-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 08 21_Atlantic
- Date: 2024-08-14 14:00 UTC
- Location: Zoom
- Attendees
- Nat Sakimura (Chair)
- Joseph Heenan
- Mike Leszcz
- Dave Tonge
- Domingos Creado
- Marcus Almgren
- Imran Ulghar
- Bjorn Hjelm
- Kosuke Koiwai
- Peter Wallach
- Hideki Ikeda
- Robert Gallagher
- Mark Andrus
- Brian Campbell
- Peter Stanley (OBL)
- Chris Wood
- Filip Skokan
- Dima Postnikov
Agenda
[TOC]
- OpenID Foundation workshop at Cisco on Monday, October 28th (prior to IAW)
- Registration open until Friday, October 18th, 12 PM Pacific Time
- Registration link - https://openid.net/registration-oidf-workshop-cisco-october-28-2024/
- Agenda will be published after finalized
2025 events added to OIDF Google Calendar and website calendar
- No activity since meeting a couple of weeks ago.
- Followed up with them regarding questions about membership makeup and other information.
- Mark Haines will solicit feedback about OIDF draft standard setting organization application.
- No activity.
- Waiting for CFPB
- In process of coordinating a public outreach workshop
- Will share details later
- Scheduled call for Monday Aiug. 26
- Starting transition plan to FAPI 2.0
- Having more discussions and activities will likely increase in September
- Organizations/ecosystems are interested in status of FAPI 2.0 and timeline
- Spec is nearing final
- There are 6 outstanding issues remaining and PRs to address them are in the works
- The expectation is that the issues will be resolved in a couple of weeks
- Once issues are resolved, the 60 days public review period will start
- Spec should be finalized around the end of the year.
-
PR #508 - fixes #691 - Tweaks to BCP195 language
- Approved and merged
-
PR #510 - fix type
- Approved and merged
-
PR #512 - add reference to fapi2 security analysis
- Adds reference to FAPI 2.0 security analysis document
- The URL now references the Wordpress document on openid.net
- Would prefer to link to the source on an academic site similar to FAPI 1.0 security analysis
- https://www.computer.org/csdl/proceedings-article/csf/2024/620300a017/1W0eVAyO3DO
- Will check with Petram to confirm URL
-
PR #511 - move normative text from security considerations to main document
- Security considerations have normative text
- Text moved unchanged to new sections under Cryptography and secrets
- approved and merged
-
Issue #684: FAPI2SP should reference formal analysis
- Formal analysis link provided by Dima.
- https://openid.net/wordpress-content/uploads/2022/12/Formal-Security-Analysis-of-FAPI-2.0_FINAL_2022-10.pdf
- Dave to review this week.
-
#695 - Very restrictive list of TLS ciphers suites
- Joseph and Filip have replied that IETF WG is better place to ask the question since current draft no longer list ciphers and fully defers to BCP195
- Closed
-
#694 - Unclear section 5.4 of FAPI2 security profile
- Dag is under the impression that FAPI2 only allows EC keys and ask why RSA keys are mentioned
- Brian and Filip clarified that others including RSA ones are allowed
- Closed
-
#692 - Consider recommendations from Cyber Safety Review Board report
- Nat provided some links to documents that addresses the various recommendations
- Can adopt FAPI for REC11
- Create security recommendation for key rotation, stateful credentials, credential linking and key scope
- Stateful credentials - performance, scalability wise, it might be easier to use short-lived access tokens
- Security considerations can mention that there is guidance that mentions OAuth 2 and OpenID. Can also mention benefits of DPoP and others
- Dave will create initial PR
-
#687 - FAPI 2 vs. Security BCP Gap Analysis
- FAPI is silent regarding response modes
- There are some recommendations in security topics related to response modes and in browser communications, e.g. check message origin, etc…
- WG does not object to closing issue
- Resolved
-
#559 - Co-ordinate a joint call with Modrna WG on claims parameter for CIBA
- Still a problem for people using eKYC and CIBA
- Easier to address in FAPI-CIBA rather than CIBA Core
- There a related issue in Modrna that is resulting in a CIBA extension
- Modrna group issue 210 - https://github.com/openid/modrna/issues/209
-
#698 - Clarification over how fast we expect implementors to update after an update is issued to BCP195
- How fast changes to BCPs will be enforced in conformance suites?
- Add suggestion by Joseph - within 12 months
- JWT BCP might have similar problem, but does not have BCP number yet
- Add note that BCP is subject to change
- No additional items raised
The meeting was adjourned after addressing all agenda items.