Skip to content

Meetings 2026

Giuseppe Lo Presti edited this page Aug 25, 2026 · 69 revisions

Date: 2026-08-25 11:00 CEST

Agenda

  • STA work status update
  • IETF call for adoption of OCM-MLS and OCM-IP
  • IETF Review
  • Upcoming events
    • Nextcloud conference
    • EOSC Symposium 2026
  • AOB: next meeting

Present

  • Mahdi Baghbani
  • Jörn Dreyer
  • Micke Nordin
  • Richard Freitag
  • Giuseppe Lo Presti

Minutes

  • STA work status update M9 is going on, will be finished by end of month. Where should we host the test suite/open OCM endpoint? We should host it at an institution, either SUNET or CERN is fine. SUNET can support MyAccessId logins.

  • IETF call for adoption of OCM-MLS and OCM-IP Everyone should make sure to reply to Thibault's both emails to the list. Both drafts were briefly discussed.

  • IETF Review We will merge notifications and the threat model, and polish in pr:s. We are looking for reviewers, especially related to security. Giuseppe will send a mail to http-dir for a review regarding .well-known. IANA will take a look at the rest of the IANA conciderations.

  • Upcoming events

    • Nextcloud conference

      Micke will hold a 30 minute talk on recent OCM developments, and a BoF regarding a roadmap for OCM in Nextcloud.

    • EOSC Symposium 2026

      Micke and Giuseppe are going. Perhaps Richard too.

  • AOB

    • OpenCloud has a new employee that can be dedicated to OCM.
    • Next meeting: in three weeks, on September 15th (back to original schedule).

Date: 2026-07-07 11:00 CEST

Agenda

  • STA work status update
  • Spec work
    • IANA Registries merged
    • Thibault's comments: we should address them before the in-person meeting
    • Datatracker is read-only as of now, Giuseppe can upload new version(s) to the Datatracker on Monday 2026-07-20
  • Preparation for IETF 126
    • Reminder that our slot is on Tuesday at 9:00, https://datatracker.ietf.org/meeting/126/agenda#agenda-day-2026-07-21
    • Possible talks for the WG meeting:
      • Intro [chairs]
      • OCM state of art and roadmap [Giuseppe]
      • IANA Registries [Micke]
      • Sharing webapps and OCM-IP [Micke]
      • Update on Notifications [Giuseppe]
      • Update on Federation and MLS over OCM notifications [Micke]
      • What would the vendors like to present?

Present

  • Julian Koberg
  • Rasmus Welinder
  • Micke Nordin
  • Richard Freitag
  • Enrique P. Arnaud
  • Giuseppe Lo Presti

Minutes

  • STA work status update
    • M8 is nearing completion, CERNBox is on track to merge webapp receiving soon. Micke will reference the spec work in the report.
    • M9 is up next, the web-based federation validator, while M10, the spec text work, will run through the completion of the STA project.
  • Spec work
    • 1.4.0 was tagged and uploaded to the datatracker. The Github release was published after the meeting.
    • We now have several IANA registries that grant the ability to extend the spec.
    • TODO: Notifications and group/life cycle. Should groups stay opaque, or should you know who are in the group? At the very least we need a notification on the removal of the last user.
  • IETF 126
    • Any presentations need to be submitted to the datatracker to end up in the agenda. Micke and Giuseppe will submit according to the suggestion above. We hope that all vendors will present something, even just a short statement about commitment to OCM.
    • datatracker is read only until Monday of IETF 126, we will use the time to polish and fix Thibaut's comments:
      1. Alphabetical order of terms, and remove duplicates - Giuseppe will fix
      2. Clean up the OCM address example, and reference base64 spec to specify which one we are using - Micke will fix
      3. Change SHOULD to MUST for http-sig in invite flow - Micke will fix then we will upload a new version to the datatracker.
    • Side meeting: Let's register one on the Tuesday, in the afternoon, for overflow discussions.

Date: 2026-06-23 11:00 CEST

Agenda

  • STA work status update
  • Spec work
    • OCM version 1.4 was tagged and published to Datatracker
  • Preparation for IETF 126
    • Our slot is on Tuesday at 9:00, https://datatracker.ietf.org/meeting/126/agenda#agenda-day-2026-07-21
    • Agenda: do we want an intro about short history and where we stand?
    • Spec format: mix of OpenAPI, JSON, and I-D. Where do we want to go?
    • Look into talking to M. Nottingham for the /.well-known/ocm endpoint?
    • Ongoing work: are we doing OK in terms of timing? What is the process of reviewing the text, once we get in all the capabilities we have in mind? [i.e. after we sort out the notifications]

Present

  • Jörn Dryer
  • Micke Nordin
  • Richard Freitag
  • Enrique P. Arnaud
  • Giuseppe Lo Presti

Minutes

  • STA work status update M8 is complete, except for the CERNBox part, Mahdi will work on that. http-sig and token exchange has been merged along with some minor PR:s in Nextcloud, like OCM Notification received event. OpenCloud,CERNBox and oCis should be able to use the same http-sig implementation, hopefully before October.
  • Spec work Version 1.4 tagged. Notifications is next. We should have an IANA registry for notifications. We should also have an IANA registry for resourceTypes and protocols, with files, folder; and webdav, webapp and ssh as the initial content (https://www.ietf.org/rfc/rfc8720.pdf ).
  • Preparation for IETF 126 Different formats of the spec: I-D is the normative one, spec.yaml is essential for implementors, and the json schema is also useful, but when the I-D is published we should make sure it is up to date. Call for adoption of the OCM-IP and OCM-MLS documents should be done.

Date: 2026-06-09 11:00 CEST

Agenda

Present

  • Julian Koberg
  • Micke Nordin
  • Richard Freitag
  • Enrique P. Arnaud
  • Giuseppe Lo Presti
  • Rasmus Oscar Welander
  • Roman Perekhod

Minutes

  • STA work status update
    • Nextcloud Contacts app (email update from Anton)
      • Review has started; work should finish this month
      • HTTP Signatures merged, releasing in Nextcloud 34
      • Moving invitations into the Contacts app is ongoing (already in use by us)
      • Token exchange: mainly waiting on Nextcloud (busy with v34), targeting Nextcloud 35
    • Nextcloud RemoteWebApp app
      • Micke has a full MVP ready for M8
    • CERNBox
      • Some discovery-endpoint tests to fix
      • Persistence of new WebApp payload to be done
  • Spec work
    • Micke to create a separate draft for an OCM integration protocol (how to integrate with application servers):
      • currently: receiving server, sending server
      • future: receiving server, webapp server, sending server
    • Media types on webapp shares: to be discussed offline
    • Targets (redirect, blank, iframe):
      • Giuseppe: do redirect and blank both need to exist? Are they the same thing?
      • Micke: let's remove redirect
    • Requirements: redundant to have in both? To be discussed
    • Issue raised by Richard: no version history when using a remote system
      • Should all permissions (version history, trashbin, etc.) map to the read/write permissions we have in OCM, or be more fine-grained?
      • Giuseppe: this is pure WebDAV, though may be specific to ownCloud/Nextcloud
      • Micke: there is an RFC for versioning in WebDAV
      • Checked offline: WebDAV extensions for versions is not used by any of the EFSSs out there. ownCloud/Nextcloud have their proprietary API, which makes interoperability essentially broken.

Date: 2026-05-26 11:00 CEST

Agenda

  • STA work status update
  • Spec work
  • IETF 126 preparation and logistics
  • AOB

Present

  • Julian Koberg
  • Micke Nordin
  • Richard Freitag
  • Enrique P. Arnaud
  • Giuseppe Lo Presti
  • Rasmus Welander

Minutes

  • STA: Micke and Enrique had a guided review with Nextcloud, and all the requested changes has been pushed to the PR.
  • STA: Webapp app is next
  • SPEC: WebApp spec is being finalized in spec.yaml and Micke will make a PR for the I-D text. Giuseppe presents the proposal for the receiving side of the protocol. We will add an IANA registry for resurceType and protocol, with file and folder as the resourceTypes and webdav, webapp and ssh as the protocols for the initial content.
  • SPEC: Micke will create a separate I-D for federated groups and for OCM Intergration Protocol.
  • IETF: Super Early Bird is ending in a couple of days, please register.

Date: 2026-05-12 11:00 CEST

Agenda

  • STA work status update
  • Spec work
  • IETF 126 preparation and logistics
  • AOB

Present

  • Julian Koberg
  • Micke Nordin
  • Richard Freitag
  • Enrique P. Arnaud
  • Giuseppe Lo Presti
  • Carl Schwan
  • Roman Perekhod
  • Rasmus Welander
  • Mahdi Baghbani

Minutes

  • STA Status Update
    • M5: Code Flow - Some architectural changes requested, as well as some history rewrite to make it more mergable, a guided review is scheduled.
    • M8: http-sig - has been reviewed, and recieved one approval
    • M8: WebApp
      • When token exchange and http-sig has been merged, everything we need is in place for implementing webapps in Nextcloud apps, not in the server.
      • CERNBox will implement the post part, and probably token exchange so we can test between implementations
    • M7: has been finished, and needs to be invoiced before the 14:th.
  • Spec work
    • JWT's: prescribing these will make integration work for webapp servers much, much easier. Implementations that don't plan to integrate (external) web apps may still use opaque tokens. We shall reflect this in the spec.
    • Request for share has been merged
  • IETF 126 preparation and logistics
    • Everyone should register, at least for remote participation, for which the IETF has a fee waiver program.
    • If someone can not get enough funding from their home organization, and needs aditional help from STA funds, we need to figure out how to do it. If this applies to you, do reach out early. The super-early registration ends on June 1st.

Date: 2026-04-28 11:00 CEST

Agenda

  • STA work status update
  • Spec work and IETF interim meeting
  • AOB

Present

  • Julian Koberg
  • Micke Nordin
  • Richard Freitag
  • Enrique P. Arnaud
  • Giuseppe Lo Presti

Minutes

  • STA work:
    • Enrique and Micke reported that the exchange-token PR is eventually passing all tests. Micke contacted Nextcloud for review and final merge.
    • Webapp is due to start next week, Giuseppe will circulate his proposal for the spec as soon as possible
  • IETF Interim
    • The other relevant topic was Notifications: Giuseppe will circulate the proposal to evolve the spec, current implementations in Nextcloud and oCIS are incompatible (and both have issues). Julian available to commit resources to adapt oCIS.
  • MLS over OCM proposal, Micke
    • In a nutshell, the proposal is to use OCM Notifications to encapsulate the MLS protocol for groups
    • Member removal: we may need to re-encrypt the shared data. Q: Can we revoke the key somehow?
      • Yes. that is baked in to the protocol proposal. Optionally you can opt not to do that, Access control is then delegated to "servers honestly discarding superseded keys", not on cryptography. That option should only be taken i certain specific environments (trusted federations).
    • Agreed to discuss this over the mailing list, and/or in a follow-up meeting

Date: 2026-04-14 11:00 CEST

Present

  • Julian Koberg
  • Yul Bahat
  • Micke Nordin
  • Richard Freitag

Minutes

Presentations by Micke Nordin Micke presented 6 topics during the meeting, as preparation for the IETF Interim Session: a. Architecture Discussion for Webapps

  • Webapp to present a resource alongside the resource itself
  • Example: Jupyter Notebook over OCM
  • Resources shared via WebDAV
  • Webapp sharing options: Inside an iframe with correct CSP/CSRF headers, Open in a new window
  • Credentials passed outside the URL using POST with form-encoded parameters b. Journaling
  • Discussed journaling features and their implementation c. Request for Share
  • Addressed the process and requirements for resource sharing d. Advertisement of Resources
  • Explored methods to advertise resources effectively e. Federated Group Management
  • Proposed as a separate internet draft
  • Utilizes MLS (Message Layer Security):
    • Reuse MLS to maintain group state between epochs
    • All members of a federated group can derive a common group key
    • Enables encrypted private messages
    • Introduces an encrypted share type: Wrapped encrypted key to access resources (e.g., WebDAV) f. Notifications
  • Standardized notifications:
    • Currently, only Nextcloud has good implementations
    • Kiteworks also provides notification endpoints
    • Sending instance can inform receiving instance of changes
    • Notifications are still underspecified and require further work (STA work)
  • Next Steps: Notification work to continue after the interim meeting

Licensing A question was asked about potential licensing issues in the webapp specification

  • Use of access tokens to access documents
  • Count access for users accessing resources
  • Outsourcing licensing to software vendors
  • Explicitly state licensing requirements

Security

  • View Mode: View-only/read-only access
  • Webapps: Discussion on where the apps are running
  • Kiteworks Security Review: Security audit expected as a deliverable
  • For IETF specifications:
    • Include security considerations
    • Provide guidance on risks and mitigation strategies
    • Identify potential fixes for the specification
    • Kiteworks to deliver their report soon
    • Specification should explicitly address:
      • Risks that cannot be prevented
      • Possibility of rogue admins
    • Mitigation: Governance strategies to address risks

Action Items and Next Steps

  • Continue work on standardized notifications after the interim meeting
  • Await Kiteworks' security review report
  • Follow up with Barend Mons for feedback
  • Address underspecified areas in notifications and licensing

References and Links

Date: 2026-03-31 11:00 CEST

Present

Minutes

  • STA work status update
    • M6 was claimed by Mahdi, can be easily integrated in ownCLoud and OpenCloud, not only CERNBox reva.
    • Mahdi is working on integrating this into Enriques work on Nextcloud, hopefully finalized next week.
  • Spec work - PR:s
    • Clarify code flow sender and receiver semantics <- Cleanup/clarification
      • This is not controversial in anyway and can be merged. token-exchange vs exchange-token, should we use must-exchange-token as criteria instead? This would align with mfa.
    • Journaling <- New feature
      • To be decided in the next IETF interim meeting, come there and discuss.
    • ResourceDiscovery <- New feature
      • Incorporates FAIR principles that are also machine actionable, also provide an alternative to dataspaces. To be decided in the next IETF interim meeting, come there and discuss.
    • RequestShare <- New feature
      • To be decided in the next IETF interim meeting, come there and discuss. Spamming could be an issue here.
  • Spec work - ISSUES:s
    • WebApp - Micke
      • Micke has a similiar report as Mahdi, will send a pr for this.
    • Notifications - Mahdi
    • Federation Sharing
      • Maybe leave this quite open in the core specification, and leave the possibility to do MLS over OCM in a future I-D, possibly needs a recharter of the working group.
  • CS3 workshop / IETF Meeting / ISGC Symposium debrief
    • Digital Sovereignty was a big topic in CS3. Richard met Barend Mons who expressed interest in OCM. We should invite him to discuss resource discovery. Micke held a Hot-Rfc talk at IETF 125, we should also keep an eye on canonical jscontact uri, which could be interesting for invitations in OCM.
  • Security review
    • ownCloud has offered to do this. We should probably also as CERN security team that has offered also, so maybe do both.
  • OCM hexagon stickers were printed along with CS3 stickers. We should give the current logo to IETF protocol badge designers and see what the come up with.

Date: 2026-03-10 11:00 CET

Agenda

  • STA work status update
    • M5 can be claimed, but Mahdi is unable to proceed given the worsening situation in his place. Can this be done on his behalf?
  • Spec work
  • CS3 workshop / IETF Meeting / ISGC Symposium
  • AOB
    • Meeting next week is canceled, then back to usual pace with March 31st, 2026, at 11:00

Present

Minutes

STA

  • Mahdi's work finished, Giuseppe to send an email to PonderSource for the invoicing [done after the meeting].
  • Enrique working on finalizing the database part, testing on his side before moving forward with PR.

Spec work

  • New PR regarding the /.well-known/ endpoint in the OpenAPI spec, to be merged and published before CS3.

CS3 Workshop (17th-19th of March) et al.

  • Richard to present at ISGC in Taipei.
  • Micke to attend IETF 125 in Shenzhen.
  • Giuseppe to present OCM, with a panel and one slide with all the vendors.
    • Seafile to implement once the RFC is finalized.
    • OneData looking into implementing OCM since they are a part of the EOSC projects.
    • Presentation by Mahdi on the test suite unfortunately to be cancelled because of the current situation
  • Rasmus to present about how OCM is used in EOSC Data Commons projects.

AOB

  • Meeting cancelled next week due to CS3 Workshop and IETF Meeting
  • Next meeting in three weeks 31st of March (original bi-weekly meeting schedule resumed)
  • Summaries of IETF, Taipei, and CS3 by Micke, Richard, and Giuseppe.
  • Pull request by Mahdi in OpenCloud finally merged.

Date: 2026-02-17 11:00 CET

Agenda

  • STA work status update
  • Spec work
  • CS3 workshop
  • AOB

Present

Minutes

STA

Enrique is waiting on Nextcloud. Reused some database fields, needs to discuss with maintainers. Next part of Nextcloud work starts after March, it is regarding application sharing.

Mahdi has been speed running the work this month, and has submitted a report PR to OCM-STA and has started to work on code flow in reva.

Giuseppe will send an email to STA to request an extension in case Mahdi needs some more time due to recent internet issues.

Spec Work

If a request is signed and the signature validation fails, for example during token exchange, what should the error be? We should review errors for the case when one part succeeds and another part fails.

It is up to vendors to decide how to handle for example Cavage style signature, no signatures etc, spec only allow the RFC style signatures.

Tooling for the ASCII art is not really sorted out, worst case we remove it. Micke will take a look.

Groups over OCM is something we should work on. Could be based on MLS with OCM specific messaging for welcome messages etc.

Is ownCloud interested in doing a security review of OCM as a protocol? CERN security expert is also interested in doing this, so two independent security reviews would be great.

CS3 workshop

Giuseppe will send a request to all vendors for a statement of support.

Mahdi is working on the slides, but may not be able to come to Oslo due to unrest.

David is coming from ownCloud, and maybe Julian will make it too.

AOB

Several EOSC projects (Future and Connect) have been approved, and both CERN and SUNET is funded to build up federations using OCM.

We have good hope for STA funding for FileSender. OneData is also thinking about implementing OCM.

Next meeting is moved to 10:th of March.

Date: 2026-02-03 11:00 CET

Agenda

  • STA work status update
  • Spec work
    • v1.3 is out. Tried to fix the formatting but failed -> need to involve the WG chairs.
  • CS3 workshop
    • Eventually we are going to have an OCM Campfire for the technology foundation, and an Interoperability and Federations session for the "consumers" of OCM.
  • AOB

Present

Minutes

  • STA work

    • Enrique [offline]: progress on fixing https://github.com/nextcloud/server/pull/57234 but some errors are due to recent changes from upstream (the PR is against master).
    • STA reached out about publicity, we should do something about this.
    • FileSender has sent a proposal to implement OCM with funding from STA
    • CernBox will merge tests soon, ownCloud and OpenCloud has not received PR:s yet.
  • Spec work

    • 1.3 is out, but formatting of ASCII art is broken, we need help with this. Giuseppe will send an email to the mailing list to see if someone can assist.
    • Request to share and discovery - is this something we want? Big Tech have this functionality, were you get knowledge about a resource, and can request access. From ownCloud side OCM is seen as complicated and mostly useful for scientific usecase, so adding features is ok even if only useful for research.
  • CS3 Workshop

    • The schedule will be cramped, but we will have two sessions, one for consumers and one for in-depth technical details. All vendors invited to describe their commitment to OCM, and willingness to come to Vienna IETF meeting.
  • AOB

    • EC call for feedback on Open Source. We will discuss in matrix if and how to respond as a community.

Date: 2026-01-20 11:00 CET

Agenda

  • STA work status update
  • Spec work
  • CS3 workshop
    • Record number of contributions => the Campfire session on Interoperability and OCM will have to be particularly effective. Giuseppe proposes to approach the 3 major vendors to give a one-slide statement on their plans to support OCM, and there are significant contributions from other actors. A draft schedule will be published soon.
  • AOB

Present

Minutes

STA

Spec work

  • We will create a 1.3 version tag and a 01 version of the spec and ask OCM-WG chairs to start a call for adoption. Micke will tag a version and upload the xml to the data tracker.

CS3 Workshop

We will hold a Campfire session in Oslo - all three major vendors will be there. European Commission may also be represented. Giuseppe will chair and Mahdi will present on the test suite.

Richard will be in Taiwan to present OCM and Micke will do the same in IETF125.

AOB

Should we keep a version field in the discovery? We need to talk about it in the Working group and decide, the options are: Prescribe a version with a point release, e.g. 1.4.1 OR prescribe version 1 without points, OR remove version completely.

Should we have a IANA register for protocols, now we have webdav, ssh and webapp, but we allow anything explicitly in the the spec, maybe they can be registered in a registry.