2025-12-03 Commonalities Break Out Session - Token Refresh

2025-12-03 Commonalities Break Out Session - Token Refresh

DRAFT

Attendees & Representation

Name

Organization

 

Name

Organization

 

Name

Organization

 

Name

Organization

 

@Pierre Close 

AT&T

 

@Randy Levensalor 

CableLabs

 

@Ben Hepworth 

CableLabs

 

@Rafal Artych 

Deutsche Telekom

x

@Herbert Damker 

Deutsche Telekom

 

@Axel Nennker 

Deutsche Telekom

 x

@Jan Friman 

Ericsson

 

@Thorsten Lohmar 

Ericsson

 

@Toyeeb Rehman

GSMA

 

@Ola Ajibola

GSMA

 

@Mark Cornall 

GSMA

 

Minesh Patel

GSMA

 

@Toshi Wakayama 

KDDI

 

@Masaharu Hattori

KDDI

 

@Appelboom, Huub 

KPN

 

@Casey Cain 

Linux Foundation

 

@Tanja De Groot (Nokia) 

Nokia

@Patrice Conil 

Orange

x

@Ludovic Robert 

Orange

 

@Ming Hui Foo 

SingTel

@Ramesh Shanmugasundaram 

SpryFoxNetworks

 

@pedro.diezgarcia@telefonica.com 

Telefonica

@Jose Luis Urien Pinedo 

Telefonica

 

@Jesús Peña García-Oliva 

Telefonica

 

@Ali Tizghadam 

Telus

 

@Murat Karabulut 

TMUS

 x

@Shilpa Padgaonkar

TMUS

 

@Sachin Kumar 

Vodafone

 

@Eric Murray 

Vodafone

 

@Kevin Smith

Vodafone

 

@ALI IQBAL

Xflow Research

 

@Nick Venezia

 

 

Zhang Zen

 

 

Marcelo Nahum

Aduna

x

Philippe Perrault

Aduna

x

Bart van Kaathoven

Ericsson

 

Emil Zhang

Ericsson

 

@Axel Nennker DT

 

x

Review of Action Items and Minutes from previous meetings

2025-11-26 Commonalities Break Out Session - Token Refresh

Agenda

The project's Antitrust Policy is linked from the LF and project websites. The policy is important when multiple companies, including potential industry competitors, are participating in meetings. Please review it, and if you have any questions, please contact your company’s legal counsel. Members of the LF may contact Andrew Updegrove at the firm Gesmer Updegrove LLP, which provides legal counsel to the LF.

-Walk trough of the updated sequence diagram regarding token refresh not possible on Event subscriptions · Issue #461 · camaraproject/Commonalities

-Question/Discussion. Can we have an architecture that does not require a authorization server on the client (Application) side?

-Question/Discussion, Can it be an excepted solution in Camara that we require an authorization on the client side to achieve a secure solution?

Minutes

Three different options were discussed:

-Keep current solution Commonalities/documentation/CAMARA-API-Event-Subscription-and-Notification-Guide.md at main · camaraproject/Commonalities

This solution have security issues.

-JWT proposal from Marcelo https://github.com/user-attachments/files/23903331/Aduna_Callback.Authentication.in.CAMARA.pptx

This requires pre-share of keys and a authentication server on the client side.

-Axel proposed a modified version.

Action Points

-Extend the invitation to also include ICM members (@Jan Friman )

-Extend the meeting series as a backup if we do not finalize (@Jan Friman )

-Marcelo to document the new proposal in the Issue token refresh not possible on Event subscriptions · Issue #461 · camaraproject/Commonalities

 

Next Meeting

 

Wednesday 10/12 13.00 UTC, 14.00 CET