-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 08 28_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Date: 2024-08-28 14:00 UTC
- Location: Zoom
Agenda
[TOC]
- Nat Sakimura (Chair)
- Mike Leszcz
- Dave Tonge
- Imran Ulghar
- Bjorn Hjelm
- Kosuke Koiwai
- Peter Wallach
- Hideki Ikeda
- Robert Gallagher
- Mark Andrus
- Brian Campbell
- Chris Wood
- Filip Skokan
- Dima Postnikov
- Kelly Burgin
- Gail Hodges
- Tuesday September 9 in DC
- Gail and Mark will be presenting on the 11th and 12th
- NIST 863-4 workshop
- Venable Jeremy Grant Organization
- Industry Workshop to Discuss the New Draft of NIST SP 800-63-4
- Friday, September 13, 2024 8:30 - 9:30 a.m. ET Breakfast and Registration 9:30 - 2:00 p.m. ET Program
- August 28
- Link to NIST SP 800-63-4 page that includes details and registration link for NIST workshop in 2 hours at 12pm - ET: https://csrc.nist.gov/pubs/sp/800/63/4/2pd
- Carlsbad, California
- Oct 14-16
- OpenID Foundation workshop at Cisco on Monday, October 28th (prior to IAW)
- Registration open until Friday, October 18th, 12 PM Pacific Time
- Registration link - https://openid.net/registration-oidf-workshop-cisco-october-28-2024/
- Agenda will be published after finalized
- Oct 29-31
- Nov 2 - 8 in Dublin
- 2025 events added to OIDF Google Calendar and website calendar
- Send any missing events information to Mike Leszcz
- Followed up with them regarding questions about membership makeup and other information.
- Mark Haines will solicit feedback about OIDF draft standard setting organization application.
- Meeting scheduled for Friday Aug 30
- Shared FAPI2 milestones and CFPB updates with them
- Mike will follow up this Friday
- Call with Canada Open Banking team scheduled for 3rd week of September
- Will have outreach workshop in October
- Waiting for date confirmation
- Will be hybrid workshop in Santiago to be led by John Bradley pending availability
- Will share details later
- Joseph and Mike met with new SAMA director on Monday Aug. 26
- Shared with them the FAPI 2.0 status and milestones
- Continuing to work on their FAPI2 transition plan scheduled for second half of 2025
- Joseph, Gail met with co-chairs Steven Smit and Franklin
- Want to work closely with OIDF
- Would like a single standards body for US and Canada
- Working on their own RFC based on FAPI and considering including the protocol in their standard
- Proposed a partnership before OIDF applies to the CFPB
- Call scheduled for Friday to prepare for in-person meeting in DC on September 13
- So far, feedback seems positive
- Updated to IEEE link provided by Pedram
- Resolved
- Add note that BCP195 updates periodically and that implementers are expected to be compliant with the new changes within 12 months or sooner depending on nature of change
- Dave to remove “should be” and change to “12 months if not sooner”
- Will merge
- Grouped them all under key compromise in security considerations
- Recommends regular automated key rotations, jwk_uri endpoint usage
- Key scope - limit keys for single purpose usage
- Stateful credentials - credentials such as access tokens and refresh tokens can be instantly revoked and prevented from being used again
- Multiple credentials from the same authorization be explicitly established and recorded so they can be revoked at the same time
- Many open banking deployments do not follow recommendations because they want certified keys for signing
- Avoid mentioning time period for key rotations due to differing requirements
- NIST document did not mention key rotation, only key scope is referenced
- Change wording from single use to single purpose
- JWT access tokens should have state and persisted in a database for checking later
- Compromised keys can be used to forge access tokens so short lived tokens do not help
- Change ‘instantly revoked” to ‘revoked’
- Need discussion on tradeoffs and impacts as recommendation may not apply for all situations
- There are other flavors of stateless tokens that differs from ones being described by recommendations
- Change hard recommendation to recommend that the tradeoffs be considered for stateful and stateless tokens
- Dave to create new PR for stateful credentials and make updates for other suggested changes
- merged
#425 - FAPI 2.0 Purpose and FAPI WG Scope
- Website text copied from charter which is outdated
- Dave proposed some changes to the charter
- Nat will confirm with OIDF consul regarding wording
#621 - Implementations of FAPI2 Message Signing - Particularly HTTP Message Signatures
- Need implementations before spec can proceed to final
- No additional items raised
The meeting was adjourned after addressing all agenda items.