-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 01 17_Atlantic
- Date & Time: 2024-01-17 14:00 UTC
- Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
Agenda
The meeting was called to order at 14:04 UTC.
- Attendees: Nat Sakimura, Joseph Heenan, Brian Campbell, Daniel Fett, Filip Skokan, George Fletcher, Kosuke Koiwai, Mark Andrus, Matt Belanger, Peter Stanley, Peter Wallach, Robert Gallager, Victor Lu, Kelley Burgin, Bjorn Hjelm, Dave Tonge, Dima Posnikov, Matt Belanger, Rifaat Shekh-Yusef
- Regrets:
Tokyo, Japan on Thursday, January 18, 2024
https://openid.net/registration-oidf-workshop-tokyo-2024/
In-person registration is full, virtual attendance is still available.
https://www.openid.or.jp/summit/2024/en/
Friday, January 19, 2024, 10:00 - 18:00
Submissions are open.
Deadline: Early February
https://oauth.secworkshop.events/osw2024
Ceasing FAPI 1.0 RW ID-2 Certification at the end of the next year.
We probably can close https://github.com/openid/fapi/issues/570
Mandating FAPI 2 Security Profile. It came out last year.
https://bitbucket.org/openid/fapi/pull-requests/455
May be external dependency on attacker numbering and attacker numbers are mentioned in security analysis but refers to one specific version of the spec
Changes were made to attacker model in response to analysis
Suggested to add note in attacker model stating that analysis was based on previous version of the attacker model
Added table to point out differences in the attacker model
Text starting on line 335 does not seem to be explicit enough.
Joseph is going to add comments
5.4. Issue #658 - Use of FAPI with mandatory MTLS
https://github.com/openid/fapi/issues/658
Various ecosystems are mandating use of MTLS everywhere
Conformance suite has ecosystem specific tests
Goal is to move away from developing ecosystem specific tests and standardize methods
If a new variant is created, it will work like the current way; vendors will test to make sure it works for each ecosystem
Currently, if non-plain FAPI profile is selected, MTLS is used everywhere and will pull in ecosystem specific tests
May not be addressed with just creating a new variant
Goal is to make it easier for new ecosystems and not make more divergence
If would be beneficial to have some note/guidance in implementation advice what to watch out for if you want to choose certain approaches/variants
Expand section on MTLS everywhere and make recommendations when MTLS everywhere is selected
Filip will create PR
5.5. Issue #647- No normative statement on id_token encryption
- https://github.com/openid/fapi/issues/647
- Discussed if ID Token encryption should just cause a warning.
- Filip and Brian argued that the line should be removed.
The meeting adjourned at 14:__.