Skip to content

FAPI_Meeting_Notes_2019 11 27_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Meeting Notes (2019-11-27)

Date & Time: 2019-11:27 14:00 UTC

Location: GoToMeeting https://global.gotomeeting.com/join/321819862

Agenda

The meeting was called to order at 14:05 UTC.

  1. Dave
  2. Nat
  3. Brian
  4. Daniel
  5. Joseph
  6. Kosuke
  7. Ralph
  8. Stuart
  9. Torsten
  10. Bjorn
  11. Pedram Hosseyni
  • Adding #153
  • Adding ETSI Report
  • Stances towards FDX, ACDS, Open Banking, etc.
  • Abstracted model for Consent and Revoke as an International Standard Token Establishment for multi-regional
    • Special Call at 5 PM Pacific Time on the December 5th.
  • Pushing JWS HTTPS.
  • Draft JWS Headers due shortly before Jan 20 next meeting.
  • eIDAS scheme are based on CMS and JWS is a good candidate to replace it.
  • Polish API, STET coming together. Portugal deferred to Berling Group. BG committed to JWS.
  • ETSI wants to reuse IANA registry.
  • Justin presented OAuth XYZ, Torsten on PAR and RAR.
  • There would be an activity to do OAuth 3.0 based on XYZ but there would be 2.1.
  • Migration path needs to be prepared, e.g., versioned endpoints.
  • Cavage was presented to Sec Dispatch and Justin and Annabel is writing a new draft to be presented to HTTP group.

https://github.com/openid/fapi/issues

5.1.   #163: more description of the security model (Daniel)

5.2.   #255: certification clarification request: location of discovery document

Joseph is going to create a pull request.

5.3.   #207: RS256 vs PS256 (again)

Nat need to create a pull request.

5.4.   #236

Closed with pull request #145

5.5.   #216 TLS_ECDHE_ECDSA cipher suites

Pending Dave's email intraction with crypto experts.

5.6.   #232: Part 1: Complete the privacy consideration section

Nat to write the text.

5.7.   #240: FAPI-R: length/entropy of authorization code / refresh token / client_secret

Waiting for Dave's text.

5.8.   #242: Missing Bibliography Reference to FAPILI

Around Xmas time by Stuart.

5.9.   #273: Security considerations re large access tokens

To be recorded in the implementer's advice document. Concrete text is needed.

https://bitbucket.org/openid/fapi/pull-requests/

The meeting was adjourned at 14:56 UTC.

Clone this wiki locally