Skip to content

FAPI_Meeting_Notes_2024 12 04_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Meeting Notes - December 4, 2024

Attendees

  • Nat Sakimura
  • Dave Tonge
  • Mike Leszcz (OIDF)
  • Imran Ulghar (OBL)
  • Peter Stanley (OBL)
  • Peter Wallach (Mastercard)
  • Bjorn Hjelm
  • Mark Andrus
  • Kosuke Koiwai
  • Chris Wood
  • Filip Skokan
  • Hideki Ikeda (Authlete)
  • George Fletcher

Agenda

  1. Roll Call
  2. Adoption of Agenda
  3. Events
  4. External Orgs & Liaisons
  5. PRs
  6. Issues
  7. AOB

Events & Ecosystem Updates (Mike L.)

Events

  • Gartner IAM Summit next week in Dallas
    • All Send presentation available
    • Shared Signals WG has presentation and 3-4 interop demonstrations
    • Sessions not available virtually
  • OSW 2025 in Iceland (end of February)
    • Final presentation submission deadline: January 12th

Ecosystem Updates

  • UAE FAPI TTP Certifications
    • Opening soon
    • Step-by-step guide developed for ecosystem
    • OIDF/FAPI overview presentation planned for UAE Central Bank officials
  • Norway Health ID
    • ~350 organizations using FAPI 2 for e-prescriptions
    • Blog post planned about successful FAPI 2 adoption

Specification Status Updates (Dave)

  • Security Profile and Attack Model
    • Last changes agreed
    • Public review process to start this week
  • FAPI 1 Errata
    • Can include normative changes for security fixes
    • No need for FAPI 1.1
  • JARM
    • PR merged fixing IANA registration text
    • Working group last call for errata to begin
  • Message Signing
    • HTTP signing separation PR to be merged
    • Working group last call to follow

Pull Requests

  1. PR #528 - Editorial changes to correct numbering
  2. PR #526 - Document link updates
  3. PR #519 - Separating HTTP signing (pending merge resolution)

Issues Discussed

  1. FAPI 1 Errata (Issue #700)
    • Private key JWT language to be imported from FAPI 2
    • New issue created to track this
  2. JARM IANA Registrations (Issue #703)
    • Fixed through merged PR
  3. Working Group Purpose and Scope (Issue #425)
    • Awaiting details on new rechartering process
    • Need to align with current working group activities

Next Steps

  1. Start public review process for Security Profile and Attack Model
  2. Proceed with FAPI 1 and JARM errata processes
  3. Begin working group last call for Message Signing after HTTP signing separation
  4. Dave to follow up on administrative tasks to move specifications forward

AOB

  • Future discussion needed on:
    • HTTP signing implementation issues
    • CIBA
    • FedCM
    • Camara
    • Android Carrier OpenID
    • Federation

The meeting ended early to allow time for moving tasks forward.

Clone this wiki locally