-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 08 14_Atlantic
Here are detailed meeting notes from the transcript in markdown format:
- Nat Sakimura (Chair)
- Dave Tonge
- Marcus Almgren
- Imran Ulghar
- Bjorn Hjelm
- Kosuke Koiwai
- Peter Wallach
- Hideki Ikeda
- Robert Gallagher
- Mark Andrus
- Brian Campbell
- Peter Stanley (OBL)
- Events
- External Liaisons
- Pull Requests
- Issues
- FAPI Security Profile
- FAPI 2.0 Message Signing
- CIBA
- Other Issues
- Any Other Business
- OpenID Foundation workshop at Cisco on Monday, October 28th (prior to IAW)
- Registration open until Friday, October 18th, 12 PM Pacific Time
- Registration link provided in chat
2025 events added to OIDF Google Calendar and website calendar
- Several OpenID Connect specifications accepted as publicly available specifications by ISO
- Will be published with ISO numbers in coming days
- PR #496 - remove grant management and other non final specs
- removes non-final specs and updates introduction
- approved and merged
-
Issue #684: FAPI2SP should reference formal analysis
- Formal analysis link provided by Dima.
- https://openid.net/wordpress-content/uploads/2022/12/Formal-Security-Analysis-of-FAPI-2.0_FINAL_2022-10.pdf
- Dave to review this week.
-
Issue #692: Consider recommendations from Cyber Safety Review Board report
- Discussed Cyber Safety Review Board report.
- Dave asked whether if there is any link to documents regarding key rotation
- NIST SP 800-57 Part 1 - https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final
- Dima commented on recommendations
- Team to review Dima's notes and suggestions.
-
Issue #690: Normative text within security considerations
- Move to appropriate clause
- Dave to remove normative references.
-
Issue #425: FAPI 2.0 Purpose and FAPI WG Scope
- Website text and charter need updating.
- Low priority for now.
-
Issue #693: Conformance testing for typ in request object for FAPI1
- Brian proposed testing for semantically equivalent typ values for Oauth-Authz-REQ+JWT for interoperability
- Certification team to discuss and report back next week.
-
Issue #691: Tweaks to BCP195 language
- PRs exist for BCP195 language
- Will be resolved when merged
-
Issue #687: FAPI 2 vs. Security BCP Gap Analysis
- Minor differences between FAPI2 and latest BCP (-29)
- PR regarding meeting requirements of BCP has been merged
- No consensus for PR for response mode.
- No objections to defer to implementation advice.
- Can be resolved
-
Issue #689: Clarification over how fast we expect implementors to update after an update is issued to BCP195
- Need clarification from WG on how soon BCP requirements will be enforced by conformance suite
- Will add warnings for now
- The certification team will discuss and report back on the Aug. 21 call.
-
Issue #678: 5.1.1. Introduction recommends Grant Management but the maturity level of the document makes it inappropriate to recommend it in the FINAL specification
- Can be closed by PR #496
-
Issue #663: HTTP Message Signatures and Digest Fields have just been published as RFCs 9421 & 9530
- Editorial issue, Dave to address this week.
-
Issue #565: Add privacy consideration
- Nat to address this week.
-
Issue #621: Implementations of FAPI2 Message Signing - Particularly HTTP Message Signatures
- No updates in 4 months. Need to check for implementations, especially of HTTP message signatures.
- Related to conformance suite issue https://gitlab.com/openid/conformance-suite/-/issues/1320
- Spec drafts need implementations to proceed to final
-
Issue #672: typ in request objects
- Resolved by PR #493
-
Issue #212: FAPI-CIBA; should id_token tie itself to the auth request?
- Old issue, needs review.
- Dave to revisit.
-
Issue #229: FAPI CIBA and ID Tokens
- Now that FAPI 2 Security Profile is mostly complete, discussion on this can begin.
- CIBA core requires openid scope
- Discuss whether ID Token is needed in CIBA for FAPI2
-
Issue #443: Missing Discovery Metadata for login_hint types and login_hint_token type: backchannel_endpoint_login_hint_token_values_supported
- PR #308 was merged but was not published
- IANA entries not registered yet
- Bjorn confirmed parallel ticket in MODRNA working group.
- Issue resolved.
-
Issue #489: Align FAPI-CIBA to FAPI2-baseline/advanced
- PR merged
- Resolved
-
Issue #506: Explicit security target
- Left open, needs review of CIBA text, especially cross-device scenarios
- Refer to cross-device flow document
-
Issue #556: Add reference to IETF cross device security doc
- Currently referring to individual draft
- Change to IETF draft version - https://datatracker.ietf.org/doc/draft-ietf-oauth-cross-device-security/
- References updated draft for cross-device security best practices.
-
Issue #558: update filenames for grant management and CIBA
- Dave to double-check and close if completed.
- filenames have been changed
- Resolved
-
Issue #559: Co-ordinate a joint call with Modrna WG on claims parameter for CIBA
- Dave to ping Joseph for feedback on EKYC group issue
-
Issue #597: CIBA - Make clear limitation of binding message
- Dave to create PR unless someone else volunteers.
-
Issue #609: FAPI CIBA
- Closed as PR #417 has been merged.
- No additional items raised
- Dave: Review formal analysis link (Issue #684)
- Dave: Remove normative references (Issue #690)
- Dave: Address editorial issues in FAPI 2.0 Message Signing (Issue #663)
- Nat: Address Issue #565
- Dave: Revisit old CIBA issue #12
- Dave: Double-check and close Issue #558 if completed
- Dave: Ping Joseph for feedback on EKYC group issue (Issue #559)
- Dave: Create PR for Issue #560 unless another volunteer steps forward
- Certification team: Discuss Issues #693 and #689, report back next week
The meeting was adjourned after addressing all agenda items.