Skip to content

FAPI_Meeting_Notes_2025 07 24_Pacific

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Agenda & Meeting Notes (2025-07-24)

Date & Time: 2025-07-24 17:00 PST

Attendees

  • Anoop
  • Dima

****** Meeting Canceled due low attendance ********

Agenda

  1. Roll Call
  2. Adoption of Agenda
  3. Events
  4. External Orgs & Liaisons
  5. PRs
  6. Issues
  7. AOB

Meeting Notes

1. Roll Call & Agenda Adoption

2. Events Update

** Events Updates**

  • IETF 120 Montreal is coming up (July 23).

    • Nat will attend remotely only
    • Two OAuth sessions and one OpenID Connect session scheduled

** Upcoming Events: **

  • July 19-25, 2025: IETF 123 — Madrid
  • October 13-16, 2025: FIDO Authenticate — Carlsbad, CA
  • October 27, 2025: OIDF events including workshop prior to IIW (date updated)
  • October 28-30, 2025: IIW Fall 2025 — Mountain View
  • November 1-7, 2025: IETF 124 — Montreal

https://docs.google.com/spreadsheets/d/1WlxZF_azuxc8TBsmWTB7V6ErC4f3j9VIWLVUiwPavcw/edit?gid=0#gid=0

The OIDF calendar on the website and Google calendar are current and available at: https://openid.net/calendar/

3. External Organizations & Liaisons

Ecosystem Support Community Group

####. Japanese Financial Market Update

Nat Sakimura provided significant update:

  • Japanese Financial Services Agency started consultation on supervisory guideline amendments
  • Phishing-resistant authentication becoming mandatory
  • This effectively ends screen scraping for financial services in Japan
  • Blog post available with machine translation: https://www.sakimura.org/en/2025/07/7271/

4. FAPI Working Group Updates

FAPI2 Final Launch

Relying Party Certifications

  • Filip's RP certifications pending
  • Final layout will follow OP format (7 columns for RPs)
  • Marcus working on setup (currently on holiday)

Call to action: Encouraged other implementers to certify their solutions now that specs are final.

Notice of Vote

Nat Sakimura mentioned the notice of vote for proposed errata corrections to JWT Secured Authorization Response Mode (JARM):

5. Issues Discussion

Issue #738 (Deprecation of FAPI2 ID2 Tests)

  • Context: With FAPI2 final tests launched, need to deprecate implementer's draft tests
  • Proposed timeline: End of March 2026 (6+ months)

Issue #736 (FAPI Post-Quantum Cryptography)

  • Discussion: Previously discussed, but unclear path for FAPI 1.1
  • FAPI 2 approach: Reference BCP 195 which will be updated for post-quantum
  • FAPI 1.1 needs: Updates for JWS/JWE algorithms beyond PS256, ES256, EdDSA

Issue #688 (TLS 1.2 Cipher Suites)

  • Context: FAPI 1 references 4 cipher suites, 2 are deprecated
  • Status: Change already made to draft spec to reference BCP 195
  • Need: Push through errata process
  • Additional: Waiting for RFC 7523 bis for private key JWT changes

Issue #725 (FAPI 2 Security Profile Final Conformance)

  • Status: Covered in conformance section
  • Action: Can be closed

Issue #737 (FAPI Without Long-lived API Access)

  • Context: Ecosystems not using refresh tokens

Issue #734 (Private Key Storage Recommendations)

  • Status: Reassigned to implementation and deployment advice
  • Joseph's view: Some security considerations already out of scope
  • Duplicate: Also related to Issue #735
  • Action:
    • Nat to request volunteer for drafting text
    • Dima suggests mailing list feedback on approach
    • Consider referencing specific NIST specifications

Issue #732 (OAuth 2.0 Attestation-based Client Authentication)

  • Status: Waiting for IETF outcome

Issue #733 (JARM Downgrade)

  • Context: Brian Campbell provided background
  • Status: Too late for errata in current JARM voting process
  • Potential solution: Brief mention in implementation advice

7. PR Discussion

PR #542 (Issue #290)

  • Status: Approved by Nat and Joseph
  • Action: Ready for merge

PR #539 (Access Token Size Considerations)

  • Status: Approved by Joseph
  • Action: To be merged post-call

PR #541 (AS Rejecting Nonsense States)

  • Discussion: Joseph agreed with Dave's suggestion for URL-safe values
  • Concern: Bullet point 4 about error responses - may create open redirect vulnerability
  • Action: Joseph to add comments on the PR

PR #540 (DPoP vs mTLS Advice)

  • Discussion: Joseph noted correct point about self-signed certificates and JWKs
  • Action: Joseph to add comments

PR #529 (Pending)

  • Status: Waiting for underlying specs to change
  • Action: Put on hold

8. Any Other Business

Clone this wiki locally