Skip to content

FAPI_Meeting_Notes_2024 07 31_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

Meeting Notes

Date: July 31, 2024
Participants: Dave Tonge, Dima Postnikov, Lukasz Jaromin, Joseph Heenan, and others

1. Introduction and Agenda

  • The meeting started with a small group. Dave Tonge suggested starting with the usual agenda and asked participants to add their names in the chat for attendance records.
  • Mike and Nat were absent. No updates were received from Mike on events.

2. Agenda Review

  • Dave Tonge shared the basic agenda and inquired if anyone had additional items to discuss. No further additions were made.

3. PR Discussion

  • PR #509:

    • Discussion on merging PR #509. There were some change requests made by Ralph and Mark, which Dima addressed.
    • Lukasz had reservations about the value of some of the changes but agreed to discuss them.
    • After further discussion, it was agreed to keep the current wording, and PR #509 was merged.
  • PR #496:

    • Dave Tonge updated on PR #496, mentioning that changes were made to follow recommendations. He requested additional approvals for merging.
    • Lukasz reviewed and approved the changes, noting that most changes involved reshuffling and aligning documents.

4. Discussion on Specifications

  • Discussion on how the use of RAR (Rich Authorization Requests) is referenced in the spec. Lukasz and Dima debated the inclusion of RAR in the current specifications.
  • It was decided to keep the RAR note in the current spec but to consider moving it to a more appropriate document in the future.

5. Key Issues Addressed

  • TLS 1.2 and BCP 195:

    • A small PR was discussed to adjust the language related to the use of TLS 1.2 and its relation to BCP 195.
    • The group agreed to remove the reference to TLS 1.2 specifically and keep the general recommendation.
  • FAPI 2 Formal Analysis:

    • A suggestion was made to ensure the FAPI 2 formal analysis is referenced correctly throughout the document. Dave agreed to handle this.
  • Cyber Safety Review Board Report:

    • Discussion on the Cyber Safety Review Board's recommendation related to key rotation and scope. Joseph highlighted the need for additional security considerations around these topics.
    • It was agreed that the group would explore referencing existing best practices from NIST or similar organizations.

6. Conclusion

  • The meeting concluded with the agreement to merge the discussed PRs and continue refining the specifications. Further work on implementation guidance and framework documents was noted as a priority.

Clone this wiki locally