Skip to content

FAPI_Meeting_Notes_2024 08 21_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes - August 14, 2024

  • Date: 2024-08-14 14:00 UTC
  • Location: Zoom
  • Attendees
    • Nat Sakimura (Chair)
    • Joseph Heenan
    • Mike Leszcz
    • Dave Tonge
    • Domingos Creado
    • Marcus Almgren
    • Imran Ulghar
    • Bjorn Hjelm
    • Kosuke Koiwai
    • Peter Wallach
    • Hideki Ikeda
    • Robert Gallagher
    • Mark Andrus
    • Brian Campbell
    • Peter Stanley (OBL)
    • Chris Wood
    • Filip Skokan
    • Dima Postnikov

Agenda

[TOC]

Events

OpenID Foundation workshop

Calendar

2025 events added to OIDF Google Calendar and website calendar

External Liaisons

CFPB

  • No activity since meeting a couple of weeks ago.
  • Followed up with them regarding questions about membership makeup and other information.
  • Mark Haines will solicit feedback about OIDF draft standard setting organization application.

Canada

  • No activity.
  • Waiting for CFPB

Chile

  • In process of coordinating a public outreach workshop
  • Will share details later

SAMA

  • Scheduled call for Monday Aiug. 26
  • Starting transition plan to FAPI 2.0

FDX

  • Having more discussions and activities will likely increase in September

FAPI 2.0 Status Update

  • Organizations/ecosystems are interested in status of FAPI 2.0 and timeline
  • Spec is nearing final
  • There are 6 outstanding issues remaining and PRs to address them are in the works
  • The expectation is that the issues will be resolved in a couple of weeks
  • Once issues are resolved, the 60 days public review period will start
  • Spec should be finalized around the end of the year.

Pull Requests

  • PR #508 - fixes #691 - Tweaks to BCP195 language

    • Approved and merged
  • PR #510 - fix type

    • Approved and merged
  • PR #512 - add reference to fapi2 security analysis

  • PR #511 - move normative text from security considerations to main document

    • Security considerations have normative text
    • Text moved unchanged to new sections under Cryptography and secrets
    • approved and merged

Issues

FAPI2 Security Profile

  • Issue #684: FAPI2SP should reference formal analysis

  • #695 - Very restrictive list of TLS ciphers suites

    • Joseph and Filip have replied that IETF WG is better place to ask the question since current draft no longer list ciphers and fully defers to BCP195
    • Closed
  • #694 - Unclear section 5.4 of FAPI2 security profile

    • Dag is under the impression that FAPI2 only allows EC keys and ask why RSA keys are mentioned
    • Brian and Filip clarified that others including RSA ones are allowed
    • Closed
  • #692 - Consider recommendations from Cyber Safety Review Board report

    • Nat provided some links to documents that addresses the various recommendations
    • Can adopt FAPI for REC11
    • Create security recommendation for key rotation, stateful credentials, credential linking and key scope
    • Stateful credentials - performance, scalability wise, it might be easier to use short-lived access tokens
    • Security considerations can mention that there is guidance that mentions OAuth 2 and OpenID. Can also mention benefits of DPoP and others
    • Dave will create initial PR
  • #687 - FAPI 2 vs. Security BCP Gap Analysis

    • FAPI is silent regarding response modes
    • There are some recommendations in security topics related to response modes and in browser communications, e.g. check message origin, etc…
    • WG does not object to closing issue
    • Resolved
  • #559 - Co-ordinate a joint call with Modrna WG on claims parameter for CIBA

    • Still a problem for people using eKYC and CIBA
    • Easier to address in FAPI-CIBA rather than CIBA Core
    • There a related issue in Modrna that is resulting in a CIBA extension
    • Modrna group issue 210 - https://github.com/openid/modrna/issues/209
  • #698 - Clarification over how fast we expect implementors to update after an update is issued to BCP195

    • How fast changes to BCPs will be enforced in conformance suites?
    • Add suggestion by Joseph - within 12 months
    • JWT BCP might have similar problem, but does not have BCP number yet
    • Add note that BCP is subject to change

Other Issues

Any Other Business

  • No additional items raised

The meeting was adjourned after addressing all agenda items.

Clone this wiki locally