-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 07 24_Pacific
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Anoop
- Dima
- Roll Call
- Adoption of Agenda
- Events
- External Orgs & Liaisons
- PRs
- Issues
- AOB
** Events Updates**
-
IETF 120 Montreal is coming up (July 23).
-
- Nat will attend remotely only
-
- Two OAuth sessions and one OpenID Connect session scheduled
** Upcoming Events: **
- July 19-25, 2025: IETF 123 — Madrid
- October 13-16, 2025: FIDO Authenticate — Carlsbad, CA
- October 27, 2025: OIDF events including workshop prior to IIW (date updated)
- October 28-30, 2025: IIW Fall 2025 — Mountain View
- November 1-7, 2025: IETF 124 — Montreal
https://docs.google.com/spreadsheets/d/1WlxZF_azuxc8TBsmWTB7V6ErC4f3j9VIWLVUiwPavcw/edit?gid=0#gid=0
The OIDF calendar on the website and Google calendar are current and available at: https://openid.net/calendar/
- New community group co-chaired by Dima, Mark Vestigi, and others
- Web pages launched: https://openid.net/cg/ecosystem-support-community-group/
- Meeting schedule to be added to OIDF calendar
####. Japanese Financial Market Update
Nat Sakimura provided significant update:
- Japanese Financial Services Agency started consultation on supervisory guideline amendments
- Phishing-resistant authentication becoming mandatory
- This effectively ends screen scraping for financial services in Japan
- Blog post available with machine translation: https://www.sakimura.org/en/2025/07/7271/
- Security profile and message signing tests launched on schedule (previous Monday)
- Announcement: https://lists.openid.net/pipermail/openid-specs-fapi/2025-July/003344.html
-
Early certifications received from:
- Authlete
- Filip Skokan
- Okta
- Australian Connect ID profile also launched with Authlete certification
- Filip's RP certifications pending
- Final layout will follow OP format (7 columns for RPs)
- Marcus working on setup (currently on holiday)
Call to action: Encouraged other implementers to certify their solutions now that specs are final.
Nat Sakimura mentioned the notice of vote for proposed errata corrections to JWT Secured Authorization Response Mode (JARM):
Issue #738 (Deprecation of FAPI2 ID2 Tests)
- Context: With FAPI2 final tests launched, need to deprecate implementer's draft tests
- Proposed timeline: End of March 2026 (6+ months)
Issue #736 (FAPI Post-Quantum Cryptography)
- Discussion: Previously discussed, but unclear path for FAPI 1.1
- FAPI 2 approach: Reference BCP 195 which will be updated for post-quantum
- FAPI 1.1 needs: Updates for JWS/JWE algorithms beyond PS256, ES256, EdDSA
Issue #688 (TLS 1.2 Cipher Suites)
- Context: FAPI 1 references 4 cipher suites, 2 are deprecated
- Status: Change already made to draft spec to reference BCP 195
- Need: Push through errata process
- Additional: Waiting for RFC 7523 bis for private key JWT changes
Issue #725 (FAPI 2 Security Profile Final Conformance)
- Status: Covered in conformance section
- Action: Can be closed
Issue #737 (FAPI Without Long-lived API Access)
- Context: Ecosystems not using refresh tokens
Issue #734 (Private Key Storage Recommendations)
- Status: Reassigned to implementation and deployment advice
- Joseph's view: Some security considerations already out of scope
- Duplicate: Also related to Issue #735
-
Action:
- Nat to request volunteer for drafting text
- Dima suggests mailing list feedback on approach
- Consider referencing specific NIST specifications
Issue #732 (OAuth 2.0 Attestation-based Client Authentication)
- Status: Waiting for IETF outcome
Issue #733 (JARM Downgrade)
- Context: Brian Campbell provided background
- Status: Too late for errata in current JARM voting process
- Potential solution: Brief mention in implementation advice
PR #542 (Issue #290)
- Status: Approved by Nat and Joseph
- Action: Ready for merge
- Status: Approved by Joseph
- Action: To be merged post-call
- Discussion: Joseph agreed with Dave's suggestion for URL-safe values
- Concern: Bullet point 4 about error responses - may create open redirect vulnerability
- Action: Joseph to add comments on the PR
- Discussion: Joseph noted correct point about self-signed certificates and JWKs
- Action: Joseph to add comments
- Status: Waiting for underlying specs to change
- Action: Put on hold