
Clone wiki

fapi / FAPI_Meeting_Notes_2023-03-29_Atlantic

FAPI WG Agenda & Meeting Notes (2023-03-29)

The meeting was called to order at 14:02 UTC.

1.   Roll Call (Dave/Nat)

  • Attending: Nat Gail, Mike, Dave, Bjorn, Craig, Dima, Domingos, Filip, George, Kelley, Kosuke, Takahiko
  • Regrets:
  • Guest:

2.   Adoption of Agenda (Dave/Nat)

  • Adopted as presented as draft agenda.

4.   Internal Liaisons

4.1.   NIST SP800-63-4ipd Comments

5.   External Orgs & Liaisons (Mike L.)

5.1.   Open Finance Brazil

  • They have seen some progress on CIBA spec.

5.2.   Open Insurance Brazil

  • Recertification - good progress.

5.3.   Saudi Arabia (Mike)

6.   Draft Updates

6.1.   Message Signing (Dave)

  • Dave has sent the fixed Implementer's draft documents to Mike J.

6.2.   Grant Management (Dima)

  • Dave is creating a submission package now.

7.   PRs (Dave)

  • Apart from one PR that we are parking until HTTP signature is settled, there is no standing PR.
  • Request/Response binding fix is waiting for IETF result next week.

8.   Issues (Dave)

8.4.   FAPI CIBA (Dave)

  • Discussed the changes it needs for supporting FAPI2.
  • Whether signing is required or not should be based on whether the base profile requires signing (e.g., FAPI2 Message Signing + CIBA should require it, while FAPI2 Security Profile + CIBA should not.)
  • Assigned to Filip.

8.6.   Network Layer Protections restrict use of more recent TLS 1.2 cyphers

  • Moving to TLS 1.3 removes the restrictions on the cyphers.
  • However, the certification suite does not support TLS 1.3.
    • Nat to create an issue on the tracker regarding this.

9.   AOB (Nat)

  • none

The call adjourned at 14:59
