-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2023 03 22_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Date & Time: 2023-03-22T14:00Z
- Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
- Self: https://github.com/openid/fapi/wiki/FAPI_Meeting_Notes_2023-03-15_Atlantic
Agenda
The meeting was called to order at 14:02 UTC.
- Attending: Dave, Nat, Chris, Takahiko, Michael, Mike L. Dima, Daniel, Justin, Kelly, Brian, Filip, Bjorn, Lukasz, Kosuke, Gail
- Regrets: Joseph
- Guest:
- Adopted as presented as draft agenda.
- Registration page is now open. * https://openid.net/2023/03/17/registration-workshop-at-microsoft/
- In the new website, it is going to be a single source.
- Mark is leading the discussion. Several meetings.
- Deadlines were postponed to April 14.
- Nat has provided a few comments pointing to FAPI as a good practice for security - security is typically not composable and has to take the protocol as a whole with an appropriate security model and analysis to go with.
- Link to the comment sheet that OIDF is compiling: * https://docs.google.com/spreadsheets/d/1JHDypzbKg8x2AMfC_z4pzDBk4waVJBp2/edit#gid=571622526
- KSA * OP Testing: https://openid.net/certification/fapi_op_testing/ * RP Testing: https://openid.net/certification/fapi_rp_testing/
- Dave has sent the fixed Implementer's draft documents to Mike J.
- Dima is applying the fix and is sending the draft out.
- Apart from one PR that we are parking until HTTP signature is settled, there is no standing PR.
- Request/Response binding fix is waiting for IETF result next week.
8.1. Proposed new FAPI certification test: private_key_jwt client authentication assertion where aud contains multiple values (Filip)
- https://github.com/openid/fapi/issues/403
- related to #501
- see https://github.com/openid/fapi/issues/403 as well.
- Filip is going to record the result of the discussion in the ticket.
- none
The call adjourned at 14:59