-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 09 18_Atlantic
- Date & Time: 2024-09-18 14:00 UTC
- Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
Agenda
- Mike Leszcz - OIDF
- Hideki Ikeda
- Robert Gallagher
- Kosuke Koiwai
- Dave Tonge
- Nat Sakimura
- Mark Andrus
- Joseph Heenan (OIDF & Authlete)
- Filip Skokan
- Lukasz Jaromin
OIDF NIST SP 800-63 Feedback Sessions tomorrow and Friday. In these workshops, we will discuss the draft, gather community inputs, and form the OIDF's formal response. https://openid.net/nist-800-63-feedback-sessions/
OIDF co-hosting mDL hackathons with CA DMV on 10/1 at the CHM and 11/1 in Sacramento. Details here: https://openid.net/oidf-cohosts-mdl-hackathons/
Oct 25 – SIDI Hub Japan in Tokyo being hosted by the Japanese Government: https://sidi-hub.community/summits/
There is also a reception planned in conjunction with it.
OIDF workshop on Monday, October 28th prior to IIW at Cisco in San Jose. Registration is open and required: https://openid.net/registration-oidf-workshop-cisco-october-28-2024/
DCP WG on Monday AM prior IIW also at Cisco for those interested. Registration is open and required: https://www.eventbrite.com/e/oidf-dcp-working-group-hybrid-meeting-at-cisco-monday-october-28-2024-tickets-991309442227.
February 26-28 OSW – Reykjavik, Iceland. Session submission deadlines are 11/24 and 1/12: https://oauth.secworkshop.events/osw2025
OIDF calendar on website is current: https://openid.net/calendar/
Six months of hard work paying off.
Successful meeting with CFPB. Our application seems to be good. We are applying minor fixes to the application.
LoI is imminent with FDX, with MoU to follow. OIDF and FDX both have their board meetings on Oct. 28.
WG especially thanked the Mastercard team for helping out.
Explained the situation with CFPB. The next meeting with the Open Banking Canada team is on Sept. 24.
An outreach workshop is being coordinated. Oct 2. Hybrid. John Bradley will be locally representing.
Domingos and Joseph are working through open issues around the certification test. Once they are cleared and confirmed, we will update the delivery schedule of the certification test.
https://bitbucket.org/openid/fapi/pull-requests/518
The FAPI Security profile already imposes algorithm restrictions, so the server is required to sign.
The PR seems to be fine, apart from the typo.
https://bitbucket.org/openid/fapi/pull-requests/520
The foundation secretariat pointed out that the attacker model is missing security considerations.
https://openid.net/wg/resources/naming-and-contents-of-specifications/
However, it does not seem to add value. The WG decided to push back.
https://bitbucket.org/openid/fapi/pull-requests/519
Removal looks fine. New draft will go through the call for adoption.
5.1. #704: RFC6125 is obsolete
- #704
- In the secretariat review, it was pointed out the RFC6125 is obsolete.
- It is superseded by https://datatracker.ietf.org/doc/rfc9525/
- Need to investigate and potentially update
5.2. #702: Multiple HTTP message signatures in a single HTTP message
- #702
- Taka's proposal for handling multiple signatures with tags
- General agreement, will create PR after other spec changes
- The issue was assigned to Dave.
5.3. #701: FAPI Overview Page text change
- #701
- Some changes made to FAPI page on OpenID Foundation website
- Additional updates needed for overview section
- Nat will further fix the page.
- JARM has not completed the IANA submission for OAuth parameters. Dave will pick it up.
- FAPI1 errata WGLC to be made.
- Tom will follow up with the scope change process next week.
None.
- Dave to push back on unnecessary security considerations for attacker model
- Dave to investigate RFC 9525 and potential updates needed
- Dave to draft IANA registration email for JARM
- Dave to prepare for last call on FAPI 1 Errata
- Dave to create PR for HTTP signing multiple signatures proposal after other changes
- Nat to update FAPI overview section on website
The meeting adjourned at 14:50 UTC