-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 11 27_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Mike Leszcz (OIDF)
- Kosuke Koiwai
- Hideki Ikeda
- Joseph Heenan (OIDF & Authlete)
- George Fletcher
- Nat Sakimura
- Dima Postnikov
- Peter Stanley (OBL)
- Dave Tonge
- Filip Skokan
- Daniel Fett
- Axel Nennker (DT)
-
Gartner Identity & Access Management Summit (December 9-11, 2024)
- In Dallas, Texas
- OIDF presentation and Shared Signals demos planned
- Details available on OIDF web and Google calendars
-
OAuth Security Workshop 2025 (February 26-28, 2025)
- https://oauth.secworkshop.events/osw2025
- Location: Reykjavik, Iceland
- OIDF is a sponsor
- Final deadline for presentation submissions: January 12, 2025
- Certification team will meet prior to workshop
- Completed workshop for UAE TTPs last week
- Overview of OIDF and FAPI spec
- Demonstration of UAE FAPI profile conformance tests
- ~45 participants from 15-20 organizations
- Recording and deck published to OIDF website
- https://openid.net/presentations-media/
- Question raised about error codes when clients don't send required DPoP requests
- Consensus that "invalid_request" is appropriate error code
- Discussion of T-Mobile US requiring sender-constrained tokens for new APIs
- Noted that some implementations may need to support both DPoP and non-DPoP flows
- Conformance suite returns invalid_grant but that could be due to the use of PAR
- PR #523 - IANA registration section updates
- PR #524 - JAR errata fixes
- PR #525 - Name spelling correction
- Extended discussion on client requirements
- Concerns about implementation complexity during transition period
- Agreement to merge based on working group consensus despite not being unanimous
- Decision to document reasoning in PR comments
copies current text regarding HTTP signatures into new draft
- Agreement to restart the public review process
- Message Signing spec to be handled separately
- One PR remaining for HTTP signatures separation
- Discussion of potential FAPI 1.1 vs errata approach for security updates
- Waiting for clarification on what changes can be included in errata
- Need to balance supporting existing ecosystems while encouraging FAPI 2 adoption
- Consideration of certification implications
- Dave to document PR #522 decision reasoning and merge
- Nat to check with Mike Jones regarding precedent for security changes in errata
- Dave to verify and close remaining issue on FAPI 2 attacker model
- Continue work on separating HTTP signatures from message signing spec
Next call will be December 4, 2024.