-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 02 12_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Date: 2025-02-12 14:00 UTC
- Location: Zoom
- Nat Sakimura (Chair)
- Dave Tonge
- Joseph Heenan (OIDF & Authlete)
- Filip Skokan
- Dima Postnikov
- Lukasz Jaromin (Raidiam)
- Imran Ulghar (OBL)
- Kosuke Koiwai
- Hideki Ikeda
- Peter Stanley (OBL)
- Mike L.
- Roll Call
- Adoption of Agenda
- Events
- External Orgs & Liaisons
- Issues
- PRs
- Action Items
- AOB
- No significant updates from Mike or other participants
- FAPI 2.0 Security Profile and Attacker Model Final Specifications vote closing on February 15th at 12pm PT
Dave Tonge reported:
- Working group last call has finished
- No pushback received
- Pull request pending to update references
- Waiting on updated reference to security research
- Need to get the correct reference from security researchers before proceeding
Extensive discussion on handling audience value restrictions in private key JWT:
Key Points:
- Current certification tests require authorization servers to accept token endpoint as audience
- Future security updates will require using issuer as audience
- Challenge: How to handle transition period and certification testing
Proposed Solutions:
- Add warning tests instead of failures for new behavior
- add test aud=issuer with warning status on failure
- Create separate certification profiles for different ecosystems
- Maintain backwards compatibility for existing ecosystems (UK/Brazil banks)
Decisions:
- Certification team will develop a proposal for handling the transition
- Need to balance security improvements with existing ecosystem stability
- May cause UK, Brazil ecosystems to fail recertification
- May also cause interoperability problems if some AS only supports new behavior and some only supports current behavior
- Working group supports not forcing new implementations to certify with soon-to-be-deprecated behavior
- Discussion of differences between implementers draft and final version
- Dima Postnikov has analysis ready and will share for blog post
- Request to share analysis before Monday for blog post preparation
- Need to update documentation to help ecosystems transition from implementers draft
#719 - FAPI2-MS: Add reference to security analysis
Waiting for Pedram
#716 - FAPI 2.0 Message Signing reliance on draft-ietf-oauth-jwt-introspection-response-12
Resolved with PR #533
#721 - fapi2 security profile / attacker model - update security BCP to RFC
Resolved with PR #532
#722 - summary of changes between FAPI2SP ID2 and final
Make summary of changes for announcements Dima has been working on it and will share when completed
#720 - FAPI2 acknowledgement updates
Resolved wit PR #532
Several PRs were reviewed and merged:
- PR #533: Updating references to RFC 9700 and 9701
- PR #532: Management updates
- Acknowledgement updates and typo fixes
- Certification team to develop proposal for handling audience value transition
- Dima to share analysis of differences between implementers draft and final version
- Team to review and approve pending PRs
- Dave to reach out to Pedram/Ralph regarding security analysis reference
- Update specs with editorial changes
Next call scheduled for same time next week.