Thanks for sending this over, Atul! 100% agreed on your topics to discuss.
To kick things off, I'd be happy to give a quick overview of the doc I wrote a while back covering
CAEP vs RISC, largely to give a reminder on the specifics of RISC that are relevant to us.
There are a few open questions (some of which you mentioned above) that I think we should talk about:
- What new event types do we need?
- Do we need to create new subject types, or can we leverage existing ones such as the "issuer + subject"?
- Agreed on looking at the transmitter configuration - what do we need to change here, if anything?
- Regarding the management API (spec is here), is there anything we need to add to either the transport or the session management? For example, do we want to talk about possible authentication strategies or leave that to the implementations?
Once we feel we have a good baseline, then I'm with you- we can run through scenarios and iterate when we find any gaps.
Looking forward to the workshop!
Jordan