Versioning for first draft of FAPI2-Advanced

Issue #520 closed
Joseph Heenan created an issue

We have a looming situation where I think we’re about to publish:

FAPI2 Security Profile Implementers Draft 2

FAPI2 Advanced Implementers Draft 1 (with a dependency on FAPI2 Security Profile Implementers Draft 2).

I suggest we ensure both specs have the same implementers draft number, perhaps by skipping draft 1 for the advanced profile. If we don’t I suspect some people will try to use FAPI2 Advanced ID1 with FAPI2 Baseline ID1, or will talk about a non-existent FAPI2 Advanced ID2 (the certification team have certainly accidentally fallen into the latter trap a few times).

Comments (7)

  1. Joseph Heenan reporter

    We discussed this on today’s call.

    Brian raised the point that there are many things that could happen in the future that will mean we end up with the security profile and messaging signing implementers draft numbering not matching up.

    Filip said that was true, but it still seemed to be a win to align them at this point.

    I mentioned that we are hoping to get FAPI2 security profile to final shortly so hopefully it’s a relatively short window, and once we get to the point of message signing implementers drafts depending on fapi2 security profile final that’s got less potential for confusion.

    Dave said it would be good to get Nat’s input but he hadn’t joined the call at this point.

  2. Dave Tonge

    @Joseph Heenan now we’ve changed the name to FAPI 2 Message Signing, perhaps this isn’t an issue any more?

  3. Nat Sakimura

    In Oct 19 call, the callers agreed that having a different implementer’s draft numbers is a non-issue, especially after we had a name change. Also, I have pointed out that we should never skip a number, as it is an indicator of how many times it went through the public review periods.

  4. Joseph Heenan reporter

    The new name doesn’t really solve any of the issues.

    Part of the issue we have is naming things in the certification suite, and on the certification pages.

    Will FAPI 2 Message Signing ID1 explicitly say it is to be used with FAPI 2 Security Profile ID2?

  5. Log in to comment