2024-03-13: SP-ICM Minutes

Identity and Consent Management meeting

Attendees (Please add or remove yourself, speakers in bold)

Companies

Attendees

Companies

Attendees

Deutsche Telekom AG

Axel Nennker, Shilpa Padgaonkar

Ericsson

Jan Friman

Gapask

Rajesh Murthy

KDDI

Tetsuya Chiba

KPN

Huub Appelboom

Nokia

Tanja De Groot, Gaurav Agarwal

Orange

Sebastien Dewet 

Simptel

Izahir Clemencia

Singtel

Foo Ming Hui

Spry Fox Networks

Ramesh Shanmugasundaram

T-Mobile PL

Artych Rafał

T-Mobile US

Karabulut, Murat

Telefónica

Jesús Peña García-Oliva, Diego Gonzalez Martínez, Fabio Garcia, Guido García,
Juan Fabio García, David Vallejo, Juan Antonio Hernando

Vodafone

Sachin Kumar

 

Nicholas Venezia

 

Kamel Idir

Camara People @Nick Venezia 

Participants

Agenda

 

  1. Welcome

    1. Please add or remove yourself from the attendees list

  2. Issues and PRs. Priority discussions (most active issues and/or dependencies for release v0.2):

  3. AoB

Welcome

 

PR Add missing offline access/refresh token doc from GSMA discussion

It was mentioned during the call whether the information agreed upon and included in the OIDC profile in #121 is sufficient to cover offline access/refresh token usage.

The GSMA documentation could only refer to the CAMARA OIDC profile in the context of the GSMA requirements for Open Gateway off-net scenarios.

It was proposed by @Axel Nennker to close the PR and during the call there were no objections from the call participants to do so (from Telefónica/@Jesús Peña García-Oliva they said they would ok to do so if that is now the WG decision).

The PR was closed during the call itself.

 

Opt-Out 

We discussed the issue #138 and work continues there.

 

Purpose

Shilpa is going to create an issue on `purpose`.

Operators are asked whether they have the requirement that multiple purposes in one request are needed.

There are UX issues if the client has to ask for each purpose separately. But still, is this a requirement to ask for multiple purposes?

Axel said that clients should ask for very specific, fine-grained access and not for the mother-of-all-access-tokens and consent for that from the user.

We want to keep the dpv syntax in the profile. Not sure were to put it. Please suggest changes.

 

Closing Remarks

 

Axel kindly asked participants to comment on issues and to review PRs and most importantly contribute text changes to PR. WGs thrive only if members become participants. So, again please participate. Please comment and review.

AoB