Wiki

Clone wiki

fapi / FAPI_Meeting_Notes_2023-04-05_Atlantic

FAPI WG Agenda & Meeting Notes (2023-04-05)

The meeting was called to order at 14:02 UTC.

1.   Roll Call (Dave/Nat)

  • Attending: Filip, Nat, Brian, Chris, Dima, Dave, Kosuke, Reinaldo, Craig, Takahiko
  • Regrets: Mike Leszcz, Joseph Heenan,
  • Guest:

2.   Adoption of Agenda (Dave/Nat)

  • Adopted as presented as draft agenda. * SmartData Foundry.

4.   Internal Liaisons

4.1.   NIST SP800-63-4ipd Comments

5.   External Orgs & Liaisons (Nat/Mike L.)

5.1.   Open Finance Brazil (Nat/Mike)

  • OIDF continue to receive FAPI recertification requests as mandated by OFBR.

5.2.   Open Insurance Brazil (Nat/Mike)

  • We continue to receive OP and RP cert requests. OPIN is considering mandating FAPI recertification and we are engaged in the conversation and working to clarify OPINs recent requirements.

5.3.   Saudi Arabia (Mike/Chris/Nat)

  • We continue to receive OP and RP cert requests from SAMA participants.
  • Recertification is likely to be on FAPI2.

5.4.   SmartData Foundry (Chris)

A standards comparison table is being compiled. Volunteers to review / add content are sought.

Currently, it includes:

  • Bahrain Open Banking Framework - Bahrain OBF
  • Bank Interfaces for Standardized Payments - BISTRA
  • Consumer Data Standards - CDR
  • Czech Standard for Open Banking - COBS
  • Financial Data Exchange API - FDX
  • Open API Framework for Hong Kong
  • India Stack
  • Japan Open Banking Framework
  • NextGenPSD2
  • Open Banking In Nigeria (draft)
  • API Centre standards
  • Open Banking Brasil
  • PolishAPI
  • STET PSD2 API
  • Singapore Financial Data Exchange - SGFinDex
  • Slovak Banking API Standard
  • SNAP
  • KSA Open Banking Standard
  • Open Banking Platform
  • Swiss NextGen API
  • UK Open Banking Standard

Also, we need to find out what is the best way of crediting individuals and the foundation of the work. Chris will ping Gail and Nat on this.

6.   Draft Updates

6.1.   Message Signing (Dave)

  • Dave has sent the fixed Implementer's draft documents to Mike J.

6.2.   Grant Management (Dima)

  • Dave is creating a submission package now.

7.   PRs (Dave)

  • Apart from one PR that we are parking until HTTP signature is settled, there is no standing PR.
  • Request/Response binding fix is waiting for IETF result next week.

8.   Issues (Dave)

8.4.   FAPI CIBA (Dave)

  • https://bitbucket.org/openid/fapi/issues/580/fapi-ciba
  • Discussed the changes it needs for supporting FAPI2.
  • Whether signing is required or not should be based on whether the base profile requires signing (e.g., FAPI2 Message Signing + CIBA should require it, while FAPI2 Security Profile + CIBA should not.)
  • 5.2.2.6
  • Assigned to Filip.

8.6.   Network Layer Protections restrict use of more recent TLS 1.2 cyphers

  • Moving to TLS 1.3 removes the restrictions on the cyphers.
  • However, the certification suite does not support TLS 1.3.
    • Nat to create an issue on the tracker regarding this.

9.   AOB (Nat)

  • none

The call adjourned at 14:59

Updated