions, since you need to measure risk and risk appetite based on the RS, the resource itself, and even the nature of the policy conditions etc. Without active revocation infrastructure, the risks are higher.
  • pat_grant_types_supported: Goes away.

Attendees

As of 3 Oct 2016, quorum is 6 of 11. (Domenico, Sal, Nagesh, Andi, Robert, Maciej, Eve, Jeffrey, Mike, Cigdem, Sarah)

...

  1. Domenico
  2. Sal
  3. Nagesh
  4. Robert
  5. Eve
  6. Mike
  7. Cigdem
  8. Sarah

Non-voting participants:

  • tbs

 

  • Francois
  • James
  • Scott F
  • Kathleen
  • Arlene
  • Jin
  • Colin
  • John W

Regrets:

  • Andi