-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2026 02 04_Atlantic
- Date: 2026-02-04
- Time: 14:00 UTC
- Location: Zoom
- Nat Sakimura (Chair)
- Gail Hodges (OIDF)
- Joseph Heenan (OIDF & Authlete)
- Chris Robbertse (Open Banking Limited)
- Imran Ulghar (Open Banking Limited)
- Matthew Murphy (Mastercard)
- Robert Gallagher (Mastercard)
- George Fletcher (Practical Identity)
- Filip Skokan (Okta)
- Dima Postnikov (Co-chair)
- Kosuke Koiwai (KDDI)
- Luiky Vasconcelos (Individual)
- Brian Campbell (Ping)
Note: Dave Tonge and Mike Leszcz was unable to attend this meeting.
- Note Well
- Roll Call
- Adoption of Agenda
- Events
- External Orgs & Liaisons
- PRs
- Issues
- AOB
Roll call conducted via chat.
Gail Hodges requested adding FAPI 1.0 and FAPI 2.0 errata progress as an agenda item to provide updates to ISO/IEC JTC 1.
No material updates. The long list of events that Mike circulated in the previous week remains current.
Gail Hodges provided an update on Peru:
- Peru continues to welcome partnership with the OpenID Foundation as they kick off their Open Banking roadmap, expected this spring
- Peru sent questions on reference FAPI profiles for their internal review to help inform their vendor selection process
- Additional clarifying questions received on topics like directed funding coverage
- Peru has requested OIDF support for a workshop event
- Staff plan to fly in Domingos for boots-on-the-ground presence at the workshop
- Plan to invite other expert speakers to participate remotely
- Workshop expected in the coming months
Action Item: Gail to follow up on Peru workshop planning
Gail Hodges provided an update on Colombia:
- Still seeking updates on the Q1 2026 Colombia event
- Resources available to support and fund the event
- Event setup depends on coordination between Authlete, Capgemini, and the Colombian government
- Joseph Heenan confirmed he has not heard any updates either
- Both Joseph and Gail will follow up with Ali and other contacts
Action Items:
- Gail to send latest email to Joseph with copy
- Nat to follow up with Ali on Friday about Colombia event status
Nat Sakimura provided an update:
- ISO/IEC JTC 1/SC 27 meeting is coming up in 4 weeks
- Need to provide the liaison letter
- Category A liaison status application was sent in January and is expected to be taken up in the SC27 plenary
- Mark Hain has been named as one of the liaisons
- Anyone else interested in participating in SC27 liaison work should contact OIDF
Action Item: Anyone wanting to contribute to the SC27 liaison letter should contact Nat
Link: https://bitbucket.org/openid/fapi/pull-requests/
Nat noted there are open pull requests that need review.
Action Item: All to provide evaluation on pending PR approvals
6.1 Issue #838 - FAPI2 Attacker Model (ISO/IEC 26083-2)
Link: https://github.com/openid/fapi/issues/838
This issue relates to ISO submission requirements for the FAPI 2.0 Attacker Model specification.
Status: Under discussion. If no objections are raised by the Pacific call Friday, Mark V. will go ahead with the current proposal.
6.2 Issue #837 - FAPI2 Security Profile (ISO/IEC 26083-1)
Link: https://github.com/openid/fapi/issues/837
This issue relates to ISO submission requirements for the FAPI 2.0 Security Profile specification.
Status: Under discussion. Same as #838.
6.3 Issue #840 - Upcoming requirement to implement TLS 1.3
Link: https://github.com/openid/fapi/issues/840
- Joseph informed the group that there is an intel that BCP 195 is getting a new RFC added to it, that will change things to “MUST TLS 1.3” and “MAY TLS 1.2”. However, there is no openly accessible documentation about it.
- When this happens, as it is written in FAPI 2.0 Security profile, FAPI2 implementors need to update their implementation to support TLS 1.3 within 12 months.
- Banks should start preparing it and this should be communicated to ecosystems through blog post etc.
6.4 Issue #835 - Network Layer Protections. (CHACHA20_POLY1305_SHA256 support for TLS 1.2)
The 2026-01-21 Atlantic meeting resolved to
- Allow any cipher supported by Java Crypto Library that is not deprecated by IANA Registry
- Link: https://github.com/openid/fapi/wiki/FAPI_Meeting_Notes_2026-01-21_Atlantic
The certification team lead asked for the guidance to be in FAPI 2.0 errata.
The WG agreed to include it in FAPI 2.0 errata, and FAPI 1.0 errata as well.
Action Items:
- Robert: Create a PR for the cipher suite changes with the assistance of Nat
Chris Robbertse provided an update:
- Reached out to a member of the OpenAPI community on an individual basis (with Pete)
- OpenAPI community is very keen to collaborate
- They want to bring people from their working groups into a FAPI call to discuss integration from their perspective
- There was a conversation on Monday that Gail participated in with Mark Hain from the open banking community
- Mark discussed the use of FAPI and OpenAPI, mentioning that the Arazzo spec was intended as a use case for solving integration problems
- Conversations are flowing with lots of interest from the OpenAPI side to make progress
- Chris attached an OpenAPI example using Arazzo to issue #648 (https://github.com/openid/fapi/issues/648)
Challenges:
- Time zone coordination - many OpenAPI participants are in America, making attendance at this call difficult
- May need to set up a dedicated meeting for this topic
Nat replied:
- Planning to discuss OpenAPI integration next week as well
- Also planning to discuss OSCAL (Open Security Controls Assessment Language) profile next week
- If there's enough interest, could start another call dedicated to the OpenAPI integration topic
- Nat may not be able to attend US-friendly time zone meetings due to time zone conflicts (would fall in middle of his night) but will ask Anoop and Dave if they can host the meeting
Chris Robbertse follow-up:
- Will give it another week and see where progress is
- Will update the group next week
- Keeping the dedicated meeting option in mind
Action Items:
- Chris Robbertse: Update next week on OpenAPI community attendance plans
- Nat Sakimura: Check with Anoop and Dave about participating in potential US time zone meetings
-
Cipher Suite Approach: Adopted a phased approach for cipher suite deprecation with warnings, transition timelines
-
Certification Testing: Allow any cipher supported by Java Crypto Library that is not deprecated by IANA Cipher Suite Registry
-
Errata Updates: Both FAPI 1.0 and FAPI 2.0 errata will be updated to reflect the cipher suite approach
-
OpenAPI Integration: Continue coordination with OpenAPI community, potentially establishing a dedicated meeting if needed
- Pull Requests: https://bitbucket.org/openid/fapi/pull-requests/
- Issue #838: https://github.com/openid/fapi/issues/838
- Issue #837: https://github.com/openid/fapi/issues/837
- Issue #840: https://github.com/openid/fapi/issues/840
- Issue #835: https://github.com/openid/fapi/issues/835
- Issue #648: https://github.com/openid/fapi/issues/648
- IANA TLS Parameters Registry: https://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml
- Previous meeting notes: https://github.com/openid/fapi/wiki/FAPI_Meeting_Notes_2026-01-21_Atlantic
- Atlantic call will continue next week at the regular time
- Topics will include:
- OpenAPI integration update from Chris
- OpenAPI and OSCAL profile discussions
- Continued progress on errata work
- Follow-up on Peru and Colombia initiatives
Meeting adjourned at the top of the hour.