Markdown Version | Session Recording

Session Date/Time: 16 Sep 2025 16:00

WIMSE

Summary

The WIMSE working group held an interim meeting to discuss the two proposed mechanisms for proof of key possession (PoP) in workload-to-workload (W2W) authentication: HTTP Message Signatures (based on RFC 9421) and the Workload Proof Token (Whippet). The discussion focused on their comparative benefits, drawbacks, and whether the draft should standardize both, only one, or pursue a different document structure. No immediate decision was reached, but a clear call was made for authors and interested parties to submit concrete proposals for document restructuring and to develop implementations to validate assumptions, particularly regarding Whippet's applicability beyond HTTP.

Key Discussion Points

Decisions and Action Items

Next Steps