V0.1
Open Questions
These are open design questions, not normative requirements. The OPEN identifiers retain the order and subjects of the ten questions in the earlier working draft. Accepted architectural decisions are recorded in Architecture Decision Records (ADRs).
OPEN-01
Select transport, operation versioning, and request/response serialization?
Publication impact: Required for wire interoperability.
OPEN-02
Approve assertion format, issuer authentication, trust anchors, and key rotation? Is ipa1 optional or mandatory for a named profile?
Publication impact: Required for assertion-profile interoperability and deployment trust.
OPEN-03
Define independently auditable fresh Principal authentication?
Publication impact: Required for trustworthy issuance.
OPEN-04
Define linearizable Account/Principal association semantics across authentication providers and reviewed equivalents to the reference epoch design?
Publication impact: Required for stale-association resistance.
OPEN-05
Define public denial/error codes, response shape, unauthenticated behavior, and timing guidance?
Publication impact: Required for transport-level privacy conformance.
OPEN-06
Freeze assertion acceptance receipts, operation identity, expiry/revocation races, and recovery vectors?
Publication impact: Required for cross-database provisioning interoperability.
OPEN-07
Define cancellation, deadlines, retry budgets, and resource-bound profiles?
Publication impact: Required for comparable availability/resource claims.
OPEN-08
Define semantic minimum conformance and profile extensions?
Publication impact: Required for meaningful conformance claims.
OPEN-09
Define consumer registration, isolation, and portable consumer-instance identity?
Publication impact: Required for interoperable consumer lifecycle.
OPEN-10
Are any Root/authority lifecycle terms still ambiguous after alignment to the current canonical model?
Publication impact: Close by source alignment unless a specific conflict is found.
PUB-01 — Publication readiness
Who owns the website, source pin/update process, versioning, and public comment endpoint? This must be resolved before public publication; the site remains separate from the service.
Proposals
Future design submissions may be called Proposals. No formal proposal numbering system is established yet.
The semantic draft can be reviewed before these questions are resolved, but it must remain explicit that transport interoperability and production trust are not specified.