2024-01-25 TRTF Meeting Notes

2024-01-25 TRTF Meeting Notes

Meeting Date

  • Jan 5, 2023 The ToIP Trust Registry Task Force (TRTF) meets weekly twice every Thursday at the following times (to cover global time zones - see the Calendar of ToIP Meetings for full meeting info including Zoom links):

    • NA/EU 07:00-8:00 PT / 15:00-16:00 UTC 

    • APAC 18:00-19:00 PT / 02:00-03:00 UTC

Zoom Meeting Link / Recording

Attendees

NA/EU Meeting

  • @Darrell O'Donnell co-lead

  • @Antti Kettunen co-lead

  • @Andor co-lead

  • @Drummond Reed 

APAC Meeting

  • @Darrell O'Donnell co-lead

  • @Andor co-lead

  • @Drummond Reed 

Agenda Items and Notes (including all relevant links)

Time

Agenda Item

Lead

Notes

5 min

  • Start recording

  • Welcome & antitrust notice

  • Introduction of new members

  • Agenda review

Chairs

  • Antitrust Policy Notice: Attendees are reminded to adhere to the meeting agenda and not participate in activities prohibited under antitrust and competition laws. Only members of ToIP who have signed the necessary agreements are permitted to participate in this activity beyond an observer role.

  • New Members:

1 min

Reminder - TSWG2 Mailing List

Chairs

Reminder that the Technology Stack Working Group has a new mailing list. You need to join this as it involves the new charter that TSWG is operating under. You can do that here:

5 min

Review of previous action items

Chairs

 

5 min

Service Profiles/Service Discovery

Chairs

Discussion of Service Discovery Task Force (SDTF)

1 min

Spec Review

@Darrell O'Donnell 

https://trustoverip.github.io/tswg-trust-registry-protocol/#terms-definitions 

10 mins

Terminology Broohaha

@Darrell O'Donnell 

When we query a trust registry to answer "does this registered entity have ______ to do the thing?"
Is it:

  • authorization; or

  • permission

Do I check the Trust Registry for "authorizations" or "permissions"? Given the NIST definitions

Discuss...

 

NIST (NOTE: NIST has MANY definitions for authorization. Best is below):

  • permission: Authorization to perform some action on a system.

  • authorization: Access privileges granted to an entity; conveys an “official” sanction to perform a cryptographic function or other sensitive activity.

    • TelegramSam  - leave in "cryptographic function".

    • Andor: does it add clarity (i.e. cryptographic function).

    • debate is about cryptographic vice gov+tech

      • implicit (leave out "cryptographic function" vs. explicit ("action uses cryptography").

    • possible - defer to NIST (leave as is) and see if that breaks thinking/flow.

      • RAISE issue - do we need something else (another term; revised definition).

 

DECISION: NIST "authorization" will be used as is. 

 

10 mins

Special topic #3

 

 

5 mins

  • Review decisions/action items

  • Planning for next meeting 

Chairs

 

Screenshots/Diagrams (numbered for reference in notes above)

#1

 

Decisions

  • Sample Decision Item

Action Items

Sample Action Item