Skip to content

FAPI_Meeting_Notes_2026 02 05_Pacific

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Agenda & Meeting Notes (2025-02-05)

Date & Time: 2025-02-05 17:00 PST

Agenda

  1. Roll Call
  2. Adoption of Agenda
  3. Events
  4. External Orgs & Liaisons
  5. PRs
  6. Issues
  7. AOB

Meeting Notes

1. Roll Call & Agenda Adoption

  • Anoop
  • Nat
  • Gail
  • Mark

2. Events Update

  • February 2 – FIDO Paris Seminar (Paris)
  • February 3 – FIDO Alliance Member Plenary (Paris)
  • February 9-12 – TIIME Unconference (Amsterdam)
  • March 9-13 – ISO/IEC JTC 1/SC 27 WG Meeting (Nürnberg, Germany)
  • March 14-20 – IETF 125 (Shenzhen, China)
  • March 16-17 – ISO/IEC JTC 1/SC 27 Plenary (Nürnberg, Germany)
  • March 16-19 – FDX Global Summit 2026 (Washington, DC)
  • April 27 – OIDF Workshop prior to IIW Spring 2026 (Mountain View)
  • April 28-30 – IIW Spring 2026 (Mountain View)
  • May 12-15 – ID4Africa (Abidjan)
  • May 19-22 – EIC 2026 (Berlin)
  • May 27-29 – OAuth Security Workshop (OSW) (Leipzig, Germany)
  • June 2 – FIDO Authenticate APAC 2026 (Singapore)
  • June 15-18 – Identiverse (Las Vegas)
  • June 22-24 – Dice 2026 (Copenhagen)
  • September 1-3 - Global Digital Collaboration Conference 2026 - Geneva
  • September 14-17 - ISO/IEC JTC1/SC 17 Plenary - Chengdu, China

Note: Please send any 2026 events to be added to the calendar to mike.leszcz@oidf.org

3. External Organizations & Liaisons

3.1 Ecosystem Partner Updates

####Peru

  • Peru continues to welcome partnership with the OpenID Foundation as they kick off their Open Banking roadmap, expected this spring
  • Peru sent questions on reference FAPI profiles for their internal review to help inform their vendor selection process
  • Additional clarifying questions received on topics like directed funding coverage
  • Peru has requested OIDF support for a workshop event. Expected in coming months

####Colombia

  • Still seeking updates on the Q1 2026 Colombia event
  • Resources available to support and fund the event
  • Event setup depends on coordination between Authlete, Capgemini, and the Colombian government
  • Joseph and Gail will follow up with Ali and other contacts

ISO/IEC JTC 1/SC 27 Liaison

  • ISO/IEC JTC 1/SC 27 meeting is coming up in 4 weeks
  • Need to provide the liaison letter
  • Category A liaison status application was sent in January and is expected to be taken up in the SC27 plenary
  • Anyone else interested in participating in SC27 liaison work should contact OIDF
  • Action Item: Anyone wanting to contribute to the SC27 liaison letter should contact Nat

4. Member Reminders

Vote Announcements

Public Review Period

  • Specification: Proposed OpenID Connect Relying Party Metadata Choices 1.0 Final Specification
  • Review Started: Friday, January 9, 2026
  • Voting Start: Scheduled for Wednesday, March 11, 2026

5. Pull Requests

PR #529 Note strict validation of audience (as per ciba)

Link: https://bitbucket.org/openid/fapi/pull-requests/529 Discussion and review conducted

Ask on PR

  • All to provide evaluation on pending PR approvals

6. Issues

Issue #838 - FAPI2 Attacker Model (ISO/IEC 26083-2)

Link: https://github.com/openid/fapi/issues/838

This issue relates to ISO submission requirements for the FAPI 2.0 Attacker Model specification.

Status: Under discussion. If no objections are raised by the Pacific call Friday, Mark V. will go ahead with the current proposal.

Action: Mark to Update the PASS submissions and circulate to the internal group.

Issue #837 - FAPI2 Security Profile (ISO/IEC 26083-1)

Link: https://github.com/openid/fapi/issues/837

This issue relates to ISO submission requirements for the FAPI 2.0 Security Profile specification.

Action: Mark to Update the PASS submissions and circulate to the internal group.

Status: Under discussion. Same as #838.

Issue #840 - Upcoming requirement to implement TLS 1.3

Link: https://github.com/openid/fapi/issues/840

  • Joseph informed the group that there is an intel that BCP 195 is getting a new RFC added to it, that will change things to “MUST TLS 1.3” and “MAY TLS 1.2”. However, there is no openly accessible documentation about it.
  • When this happens, as it is written in FAPI 2.0 Security profile, FAPI2 implementors need to update their implementation to support TLS 1.3 within 12 months.
  • Banks should start preparing it and this should be communicated to ecosystems through blog post etc.

Issue #835 - Network Layer Protections. (CHACHA20_POLY1305_SHA256 support for TLS 1.2)

The 2026-01-21 Atlantic meeting resolved to Allow any cipher supported by Java Crypto Library that is not deprecated by IANA Registry

Link: https://github.com/openid/fapi/wiki/FAPI_Meeting_Notes_2026-01-21_Atlantic

  • The certification team lead asked for the guidance to be in FAPI 2.0 errata.
  • The WG agreed to include it in FAPI 2.0 errata, and FAPI 1.0 errata as well.

Action: Robert (MasterCard): Draft and publish a blog post on the upcoming TLS 1.3 requirements and algorithm deprecations, with support/examples from Gail. Certification Team: Begin deprecating old ciphers and adding new ciphers in the certification suite, providing warnings during the 12-month transition period, and eventually blocking non-compliant implementations as per new requirements.

7. Any Other Business

  • OpenAPI/Arazzo engagement (Anoop ?) Chris Roberts (Open Banking UK): Report back to the group next week on progress with OpenAPI core team regarding FAPI support.

Clone this wiki locally