Skip to content

FAPI_Meeting_Notes_2024 08 28_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes - August 28, 2024

  • Date: 2024-08-28 14:00 UTC
  • Location: Zoom

Agenda

[TOC]

Attendees

  • Nat Sakimura (Chair)
  • Mike Leszcz
  • Dave Tonge
  • Imran Ulghar
  • Bjorn Hjelm
  • Kosuke Koiwai
  • Peter Wallach
  • Hideki Ikeda
  • Robert Gallagher
  • Mark Andrus
  • Brian Campbell
  • Chris Wood
  • Filip Skokan
  • Dima Postnikov
  • Kelly Burgin
  • Gail Hodges

Events

SIDI Hub

  • Tuesday September 9 in DC

Identity Week

  • Gail and Mark will be presenting on the 11th and 12th
  • NIST 863-4 workshop
  • Venable Jeremy Grant Organization
  • Industry Workshop to Discuss the New Draft of NIST SP 800-63-4
  • Friday, September 13, 2024 
8:30 - 9:30 a.m. ET Breakfast and Registration
9:30 - 2:00 p.m. ET Program

NIST SP 864-3 Webinar

Fido Authenticate

  • Carlsbad, California
  • Oct 14-16

OpenID Foundation workshop

IIW

  • Oct 29-31

IETF

  • Nov 2 - 8 in Dublin

Calendar

  • 2025 events added to OIDF Google Calendar and website calendar
  • Send any missing events information to Mike Leszcz

External Liaisons

CFPB

  • Followed up with them regarding questions about membership makeup and other information.
  • Mark Haines will solicit feedback about OIDF draft standard setting organization application.
  • Meeting scheduled for Friday Aug 30

Canada

  • Shared FAPI2 milestones and CFPB updates with them
  • Mike will follow up this Friday
  • Call with Canada Open Banking team scheduled for 3rd week of September

Chile

  • Will have outreach workshop in October
  • Waiting for date confirmation
  • Will be hybrid workshop in Santiago to be led by John Bradley pending availability
  • Will share details later

SAMA

  • Joseph and Mike met with new SAMA director on Monday Aug. 26
  • Shared with them the FAPI 2.0 status and milestones
  • Continuing to work on their FAPI2 transition plan scheduled for second half of 2025

FDX

  • Joseph, Gail met with co-chairs Steven Smit and Franklin
  • Want to work closely with OIDF
  • Would like a single standards body for US and Canada
  • Working on their own RFC based on FAPI and considering including the protocol in their standard
  • Proposed a partnership before OIDF applies to the CFPB
  • Call scheduled for Friday to prepare for in-person meeting in DC on September 13
  • So far, feedback seems positive

Pull Requests

PR #512 - add reference to fapi2 security analysis

  • Updated to IEEE link provided by Pedram
  • Resolved

PR #513 - Add a note alerting readers to the fact bcp195 changes

  • Add note that BCP195 updates periodically and that implementers are expected to be compliant with the new changes within 12 months or sooner depending on nature of change
  • Dave to remove “should be” and change to “12 months if not sooner”
  • Will merge

PR #514 - attempt at address key compromise issue

  • Grouped them all under key compromise in security considerations
  • Recommends regular automated key rotations, jwk_uri endpoint usage
  • Key scope - limit keys for single purpose usage
  • Stateful credentials - credentials such as access tokens and refresh tokens can be instantly revoked and prevented from being used again
  • Multiple credentials from the same authorization be explicitly established and recorded so they can be revoked at the same time
  • Many open banking deployments do not follow recommendations because they want certified keys for signing
  • Avoid mentioning time period for key rotations due to differing requirements
  • NIST document did not mention key rotation, only key scope is referenced
  • Change wording from single use to single purpose
  • JWT access tokens should have state and persisted in a database for checking later
  • Compromised keys can be used to forge access tokens so short lived tokens do not help
  • Change ‘instantly revoked” to ‘revoked’
  • Need discussion on tradeoffs and impacts as recommendation may not apply for all situations
  • There are other flavors of stateless tokens that differs from ones being described by recommendations
  • Change hard recommendation to recommend that the tradeoffs be considered for stateful and stateless tokens
  • Dave to create new PR for stateful credentials and make updates for other suggested changes

PR #515 - update refs to RFCs for http signatures

  • merged

Issues

FAPI2 Security Profile

#425 - FAPI 2.0 Purpose and FAPI WG Scope

  • Website text copied from charter which is outdated
  • Dave proposed some changes to the charter
  • Nat will confirm with OIDF consul regarding wording

#621 - Implementations of FAPI2 Message Signing - Particularly HTTP Message Signatures

  • Need implementations before spec can proceed to final

Other Issues

Any Other Business

  • No additional items raised

The meeting was adjourned after addressing all agenda items.

Clone this wiki locally