Skip to content

FAPI_Meeting_Notes_2019 11 20_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Meeting Notes (2019-11-20)

Date & Time: 2019-11:20 14:00 UTC

Location: GoToMeeting https://global.gotomeeting.com/join/321819862

Agenda

The meeting was called to order at 14:05 UTC.

  1. Bjorn
  2. Nat
  3. Craig Borysowich (Payments Canada)
  4. Dima Postnikov
  5. Joseph
  6. Kosuke
  7. Stuart Low
  8. Rob Otto

Open Banking shared a new roadmap consultation mainly focused to wrap up functional spec. e.g., 9 CMA banks should be made available the sweeping service. CMA 9 must pass the functional test.

Nat started to explore getting PAS Submitter status.

Justin's slide https://datatracker.ietf.org/meeting/106/materials/slides-106-secdispatch-http-signing

It was discussed in the Dispatch group. Advised to do it in HTTP group.

Annabel has split Justin's PoP spec. into HTTP bit and OAuth Token presentation bit.

It looks like some evolution of Cavage may happen but it still is in the early days.

Tomorrow 8AM UTC.

https://www.youtube.com/watch?v=q096sY6L9-E

Exploring whether Justin's or Torsten's spec to be adopted.

Analysis of the current draft needs to be done.

Joseph has been talking with the EY team on testing. EY + Data 61 to drawing the testing plan. Data 61 wants to start an independent test.

https://bitbucket.org/openid/fapi/pull-requests/

https://github.com/openid/fapi/issues

5.1.   #255: certification clarification request: location of discovery document

Joseph is going to create a pull request.

5.2.   #207: RS256 vs PS256 (again)

Nat need to create a pull request.

5.3.   #236

Closed with pull request #145

5.4.   #216 TLS_ECDHE_ECDSA cipher suites

Pending Dave's email intraction with crypto experts.

5.5.   #232: Part 1: Complete the privacy consideration section

Nat to write the text.

5.6.   #240: FAPI-R: length/entropy of authorization code / refresh token / client_secret

Waiting for Dave's text.

5.7.   #242: Missing Bibliography Reference to FAPILI

Around Xmas time by Stuart.

5.8.   #273: Security considerations re large access tokens

To be recorded in the implementer's advice document. Concrete text is needed.

The meeting was adjourned at 14:56 UTC.

Clone this wiki locally