Wiki
Clone wikifapi / FAPI_Meeting_Notes_2024-05-16_Pacific
FAPI WG Agenda & Meeting Notes (2024-05-16)
Date & Time: 2024-05-16 00:00 UTC Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
Agenda
The meeting was called to order at 00:00 UTC.
1. Roll Call (Anoop)
- Attendees: Mark, Nat, Dima and Ed
- Regrets:
2. Events Update
2.1. Identiverse
- May 28-31 in Las Vegas – OIDF is planning to have breakout room if the WG is interested in meeting
- FAPI WG is confirmed for F2F meeting on Wednesday, May 29, 2024 7-8am PT in Bluethorn 8 on the same level as the expo floor.
2.2. EIC
- June 4-7 in Berlin. OIDF Workshop on June 4.
2.3. Open Banking Expo Canada
- June 11th: https://www.openbankingexpo.com/canada/. OIDF doesn't currently have anyone attending but that may change
2.4. OIDF Workshop Fall
- OIDF workshop in the Mountain View area on Monday, October 28th prior to IIW. Location yet to be determined.
3. Liaison/Ext Org
3.1. CFPB
- Open Banking Rule Making in the US. OIDF putting together open letter to CFPB director to clarify points made in recent remarks at FDX Summit.
- Will share with Board of Directors for feedback before publishing the letter to the OIDF website
4. Issues & PRs
4.1. Issue 685 - TLS 1.2 Cipher
https://bitbucket.org/openid/fapi/issues/685/use-of-tls-12-ciphers Notes From Atlantic call to review: - Agreement current clause allows for a wider set of cipher suites for endpoints used by web browsers - Discussion around some banks supporting legacy ciphers for compliance reasons - Proposal to add a line to the FAPI 1 vs FAPI 2 differences table to clarify FAPI 2 is more permissive in this area - Restriction are for non-browser endpoints - Text from FAPI 1
4.2. 692 - CAA records
Notes from Atlantic call to be reviewd:
- https://bitbucket.org/openid/fapi/issues/692/caa-records
- Provide hints to implementers to mitigate impersonated domain validated certificates
- It is hard to test and so we will not make it normaitve.
- Consensus to leave current text as-is recommending but not requiring CAA records, as requiring them would be outside the scope of FAPI
6. FAPI 2 Status Update
- Still processing last call working group comments, on track for FAPI 2 to be final by end of August
7. Next Call
Next call will be an Pacific Call. Next Pacific call will be in two weeks (05-30-2024 @ 5pm PST) UTC - 05-31-2024 1:00 AM.
Updated