-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 06 12_Pacific
Nat Sakimura edited this page Jul 10, 2026
·
2 revisions
- Date & Time: 2025-06-13 01:00 UTC
- Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
[ Meeting Cancelled due to Low Quorum ]
Agenda
The meeting was called to order at 00:00 UTC.
- Attendees: Anoop, Dima, Mark
- Regrets:
- June 3-6 - Identiverse - Las Vegas
- June 17-18 - Identity Week Europe 2025 - Amsterdam
- July 19-25 - IETF 123 - Madrid
- October 20: OIDF events including workshop prior to IIW
- November 1-7: IETF 124 in Montreal
OIDF calendar on website is current: https://openid.net/calendar/ Members can contact mike.leszcz@oidf.org with any events for the second half of 2025.
- Mike shared current public review periods for (on Atlantic call):
-
- Proposed Final EAP ACR Values Specification
-
- Proposed OpenID Attachments 1.0 Final Specification
-
- Proposed OpenID for Verifiable Presentations Final Specification
-
- Proposed Implementer's Draft of OpenID Connect Relying Party Metadata Choices
PR #540 * Has ongoing discussions * Members asked to review and continue discussions for next week
PR #541 * There's a pending comment regarding URL-safe values for state parameters * Needs concrete proposal or text changes before accepting
PR #542 * Related to FAPI 2 implementation guidance on x-<headers> * Nat asked members to review it during the week * https://github.com/openid/fapi/issues/290
- Issuer Identifier with MTLS#. [ Follow up from last call ]
-
- Mark raised a new concern regarding issuer identifiers when using MTLS
-
- Many Australian banks host their discovery document on one domain (e.g., cdr.bank.com.au) but have MTLS endpoints on a different domain (e.g., secure.cdr.bank.com.au)
-
- Issue with what the correct issuer should be in this scenario
-
- Dima offered to follow up with Mark offline
-
- Mark will create a ticket to track this issue
Issue #730: FAPI 1 Baseline 5.2.3 Public Client Interpretation
- Nat filed this issue just before the call after receiving a question earlier in the day. The issue concerns section 5.2.3 (Public Client) of FAPI 1 Baseline, specifically the interpretation of:
-
- "If 'openid' is not in the scope value, then public client: 9. shall include the state parameter defined in Section 4.1.1 of [RFC6749]; 10. shall verify the scope received in the token response is either an exact match, or contains a subset of the scope sent in the request; 11. shall verify state received in the authorization response is identical to the state provided by the client in the authorization request."
-
- The question is whether points 10 and 11 apply only if 'openid' is not in the scope (as the current text suggests), or if they should apply regardless. Peter Stanley noted that based on the structure, the natural reading would be that all three points (9, 10, 11) are conditional on 'openid' not being in the scope.
Next call will be an Atlantic Call.