Skip to content

FAPI_Meeting_Notes_2025 07 16_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes

Date: 2025-07-16
Time: 14:01 UTC

Attendees

  • Nat Sakimura (Chair)
  • Mike Leszcz - OIDF
  • Joseph Heenan (OIDF & Authlete)
  • Peter Stanley
  • Kosuke Koiwai
  • Dima Postnikov
  • Bjorn Hjelm
  • Christopher Robbertse (OB)
  • Guilherme Niero
  • Robert Gallagher (Mastercard)
  • Hideki Ikeda
  • Filip Skokan
  • Brian Campbell
  • Imran Ulghar (OBL) - left early

Agenda

  1. Roll Call
  2. Adoption of Agenda
  3. Events
  4. External Orgs & Liaisons
  5. Conformance updates (Joseph)
  6. PRs
  7. Issues
  8. AOB

1. Events

Mike Leszcz provided updates on upcoming events:

  • July 19-25: IETF 123 — Madrid
  • October 13-16: FIDO Authenticate — Carlsbad, CA
  • October 27: OIDF events including workshop prior to IIW (date updated)
  • October 28-30: IIW Fall 2025 — Mountain View
  • November 1-7: IETF 124 Montreal

Key highlight: OIDF will host events on Monday, October 27th at Cisco San Jose with an after-lunch workshop. The DCP Working Group will meet in the morning, followed by the workshop, with the Board meeting in the afternoon.

Additional note: There will be an authentication booth session at IETF 123 Madrid. Filip Skokan confirmed attendance (3-hour trip from his location).

2. External Organizations & Liaisons

Mike Leszcz reported on ecosystem engagement:

Saudi Arabia (SAMA)

  • Domingos leading the KSA FAPI2 Profile development
  • Development plan to be shared with SAMA soon
  • Mike finalizing directed funding through Ozone to support development

Canada

  • Whiteboard session held July 9th with OB CA team
  • Participants: Gail, Joseph, Mark H., Mike L.
  • Addressed FAPI2 questions and shared ecosystem experiences
  • Next steps:
    • CA to continue regulatory process
    • OIDF to share global reference architecture via Ecosystem Support CG
    • Follow-up session to introduce Shared Signals

Ecosystem Support Community Group

3. Japanese Financial Market Update

Nat Sakimura provided significant update:

  • Japanese Financial Services Agency started consultation on supervisory guideline amendments
  • Phishing-resistant authentication becoming mandatory
  • This effectively ends screen scraping for financial services in Japan
  • Blog post available with machine translation: https://www.sakimura.org/en/2025/07/7271/

4. Conformance Updates

Joseph Heenan reported successful launch of FAPI2 Final tests:

FAPI2 Final Launch

Relying Party Certifications

  • Filip's RP certifications pending
  • Final layout will follow OP format (7 columns for RPs)
  • Marcus working on setup (currently on holiday)

Call to action: Encouraged other implementers to certify their solutions now that specs are final.

5. Notice of Vote

Nat Sakimura mentioned the notice of vote for proposed errata corrections to JWT Secured Authorization Response Mode (JARM):

6. Pull Requests

All PRs discussed from: https://bitbucket.org/openid/fapi/pull-requests/

PR #542 (Issue #290)

  • Status: Approved by Nat and Joseph
  • Action: Ready for merge

PR #539 (Access Token Size Considerations)

  • Status: Approved by Joseph
  • Action: To be merged post-call

PR #541 (AS Rejecting Nonsense States)

  • Discussion: Joseph agreed with Dave's suggestion for URL-safe values
  • Concern: Bullet point 4 about error responses - may create open redirect vulnerability
  • Action: Joseph to add comments on the PR

PR #540 (DPoP vs mTLS Advice)

  • Discussion: Joseph noted correct point about self-signed certificates and JWKs
  • Action: Joseph to add comments

PR #529 (Pending)

  • Status: Waiting for underlying specs to change
  • Action: Put on hold

7. Issues

Active issues discussed from: https://github.com/openid/fapi/issues

Issue #738 (Deprecation of FAPI2 ID2 Tests)

  • Context: With FAPI2 final tests launched, need to deprecate implementer's draft tests
  • Proposed timeline: End of March 2026 (6+ months)
  • Affected ecosystems:
    • Connect ID: Dima confirmed March 2026 timeline works
    • UAE: Joseph to confirm with contacts
  • Action: Joseph to coordinate with UAE team

Issue #736 (FAPI Post-Quantum Cryptography)

  • Discussion: Previously discussed, but unclear path for FAPI 1.1
  • FAPI 2 approach: Reference BCP 195 which will be updated for post-quantum
  • FAPI 1.1 needs: Updates for JWS/JWE algorithms beyond PS256, ES256, EdDSA
  • Peter Stanley's request: Wants clarity on OIDF approach for FAPI 1.1 ecosystems
  • Action: Nat to follow up on overall FAPI 1.1 status

Issue #688 (TLS 1.2 Cipher Suites)

  • Context: FAPI 1 references 4 cipher suites, 2 are deprecated
  • Status: Change already made to draft spec to reference BCP 195
  • Need: Push through errata process
  • Additional: Waiting for RFC 7523 bis for private key JWT changes
  • Peter's request: Wants comprehensive FAPI 1.1 agenda item for future meeting

Issue #725 (FAPI 2 Security Profile Final Conformance)

  • Status: Covered in conformance section
  • Action: Can be closed

Issue #737 (FAPI Without Long-lived API Access)

  • Context: Ecosystems not using refresh tokens
  • Filip's analysis: No failure conditions in OIDC suite for missing refresh tokens
  • Joseph's note: Client test for refresh token rotation marked as UAE-specific
  • Dima's request:
    • Mark Haine to review
    • Joseph to comment on certification approach
  • Outcome: Likely no certification suite changes needed

Issue #734 (Private Key Storage Recommendations)

  • Status: Reassigned to implementation and deployment advice
  • Joseph's view: Some security considerations already out of scope
  • Duplicate: Also related to Issue #735
  • Action:
    • Nat to request volunteer for drafting text
    • Dima suggests mailing list feedback on approach
    • Consider referencing specific NIST specifications

Issue #732 (OAuth 2.0 Attestation-based Client Authentication)

  • Status: Waiting for IETF outcome
  • Action: Filip to report after IETF 123 Madrid

Issue #733 (JARM Downgrade)

  • Context: Brian Campbell provided background
  • Status: Too late for errata in current JARM voting process
  • Potential solution: Brief mention in implementation advice
  • Action: Comment on issue if actionable changes needed

8. Action Items

  1. Nat Sakimura: - Follow up on FAPI 1.1 errata process status - Request volunteer for Issue #734 text drafting - Add comprehensive FAPI 1.1 agenda item for future meeting

  2. Joseph Heenan: - Merge approved PRs #542 and #539 - Add comments to PRs #541 and #540
    - Coordinate with UAE team on test deprecation timeline - Comment on Issue #737 regarding certification approach

  3. Dima Postnikov: - Send ecosystem support CG meeting dates to Mike - Ping Mark Haine for Issue #737 review - Report on Connect ID migration progress

  4. Filip Skokan: - Report on IETF 123 outcomes for Issue #732

  5. Peter Stanley: - Monitor FAPI 1.1 developments - Consider creating issue for cipher suite updates if needed

9. Any Other Business

No additional business items raised.

Meeting adjourned at 15:00 UTC

Next Meeting

Regular weekly meeting scheduled for following week.

Clone this wiki locally