-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 01 23_Pacific
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
Date & Time: 2025-01-24 00:00 UTC Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
Agenda
The meeting was called to order at 00:00 UTC.
- Attendees: Nat, Mark, Anoop
- Regrets:
- OAuth Security Workshop 2025 (February 26-28, 2025) Location: Reykjavik, Iceland
- OIDF is a sponsor
-
- Final deadline for presentation submissions: January 12, 2025
-
- Certification team will meet prior to workshop
- DICE: March 4-5 in Zurich
- ISO/IEC JTC 1/SC 27/WG5: March 10-15, 2025 in Fairfax
- ISO/IEC JTC 1/SC 27: March 17-18, 2025 in Fairfax
- MOSIP Connect: March 11-13 in Philippines
- IETF: March 15-21 in Bangkok
- OIDF Workshop: April 7th (prior to IIW)
- IIW Spring 2025: April 8-10
- FDX (US) Summit April 21-24 (Washington/Gaylord National Harbor, US)
OIDF calendar on website is current: https://openid.net/calendar/
- US open banking CFBB approves FDX (Financial Data Exchange) as standard body.
- [Issue #716] Message Signing reliance draft - https://github.com/openid/fapi/issues/716
-
- discussed regarding reliance on draft OAuth 2.0 JWT Introspection Response and Agreement to:
-
-
- Add a note in the document about the draft reference to be updated before final publication
-
-
-
- Update references once RFC is published
-
- [Issue #597 ] Binding message limitation - https://github.com/openid/fapi/issues/597
-
- Need to reference cross-device BCP and security analysis
-
- Tim provided diagram illustrating binding message limitations
-
- Agreement to reference relevant sections from cross-device BCP
- [Issue #674] Same-device flows. Raised by Curity https://github.com/openid/fapi/issues/674 . Consensus that:
-
- Same-device flows should use redirect rather than CIBA
-
- Adding special tokens for same-device flows not recommended
-
- May be better suited for discussion at OSW (Security workshop)
FAPI CIBA and OpenID connect Integration - Should FAPI CIBA require OpenID Connect.
Current status:
- Core CIBA spec is heavily tied to OpenID Connect
- Discussion about making it optional in FAPI CIBA profile
- Concerns raised about maintaining consistency between core CIBA and FAPI CIBA
Key points:
- Could borrow parameters like login_hint from OpenID Connect without requiring full implementation
- Need to consider impact on existing implementations
- Agreement to draft potential wording for making OpenID Connect optional
- Private Key JWT Audience Restriction. [PR # 529] https://bitbucket.org/openid/fapi/pull-requests/529
-
- Discussion on approach for different specs:
-
- For FAPI 1 errata: Decision to wait for underlying specs to be updated
-
- For FAPI CIBA: Agreement that it falls back to core FAPI specifications
-
- For CIBA itself: Recommendation to wait for OIDC errata rather than making piecemeal changes
-
- Action: Dave to add comments to both PRs explaining the decision
- Final Review Process
-
- Agreement to restart the public review process
-
-
- Final Specification public review period: Monday, December 9, 2024 to Friday, February 7, 2025 (60 days)
-
-
-
- Final Specification vote announcement: Saturday, January 25, 2025
-
-
-
- Final Specification early voting opens: Saturday, February 1, 2025
-
-
-
- Final Specification voting period: Saturday, February 8, 2024 to Saturday, February 15, 2025 (7 days)*
-
-
- Message Signing spec to be handled separately
-
- One PR remaining for HTTP signatures separation
Discussion of three main areas to focus on:
- FAPI CIBA
- HTTP Signatures
- Implementation & Deployment Advice
Decision: Prioritize FAPI CIBA due to:
- Existing conformance tests
- Potential deployment plans in Brazil
- Relatively contained scope of remaining work
- FAPI WG Charter update (scope, process ...) Soon it is going to be published WG openid charter page.
Next call will be an Pacific Call. Next Pacific call will be in Next year (02-06-2025 @ 5pm PST) UTC - 02-07-2025 1:00 AM.