-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 09 11_Atlantic
- Date & Time: 2024-09-11-14:00 UTC
- Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
- Bjorn Hjelm
- Nat Sakimura
- Lukasz Jaromin
- Robert Gallagher
- Imran Ulghar
- Aaron Parecki
- Dave Tonge
- Hideki Ikeda
- Brian Campbell
- Dima Postnikov
This week in Washington DC
Tuesday SIDI
Wednesday - Thursday Identity Week
Veneable NIST SP-863-4 Workshop Friday
Sep 10-12
September 10 @ 8:00 am – September 11 @ 5:00 pm
https://fidoalliance.org/event/fido-apac-summit-2024/
OpenID Foundation workshop at Cisco on Monday, October 28th (prior to IAW) Registration open until Friday, October 18th, 12 PM Pacific Time
Registration link - https://openid.net/registration-oidf-workshop-cisco-october-28-2024/
Agenda will be published after finalized.
Please note that the DCP WG is confirmed to meet at Cisco on Monday, October 28th 9am-12pm PT prior to IIW Fall 2024:
Cisco Campus - Bldg. 10 - Union Square - 300 E Tasman Dr - San Jose, CA 95134
Registration link: https://www.eventbrite.com/e/oidf-dcp-working-group-hybrid-meeting-at-cisco-monday-october-28-2024-tickets-991309442227.
Dublin, Ireland Nov 2 - 8
Prior to SIDI Hub events in Tokyo
No substantial updates.
There is no open PRs right now.
Dave, Aaron, Nat, Imran, Brian, and others discussed the need for explicit verification of #699 ID tokens in their security profile. They considered the implications of not validating tokens, the potential for non-repudiation scenarios, and the limitations of their security analysis. The team also discussed the possibility of creating a separate specification for OpenID Connect in conjunction with their current profile.
ID Tokens are not mentioned much in the spec. Verifying the ID Token doesn’t add much more security because it’s returned in a TLS back-channel but it should be verified for non-repudiation purposes and best practices.
OIDC does not require ID Token signature validation returned from the back-channel and also allows unsigned ID Tokens.
NIST SP-863-4 public draft now requires signature verification for FAL-1.
Security Analysis shows that signature verification is not required.
Security Profile only specifies requirements for the attacker model and is independent of OIDC.
Brian expressed concerns about the disjoint and reactive nature of the current spec, suggesting a need for a more cohesive approach. Dave proposed reassigning the issue to the message signing spec and having a discussion with Dima and Philip. Nat suggested creating a small document providing guidance for those using FAPI with OpenID Connect. Dima agreed with these suggestions, noting that most ecosystems will likely use FAPI 2 in conjunction with OpenID Connect. Dave and Dima discussed the placement of a security profile within their project, with Dima suggesting it could be included in the ecosystem level profile.
Dave, Aaron, Dima, and Nat discussed the status of the Fedcm feature, which is currently experimental and at risk of not making it into the final API if there's insufficient interest. Dima expressed his intention to provide feedback on this.
Assigned as Message Signing issue.
5.2. #677: FAPI + FedCM
Dave, Aaron, Dima, and Nat discussed the status of the Fedcm feature (#677), which is currently experimental and at risk of not making it into the final API if there's insufficient interest. Dima expressed his intention to provide feedback on this. Folks should chime in into the issue.
Could possibly affect Open Banking use cases where not all RPs are registered with all AS and relationships are managed through Federation
5.3. #698 - FAPI2 Acknowledgements
Added additional acknowledgements
5.4. #697 - Separate out HTTP signatures from the message signing spec
Dave is working on PR
Dave also mentioned the need to update the working group's charter and website content, which is outdated. For scope change, Nat will ask the foundation counsel what process is needed to make the scope smaller. For the overview page, Nat will see if he can edit the page. (The issue #701 was created for this.) It still mentions developing JSON schemas. Change “utilized the data stored in a financial account and interact with the financial account” to “provide and use secure APIs”.
Brian asked if Tony Nodelin still Co-chairs the working group. Technically he still does as he has not yet stepped down. Nat will ask Tony his intention.
Nat asked the team to consider whether they're ready to start the security analysis on the Grant management. This issue will be taken up next week.
The WG should review FAPI1 Errata changes to start the review process. Dave will create a diff of the changes
The meeting adjourned at 14:45 UTC