-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 08 20_Atlantic
Date: August 20, 2025
Time: 14:00-15:00 GMT
Meeting Type: FAPI Working Group Call
- Nat Sakimura (Co-chair)
- Dave Tonge (Co-chair)
- Mike Leszcz - OIDF
- Peter Stanley
- Kosuke Koiwai
- Robert Gallagher - Mastercard
- Hideki Ikeda
- Bjorn Hjelm
- George Fletcher
- Peter Wallach
- Christopher Robbertse - OB
- Filip Skokan
- Brian Campbell
- Dima Postnikov
- Roll Call (Dave/Nat)
- Adoption of Agenda (Dave/Nat)
- Events (Mike L.)
- External Orgs & Liaisons (Mike L.)
- PRs (Dave)
- Issues (Dave)
- AOB (Nat)
- Mike Leszcz presented the Note Well statement covering:
- Code of Conduct Policy emphasizing honesty, fairness, integrity, respect and dignity
- Antitrust policy governing all Foundation meetings
- Requirement for signed contribution agreement for OpenID Foundation working groups
- Requirement for signed participation agreement for OIDF community groups
- All policies available at openid.net/policies
- Agenda adopted with no additional items
-
September 8-10 – Finance of Tomorrow – Rio de Janeiro
- Mark Haine and Domingos Creado representing OIDF
-
October 13-16 – FIDO Authenticate – Carlsbad, CA
- Mike Jones likely to represent OIDF
-
October 20 – OIDF events including after lunch workshop prior to IIW (NEW DATE)
- Host still TBC (likely Cisco based on date changes)
- Schedule:
- Morning: DCP working group meeting
- 12:30-3:45 PM: After-lunch workshop
- 4:00-6:00 PM: OpenID Foundation Board of Directors meeting
- October 21-23 – IIW Fall 2025 – Mountain View (NEW DATES - moved from Oct 28-31)
- November 1-7 – IETF 124 Montreal
- Date change from October 28-31 to October 21-23 has "wreaked havoc" on many personal and foundation plans
- OIDF adjusting their Monday events to October 20th accordingly
- Calendar on website and OIDF Google calendar are current
-
Vote to Approve Three Shared Signals Final Specifications
- Vote started August 15th (delayed from August 11th to address review comments)
- Link: https://openid.net/notice-of-vote-to-approve-three-shared-signals-specifications/
- Members encouraged to vote to achieve quorum
-
JARM Errata Poll
- Poll passed, formal announcement pending due to file format updates
-
Digital Identity Technology Standard Forum (Korea)
- Working to coordinate introduction call
- Challenging due to holidays and time zones
-
Peruvian Financial Authority
- Defining Peruvian Open Banking regulation
- Call confirmed for Friday, August 22nd
- Participants: Mark Haine, Domingos Creado, Mike Leszcz (while Gail is on holiday)
-
ISO TC68 FinTech TAG meeting September 19th
- Agenda not busy yet, time slots available for OIDF reports
- Contributions welcome
-
SC27 Meeting in second week of September
- Liaison statement to SC27 WG5 needed soon
- Regular report will be sent unless special contributions received
-
PR #544 - Editorial update to Philip's affiliation in JAM spec
- Simple editorial change that was missed
- Approved by Nat during meeting
- Several HTTP signing related PRs not ready for review yet
- Dave needs to schedule time to work on remaining PRs
Issue #739: Collective Issues Impacting FAPI-1
Status: Active preparation by Nat Sakimura
Background:
- Peter Stanley raised issue to get spotlight on all FAPI-1 impacting changes
- Two main FAPI-1 issues waiting for RFC updates and BCP on crypto algorithms
- Need to assess impact on FAPI-1 test suite
Key Dependencies:
- RFC 7523 updates (audience claim changes)
- Crypto algorithm BCP updates
- Both PRs still under review in IETF
Current Status (Brian Campbell & Filip Skokan):
- RFC 7523 moving slowly despite interest in quick resolution
- Significant rewrite efforts by Mike caused overreaching changes
- Now working to back changes into more reasonable scope
- Last IETF update was significant improvement
- Filip has PRs to further improve content
- One PR aims to relax requirement from strictly string value to single value for audience claim
Timeline Concerns:
- Peter Stanley expects resolution in 2026 rather than 2025
- Early visibility needed for ecosystem planning
- Ecosystem recently moved to FAPI-1 Advanced
- Need consistent view on approach (errata vs new release)
Good News:
- FAPI-1 ecosystems using MTLS were not impacted by vulnerability
- Two RFC 7523 authors (Brian Campbell, Filip Skokan) regularly participate in working group
- Working to minimize scope of necessary changes
Next Steps:
- Nat plans to drive toward closure by Montreal IETF meeting (November)
- Peter will contribute time after holiday to update ticket
- Need to determine whether errata or new release approach for FAPI-1
Issue #737: FAPI Without Long-lived API Access
Status: Resolved via working group decision
Resolution (Dima Postnikov):
- OIDF certification test profiles for specific ecosystems can be updated on request not to test:
- Refresh token support where ecosystem rules out support
- Sender-constraining access tokens where ecosystem rules out resource server APIs
- Default FAPI2 certification profiles will continue testing for these features
- Ecosystem-specific test profiles must be funded by requesting ecosystem
Funding Model (Mike Leszcz):
- Directed funding required for ecosystem-specific profiles
- Examples:
- Open Finance Brazil provided significant funding
- ConnectID Australia provided directed funding
- SAMA Saudi Arabia funding FAPI2 KSA profile (in process)
Next Steps:
- Leave open one more week for final comments before resolution
- Joseph will be back next week for additional input
Issue #733: JARM Downgrade
Status: Assigned to implementation advice
Resolution:
- Issue to be picked up in implementation advice document
- Assigned to Yaron for text contribution
- Good opportunity for community PR contribution
Note on JARM Errata:
- Errata vote passed successfully
- This particular issue not included in errata (appropriately)
- Better suited for implementation advice than formal errata
Issue #740: Request for Tailored FAPI 2.0 Conformance
Status: Under discussion
Background (Robert - Mastercard):
- Mastercard implementing FAPI-compliant machine-to-machine system
- No user authentication involved
- Current conformance tests fail because optional FAPI features not implemented
- Large ecosystem impact: top 10 banks, top 5 merchants globally
Technical Discussion (Dima Postnikov):
- Valid use case discussed couple years ago
- Current FAPI2 specification allows non-user participating flows
- Some statements may be misplaced due to spec structure
- General section vs authorization code-specific sections need clarification
- Would benefit from dedicated conformance test profile
Working Group Opinions:
- Brian Campbell: Questioning value of machine-to-machine specific tests, beyond FAPI scope
- Dave Tonge: Sees value in standardization of machine-to-machine protocols
- Dima Postnikov: Strong support, has live implementations that cannot be tested
Key Technical Issue:
- Client requirement: "shall initiate authorization process only with end user's explicit or implicit consent"
- Problematic placement for machine-to-machine flows
Next Steps:
- Keep open for discussion when Joseph returns
- Need comments from Brian and Dima on relative positions
- Determine if spec clarification needed vs conformance profile only
Issue #741: Is NBF Mandatory Requirement for Request Objects?
Status: Under discussion
Background (Dima Postnikov):
- Question about mandatory NBF (Not Before) claim in request objects
- Implementers asking for rationale
- Complexity concerns around validation logic and clock skew
Technical Context (Filip Skokan & Brian Campbell):
- Current Status: Text says NBF is mandatory
- FAPI-1 Rationale: IAT timestamp doesn't have defined validation in JWT spec
- NBF provides 100% way to ensure timestamp is in past/close to now
- Important for front-channel scenarios in FAPI-1
- FAPI-2 Context: Different security model, less reliance on NBF
Historical Context (Brian Campbell):
- Likely added for attacker controlling clock on signing side
- Decision made during working group calls
- Some uncertainty about original rationale
Implementation Impact:
- Filip Skokan: FAPI2 message signing conformance profiles already live
- People already implementing with NBF requirement
- Changing now would impact existing implementations
- Suggests keeping as-is for stability
Security Analysis Request:
- Dima requested feedback from security researchers
- Need to understand if requirement considered during security analysis
Different Specs Comparison:
- FAPI2 Security Profile: NBF not mandatory
- FAPI2 Message Signing: NBF is mandatory for request objects
- Differences table notes NBF/EXP not used for replay prevention in Security Profile
Next Steps:
- Document rationale referencing previous issues (Dave Tonge)
- Reference issue #177 for historical context
- Consider for future FAPI 2.1 rather than current spec changes
- Review alignment with CIBA flows
- Keep issue open for rationale documentation
- No additional business raised
- Good discussion overall on various technical issues
- Nat Sakimura: Continue preparation of FAPI-1 collective issues impact assessment
- Peter Stanley: Contribute time after holiday to update issue #739
- Yaron: Provide text for JARM downgrade implementation advice (issue #733)
- Brian Campbell & Dima Postnikov: Provide comments on issue #740 (machine-to-machine conformance)
- Dave Tonge: Document NBF rationale referencing historical issues (issue #741)
- Mike Leszcz: Confirm OIDF October 20th event details and publish blog with registration
- All members: Vote on Three Shared Signals specifications to achieve quorum