-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 05 07_Atlantic
- Dave Tonge (Chair)
- Mike Leszcz (OIDF)
- Kosuke Koiwai
- Robert Gallagher (Mastercard)
- Bjorn Hjelm
- Jake Fenley
- Filip Skokan
- Brian Campbell
- Imran Ulghar (OBL)
- Roll Call
- Adoption of Agenda
- Events (Mike L.)
- External Orgs & Liaisons (Mike L.)
- PRs (Dave)
- Issues (Dave)
- AOB (Nat)
Mike Leszcz provided the following updates:
- May 5 – DCP WG event – Berlin (prior to EIC) – presentations published: https://openid.net/presentations-media/
- May 6-9 -- EIC –– Berlin
- Workshop deck published: https://openid.net/presentations-media/
- May 20-23 -- ID4Africa -– Addis Ababa, Ethiopia (https://id4africaevents.com/) (Gail & Elizabeth)
- May -- Rwanda Open Banking Event/Workshop (private) – May (Mark Haine will be participating virtually)
- June 3-6 -- Identiverse – Las Vegas
- June 17-18 -- Identity Week Europe 2025 — Amsterdam
- July 19-25 -- IETF 123 — Madrid
The OIDF calendar on the website is current (as is the OIDF Google calendar): https://openid.net/calendar/
Mike Leszcz noted the following public review periods in progress:
- Public Review Period for Proposed Final EAP ACR Values Specification: https://openid.net/public-review-period-for-proposed-final-eap-acr-values-specification/
- Public Review Period for Proposed OpenID Attachments 1.0 Final Specification: https://openid.net/public-review-period-for-proposed-proposed-openid-attachements-1-0-final-specification/
- Public Review Period for Proposed OpenID for Verifiable Presentations Final Specification: https://openid.net/public-review-period-for-proposed-openid-verifiable-presentations-final-specification/
The group discussed finalizing the FAPI 2.0 Message Signing specification, focusing on creating an appropriate abstract for the document as part of the OIDF process requirements.
Key discussion points:
-
Initially, Dave proposed describing it as "an API security profile that provides interoperable support for non-repudiation against OAuth 2 base request and responses."
-
Issues raised:
- Filip suggested changing "OAuth 2" to "FAPI 2" to be more specific
- Brian raised concerns about claiming "non-repudiation" in the abstract when that claim is qualified later in the document
-
Brian noted that the spec is essentially profiling three specific artifacts for signing:
- Signed authorization requests
- Signed authorization responses
- Signed introspection responses
-
After discussion, a simpler abstract was proposed:
"OIDF FAPI 2.0 Message Signing is an API security profile that provides interoperable support for:
- Signed authorization requests
- Signed authorization responses
- Signed introspection responses"
-
Brian also raised concerns about retroactively applying process requirements to finalized documents, specifically regarding JARM errata fixes being combined with the Message Signing PR.
-
Resolution: Dave will adjust the PR to:
- Use the simplified abstract that accurately describes what the spec provides
- Remove the JARM-related changes from this PR to decouple them
- Handle the JARM errata separately
Dave noted that there are other pending PRs related to implementation advice that need to be addressed in future meetings.
No specific issues were discussed.
No additional business was raised.
Next regular call will be held on May 14, 2025.
Meeting adjourned after approximately 19 minutes due to light attendance (many members attending EIC in Berlin).