Markdown Version | Recording 1 | Recording 2 | Recording 3

Session Date/Time: 07 Nov 2023 14:30

# oauth

## Summary

This meeting focused on two main topics: a discussion on the OAuth working group's charter in light of recent document adoptions and a presentation on the latest changes to the Selective Disclosure for JSON Web Tokens (SD-JWT) specification. The charter discussion centered on defining the scope of the working group and its role in relation to other IETF efforts like JOSE and COSE. The SD-JWT presentation highlighted updates to the specification, including a new hash value for integrity protection.

## Key Discussion Points

*   **OAuth Charter Scope:**
    *   Should the charter be changed to fit documents already adopted, or should the group determine its core remit first?
    *   What constitutes an "extension" to OAuth, and how far should the scope extend?
    *   Is the working group's identity clear, given that it's no longer building OAuth itself?
    *   The group is doing a lot of good work, so is a course correction needed?
    *   Should the charter include what is being discussed (i.e. jot)
    *   Is it right that Jots were developed in oauth instead of JOSE
    *   JWTs were developed within this group as a way to standardize the Access Token Format
    *   Concern about the charter being "too welcoming" such that vaguely related topics are brought to the working group.

*   **SD-JWT Updates:**
    *   Introduction of `_st_hash` for presentation integrity, hashing the SD-JWT and disclosures.
    *   Clarifications to the specification, including stricter verification requirements and reserved claim names.
    *   Discussion of potential attack scenarios that motivated the addition of the new hash.
    *   Need for agility of hash algorithm.

*   **Key Binding in SD-JWT:**
    *   Whether the key binding mechanism is orthogonal to selective disclosures and should be separated into another specification.
    *   Whether formal modeling of the key binding aspect is worthwhile.

*   **Future of SD-JWT:**
    *   A profile on how to use SD-JWT within OAuth would be useful (for access tokens).

## Decisions and Action Items

*   **Charter Revision:** The OAuth working group will work on revising the charter to better reflect the work it has delivered and is currently doing, taking into account the points raised in the discussion.

## Next Steps

*   Continue discussion on the OAuth charter on the mailing list.
*   Address remaining issues on the SD-JWT issue tracker, including cryptography clarifications.
*   Consider a working group last call for SD-JWT once outstanding issues are resolved.

Session Date/Time: 08 Nov 2023 13:30

oauth

Summary

The OAuth working group held a meeting covering several topics, including resource server metadata, SD-JWT based verifiable credentials, attestation based client authentication, browser based apps, cross device flows, and OAuth status lists. Discussions focused on clarifying specifications, addressing open issues, and exploring future directions for each topic.

Key Discussion Points

Decisions and Action Items

Next Steps


Session Date/Time: 10 Nov 2023 12:00

oauth

Summary

This OAuth working group meeting covered several key topics, including transaction tokens for microservices, identity chaining across trust domains, client attestation in dynamic client registration, OAuth for first-party applications, and global token revocation. Discussions focused on refining specifications, addressing security concerns, and exploring potential overlaps and synergies between different drafts. Several drafts were considered for working group adoption.

Key Discussion Points

Decisions and Action Items

Next Steps