-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 11 19_Atlantic
- Date and Time * 2025-11-19 14:00 UTC
- Nat Sakimura (Co-Chair)
- Dave Tonge (Co-Chair)
- Filip Skokan
- Matthew Murphy (Mastercard)
- Robert Gallagher (Mastercard)
- Hideki Ikeda
- Brian Campbell
- Mike Leszcz
- Roll Call (Dave/Nat)
- Adoption of Agenda (Dave/Nat)
- Events (Mike L.)
- External Orgs & Liaisons (Mike L.)
- PRs (Dave)
- Issues (Dave)
- AOB (Nat)
Roll call was conducted via chat. Attendees entered their names in the chat window.
The default agenda was presented. No additional items were proposed, and the agenda was adopted as presented.
Nat presented the events update on behalf of Mike Leszcz (who sent regrets).
- March 9-13: ISO/IEC JTC 1/SC 27 Working Group Meeting – Nürnberg, Germany
- March 14-20: IETF 125 – Shenzhen, China
- March 16-17: ISO/IEC JTC 1/SC 27 Plenary – Nürnberg, Germany
- Please send any 2026 events to be added to the calendar to mike.leszcz@oidf.org
- End-of-year coordination calls are being scheduled with all ecosystem partners for input into 2026 planning and budgeting
- Some meetings have been completed; others are being coordinated
- No specific ecosystem updates were reported
- An OECD meeting was held yesterday (November 18)
- Nat was unable to attend but will share any relevant information for the working group when the report is received
-
OpenID4VC High Assurance Interoperability Profile (HAIP) 1.0 Final Specification
- Public review period: Through Monday, December 8th
- Voting opens: Tuesday, December 9th
- Link: https://openid.net/public-review-period-for-proposed-openid4vc-high-assurance-interoperability-profile-1-final-specification/
-
Authorization API 1.0 Final Specification
- Public review period: Through Monday, December 22nd
- Voting opens: Tuesday, December 23rd
- Note: Voting timing coincides with holiday period, which may affect quorum
- Link: https://openid.net/public-review-period-for-proposed-authorization-api-1-final-specification/
- December 8: Blog to be published noting nominations open with full details
- December 26: Nominations close
- December 29: 2026 elections begin
- January 12: 2026 elections conclude
Dave led the review of pull requests, focusing on ISO-related editorial changes.
- Link: https://bitbucket.org/openid/fapi/pull-requests/549
- Description: Removes a reference to a non-existent section in JARM
- Status: Approved
- Link: https://bitbucket.org/openid/fapi/pull-requests/552
- Description: Another editorial fix removing a reference to a non-existent section in JARM
- Status: Approved
- Link: https://bitbucket.org/openid/fapi/pull-requests/557
- Description: Updates the draft version date and changes section
- Status: Approved (purely editorial)
- Link: https://bitbucket.org/openid/fapi/pull-requests/556
- Description: Updates the reference link for "Single Sign-On Security and Evaluation of OpenID Connect" from a German university website to the published IEEE link
- Discussion: Confirmed the IEEE link is not behind a paywall
- Status: Approved
- Link: https://bitbucket.org/openid/fapi/pull-requests/555
- Related Commit: https://bitbucket.org/openid/fapi/commits/8dd80d4347a6c7b098034e9c577874e23973f801
- Description: Updates the arXiv link to the DOI/published paper link for the formal analysis of OAuth 2.0
- Discussion: Filip noted the PR shows no file changes in the web interface; Nat explained this may be due to using the command line for conflict resolution. The change appears to already be in master.
- Status: Approved based on the commit
- Link: https://bitbucket.org/openid/fapi/pull-requests/545/overview
- Description: Yaron proposed text for a security consideration related to JARM downgrade protection
- Discussion: Lucas left a comment that has not been addressed; neither Yaron nor Lucas were present on the call
- Status: Pending – awaiting Yaron's response to Lucas's comment
- Implementation considerations cleanup PRs remain pending
- Dave acknowledged needing to organize these issues but noted it's not suitable for the call
- Status: Dave sent emails for IANA registrations for both JARM and HTTP Message Signing
- Filip confirmed the registrations have not been actioned yet
- Action Item: Dave to follow up on IANA registration requests
Issue #831 – Browser Swapping Attacks
-
Access Issue: Filip reported that he could not access the issue due to spam prevention settings ("We can't let you see this page")
- This same issue occurred in the Connect call the previous week
- Nat changed the settings to completely reopen the issue
- Filip confirmed access was restored
- Nat will investigate the appropriate balance between spam control and working group access
-
Technical Discussion:
- Tim referenced a prior discussion in Issue #543 (browser swap attack discussed by Daniel)
- The previous resolution was to change the attacker model rather than try to prevent this type of attack at the protocol level
- Joseph shared slides on this topic at IETF
- Ongoing discussion on the IETF OAuth mailing list
- Filip noted the discussion is still active
-
Decision: Leave the issue open and monitor the IETF discussion for any consensus that may be relevant to the FAPI Working Group
-
Action Item: Dave to add a link to the IETF mailing list thread in the issue
Issue #778 – FAPI 1 ISO/IEC 25791-1 Review Comments: Key Length
-
Background: A national body comment in the ISO process raised concerns that the key lengths specified in FAPI 1.0 may become outdated
- The suggestion was to reference an external document that provides recommended key sizes
- Nat discussed this with Brian at IETF
-
Challenge: Finding authoritative external documents that provide key length guidance
- German BSI document (published this year) exists
- NIST doesn't specifically address key length
- BCP 195 doesn't discuss key length
- There are documents providing guidance on algorithms, but not specifically on key lengths
-
Discussion:
- Dave noted the working group has tried to avoid defining cryptographic properties directly
- The NIST document discusses security strength/entropy calculation, but not specific key length recommendations
- Dave asked if anyone knows of a document that could provide backup for these values
-
Decision:
- Nat will conduct additional research to find appropriate reference documents
- Nat to send a proposal to the mailing list and update the issue
- If no suitable document is found, the specification will remain as-is
-
Action Item: Nat to research key length guidance documents and send proposal to mailing list
Issue #743
- Status: Waiting for DEMA
Robert Gallagher noted in the chat that Mastercard can support a call (context: related to key length discussion).
- Discussion: Next week (November 26) is Thanksgiving week in the United States
- Mike Leszcz indicated he cannot make the call
- Brian Campbell will be on holiday
- Decision: Cancel the November 26 Atlantic call
- Next Meeting: The following week (December 3, 2025)
| Action Item | Owner | Status |
|---|---|---|
| Send 2026 events to calendar | All members | Ongoing |
| Follow up on IANA registrations for JARM and HTTP Message Signing | Dave Tonge | In Progress |
| Add link to IETF mailing list thread in Issue #831 | Dave Tonge | New |
| Respond to Lucas's comment on PR #545 | Yaron | Pending |
| Research key length guidance documents and send proposal to mailing list | Nat Sakimura | New |
| Investigate Bitbucket access control settings for spam prevention | Nat Sakimura | New |
- Date: December 3, 2025 (November 26 call cancelled due to US Thanksgiving)
- Note: The November 26, 2025 Atlantic call is cancelled
- PR #549: https://bitbucket.org/openid/fapi/pull-requests/549
- PR #552: https://bitbucket.org/openid/fapi/pull-requests/552
- PR #557: https://bitbucket.org/openid/fapi/pull-requests/557
- PR #556: https://bitbucket.org/openid/fapi/pull-requests/556
- PR #555: https://bitbucket.org/openid/fapi/pull-requests/555
- PR #545: https://bitbucket.org/openid/fapi/pull-requests/545/overview
- Commit (PR #555): https://bitbucket.org/openid/fapi/commits/8dd80d4347a6c7b098034e9c577874e23973f801
- Issue #831 (Browser Swapping Attacks): https://github.com/openid/fapi/issues/831
- Issue #778 (Key Length): https://github.com/openid/fapi/issues/778