Skip to content

FAPI_Meeting_Notes_2024 08 14_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

Here are detailed meeting notes from the transcript in markdown format:

FAPI Working Group Meeting Notes - August 14, 2024

Attendees

  • Nat Sakimura (Chair)
  • Dave Tonge
  • Marcus Almgren
  • Imran Ulghar
  • Bjorn Hjelm
  • Kosuke Koiwai
  • Peter Wallach
  • Hideki Ikeda
  • Robert Gallagher
  • Mark Andrus
  • Brian Campbell
  • Peter Stanley (OBL)

Agenda

  1. Events
  2. External Liaisons
  3. Pull Requests
  4. Issues
    • FAPI Security Profile
    • FAPI 2.0 Message Signing
    • CIBA
    • Other Issues
  5. Any Other Business

Events

OpenID Foundation workshop

  • OpenID Foundation workshop at Cisco on Monday, October 28th (prior to IAW)
  • Registration open until Friday, October 18th, 12 PM Pacific Time
  • Registration link provided in chat

Calendar

2025 events added to OIDF Google Calendar and website calendar

External Liaisons

ISO

  • Several OpenID Connect specifications accepted as publicly available specifications by ISO
  • Will be published with ISO numbers in coming days

Pull Requests

  • PR #496 - remove grant management and other non final specs
    • removes non-final specs and updates introduction
    • approved and merged

Issues

FAPI Security Profile

  • Issue #684: FAPI2SP should reference formal analysis

  • Issue #692: Consider recommendations from Cyber Safety Review Board report

    • Discussed Cyber Safety Review Board report.
    • Dave asked whether if there is any link to documents regarding key rotation
    • NIST SP 800-57 Part 1 - https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final
    • Dima commented on recommendations
    • Team to review Dima's notes and suggestions.
  • Issue #690: Normative text within security considerations

    • Move to appropriate clause
    • Dave to remove normative references.
  • Issue #425: FAPI 2.0 Purpose and FAPI WG Scope

    • Website text and charter need updating.
    • Low priority for now.
  • Issue #693: Conformance testing for typ in request object for FAPI1

    • Brian proposed testing for semantically equivalent typ values for Oauth-Authz-REQ+JWT for interoperability
    • Certification team to discuss and report back next week.
  • Issue #691: Tweaks to BCP195 language

    • PRs exist for BCP195 language
    • Will be resolved when merged
  • Issue #687: FAPI 2 vs. Security BCP Gap Analysis

    • Minor differences between FAPI2 and latest BCP (-29)
    • PR regarding meeting requirements of BCP has been merged
    • No consensus for PR for response mode.
    • No objections to defer to implementation advice.
    • Can be resolved
  • Issue #689: Clarification over how fast we expect implementors to update after an update is issued to BCP195

    • Need clarification from WG on how soon BCP requirements will be enforced by conformance suite
    • Will add warnings for now
    • The certification team will discuss and report back on the Aug. 21 call.
  • Issue #678: 5.1.1. Introduction recommends Grant Management but the maturity level of the document makes it inappropriate to recommend it in the FINAL specification

    • Can be closed by PR #496

FAPI 2.0 Message Signing

  • Issue #663: HTTP Message Signatures and Digest Fields have just been published as RFCs 9421 & 9530

    • Editorial issue, Dave to address this week.
  • Issue #565: Add privacy consideration

    • Nat to address this week.
  • Issue #621: Implementations of FAPI2 Message Signing - Particularly HTTP Message Signatures

  • Issue #672: typ in request objects

    • Resolved by PR #493

CIBA

  • Issue #212: FAPI-CIBA; should id_token tie itself to the auth request?

    • Old issue, needs review.
    • Dave to revisit.
  • Issue #229: FAPI CIBA and ID Tokens

    • Now that FAPI 2 Security Profile is mostly complete, discussion on this can begin.
    • CIBA core requires openid scope
    • Discuss whether ID Token is needed in CIBA for FAPI2
  • Issue #443: Missing Discovery Metadata for login_hint types and login_hint_token type: backchannel_endpoint_login_hint_token_values_supported

    • PR #308 was merged but was not published
    • IANA entries not registered yet
    • Bjorn confirmed parallel ticket in MODRNA working group.
    • Issue resolved.
  • Issue #489: Align FAPI-CIBA to FAPI2-baseline/advanced

    • PR merged
    • Resolved
  • Issue #506: Explicit security target

    • Left open, needs review of CIBA text, especially cross-device scenarios
    • Refer to cross-device flow document
  • Issue #556: Add reference to IETF cross device security doc

  • Issue #558: update filenames for grant management and CIBA

    • Dave to double-check and close if completed.
    • filenames have been changed
    • Resolved
  • Issue #559: Co-ordinate a joint call with Modrna WG on claims parameter for CIBA

    • Dave to ping Joseph for feedback on EKYC group issue
  • Issue #597: CIBA - Make clear limitation of binding message

    • Dave to create PR unless someone else volunteers.
  • Issue #609: FAPI CIBA

    • Closed as PR #417 has been merged.

Other Issues

Any Other Business

  • No additional items raised

Action Items

  1. Dave: Review formal analysis link (Issue #684)
  2. Dave: Remove normative references (Issue #690)
  3. Dave: Address editorial issues in FAPI 2.0 Message Signing (Issue #663)
  4. Nat: Address Issue #565
  5. Dave: Revisit old CIBA issue #12
  6. Dave: Double-check and close Issue #558 if completed
  7. Dave: Ping Joseph for feedback on EKYC group issue (Issue #559)
  8. Dave: Create PR for Issue #560 unless another volunteer steps forward
  9. Certification team: Discuss Issues #693 and #689, report back next week

The meeting was adjourned after addressing all agenda items.

Clone this wiki locally