Re: removing keygen from HTML

Harry Halpin <[email protected]> Mon, 30 May 2016 04:14:09 -1000
Newsgroups gmane.org.w3c.tag
Message-ID <CAE1ny+7fk2UyvQqCmLbqQev7H0m_EpHE7ZhJGPoEMvp01xMsVQ@mail.gmail.com>
--001a113a803ab7e9c205340fde36
Content-Type: text/plain; charset=UTF-8

FYI,

Some folks are using <keygen>, although I think everyone has been notified
of the upcoming deprecation quite a while ago and so hopefully are
preparing for a post-<keygen> world if they use client certs in the browser
outside of TLS (such as for authentication). One deployment, MIT is working
to moving to OpenID with Duo two-factor.

It has been requested not to remove it until the replacement is ready, and
I think WebAuthn fulfils the requirements in a way that is coherent with
the Web Security Model.

Here's the WebAuthn schedule - so thus, one-factor cryptographic
authentication should be working across most browsers later in the year, as
early as October. So far, the Working Group has been moving very fast.

https://lists.w3.org/Archives/Public/public-webauthn/2016May/0213.html

Schedule:
We're aiming to reach Recommendation by February 2017, when the group's
charter ends. We agreed (with an ongoing CfC on the mailing list) to
publish a First Public Working Draft from the current Editors' Draft.
The plan:
* May: FPWD
* June: WD-01, a feature complete Working Draft
* July-Aug: Further issue resolution and Wide Review;
	additional WDs as needed
* September (TPAC): Candidate Recommendation, features stable
* Oct-Nov: Implementation and testing
* December: Proposed Recommendation
* January '17: Advisory Committee Review (4 weeks)
* February '17: Recommendation

   cheers,
       harry

On Sun, May 29, 2016 at 11:40 PM, Chaals McCathie Nevile <
[email protected]> wrote:

> Hi folks,
>
> there is an open issue [1] and open call for consensus [2] to remove
> keygen from HTML. Since the TAG, or its members, appear to have opinions
> about our spec, we'd be grateful to hear them.
>
> cheers
>
> Chaals
>
> [1] https://github.com/w3c/html/issues/43
> [2] http://www.w3.org/mid/[email protected]
>
> --
> Charles McCathie Nevile - web standards - CTO Office, Yandex
>  [email protected] - - - Find more at http://yandex.com
>
>

--001a113a803ab7e9c205340fde36
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div>FYI, <br><br></div>Some folks are using &lt=
;keygen&gt;,=20
although I think everyone has been notified of the upcoming deprecation=20
quite a while ago and so hopefully are preparing for a=20
post-&lt;keygen&gt; world if they use client certs in the browser=20
outside of TLS (such as for authentication). One deployment, MIT is=20
working to moving to OpenID with Duo two-factor. <br><br>It has been=20
requested not to remove it until the replacement is ready, and I think=20
WebAuthn fulfils the requirements in a way that is coherent with the Web
 Security Model. <br><br></div>Here&#39;s the WebAuthn schedule - so thus,=
=20
one-factor cryptographic authentication should be working across most=20
browsers later in the year, as early as October. So far, the Working=20
Group has been moving very fast. <br><br><a href=3D"https://lists.w3.org/Ar=
chives/Public/public-webauthn/2016May/0213.html" target=3D"_blank">https://=
lists.w3.org/Archives/Public/public-webauthn/2016May/0213.html</a><br><pre>=
Schedule:
We&#39;re aiming to reach Recommendation by February 2017, when the group&#=
39;s
charter ends. We agreed (with an ongoing CfC on the mailing list) to
publish a First Public Working Draft from the current Editors&#39; Draft.
The plan:
* May: FPWD
* June: WD-01, a feature complete Working Draft
* July-Aug: Further issue resolution and Wide Review;
	additional WDs as needed
* September (TPAC): Candidate Recommendation, features stable
* Oct-Nov: Implementation and testing
* December: Proposed Recommendation
* January &#39;17: Advisory Committee Review (4 weeks)
* February &#39;17: Recommendation
</pre>=C2=A0=C2=A0 cheers,<br></div>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 ha=
rry</div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Sun, =
May 29, 2016 at 11:40 PM, Chaals McCathie Nevile <span dir=3D"ltr">&lt;<a h=
ref=3D"mailto:[email protected]" target=3D"_blank">[email protected]=
u</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margi=
n:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi folks,<br>
<br>
there is an open issue [1] and open call for consensus [2] to remove keygen=
 from HTML. Since the TAG, or its members, appear to have opinions about ou=
r spec, we&#39;d be grateful to hear them.<br>
<br>
cheers<br>
<br>
Chaals<br>
<br>
[1] <a href=3D"https://github.com/w3c/html/issues/43" rel=3D"noreferrer" ta=
rget=3D"_blank">https://github.com/w3c/html/issues/43</a><br>
[2] <a href=3D"http://www.w3.org/mid/[email protected]" rel=
=3D"noreferrer" target=3D"_blank">http://www.w3.org/mid/op.yhs220oos7agh9@w=
idsith.local</a><span class=3D"HOEnZb"><font color=3D"#888888"><br>
<br>
-- <br>
Charles McCathie Nevile - web standards - CTO Office, Yandex<br>
=C2=A0<a href=3D"mailto:[email protected]" target=3D"_blank">chaals@yan=
dex-team.ru</a> - - - Find more at <a href=3D"http://yandex.com" rel=3D"nor=
eferrer" target=3D"_blank">http://yandex.com</a><br>
<br>
</font></span></blockquote></div><br></div>

--001a113a803ab7e9c205340fde36--