2025-12-03 Commonalities Break Out Session - Token Refresh
DRAFT
Attendees & Representation
Name | Organization |
|
|---|
Name | Organization |
|
|---|---|---|
@Pierre Close | AT&T |
|
@Randy Levensalor | CableLabs |
|
@Ben Hepworth | CableLabs |
|
@Rafal Artych | Deutsche Telekom | x |
@Herbert Damker | Deutsche Telekom |
|
@Axel Nennker | Deutsche Telekom | x |
@Jan Friman | Ericsson |
|
@Thorsten Lohmar | Ericsson |
|
@Toyeeb Rehman | GSMA |
|
@Ola Ajibola | GSMA |
|
@Mark Cornall | GSMA |
|
Minesh Patel | GSMA |
|
@Toshi Wakayama | KDDI |
|
@Masaharu Hattori | KDDI |
|
@Appelboom, Huub | KPN |
|
@Casey Cain | Linux Foundation |
|
@Tanja De Groot (Nokia) | Nokia | x |
@Patrice Conil | Orange | x |
@Ludovic Robert | Orange |
|
@Ming Hui Foo | SingTel | x |
@Ramesh Shanmugasundaram | SpryFoxNetworks |
|
@pedro.diezgarcia@telefonica.com | Telefonica | x |
@Jose Luis Urien Pinedo | Telefonica |
|
@Jesús Peña García-Oliva | Telefonica |
|
@Ali Tizghadam | Telus |
|
@Murat Karabulut | TMUS | x |
@Shilpa Padgaonkar | TMUS |
|
@Sachin Kumar | Vodafone |
|
@Eric Murray | Vodafone |
|
@Kevin Smith | Vodafone |
|
@ALI IQBAL | Xflow Research |
|
@Nick Venezia |
|
|
Zhang Zen |
|
|
Marcelo Nahum | Aduna | x |
Philippe Perrault | Aduna | x |
Bart van Kaathoven | Ericsson |
|
Emil Zhang | Ericsson |
|
@Axel Nennker DT |
| x |
Review of Action Items and Minutes from previous meetings
2025-11-26 Commonalities Break Out Session - Token Refresh
Agenda
The project's Antitrust Policy is linked from the LF and project websites. The policy is important when multiple companies, including potential industry competitors, are participating in meetings. Please review it, and if you have any questions, please contact your company’s legal counsel. Members of the LF may contact Andrew Updegrove at the firm Gesmer Updegrove LLP, which provides legal counsel to the LF.
-Walk trough of the updated sequence diagram regarding token refresh not possible on Event subscriptions · Issue #461 · camaraproject/Commonalities
-Question/Discussion. Can we have an architecture that does not require a authorization server on the client (Application) side?
-Question/Discussion, Can it be an excepted solution in Camara that we require an authorization on the client side to achieve a secure solution?
Minutes
Three different options were discussed:
-Keep current solution Commonalities/documentation/CAMARA-API-Event-Subscription-and-Notification-Guide.md at main · camaraproject/Commonalities
This solution have security issues.
-JWT proposal from Marcelo https://github.com/user-attachments/files/23903331/Aduna_Callback.Authentication.in.CAMARA.pptx
This requires pre-share of keys and a authentication server on the client side.
-Axel proposed a modified version.
Action Points
-Extend the invitation to also include ICM members (@Jan Friman )
-Extend the meeting series as a backup if we do not finalize (@Jan Friman )
-Marcelo to document the new proposal in the Issue token refresh not possible on Event subscriptions · Issue #461 · camaraproject/Commonalities
Next Meeting
Wednesday 10/12 13.00 UTC, 14.00 CET