-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 07 16_Atlantic
Date: 2025-07-16
Time: 14:01 UTC
- Nat Sakimura (Chair)
- Mike Leszcz - OIDF
- Joseph Heenan (OIDF & Authlete)
- Peter Stanley
- Kosuke Koiwai
- Dima Postnikov
- Bjorn Hjelm
- Christopher Robbertse (OB)
- Guilherme Niero
- Robert Gallagher (Mastercard)
- Hideki Ikeda
- Filip Skokan
- Brian Campbell
- Imran Ulghar (OBL) - left early
- Roll Call
- Adoption of Agenda
- Events
- External Orgs & Liaisons
- Conformance updates (Joseph)
- PRs
- Issues
- AOB
Mike Leszcz provided updates on upcoming events:
- July 19-25: IETF 123 — Madrid
- October 13-16: FIDO Authenticate — Carlsbad, CA
- October 27: OIDF events including workshop prior to IIW (date updated)
- October 28-30: IIW Fall 2025 — Mountain View
- November 1-7: IETF 124 Montreal
Key highlight: OIDF will host events on Monday, October 27th at Cisco San Jose with an after-lunch workshop. The DCP Working Group will meet in the morning, followed by the workshop, with the Board meeting in the afternoon.
Additional note: There will be an authentication booth session at IETF 123 Madrid. Filip Skokan confirmed attendance (3-hour trip from his location).
Mike Leszcz reported on ecosystem engagement:
- Domingos leading the KSA FAPI2 Profile development
- Development plan to be shared with SAMA soon
- Mike finalizing directed funding through Ozone to support development
- Whiteboard session held July 9th with OB CA team
- Participants: Gail, Joseph, Mark H., Mike L.
- Addressed FAPI2 questions and shared ecosystem experiences
-
Next steps:
- CA to continue regulatory process
- OIDF to share global reference architecture via Ecosystem Support CG
- Follow-up session to introduce Shared Signals
- New community group co-chaired by Dima, Mark Vestigi, and others
- Web pages launched: https://openid.net/cg/ecosystem-support-community-group/
- Meeting schedule to be added to OIDF calendar
Nat Sakimura provided significant update:
- Japanese Financial Services Agency started consultation on supervisory guideline amendments
- Phishing-resistant authentication becoming mandatory
- This effectively ends screen scraping for financial services in Japan
- Blog post available with machine translation: https://www.sakimura.org/en/2025/07/7271/
Joseph Heenan reported successful launch of FAPI2 Final tests:
- Security profile and message signing tests launched on schedule (previous Monday)
- Announcement: https://lists.openid.net/pipermail/openid-specs-fapi/2025-July/003344.html
-
Early certifications received from:
- Authlete
- Filip Skokan
- Okta
- Australian Connect ID profile also launched with Authlete certification
- Filip's RP certifications pending
- Final layout will follow OP format (7 columns for RPs)
- Marcus working on setup (currently on holiday)
Call to action: Encouraged other implementers to certify their solutions now that specs are final.
Nat Sakimura mentioned the notice of vote for proposed errata corrections to JWT Secured Authorization Response Mode (JARM):
All PRs discussed from: https://bitbucket.org/openid/fapi/pull-requests/
PR #542 (Issue #290)
- Status: Approved by Nat and Joseph
- Action: Ready for merge
- Status: Approved by Joseph
- Action: To be merged post-call
- Discussion: Joseph agreed with Dave's suggestion for URL-safe values
- Concern: Bullet point 4 about error responses - may create open redirect vulnerability
- Action: Joseph to add comments on the PR
- Discussion: Joseph noted correct point about self-signed certificates and JWKs
- Action: Joseph to add comments
- Status: Waiting for underlying specs to change
- Action: Put on hold
Active issues discussed from: https://github.com/openid/fapi/issues
Issue #738 (Deprecation of FAPI2 ID2 Tests)
- Context: With FAPI2 final tests launched, need to deprecate implementer's draft tests
- Proposed timeline: End of March 2026 (6+ months)
-
Affected ecosystems:
- Connect ID: Dima confirmed March 2026 timeline works
- UAE: Joseph to confirm with contacts
- Action: Joseph to coordinate with UAE team
Issue #736 (FAPI Post-Quantum Cryptography)
- Discussion: Previously discussed, but unclear path for FAPI 1.1
- FAPI 2 approach: Reference BCP 195 which will be updated for post-quantum
- FAPI 1.1 needs: Updates for JWS/JWE algorithms beyond PS256, ES256, EdDSA
- Peter Stanley's request: Wants clarity on OIDF approach for FAPI 1.1 ecosystems
- Action: Nat to follow up on overall FAPI 1.1 status
Issue #688 (TLS 1.2 Cipher Suites)
- Context: FAPI 1 references 4 cipher suites, 2 are deprecated
- Status: Change already made to draft spec to reference BCP 195
- Need: Push through errata process
- Additional: Waiting for RFC 7523 bis for private key JWT changes
- Peter's request: Wants comprehensive FAPI 1.1 agenda item for future meeting
Issue #725 (FAPI 2 Security Profile Final Conformance)
- Status: Covered in conformance section
- Action: Can be closed
Issue #737 (FAPI Without Long-lived API Access)
- Context: Ecosystems not using refresh tokens
- Filip's analysis: No failure conditions in OIDC suite for missing refresh tokens
- Joseph's note: Client test for refresh token rotation marked as UAE-specific
-
Dima's request:
- Mark Haine to review
- Joseph to comment on certification approach
- Outcome: Likely no certification suite changes needed
Issue #734 (Private Key Storage Recommendations)
- Status: Reassigned to implementation and deployment advice
- Joseph's view: Some security considerations already out of scope
- Duplicate: Also related to Issue #735
-
Action:
- Nat to request volunteer for drafting text
- Dima suggests mailing list feedback on approach
- Consider referencing specific NIST specifications
Issue #732 (OAuth 2.0 Attestation-based Client Authentication)
- Status: Waiting for IETF outcome
- Action: Filip to report after IETF 123 Madrid
Issue #733 (JARM Downgrade)
- Context: Brian Campbell provided background
- Status: Too late for errata in current JARM voting process
- Potential solution: Brief mention in implementation advice
- Action: Comment on issue if actionable changes needed
-
Nat Sakimura: - Follow up on FAPI 1.1 errata process status - Request volunteer for Issue #734 text drafting - Add comprehensive FAPI 1.1 agenda item for future meeting
-
Joseph Heenan: - Merge approved PRs #542 and #539 - Add comments to PRs #541 and #540
- Coordinate with UAE team on test deprecation timeline - Comment on Issue #737 regarding certification approach -
Dima Postnikov: - Send ecosystem support CG meeting dates to Mike - Ping Mark Haine for Issue #737 review - Report on Connect ID migration progress
-
Filip Skokan: - Report on IETF 123 outcomes for Issue #732
-
Peter Stanley: - Monitor FAPI 1.1 developments - Consider creating issue for cipher suite updates if needed
No additional business items raised.
Meeting adjourned at 15:00 UTC
Regular weekly meeting scheduled for following week.