Skip to content

FAPI_Meeting_Notes_2025 02 12_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Meeting Notes (February 12, 2025)

  • Date: 2025-02-12 14:00 UTC
  • Location: Zoom

Participants

  • Nat Sakimura (Chair)
  • Dave Tonge
  • Joseph Heenan (OIDF & Authlete)
  • Filip Skokan
  • Dima Postnikov
  • Lukasz Jaromin (Raidiam)
  • Imran Ulghar (OBL)
  • Kosuke Koiwai
  • Hideki Ikeda
  • Peter Stanley (OBL)

Regret

  • Mike L.

Agenda

  1. Roll Call
  2. Adoption of Agenda
  3. Events
  4. External Orgs & Liaisons
  5. Issues
  6. PRs
  7. Action Items
  8. AOB

Notes

1. Events & External Updates

  • No significant updates from Mike or other participants
  • FAPI 2.0 Security Profile and Attacker Model Final Specifications vote closing on February 15th at 12pm PT

2. Message Signing Status

Dave Tonge reported:

  • Working group last call has finished
  • No pushback received
  • Pull request pending to update references
  • Waiting on updated reference to security research
  • Need to get the correct reference from security researchers before proceeding

3. FAPI 1.0 Private Key JWT Issues

Extensive discussion on handling audience value restrictions in private key JWT:

Key Points:

  • Current certification tests require authorization servers to accept token endpoint as audience
  • Future security updates will require using issuer as audience
  • Challenge: How to handle transition period and certification testing

Proposed Solutions:

  1. Add warning tests instead of failures for new behavior
    • add test aud=issuer with warning status on failure
  2. Create separate certification profiles for different ecosystems
  3. Maintain backwards compatibility for existing ecosystems (UK/Brazil banks)

Decisions:

  • Certification team will develop a proposal for handling the transition
  • Need to balance security improvements with existing ecosystem stability
    • May cause UK, Brazil ecosystems to fail recertification
    • May also cause interoperability problems if some AS only supports new behavior and some only supports current behavior
  • Working group supports not forcing new implementations to certify with soon-to-be-deprecated behavior

4. FAPI 2 Implementation Updates

  • Discussion of differences between implementers draft and final version
  • Dima Postnikov has analysis ready and will share for blog post
  • Request to share analysis before Monday for blog post preparation
  • Need to update documentation to help ecosystems transition from implementers draft

5 Issues

#719 - FAPI2-MS: Add reference to security analysis

Waiting for Pedram

#716 - FAPI 2.0 Message Signing reliance on draft-ietf-oauth-jwt-introspection-response-12

Resolved with PR #533

#721 - fapi2 security profile / attacker model - update security BCP to RFC

Resolved with PR #532

#722 - summary of changes between FAPI2SP ID2 and final

Make summary of changes for announcements Dima has been working on it and will share when completed

#720 - FAPI2 acknowledgement updates

Resolved wit PR #532

6. PRs Reviewed

Several PRs were reviewed and merged:

  • PR #533: Updating references to RFC 9700 and 9701
  • PR #532: Management updates
  • Acknowledgement updates and typo fixes

7. Action Items

  1. Certification team to develop proposal for handling audience value transition
  2. Dima to share analysis of differences between implementers draft and final version
  3. Team to review and approve pending PRs
  4. Dave to reach out to Pedram/Ralph regarding security analysis reference
  5. Update specs with editorial changes

8. Next Meeting

Next call scheduled for same time next week.

Links Referenced

Clone this wiki locally