-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 08 13_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
Date: August 13, 2025
Time: 14:00 GMT
Chair: Nat Sakimura (Dave unavailable)
- Nat Sakimura (Chair)
- Filip Skokan
- Joe DeCock
- Robert Gallagher (Mastercard)
- Peter Wallach
- Dima Postnikov
- Chris Wood
- Bjorn Hjelm
- Joseph Heenan (OIDF & Authlete)
- Christopher Robbertse (OB)
- Hideki Ikeda
- Imran Ulghar (OBL)
- Peter Stanley
- Kosuke Koiwai
- Attendees confirmed via chat
- Agenda adopted without modifications
- Dave unavailable but provided reports for events and external orgs
-
September 8-10: Finance of Tomorrow - Rio de Janeiro
- Mark Haine and Domingos Creado representing OIDF
-
October 13-16: FIDO Authenticate - Carlsbad, CA
- Mike Jones likely to represent OIDF
-
October 20: OIDF events including after lunch workshop prior to IIW (NEW DATE)
- Host still TBC (likely Cisco based on date changes)
-
October 21-23: IIW Fall 2025 - Mountain View (NEW DATES)
- IIW shifted dates one week earlier, causing scheduling conflicts
- November 1-7: IETF 124 Montreal
-
Joe DeCock: Duende Software livestream on August 21, 2025 at 10:00 EST / 16:00 CEST / 14:00 UTC
- Celebrating IdentityServer 7.3.0 release with FAPI 2.0 conformance
- Focus on FAPI 2.0 requirements, SDK usage, and OIDF conformance suite
- Registration: https://duendesoftware.com/webinars/duende-identityserver-7-3-fapi-2-0
-
Joseph Heenan: Authlete published FAPI2 overview recording on YouTube
- 40-minute presentation covering FAPI 2 background and main features
- Link: https://www.youtube.com/watch?v=jTXKYqg7glI
- Kicked off Monday, July 28th
- First "Pacific" call: Friday, August 15th 10am Sydney (Thursday, August 14th 5pm PT/8pm ET)
- Existing ecosystem partners being invited to participate
- Details and participation agreement: https://openid.net/cg/ecosystem-support-community-group/
- Note: Separate participation agreement required (different from working group agreement)
- Dima Postnikov: Sign participation agreement to access mailing list and Slack channel
-
FAPI1 ISO Vote: Approved with one negative vote
- 149 comments received requiring disposition
- Hodari McClain working on addressing the negative vote
- Subgroup formation needed to create disposition of comments
- Work to be conducted on Slack channel and Zoom calls
- Nat to send participation request after meeting
- Public consultation on authentication in stockbrokerage and securities companies
- Translated version shared with liaison committee
- Considering response from OpenID Foundation perspective
- TC68: Currently liaison A status
- SC27 & SC17: Currently liaison C status (working group level only)
- Nat drafted letter to upgrade SC27 liaison from Category C to Category A
- Similar upgrade may be needed for SC17
- Bjorn Hjelm confirmed: WG4 and WG10 have liaison A status for technical comments
- SC27 meeting in September - upgrade request needs to be submitted soon
- Dormant for 4 years post-COVID, recently restarted
- First reconvening meeting held week prior
- Next meeting in few weeks with more substantial content
- Waiting for Dave's return to resolve conflicts
- PR 529: Joe DeCock reported waiting on BIS 7523 audience changes resolution
Issue #740: Tailored FAPI 2.0 Conformance Testing (Mastercard)
Context: Mastercard seeks FAPI compliance but current conformance suite assumes optional features are in use.
Requirements:
- Client Authentication Type: private_key_jwt
- Sender Constraining: DPoP
- Authorization Request Type: None (this option doesn't exist)
- Test OpenID: None (should be optional)
- FAPI Profile: plain_fapi
Discussion Points:
- Need for client credentials grant-only certification profiles
- No authorization endpoint interactions required
- Access token binding to TLS certificate or DPoP for client credentials flow
- Robert Gallagher: Machine-to-machine only, no ID/password flows
Technical Analysis:
- Joseph Heenan: Need FAPI certification profiles for client credentials grant only
-
Joe DeCock: Spec language assumes authorization codes will be issued
- Example: "authorization servers shall issue authorization codes with maximum lifetime of 60 seconds"
- May need errata to clarify applicability
-
Dima Postnikov: Spec already split into sections:
- General requirements for authorization server
- Authorization code flows
- Most requirements properly sectioned, some cleanup needed
Resolution:
- Working group supports creating machine-to-machine certification profiles
- Prioritization depends on OIDF resource allocation and member funding
- Need to assess broader demand beyond Mastercard
- Joe DeCock: Will create PR to move misplaced authorization code requirement
- May require FAPI 2.1 for proper specification support
Issue #706: HTTP Signature Requirements
Status:
- Justin and Takahiko actively discussing
- Waiting for their conclusions before proceeding
- Open for additional participant input
Issue #741: NBF (Not Before) Claim Requirement
Status:
- Waiting for additional implementer feedback
- Dima Postnikov: Will send reminder to mailing list for broader input
- Secondary concern about statement placement (may belong in message signing vs main profile)
Issue #739: FAPI 1 Collective Issues
Status:
- Nat added diff list to ticket
- Peter Stanley: Requests previous chat content be added to ticket
- Need comprehensive view of all proposed FAPI1 changes
- Determine errata vs new release approach
- Action: Nat to find and add previous chat logs to ticket
Issue #733: JARM Downgrade
Resolution:
- Too late for JARM errata (voting in progress)
- Agreed to provide clarification in FAPI Implementation Advice Document
- Action: Component changed from JARM to Implementation Advice Document
Issue #737: FAPI Without Long-Lived API Access
Background:
- Mark Haine raised concerns about sender constraining requirements
- Two main issues:
- Refresh token issuance requirements
- Access token sender constraining when no resource server used
Discussion:
- Joseph Heenan: Generic FAPI clients should still support access tokens
- Only update tests for specific ecosystem profiles with different requirements
- Dima Postnikov: Apply same logic for both refresh tokens and access tokens
- If ecosystem governing body specifies no resource server needed, implementations shouldn't fail conformance
Technical Considerations:
- Joseph Heenan: May need additional endpoint to end client tests
- Dima Postnikov: Will summarize discussion in ticket for clarity
Resolution:
- Ecosystem-specific profiles can relax requirements
- Generic FAPI maintains current requirements
- Consider FAPI 2.1 for specification updates
Issue #738: FAPI2 ID2 Tests Deprecation
Status Check:
- March 26 deadline works for Connect ID
- Joseph Heenan: Will check with UAE (Mike Les)
- Peter Stanley: UK still using FAPI1, no impact
- Awaiting final confirmation from UAE
-
Nat Sakimura:
- Send ISO subgroup participation request after meeting
- Find and add previous chat logs to Issue #739
- Submit SC27 liaison upgrade request before September meeting
- Get SC17 meeting schedule information
-
Dima Postnikov:
-
Joe DeCock:
- Create PR to move authorization code requirement to appropriate section
-
Joseph Heenan:
- Check with UAE regarding Issue #738 timeline
-
Bjorn Hjelm:
- Provide ISO liaison status documentation link
- Continue monitoring PR resolution pending Dave's return
- Await ecosystem feedback on various issues
- Proceed with ISO liaison upgrade processes
- Follow up on certification profile requirements for machine-to-machine scenarios
Meeting adjourned early, giving back 4 minutes before eKYC Working Group session.