[Ztcpp] Re: CSA/IETF ZTCPP and the OIDF/SSF Info Sharing

Atul Tulshibagwale <atul.tulshibagwale@crowdstrike.com> Mon, 29 June 2026 01:24 UTC

Return-Path: <prvs=3640f681ce=atul.tulshibagwale@crowdstrike.com>
X-Original-To: ztcpp@mail2.ietf.org
Delivered-To: ztcpp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 0BA8C1097B057 for <ztcpp@mail2.ietf.org>; Sun, 28 Jun 2026 18:24:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782696257; bh=rw03eXaOQVjaFcWw/djPzRz0RXeyqbwTgWcjfmfrB6Y=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=qzgNy7j8GOwDGFEaZnHIIBJMeL1Hq/s2FK/ljfcw2tNf8jRKzWpL0x9Lv3zNjTpGS C8NPE4Chm39Mbinh9leVUeHfH+LXVpWT2hgLZNLvLlINcRMPM9JdYjPiWB6HkVd1BA jWYEZ3/yNkC5OLZuJD73jpAe3N3L2XcNBgWqPAiY=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.293
X-Spam-Level:
X-Spam-Status: No, score=-2.293 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URI_NOVOWEL=0.5] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=crowdstrike.com header.b="FyZzipa5"; dkim=pass (2048-bit key) header.d=crowdstrike.com header.b="DIgxYKoW"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id P2nDhKoDGA5F for <ztcpp@mail2.ietf.org>; Sun, 28 Jun 2026 18:24:15 -0700 (PDT)
Received: from mx0a-00206402.pphosted.com (mx0a-00206402.pphosted.com [148.163.148.77]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D8AC81097B030 for <ztcpp@ietf.org>; Sun, 28 Jun 2026 18:24:02 -0700 (PDT)
Received: from pps.filterd (m0354652.ppops.net [127.0.0.1]) by mx0a-00206402.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 65SM9mqd3940252 for <ztcpp@ietf.org>; Mon, 29 Jun 2026 01:23:55 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=crowdstrike.com; h=cc:content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to; s=default; bh=hZ0/LNK0+JZINki5KynWJVXpXf 9kPFdks0gyzg8ngwo=; b=FyZzipa53Igw9TxI55ZDNF/VwsnauBa5z4a7CgHBBe 7kN1IOcr1CtM89/ADafqpUfF7kewOzNgNIGjZEUijdRSc8/U/jfoYFduR2KR3sIs b6maBvQPaDEGnCFcBvRiMtrg+KmixB2uE1WHhVuKetSj1bsqW0LjyfgdHuPYijeD 2h6XUwrfdX+ANnXqhUTJ3zqSUC4wsEXtDM1BwRrQqJMB4fLMJ4F3R4egQmWntkjB gM8Zv3rnJOX4qLtVEuzcMjj6EplhVN4m+9zbO+ZodwU9ShpIzFJe/VccTI8sdgi0 cmRQ4L8UhFmQWRx+AhfOuEqtTcd4x9tjx3I6cDqs4QZw==
Received: from mail-oi1-f199.google.com (mail-oi1-f199.google.com [209.85.167.199]) by mx0a-00206402.pphosted.com (PPS) with ESMTPS id 4f2vb01yn4-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for <ztcpp@ietf.org>; Mon, 29 Jun 2026 01:23:54 +0000 (GMT)
Received: by mail-oi1-f199.google.com with SMTP id 5614622812f47-49226201eb8so2411295b6e.1 for <ztcpp@ietf.org>; Sun, 28 Jun 2026 18:23:54 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1782696234; cv=none; d=google.com; s=arc-20260327; b=V6sKzmEkg8vKr0YK7fmRunK4Q111eMe6pVSI80tF8SFEy1ZMYmzYaMtAu0i719kL+R ZGsxREMbekktYmV48lYGfxPghxSauIMfEz8Ui3wPGzhSM0etFWR4sIE+gu7cbIM46AZh ndbpJDlUFwqugbCoBxXW4pRpyUWkF9F7ToHm1MGx5ucUPZgDA4QvvJZVXziCDJKSf2dA zFTJl9COeoakWah9kGFelOcGNIjq03EVrQVpnaWpk7AV+XDWhY8qBQuIloLfRwYkI1jo eydzGvm3+e74J0YTMSjIZYsb/f6i4j+jjrf0vIsF+7brJSXts6Z6SIkd5enX0fmX/tuU 1j8g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=hZ0/LNK0+JZINki5KynWJVXpXf9kPFdks0gyzg8ngwo=; fh=RTuzaQk+0OH59NryFnXsuq6wltsFcfUrYLFbn/u5h8k=; b=RQPHFjWFYoOwSbCD7VHxHpiY78W+/0TvXFXivD6uKI3jtiSSKyvYwrUt3xuU+E6U7O gmyW+ToRIvrbT9HJzlJNi5k0o+mmMxOeB0zJe2NdhAE9p3LpZY72xiX3pNT8hH7vat/P BOXvTEtjTTUlqxREs+8Bgp9EXWUl2BqTyEffR5lV800YDA2OEQPd/UR0KiJm7UxOih4B lInufOrNjnF4GF+obJWEieqMsWZQZviVk4hoi1C9XSYEy2N1E3b1jW7pwxL7I0svniaM vKj9aeYKozv0vuV3X59MDXmrA7o4Ps14CmILCclavGceIYaGSWI+nCMqGe0dCIW5R2BY Ouow==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=crowdstrike.com; s=google; t=1782696234; x=1783301034; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=hZ0/LNK0+JZINki5KynWJVXpXf9kPFdks0gyzg8ngwo=; b=DIgxYKoWqMH6BLjh07bZkukJgCv9IGwWPPYbNUfs+omL6jxVaZIOyhMd07uLRP2fvY CLRG2Cfm5nxo37O2pNF73+ART4YasYnp3GYf7qMxmeinTtxxS4BL9BjUVl2B5y5SFcxL qUQdakqTwi2GU6t9u6Em73QCTqTMNCzOVOUQ6z4VuZ7VUsJaiwAbfhEEDlK1jCiN2bvL 8XhiFS0rLKd6NjqNMKO9c6IaWCE7Mfx4c5YaThNWmcrkzPQfPZGjKVMk4nnnUWIG8lqu Jw+d9105qIYv+SLzUvf/CNWbbNUWOtj67id+n57PEQ7+/6M9CFrLB4iNmCRKhP1jqB0M Cdig==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782696234; x=1783301034; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=hZ0/LNK0+JZINki5KynWJVXpXf9kPFdks0gyzg8ngwo=; b=fk6RBs7u/8rzX9dmpc63jUVWMAJenT+LXNrg+umwDWQhJ/3PHnxUIS8Y50VAhBbxqx XeuoWSTHUWvip27TufXH02apNQB8R2QGbv1NcbrUJB/6uyuVam0XF0o/+mDDW2hr7nBt 0IrhC5bklIWtrUQRylxZC8x7nQr7G2eBLFdypC7rhn5QoJNNtN3TVdhc5q/yVfGFL1JL ciEgB6ftj48luAkQM2wAiNTrpg5YXS9mRUbCUA1n42XLZo01mPW7pt2wXaaw26VW7coH abiRPxT7Sn2LNl4p+xiwUqDwpk+A8cQUlP5cvODlKWQ32XtYQ+7zguhFd4JJZP+YxGMB rArg==
X-Forwarded-Encrypted: i=1; AFNElJ9sepqMlCjEZ5fQSVHW7/plly7R5s1I/Z57DVamwt6AkPSQhEDaubUDT/p8RcZ63TjPS+fn3Q==@ietf.org
X-Gm-Message-State: AOJu0Yxki6LgpciYh2p6izSl2POLzZK8rys6/tJrxJBlb1Bm3284gBLM tV8j5OEmgC/1cvsYXqwNigYMl7ik5LAkzHqSZWpz7Hu/IdnkyR8NHqsSBA6OwPUjSR4+8LfjNEM sAygODcmiD2HLwMgSyTpBxJynA1qqLh0a6acVjLyLiCHpE/b6uTLbyxenhYEyGECMXr1icY1XLA qTVpLGGQb8eW5jth+1RzV+WA==
X-Gm-Gg: AfdE7cnmzXQs38A+WYwUVUI5hifGbQIBi4SaOhsT+SBCbpze8jaHOF2g4shS7mzpb0m B2GhcO9pfqp9nPw3eHCcE4aUuWvZ7kCYyLzdpWoRAs+bAsTZpoTV0Xa8Q9l/LXo26ECYIsJv+En UG2vT8eSEavhm/4Vk2KGxL6O0yGlboDNFND8hUSUSLUYfAa26d0EC4n3QzhLlAWmnTYsZLFCdo/ n+0k1gG/GdIUx6U653Zgm3VaVcBG1IgdQUqh6pp/QlvL0mKIxSu7F9At/VRgA==
X-Received: by 2002:a05:6808:f8d:b0:489:38b6:ba0e with SMTP id 5614622812f47-49218d08f8cmr11962566b6e.43.1782696233616; Sun, 28 Jun 2026 18:23:53 -0700 (PDT)
X-Received: by 2002:a05:6808:f8d:b0:489:38b6:ba0e with SMTP id 5614622812f47-49218d08f8cmr11962551b6e.43.1782696232850; Sun, 28 Jun 2026 18:23:52 -0700 (PDT)
MIME-Version: 1.0
References: <CABetrwB84--adUYV1vj7f8Wbuh6E6+6QrKwQUP7c5HrGE_Lckg@mail.gmail.com> <5BA7884C-6089-4B16-8271-7357FF3334DB@cloudsecurityalliance.org> <000001dcfca1$79d700a0$6d8501e0$@tsinghua.org.cn> <CABetrwB5Ja-7n+0a_8dsUV9+tYw1fHn-MxH81XzeGyuQwmYJzw@mail.gmail.com> <CABetrwCGeQr5X-y-wN36Qd6Rp7C0quN78k2-XxxKapFtdMMB8A@mail.gmail.com> <CABetrwA3xUpUodRP2aLADWPrtHxVAw-=kMy=nS8zUAgS2XfTWg@mail.gmail.com> <CABetrwCyK9QaoNwJuui28x_tXHe7bvVb9pLsqZVm+4z4_DVKpQ@mail.gmail.com> <CA+6i7nB1BEPe8k+8VSt70xAD1KQ_+nsGREwHDi8muFvk_sJCvg@mail.gmail.com> <035e01dd0764$27b091b0$7711b510$@tsinghua.org.cn>
In-Reply-To: <035e01dd0764$27b091b0$7711b510$@tsinghua.org.cn>
From: Atul Tulshibagwale <atul.tulshibagwale@crowdstrike.com>
Date: Sun, 28 Jun 2026 18:23:42 -0700
X-Gm-Features: AVVi8CeUD3iv1rmmUbcU1XJXflLB9YinBPCkkCF2g7xDwNyVKJC8_FkoXoemyaU
Message-ID: <CA+6i7nCBLba8PQuETUDuXx6JcKaUHKsEARE2_qazKRDbZAKmPA@mail.gmail.com>
To: Aijun Wang <wangaijun@tsinghua.org.cn>, "ztcpp@ietf.org" <ztcpp@ietf.org>
Content-Type: multipart/related; boundary="000000000000b3f1a806555a4f14"
X-Proofpoint-GUID: cloGCyaXaA-ysJ-4xYn_kZGrJRAuB7fs
X-Proofpoint-Spam-Info: AW1haW4tMjYwNjI5MDAxMCBTYWx0ZWRfX6Y8b8Nq54as9 olScUtduGBxEdYRiQhp+1pA/dD+QJGnDjm67evuYFe2wEL35p2W17ZrWXnxI7aZMwh7df+v4f0s 8QVjqxFlbs6F1eP+7CQ2nkigIj4S6LepGwgXzt3jAwd0o+iqiftk
X-Authority-Analysis: v=2.4 cv=EN02FVZC c=1 sm=1 tr=0 ts=6a41c92a cx=c_pps a=yymyAM/LQ7lj/HqAiIiKTw==:117 a=FelO9ux0wxsA:10 a=KZhmPCYDdY0A:10 a=VkNPw1HP01LnGYTKEx00:22 a=T2KQ53IYiC3MXPrxx8bB:22 a=2KvRFfd_T_-xjmS8C1aD:22 a=pl6vuDidAAAA:8 a=jU4qhlNgAAAA:8 a=-d-E2DxQAAAA:8 a=is3RsFX7AAAA:8 a=TTjGEWenAAAA:8 a=1XWaLZrsAAAA:8 a=lC1GrLM2AAAA:20 a=48vgC7mUAAAA:8 a=GAm0R9UbAAAA:20 a=RpNjiQI2AAAA:8 a=uherdBYGAAAA:8 a=zT09LpwfAAAA:8 a=3yH_6LRJAAAA:8 a=ruYZKog3AAAA:8 a=HpXBYD_CAAAA:8 a=tQmJz29qAAAA:8 a=842pQJVXAAAA:8 a=oHQIPucjAAAA:8 a=pGLkceISAAAA:8 a=oJ4GGWQyAAAA:8 a=J5e4UohxAAAA:8 a=uMSFk_gm-2LFNReOwy0A:9 a=lqcHg5cX4UMA:10 a=QEXdDO2ut3YA:10 a=hziOpVa-AAAA:20 a=Ji488cJyY-d5m4f20W4A:9 a=Gh4LxZYFu7J59Odq:21 a=HXjIzolwW10A:10 a=T6a71-JsGAwA:10 a=efpaJB4zofY2dbm2aIRb:22 a=83O3dQagCPYdzT-VN2Mh:22 a=CvJ-9y_HEmGQg9NJmnFv:22 a=zL9ByepIIW4QtCtvXEit:22 a=hksshU0T4_nG3tge8lZI:22 a=ZBgFQaiV0RbA0k4Jie6G:22 a=iVAeh_6tmgTtQvVYgxpC:22 a=Ryw_UUHOqUy6DGRel2OW:22 a=LBtTsBf3jnVai1wd4AUi:22 a=kUwOUybKi0F-R4U65a87:22 a=ZnEM8hzkeS1ON7ewEc08:22 a=GL0wURuKkRwD23UuTcK_:22 a=bA3UWDv6hWIuX7UZL3qL:22
X-Proofpoint-ORIG-GUID: cloGCyaXaA-ysJ-4xYn_kZGrJRAuB7fs
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjI5MDAxMCBTYWx0ZWRfXy82qUmgdrYfj VOUHzxHlNyDzFZTHLdq8tQDMZ2tCJwabEMP8IGSSkKGKVWtBKVyNvu6aTMGCcqiehQVY37bBYi7 NrZ+N3g5Sw+81zJZv7jZHKdRczi9lMBMZzX5d7rNDkHHL2U/V3/xtSmTpevf3D8pW6dGI87kFUs Ojlr3J9gazHdBBNmhQUz0HEhMrrlAQ1eQBr/xEm6AdwDZDanp/B+qMu4obdEOo6nhKt15sDbRF+ J48hUeLjauj14BjllIo9U+wDDe1wdiJdqct2u2MpjjLmirI78Qeq87Oo3djqdHSfLQyk5RCuEf0 OxhAIXFdZgwR9GY/sfMu0GWLbmGgiPQ5okb0gKhLQNUZI+QdY6KPYGxxDn7BvLAG9aFtgl2df8C 3DKPiBsIeee5JZjcLFkvjZmW/AjnSrhOME8the3wfHDH0MGjEXXyQxIqNqgCYEXpTUd0+neDaSl MGD/iF3HhB3ehYfTVWQ==
X-Proofpoint-Virus-Version:
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 impostorscore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 adultscore=0 malwarescore=0 clxscore=1011 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2606290010
X-MailFrom: prvs=3640f681ce=atul.tulshibagwale@crowdstrike.com
X-Mailman-Rule-Hits: max-recipients; max-size
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; news-moderation; no-subject; digests; suspicious-header
Message-ID-Hash: 6DDXM3LLZI4CEHPRH34BXC6LPLWFATC6
X-Message-ID-Hash: 6DDXM3LLZI4CEHPRH34BXC6LPLWFATC6
X-Mailman-Approved-At: Sun, 28 Jun 2026 23:13:26 -0700
CC: Erik Johnson <ejohnson@cloudsecurityalliance.org>, Jerry Chapman <jerry.chapman@numberlinesecurity.com>, Gail Hodges <gail@oidf.org>, Eve Maler <eve@vennfactory.com>, Philip Griffiths <philip.griffiths@netfoundry.io>, Mike Kiser <mike.kiser@sailpoint.com>, Jason Garbis <jason.garbis@numberlinesecurity.com>, Sean Connelly <sconnelly@zscaler.com>, John Kindervag <john.kindervag@illumio.com>, Shruti Kulkarni <s.shruti.kulkarni@gmail.com>, Daniele Catteddu <dcatteddu@cloudsecurityalliance.org>, Sean O'Dentity <iam@seanodentity.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Ztcpp] Re: CSA/IETF ZTCPP and the OIDF/SSF Info Sharing
List-Id: Zero Trust Control and Policy Protocol <ztcpp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ztcpp/NiNz_xonzoVZcld7eLBNbA_6YVQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ztcpp>
List-Help: <mailto:ztcpp-request@ietf.org?subject=help>
List-Owner: <mailto:ztcpp-owner@ietf.org>
List-Post: <mailto:ztcpp@ietf.org>
List-Subscribe: <mailto:ztcpp-join@ietf.org>
List-Unsubscribe: <mailto:ztcpp-leave@ietf.org>

+ztcpp@ietf.org <ztcpp@ietf.org> for documentation of this thread.

On Sun, Jun 28, 2026, 6:11 PM Aijun Wang <wangaijun@tsinghua.org.cn> wrote:

> Hi, Atul:
>
>
>
> Thanks for your material!
>
> I think such material is the document that can lead to the discussions and
> converge that what’s protocols we can standardize in the ztccp efforts in
> IETF.
>
>
>
> And, one suggestion, can we take the following discussions on the
> ztcpp@ietf.org which can be easily archived and retrieved?(let’s start
> from the introduction of AuthZEN?
>
> Discussions on the ztcpp@ietf.org can certainly help us invite more
> experts on the coming planned IETF 126 side meeting.
>
>
>
> If we want to explore the possible standard opportunities within the
> ztcpp, we should analyze the necessary based on NIST zero trust
> architecture, for example, in the page 25 of Atul’s material, which is easy
> to help the experts get the key points quickly.
>
>
>
> Aijun
>
>
>
>
>
> *From:* Atul Tulshibagwale [mailto:atul.tulshibagwale@crowdstrike.com]
> *Sent:* Saturday, June 27, 2026 1:16 AM
> *To:* Erik Johnson <ejohnson@cloudsecurityalliance.org>
> *Cc:* Jerry Chapman <jerry.chapman@numberlinesecurity.com>; Gail Hodges <
> gail@oidf.org>; Eve Maler <eve@vennfactory.com>; Aijun Wang <
> wangaijun@tsinghua.org.cn>; Philip Griffiths <
> philip.griffiths@netfoundry.io>; Mike Kiser <mike.kiser@sailpoint.com>;
> Jason Garbis <jason.garbis@numberlinesecurity.com>; Sean Connelly <
> sconnelly@zscaler.com>; John Kindervag <john.kindervag@illumio.com>;
> Shruti Kulkarni <s.shruti.kulkarni@gmail.com>; Daniele Catteddu <
> dcatteddu@cloudsecurityalliance.org>; Sean O'Dentity <iam@seanodentity.com
> >
> *Subject:* Re: CSA/IETF ZTCPP and the OIDF/SSF Info Sharing
>
>
>
> Hi all,
>
> Thanks for the call today, and great talking to you. Here are the slides
> of the Authorization masterclass we presented at Identiverse last week,
> which talk about Shared Signals, AuthZEN and Transaction Tokens standards.
>
>
>
> Atul
>
>
>
> On Tue, Jun 23, 2026 at 1:31 PM Erik Johnson <
> ejohnson@cloudsecurityalliance.org> wrote:
>
>
> Thanks to all the folks who responded.
>
>
>
> It looks like the best time for CSA+OIDF representation is noon ET on
> Friday. I'll send that invite out shortly.
>
> [image: image.png]
>
>
>
> But we also need to make sure our IETF contact Aijun is looped in. He's
> based in China so time zones are challenging and early morning works best.
> So I'll also send an invite for 9AM ET on Wednesday 7/1 to loop him in.
>
> [image: image.png]
>
>
>
> Others are encouraged to join at one or both of these times if you're
> able. Thanks to all for your patience. I'm looking forward to the
> collaboration.
>
>
>
> Best Regards,
>
> Erik Johnson
>
> Senior Research Analyst (CCSK, CISSP, CCSP, PMP) - Zero Trust and
> Financial Services
>
> Cloud Security Alliance
>
> ejohnson@cloudsecurityalliance.org
>
> https://www.linkedin.com/in/erikjohnson2/ [linkedin.com]
> <https://urldefense.com/v3/__https:/www.linkedin.com/in/erikjohnson2/__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skOSS4mqoQ$>
>
>
>
>
>
> On Mon, Jun 22, 2026 at 10:15 AM Erik Johnson <
> ejohnson@cloudsecurityalliance.org> wrote:
>
> Thanks to those who've completed the collaboration info sharing meeting
> time poll.  Unfortunately, there was no one time that accommodate the key
> players from both CSA/IETF (Philip & Aijun) and from the OIDF/SSF clan
> (Gail and one or more of the SSF co-chairs).  Part of the problem may be
> the diversity of time zones (US, Europe and China). So I've added a few
> more times for this week and next, and encourage folks to (re)take the poll
> [calendly.com]
> <https://urldefense.com/v3/__https:/calendly.com/d/d2cc-xxc-wxg/ietf-csa-ztcpp-openid-ssf-collaboration-exploration__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skPjMEFLCA$>
> ASAP and select as many times as possible so we can get this call scheduled.
>
>
>
> https://calendly.com/d/d2cc-xxc-wxg/ietf-csa-ztcpp-openid-ssf-collaboration-exploration
> [calendly.com]
> <https://urldefense.com/v3/__https:/calendly.com/d/d2cc-xxc-wxg/ietf-csa-ztcpp-openid-ssf-collaboration-exploration__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skPjMEFLCA$>
>
>
>
>
> Thanks and I look forward to the discussions.
>
>
>
> Best Regards,
>
> Erik Johnson
>
> Senior Research Analyst (CCSK, CISSP, CCSP, PMP) - Zero Trust and
> Financial Services
>
> Cloud Security Alliance
>
> ejohnson@cloudsecurityalliance.org
>
> https://www.linkedin.com/in/erikjohnson2/ [linkedin.com]
> <https://urldefense.com/v3/__https:/www.linkedin.com/in/erikjohnson2/__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skOSS4mqoQ$>
>
>
>
>
>
> On Thu, Jun 18, 2026 at 12:40 PM Erik Johnson <
> ejohnson@cloudsecurityalliance.org> wrote:
>
> Gentle reminder to please complete the meeting time poll for next week -
> particularly the OpenID folks who haven't weighed in as yet (at Identiverse
> maybe?).
>
>
>
> So far 9AM ET on 6/24 looks like the winner. Please let me know if that
> time does NOT work for you.
>
>
>
> [image: image.png]
>
>
>
> Best Regards,
>
> Erik Johnson
>
> Senior Research Analyst (CCSK, CISSP, CCSP, PMP) - Zero Trust and
> Financial Services
>
> Cloud Security Alliance
>
> ejohnson@cloudsecurityalliance.org
>
> https://www.linkedin.com/in/erikjohnson2/ [linkedin.com]
> <https://urldefense.com/v3/__https:/www.linkedin.com/in/erikjohnson2/__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skOSS4mqoQ$>
>
>
>
>
>
> On Mon, Jun 15, 2026 at 6:19 PM Erik Johnson <
> ejohnson@cloudsecurityalliance.org> wrote:
>
> Zero Trust colleagues,
>
>
>
> All are invited to please complete this meeting poll as soon as you can so
> we can schedule an hour-long call for next week.
>
> The CSA/IETF and OpenID SSF teams should each assemble a few slides for a
> 15-20 minute summary presentation of the goals, status and plans for their
> initiative to set the table for a discusison of collaboration opportunities.
>
>
>
> https://calendly.com/d/d2cc-xxc-wxg/ietf-csa-ztcpp-openid-ssf-collaboration-exploration
> [calendly.com]
> <https://urldefense.com/v3/__https:/calendly.com/d/d2cc-xxc-wxg/ietf-csa-ztcpp-openid-ssf-collaboration-exploration__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skPjMEFLCA$>
>
>
>
>
> Looking forward to the discussion.
>
>
>
> Best Regards,
>
> Erik Johnson
>
> Senior Research Analyst (CCSK, CISSP, CCSP, PMP) - Zero Trust and
> Financial Services
>
> Cloud Security Alliance
>
> ejohnson@cloudsecurityalliance.org
>
> https://www.linkedin.com/in/erikjohnson2/ [linkedin.com]
> <https://urldefense.com/v3/__https:/www.linkedin.com/in/erikjohnson2/__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skOSS4mqoQ$>
>
>
>
>
>
> On Mon, Jun 15, 2026 at 4:32 AM Aijun Wang <wangaijun@tsinghua.org.cn>
> wrote:
>
> Hi, Erik and all:
>
>
>
> I have conducted a preliminary review of https://openid.net/specs/openid-sharedsignals-framework-1_0.html
> [openid.net]
> <https://urldefense.com/v3/__https:/openid.net/specs/openid-sharedsignals-framework-1_0.html__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skPXa_49lg$>
> and believe this document may be a candidate for further discussion on the
> ztcpp@ietf.org mailing list within the IETF.
>
> However, it should first clarify what it aims to standardize, as well as
> its relationship with the foundational RFCs: RFC 8417, RFC 8935, RFC 8936
> and RFC 9493.
>
>
>
> The objectives of the Shared Signals Working Group are aligned with those
> of the ZTCPP working group.
>
> Are there any other standardization efforts that could be pursued within
> the IETF ZTCPP working group?
>
>
>
> I would prefer to hold a coordination call in the week of June 22nd, to
> leave more time for preparations for the IETF 126 meeting in Vienna.
>
>
>
> Aijun
>
>
>
> *From:* Daniele Catteddu [mailto:dcatteddu@cloudsecurityalliance.org]
> *Sent:* Sunday, June 14, 2026 3:36 PM
> *To:* Erik Johnson <ejohnson@cloudsecurityalliance.org>
> *Cc:* Gail Hodges <gail@oidf.org>; Mike Kiser <mike.kiser@sailpoint.com>;
> Atul Tulshibagwale <atul.tulshibagwale@crowdstrike.com>; Eve Maler <
> eve@vennfactory.com>; Sean O'Dentity <iam@seanodentity.com>; Philip
> Griffiths <philip.griffiths@netfoundry.io>; Aijun Wang <
> wangaijun@tsinghua.org.cn>; Shruti Kulkarni <s.shruti.kulkarni@gmail.com>;
> Jerry Chapman <jerry.chapman@numberlinesecurity.com>; Jason Garbis <
> jason.garbis@numberlinesecurity.com>
> *Subject:* Re: E-introductions: Erik Johnson of CSA and the OIDF/SSF clan
>
>
>
> Hi Erik,
>
> A short document (a couple of pages) for R&D Leadership and Exec as target
> is to what I was looking for.
>
>
>
> Best
>
> Daniele
>
>
>
>
>
>
>
> Sent from my iPhone
>
>
>
> On 12. Jun 2026, at 21.55, Erik Johnson <
> ejohnson@cloudsecurityalliance.org> wrote:
>
> 
>
> Thanks Eve
>
>
>
> Gail, Mike, Atul, et al - It's a pleasure to meet you all.
>
>
>
> I won't be at Identiverse, but the CSA will have a booth (#146). I've
> copied the appropriate folks from our ZT leadership team and our IETF POC.
> I'll plan to set up a meeting time poll for the week of 6/22 and/or 7/6
> where we can get together share information about our respective efforts
> and explore collaboration opportunities (potentially leading to some sort
> of liaison or partnership agreement, as appropriate).
>
>
>
> In the meantime I've included some notes and links below for reference FYI
> and we'd welcome any additional info you have to share as well.
>
>
>
> Best Regards,
>
> Erik Johnson
>
> Senior Research Analyst (CCSK, CISSP, CCSP, PMP) - Zero Trust and
> Financial Services
>
> Cloud Security Alliance
>
> ejohnson@cloudsecurityalliance.org
>
> https://www.linkedin.com/in/erikjohnson2/ [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Awww.linkedin.com*in*erikjohnson2*&source=gmail-imap&ust=1781895327000000&usg=AOvVaw0FR9jKGdBEyQl8ZowNeoDk__;Ly8vLy8!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skO2fjgOFg$>
>
>
>
>
>
> ·       IETF/CSA - Zero Trust Control and Policy Protocols (ZTCPP)
> initiative
>
> o   Draft charter [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Agithub.com*ietf-ztcpp*Charter*blob*main*Charter.md&source=gmail-imap&ust=1781895327000000&usg=AOvVaw1u-t7DeT-azmK-MiXD3tGD__;Ly8vLy8vLw!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skPqAftWeg$>
> for the Zero Trust Control and Policy Protocols (ZTCPP) WG
>
> o   CSA proposed protocol gap analysis which was presented last month
>
> o   IETF and CSA collaborative mailing lists and shares have been
> created; folks encouraged to join
>
> §  ztcpp@ietf.org - Sign up:
> https://mailman3.ietf.org/mailman3/lists/ztcpp.ietf.org/ [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Amailman3.ietf.org*mailman3*lists*ztcpp.ietf.org*&source=gmail-imap&ust=1781895327000000&usg=AOvVaw2MV-Ub6alZLDMLtnH81BwD__;Ly8vLy8v!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skNn4DRdlw$>
>
>
> §  CSA ZT-IETF Collaboration (
> CSA-ZT-IETF-Collaboration@groups.cloudsecurityalliance.org)
>
> §  CSA IETF collaboration folder [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Adrive.google.com*drive*folders*1HWJfpEtDz-PezrjnnI-s3XMhAG0YO4mF*usp*3Dsharing&source=gmail-imap&ust=1781895327000000&usg=AOvVaw0oLvB_inQ8FadVUG4PqwDK__;Ly8vLy8_JQ!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skOh0blZDw$>
>
> o   IETF 126 Meeting in Vienna, AU 7/18-24 *- generate more engagement*
>
> o   IETF 127 in SF, CA 11/14-20 - *target for official ZTCPP initiative
> approval & kick-off*
>
> ·       OpenID Shared Signals Framework (SSF) - related, but seemingly
> not duplicative initiative
>
> o   Shared Signals Working Group - OpenID Foundation [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Aopenid.net*wg*sharedsignals*&source=gmail-imap&ust=1781895327000000&usg=AOvVaw0_-UaFXU6MdEIWRkbrDq2-__;Ly8vLy8!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skPiAn_LHA$>
>
> o   OpenID Shared Signals Framework Specification 1.0 [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Aopenid.net*specs*openid-sharedsignals-framework-1_0.html&source=gmail-imap&ust=1781895327000000&usg=AOvVaw0JcefuPZiJWXpYJi09dQ4j__;Ly8vLw!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skOzRkO3BQ$>
>
>
> o   CrowdStrike and Zscaler Bring Continuous Identity Security to Zero
> Trust Access [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Awww.crowdstrike.com*en-us*blog*crowdstrike-zscaler-bring-continuous-identity-security-to-zero-trust-access*&source=gmail-imap&ust=1781895327000000&usg=AOvVaw0lpvu_9oDga2w8PmnPs_05__;Ly8vLy8v!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skNIJ88g7w$>
> (using SSF)
>
> o   Further investigation and outreach are appropriate and underway
>
>
>
> On Wed, Jun 10, 2026 at 7:03 PM Gail Hodges <gail@oidf.org> wrote:
>
> Erik
>
>
>
> I will join the welcome party, lovely to meet you and be connected with
> CSA. These are topics very close to our heart, and it is good to hear of
> your and IETF discussions.
>
>
>
> Cochairs are best placed to exchange in first instance.
>
>
>
> Myself and the staff team are more than happy to support on liaison
> agreements etc as your conversations mature, and you get a sense of how we
> might want to proceed. Feel free to cc me, but no need to await my
> availability.
>
>
>
> Gail
>
>
>
> *From: *Mike Kiser <mike.kiser@sailpoint.com>
> *Date: *Wednesday, June 10, 2026 at 3:47 PM
> *To: *Atul Tulshibagwale <atul.tulshibagwale@crowdstrike.com>, Eve Maler <
> eve@vennfactory.com>, Sean O'Dentity <iam@seanodentity.com>
> *Cc: *Erik Johnson <ejohnson@cloudsecurityalliance.org>, Gail Hodges <
> gail@oidf.org>
> *Subject: *Re: E-introductions: Erik Johnson of CSA and the OIDF/SSF clan
>
> Erik -
>
>
>
>   As Atul said, we can certainly carve out some time to discuss all things
> SSF (and other topics as they arise).
>
>
>
>    Thanks for the introduction, Eve....
>
>
>
> -Mike
> ------------------------------
>
> *From:* Atul Tulshibagwale <atul.tulshibagwale@crowdstrike.com>
> *Sent:* Wednesday, June 10, 2026 17:36
> *To:* Eve Maler <eve@vennfactory.com>; Sean O'Dentity <
> iam@seanodentity.com>
> *Cc:* Erik Johnson <ejohnson@cloudsecurityalliance.org>; gail.hodges <
> gail.hodges@oidf.org>; Mike Kiser <mike.kiser@sailpoint.com>
> *Subject:* Re: E-introductions: Erik Johnson of CSA and the OIDF/SSF clan
>
>
>
> @Sean O'Dentity <iam@seanodentity.com> FYI
>
>
>
> Hi Eve,
>
> Thanks for the introduction.
>
>
>
> Hi Erik,
>
> Nice to meet you, and happy to connect. Are you going to be at
> Identiverse? If so, we could schedule a time to meet while we are there.
> The three of us (Sean, Mike and I) have a session on Thursday, so we could
> meet then. If not, I'm happy to meet earlier.
>
>
>
> Thanks,
>
> Atul
>
>
>
> On Wed, Jun 10, 2026 at 2:30 PM Eve Maler <eve@vennfactory.com> wrote:
>
> Hi all,
>
>
>
> I got introduced to Erik Johnson of CSA through John Kindervag. Erik has
> been looking for the right connections in OIDF as follows:
>
>
>
> *We wanted to reach out to the OpenID foundation to share information and
> explore potential collaboration related to the Shared Signals Framework
> (SSF), *
>
> *and a seemingly related Zero Trust Control and Policy Interoperability
> (ZTCPP) initiative that we're collaborating with the IETF on.*
>
>
>
> *We'd like to connect with the appropriate SSF contacts and suggest
> arranging an information-sharing session to build awareness and explore
> collaboration opportunities. Please let us know who that would be on your
> end and I'll engage the right folks from the CSA Zero trust workgroup and
> our IETF ZTCPP counterparts. *
>
>
>
> *Best Regards,*
>
> *Erik Johnson*
>
> *Senior Research Analyst (CCSK, CISSP, CCSP, PMP) - Zero Trust and
> Financial Services*
>
> *Cloud Security Alliance*
>
> *ejohnson@cloudsecurityalliance.org <ejohnson@cloudsecurityalliance.org> *
>
> *https://www.linkedin.com/in/erikjohnson2/ [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Aurldefense.proofpoint.com*v2*url*u*3Dhttps-3A__www.linkedin.com_in_erikjohnson2_*26d*3DDwMFaQ*26c*3DeuGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM*26r*3D5sBoSfxIiqLtQortm8AmD_Id3ey-NnrSxMQ86O4reUc*26m*3Dl5fH92ok_AfOUxb8Xmnnkpi_UC2TLz27d5752O-050kefvKrJpFAxndXGWF6B-ay*26s*3Dnxoce5BVLbb4ixkH0TdVh_7tAJiz6-kwuTt4jBBUPYU*26e*3D&source=gmail-imap&ust=1781895327000000&usg=AOvVaw1QXmZFE2HHgHIw1ody_j7W__;Ly8vLz8lJSUlJSUlJSUlJSUl!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skOCL0J55A$>*
>
>
>
> Gail Hodges is OIDF’s Executive Director, and I’ve also added two of the
> three co-chairs of the Shared Signals Working Group, Atul Tulshibagwale of
> Crowdstrike and Mike Kiser of SailPoint. (Sean O’Dell of CVS Health is
> also a co-chair, but I’m afraid I don’t have his new email yet.)
>
>
>
> I hope this connection proves useful to all.
>
>
>
> Best,
>
> Eve
>
>
>
> <Logo (6) small.jpg>
>
>
> President & Founder, Venn Factory
>
> Digital Identity Strategist
>
> Author & Speaker
>
> Board Member
>
> *Cell and Signal: +1 (425) 345-6756 <+14253456756>*
>
>
>
> Eve’s new book, *Mastering Digital Identity*, is *available now
> [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Aurldefense.com*v3*__https:**Amasteringdigitalidentity.com__;!!BmdzS3_lV9HdKG8!zUii2t-Ee4HsVp0kJiUAOs4G7T4I1_Nt7Fvw1PZDi6ArcyNWooCHcIBZxTCCMBTpyVJ0RhklDbtRnpFp2yHUB9KYvr0$&source=gmail-imap&ust=1781895327000000&usg=AOvVaw2hCekh9ahyAqBydv2xzlaJ__;Ly8vLy8v!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skNMcXJ6Gw$>* [masteringdigitalidentity.com]
> [google.com]
> <https://urldefense.com/v3/__https:/www.google.com/url?q=https:**Aurldefense.com*v3*__https:**Amasteringdigitalidentity.com__;!!BmdzS3_lV9HdKG8!zUii2t-Ee4HsVp0kJiUAOs4G7T4I1_Nt7Fvw1PZDi6ArcyNWooCHcIBZxTCCMBTpyVJ0RhklDbtRnpFp2yHUB9KYvr0$&source=gmail-imap&ust=1781895327000000&usg=AOvVaw2hCekh9ahyAqBydv2xzlaJ__;Ly8vLy8v!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skNMcXJ6Gw$>
>
>
>
>
> [image: AICM CSO Award Winner - Email Signature.png]
> [cloudsecurityalliance.org]
> <https://urldefense.com/v3/__https:/cloudsecurityalliance.org/artifacts/ai-controls-matrix__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skNKSDMmaQ$>
>
>
> [image: AICM CSO Award Winner - Email Signature.png]
> [cloudsecurityalliance.org]
> <https://urldefense.com/v3/__https:/cloudsecurityalliance.org/artifacts/ai-controls-matrix__;!!BmdzS3_lV9HdKG8!2COeNO5Qf_DQgnH-xsIgkC64L6-EDRaSj8xX7xIdKS7JK5uliIh93wErGc-Vh6B2gs_G6ToRU5Q4Wyw4sULycPXn7jDZjmi4skNKSDMmaQ$>
>
>