Tech 2026-07-06 Meeting Notes

Tech 2026-07-06 Meeting Notes

Meeting Link: https://zoom-lfx.platform.linuxfoundation.org/meeting/98672413297?password=51957ead-1050-4507-8c43-e48ed81913c7

Recording

Meeting Recording: https://zoom.us/rec/share/pFa8fVewxD1CmN3f3Dvg5lGgeNDnnmZx9VKKibU0fqjruX79DemO4PlWf2KcgUaV.jIJzYhd0Ufv1rxyX

Antitrust Disclaimer

Attendees

@Antonio Murdaca

Red Hat

Miguel Martin

Red Hat

Brad Goodman

DELL

Sven Uthe

Devity

 

Discussion items

Sl No

Item

Notes

Sl No

Item

Notes

1

java->go transition

2

Deprecation of the C sdk/client

  • unmaintained, too many intel’s specifics in there (add-ons, runtime/build time)

  • Talk to Bryan (Intel) to check if Intel will maintain it

  • Move to rust if it compiles to a smaller binary

    • Brad got rust to 600k but no openssl built in

  • Brad will meet with Bryan in the future for planning

  • Sven uses the C library internally, there’s interest in contributing to Rust, “potentially” dropping the C library

3

go-fdo 2.0 updates

https://github.com/fido-device-onboard/go-fdo/pull/208

4

update on Intel’s policies to work with LF Edge’s FDO GH

Bryan to reconcile intel’s policies to work with LF Edge upstream (i.e. https://github.com/orgs/fido-device-onboard/teams/security-manager )

  • in progress 03/30

  • turn intel and everybody into normal contributors vs “offical Intel devs” - avoid Intel-specific policy.

5

Additional Golang FDO contributions

Potential FDO-related contributions from Brad: https://github.com/bkgoodman?tab=repositories

  • Goal: move FDO applications/tools implementations to an “official” repo

    • decision TBD:

      • can these be moved into the Github FDO Alliance Org? (Action item for Antonio added)

Need: review + feedback:

  • 2.0 go-fdo

  • rust +2.0

  • go applications - various

  • non-go: UEFI “shim” compontent - enable secure firmware update, load TO2 from Rendezvous and perform signature verification of payload

6

Lifecycle for Rust Impl

https://github.com/fdo-rs/fido-device-onboard-rs

Issue: Currently marked “deprecated”, but other groups/orgs are using it.

Need:

  • new maintainers and identify stakeholders and encourage them to attend this meeting.

  • TBD: will maintainers support both client and server, or will only one role be maintained?

7

Community Lab Support

UNH Interopt (IOL) lab - involved with all LF Edge projects, can host infrastructure needed for the project (github runners, rendezvous servers, etc). Non-commercial.

See Wiki (meeting info, etc): Shared Community Lab

This is a resource at our disposal. Ideas for use cases TBD.

8

FIPS Compliance

Miguel reviewing FIPS compliance with respect to go implementation. Will be following up with related issues/pull requests at github. For reference:

9

PQC

 

10

TPM

status of the draft specification

  • as of 06/22 “feels” close, the quiet period should end in July

11

 

is https for to1/to2 really necessary? as implementors we can chose to just say “no” and say “fdo protocol is already secure” right? what about DI instead?

  • Servers shall/must support https/http

  • clients can only support HTTP

Action items

Doug (or …) to create an issue upstream in go-fdo-server to describe the missing java functionality around per device FSIM
Miguel/@Antonio - reach out to Peter Robinson to determine state of maintainership of rust impl
@ben.krieger to follow up on mfg key import to clarify what the java impl does for this
Miguel: how will FIPS compliance be verified?
@Antonio Murdaca et team - review Brad’s 2.0 update and integration with client/server
@Antonio Murdaca what is the procedure for adding Brad’s work to fido alliance github org?
@Antonio Murdaca reach out to Ben Krieger (related to Java’s maintainership)
@Antonio Murdaca organization token for dependabot&others in go-fdo
Brad Goodman - will query for possible java maintainership within DELL
Sven Uthe interested
@Ken Giusti/ @Antonio Murdaca - does Red Hat have a security/crypto security specialist or audit process to review go-fdo 2.0 pre-tag?
Brad Goodman - check if possible to run mythos scan on go-fdo code
@Ken Giusti - what is the origin of “trusted network” for DI (red hat?) What is the user case driving this?
no statements around the need to support https in manufacturing, it is assumed that the manufacturter and DI run within a secure network