Skip to content

FAPI_Meeting_Notes_2026 04 16_Pacific

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Agenda & Meeting Notes (2025-04-16)

Date & Time: 2025-04-16 17:00 PST

Agenda

  1. Roll Call
  2. Adoption of Agenda
  3. Events
  4. External Orgs & Liaisons
  5. PRs
  6. Issues
  7. AOB

Meeting Notes

1. Roll Call & Agenda Adoption

  • Anoop
  • Nat

2. Events Update

All 2026 internal meetings and industry events have been added to all OIDF calendars (Google Calendar, website calendar, and internal director calendars). Mike Jones and other colleagues were noted to be attending the TIIME Unconference in Amsterdam during the week of the call.

Upcoming events:

  • February 9–12 — TIIME Unconference, Amsterdam
  • March 9–13 — ISO/IEC JTC 1/SC 27 WG Meeting, Nürnberg, Germany
  • March 14–20 — IETF 125, Shenzhen, China
  • March 16–17 — ISO/IEC JTC 1/SC 27 Plenary, Nürnberg, Germany
  • March 16–19 — FDX Global Summit 2026, Washington, DC
  • April 27 — OIDF Workshop (prior to IIW Spring 2026), Mountain View
  • April 28–30 — IIW Spring 2026, Mountain View
  • May 12–15 — ID4Africa, Abidjan
  • May 19–22 — EIC 2026, Berlin
  • May 27–29 — OAuth Security Workshop (OSW), Leipzig, Germany
  • June 2 — FIDO Authenticate APAC 2026, Singapore
  • June 15–18 — Identiverse, Las Vegas
  • June 22–24 — DICE 2026, Copenhagen
  • July 18–24 — IETF 126, Vienna
  • September 1–3 — Global Digital Collaboration Conference 2026, Geneva
  • September 14–17 — ISO/IEC JTC1/SC 17 Plenary, Chengdu, China
  • October 19–21 — FIDO Authenticate 2026, Carlsbad, CA
  • November 2 — OIDF Workshop (prior to IIW Fall 2026), Mountain View
  • November 3–5 — IIW Fall 2026, Mountain View
  • November 14–20 — IETF 127, San Francisco
  • December 7–9 — Gartner IAM US, Las Vegas

Note: Nat flagged a newly announced OECD Working Party on Digital Security on 14 April. One of the agenda item is security on artificial intelligence, and quantum computing. Mike will add the date to the OIDF calendar.

To add a 2026 event to the calendar, contact: mike.leszcz@oidf.org

3. External Organizations & Liaisons

3.1 Ecosystem Partner Updates

4. Member Updates & Reminders

Vote Announcements

5. Pull Requests

6. Issues

Issue #838 — FAPI 2.0 Attacker Model: ISO/IEC 26083-2

Link: https://github.com/openid/fapi/issues/840

  • Most comments are editorial
  • The group has conflicting style conventions across specifications; the approach is to move common goals to a shared section applicable to both the Security Profile and Attacker Model. A draft version of such a document has been created. (review comment from Atlantic call)

OSCAL Integration with FAPI (Issue #839)

Link: https://github.com/openid/fapi/issues/839

Background

  • Damian Hickey introduced Issue #839, which he raised on Bitbucket and was invited by Nat to discuss with the group.
  • Duende's identity server can be configured to be FAPI 2.0 conformant. Damian explored the next stage: automated compliance reporting for auditors.
  • Auditors need to understand if a system is fully or partially compliant, what remediations exist, and whether configuration drift has caused non-compliance over time.
  • Duende is building an HTML/PDF report for auditors that gives a configuration breakdown of the identity server. Looking further ahead, Damian explored OSCAL (Open Security Controls Assessment Language) — a NIST-driven standard for machine-readable schema defining how a system conforms to a set of controls.
  • The core question: can an OSCAL profile be defined for FAPI 2.0 that maps FAPI controls to machine-readable, auditable representations consumable by GRC systems (such as Drata, Vanta, etc.)?

Action Item

  • Damian Hickey: Develop a few specific OSCAL examples relevant to FAPI 2.0 (focusing on controls that are within FAPI scope), and explore an initial OSCAL profile draft for FAPI. Update Bitbucket Issue #839 with findings.
  • Dima Postnikov: Mention the OSCAL topic in the next Ecosystem Support Community Group call.

Clone this wiki locally