Skip to content

FAPI_Meeting_Notes_2025 11 19_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Atlantic Call

  • Date and Time * 2025-11-19 14:00 UTC

Attendees

  • Nat Sakimura (Co-Chair)
  • Dave Tonge (Co-Chair)
  • Filip Skokan
  • Matthew Murphy (Mastercard)
  • Robert Gallagher (Mastercard)
  • Hideki Ikeda
  • Brian Campbell

Regrets

  • Mike Leszcz

Agenda

  1. Roll Call (Dave/Nat)
  2. Adoption of Agenda (Dave/Nat)
  3. Events (Mike L.)
  4. External Orgs & Liaisons (Mike L.)
  5. PRs (Dave)
  6. Issues (Dave)
  7. AOB (Nat)

1. Roll Call

Roll call was conducted via chat. Attendees entered their names in the chat window.

2. Adoption of Agenda

The default agenda was presented. No additional items were proposed, and the agenda was adopted as presented.


3. Events

Nat presented the events update on behalf of Mike Leszcz (who sent regrets).

Q1 2026 Events Added to Calendars

  • March 9-13: ISO/IEC JTC 1/SC 27 Working Group Meeting – Nürnberg, Germany
  • March 14-20: IETF 125 – Shenzhen, China
  • March 16-17: ISO/IEC JTC 1/SC 27 Plenary – Nürnberg, Germany

Action Item


4. External Organizations & Liaisons

Ecosystem Engagement

  • End-of-year coordination calls are being scheduled with all ecosystem partners for input into 2026 planning and budgeting
  • Some meetings have been completed; others are being coordinated
  • No specific ecosystem updates were reported

OECD Meeting

  • An OECD meeting was held yesterday (November 18)
  • Nat was unable to attend but will share any relevant information for the working group when the report is received

5. Member Reminders

Public Review Periods

  1. OpenID4VC High Assurance Interoperability Profile (HAIP) 1.0 Final Specification

  2. Authorization API 1.0 Final Specification

2026 OIDF Board Elections Schedule

  • December 8: Blog to be published noting nominations open with full details
  • December 26: Nominations close
  • December 29: 2026 elections begin
  • January 12: 2026 elections conclude

6. Pull Requests

Dave led the review of pull requests, focusing on ISO-related editorial changes.

PR #549 – JARM Section Reference Removal

PR #552 – JARM Section Number Editorial Fix

PR #557 – Draft Version Date and Changes Section Update

PR #556 – Single Sign-On Security Evaluation Link Update

  • Link: https://bitbucket.org/openid/fapi/pull-requests/556
  • Description: Updates the reference link for "Single Sign-On Security and Evaluation of OpenID Connect" from a German university website to the published IEEE link
  • Discussion: Confirmed the IEEE link is not behind a paywall
  • Status: Approved

PR #555 – OAuth 2.0 Formal Analysis Link Update

PR #545 – JARM Downgrade Protection Security Consideration

  • Link: https://bitbucket.org/openid/fapi/pull-requests/545/overview
  • Description: Yaron proposed text for a security consideration related to JARM downgrade protection
  • Discussion: Lucas left a comment that has not been addressed; neither Yaron nor Lucas were present on the call
  • Status: Pending – awaiting Yaron's response to Lucas's comment

Other PRs

  • Implementation considerations cleanup PRs remain pending
  • Dave acknowledged needing to organize these issues but noted it's not suitable for the call

7. Issues

IANA Registrations (Issues #832 and #703)

  • Status: Dave sent emails for IANA registrations for both JARM and HTTP Message Signing
  • Filip confirmed the registrations have not been actioned yet
  • Action Item: Dave to follow up on IANA registration requests

Issue #831 – Browser Swapping Attacks

  • Link: https://github.com/openid/fapi/issues/831

  • Access Issue: Filip reported that he could not access the issue due to spam prevention settings ("We can't let you see this page")

    • This same issue occurred in the Connect call the previous week
    • Nat changed the settings to completely reopen the issue
    • Filip confirmed access was restored
    • Nat will investigate the appropriate balance between spam control and working group access
  • Technical Discussion:

    • Tim referenced a prior discussion in Issue #543 (browser swap attack discussed by Daniel)
    • The previous resolution was to change the attacker model rather than try to prevent this type of attack at the protocol level
    • Joseph shared slides on this topic at IETF
    • Ongoing discussion on the IETF OAuth mailing list
    • Filip noted the discussion is still active
  • Decision: Leave the issue open and monitor the IETF discussion for any consensus that may be relevant to the FAPI Working Group

  • Action Item: Dave to add a link to the IETF mailing list thread in the issue

Issue #778 – FAPI 1 ISO/IEC 25791-1 Review Comments: Key Length

  • Link: https://github.com/openid/fapi/issues/778

  • Background: A national body comment in the ISO process raised concerns that the key lengths specified in FAPI 1.0 may become outdated

    • The suggestion was to reference an external document that provides recommended key sizes
    • Nat discussed this with Brian at IETF
  • Challenge: Finding authoritative external documents that provide key length guidance

    • German BSI document (published this year) exists
    • NIST doesn't specifically address key length
    • BCP 195 doesn't discuss key length
    • There are documents providing guidance on algorithms, but not specifically on key lengths
  • Discussion:

    • Dave noted the working group has tried to avoid defining cryptographic properties directly
    • The NIST document discusses security strength/entropy calculation, but not specific key length recommendations
    • Dave asked if anyone knows of a document that could provide backup for these values
  • Decision:

    • Nat will conduct additional research to find appropriate reference documents
    • Nat to send a proposal to the mailing list and update the issue
    • If no suitable document is found, the specification will remain as-is
  • Action Item: Nat to research key length guidance documents and send proposal to mailing list

Issue #743

  • Status: Waiting for DEMA

8. Any Other Business

Mastercard Participation

Robert Gallagher noted in the chat that Mastercard can support a call (context: related to key length discussion).

Next Week's Call – Thanksgiving Week

  • Discussion: Next week (November 26) is Thanksgiving week in the United States
  • Mike Leszcz indicated he cannot make the call
  • Brian Campbell will be on holiday
  • Decision: Cancel the November 26 Atlantic call
  • Next Meeting: The following week (December 3, 2025)

Action Items Summary

Action Item Owner Status
Send 2026 events to calendar All members Ongoing
Follow up on IANA registrations for JARM and HTTP Message Signing Dave Tonge In Progress
Add link to IETF mailing list thread in Issue #831 Dave Tonge New
Respond to Lucas's comment on PR #545 Yaron Pending
Research key length guidance documents and send proposal to mailing list Nat Sakimura New
Investigate Bitbucket access control settings for spam prevention Nat Sakimura New

Next Meeting

  • Date: December 3, 2025 (November 26 call cancelled due to US Thanksgiving)
  • Note: The November 26, 2025 Atlantic call is cancelled

Resources & Links

Pull Requests Discussed

Issues Discussed

FAPI 1.0 Part 2 Reference

Public Review Links

Clone this wiki locally