[Openid-specs-fapi] Recent-ish new FAPI tests (was Re: EXTERNAL : Updated invitation: FAPI Atlantic Call (Regular) @ Wed 2020-12-16 11pm - Thu 2020-12-17 12am (JST) (openid-specs-fapi at lists.openid.net))

Joseph Heenan joseph at authlete.com
Wed Dec 16 14:51:13 UTC 2020


Hi Chris

I believe this is referring to the new tests as mentioned here:

https://bitbucket.org/openid/fapi/issues/308/for-info-feedback-new-fapi-rw-id2

(And also I believe you or Freddi shared the similar list I sent to OBIE with TDA/similar)

We didn’t receive any negative feedback about these tests before we put them live, despite sending out these notifications to the FAPI WG mailing list and OBIE. For some of the tests we also had a 3 month grace period after adding the tests where we accepted certifications that didn’t have some of the new tests (that period has now expired).

If you can share some detail of which test they’re having a problem with that would help, but if they are failing the tests it appears they’re not conformant with the standards - and (aside from the new security check for private_key_jwt that no one should fail) these are interoperability issues that were originally reported by UK TPPs as real problems they ran into with banks.

As far as I know I’ve not had any contact from vendors expressing issues with this (apart from one vendor that very quickly issued a hot fix for a particular issue that several banks have already applied), so I’m not aware of any big problems here.

(If this is the bank I’m thinking of, their vendor definitely passes the current FAPI certification tests, and that bank is also failing tests they’ve passed before where the problem is they’ve broken their system since the last time they ran the tests.)

If you have any suggestions what else we could do when rolling out new tests please do share them.

Thanks

Joseph


> On 16 Dec 2020, at 14:23, Chris Michael via Openid-specs-fapi <openid-specs-fapi at lists.openid.net> wrote:
> 
> Hi All
>  
> Apologies I am on another call so cannot make today’s meeting
>  
> One topic which has been raised by one of the UK banks is regarding new tests in the FAPI tool - where they previously passed and are now failing – and this is a challenge for their vendor. Can we discuss at next meeting please.
>  
> Thanks
> Chris
>  
>  
>  
> From: Openid-specs-fapi <openid-specs-fapi-bounces at lists.openid.net <mailto:openid-specs-fapi-bounces at lists.openid.net>>
> Date: Wednesday, 16 December 2020 at 10:05
> To: Dave Tonge <dave.tonge at moneyhub.com <mailto:dave.tonge at moneyhub.com>>, sakimura at gmail.com <mailto:sakimura at gmail.com> <sakimura at gmail.com <mailto:sakimura at gmail.com>>, wesleydunnington at pingidentity.com <mailto:wesleydunnington at pingidentity.com><wesleydunnington at pingidentity.com <mailto:wesleydunnington at pingidentity.com>>, Brian Campbell <bcampbell at pingidentity.com <mailto:bcampbell at pingidentity.com>>, Steinar Noem <steinar at udelt.no <mailto:steinar at udelt.no>>, bjorn.hjelm at verizonwireless.com <mailto:bjorn.hjelm at verizonwireless.com> <bjorn.hjelm at verizonwireless.com <mailto:bjorn.hjelm at verizonwireless.com>>, openid-specs-fapi at lists.openid.net <mailto:openid-specs-fapi at lists.openid.net> <openid-specs-fapi at lists.openid.net <mailto:openid-specs-fapi at lists.openid.net>>
> Subject: EXTERNAL : [Openid-specs-fapi] Updated invitation: FAPI Atlantic Call (Regular) @ Wed 2020-12-16 11pm - Thu 2020-12-17 12am (JST) (openid-specs-fapi at lists.openid.net <mailto:openid-specs-fapi at lists.openid.net>)
> 
> CAUTION: This email originated from outside of the organisation. Do not click links or open attachments unless you have validated the sender’s email address and know the content is safe.
> This event has been changed.
> FAPI Atlantic Call (Regular)
> When
> Wed 2020-12-16 11pm – Thu 2020-12-17 12am Japan Standard Time
> Where
> https://global.gotomeeting.com/join/321819862, OpenID Foundation (map <https://gbr01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.google.com%2Fmaps%2Fsearch%2Fhttps%3A%252F%252Fglobal.gotomeeting.com%252Fjoin%252F321819862%2C%2BOpenID%2BFoundation%3Fhl%3Den&data=04%7C01%7CChris.Michael%40openbanking.org.uk%7Ccaae088f77da4e5288e508d8a1aa1cc2%7C3450fc49f14b45629b6a03faee2a42c4%7C0%7C0%7C637437099327537586%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=xdFHMgCpVZWHZQsl8FoC8VIWUChRi%2Fs9kytRcxf4jfI%3D&reserved=0>)
> Calendar
> openid-specs-fapi at lists.openid.net
> Who
>> sakimura at gmail.com - creator
>> Dave Tonge
>> wesleydunnington at pingidentity.com
>> Brian Campbell
>> Steinar Noem
>> bjorn.hjelm at verizonwireless.com
>> openid-specs-fapi at lists.openid.net
>  
> more details » <https://gbr01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcalendar.google.com%2Fcalendar%2Fevent%3Faction%3DVIEW%26eid%3Da3R2bG11b2Y3OTExZjJiMG10Mzltam5oZTdfMjAyMDEyMTZUMTQwMDAwWiBvcGVuaWQtc3BlY3MtZmFwaUBsaXN0cy5vcGVuaWQubmV0%26tok%3DNTIjbzZ2YzJvNG5ydjhpaGkxZG5nMGwycmhmaHNAZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbTYwOWViMTJkYjVjMmJhY2I3OGU4YTkwNjlmYjEzMTFhNmY0NTc5NTU%26ctz%3DAsia%252FTokyo%26hl%3Den%26es%3D0&data=04%7C01%7CChris.Michael%40openbanking.org.uk%7Ccaae088f77da4e5288e508d8a1aa1cc2%7C3450fc49f14b45629b6a03faee2a42c4%7C0%7C0%7C637437099327547547%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=QuvpWUOiDLw69fWhQ2eZfW%2FqframxoGRtas5kdkfli0%3D&reserved=0>
> Changed: OIDF FAPI WG Atlantic Call (Regular Call)
> 
> Agenda
> ------------------
> 1. Roll Call
> 2. Adoption of Agenda (Nat)
> 3. Events (Nat)
> 4. External Organizations (Nat)
> 5. FAPI 1.0 Status (Nat)
> 5.1. PRs (Dave)
> 5.2. Issues (Dave)
> 5.3. Voting (Nat)
> 5.4. Certification (Joseph)
> 6. Drafts
> 6.1. FAPI 2.0 (Daniel)
> 6.2. HTTP Signing (Dave)
> 6.3. Grant management (Torsten/Dima)
> 7. Issues (Dave/Nat)
> 8. AOB
> 
> Call in Information
> -----------------------------
> 1. Please join my meeting.
> https://global.gotomeeting.com/join/321819862 <https://gbr01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.google.com%2Furl%3Fq%3Dhttps%253A%252F%252Fglobal.gotomeeting.com%252Fjoin%252F321819862%26sa%3DD%26ust%3D1608545093886000%26usg%3DAOvVaw1DHrWaoEoxl9kQK5OF4xqA&data=04%7C01%7CChris.Michael%40openbanking.org.uk%7Ccaae088f77da4e5288e508d8a1aa1cc2%7C3450fc49f14b45629b6a03faee2a42c4%7C0%7C0%7C637437099327547547%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=FCKq4xxyehqvRws0bI1LRyrRCuaYtiKe3q08b%2F2IbW0%3D&reserved=0>
> 
> 2. Use your microphone and speakers (VoIP) - a headset is recommended. Or, call in using your telephone.
> 
> United States: +1 (224) 501-3316
> United Kingdom: +44 (0) 20 3713 5011
> 
> Access Code: 321-819-862
> Audio PIN: Shown after joining the meeting
> 
> Meeting ID: 321-819-862
> 
> GoToMeeting®
> Online Meetings Made Easy®
> 
> Not at your computer? Click the link to join this meeting from your iPhone®, iPad®, Android® or Windows Phone® device via the GoToMeeting app.
> Going (openid-specs-fapi at lists.openid.net)?    Yes <https://gbr01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcalendar.google.com%2Fcalendar%2Fevent%3Faction%3DRESPOND%26eid%3Da3R2bG11b2Y3OTExZjJiMG10Mzltam5oZTdfMjAyMDEyMTZUMTQwMDAwWiBvcGVuaWQtc3BlY3MtZmFwaUBsaXN0cy5vcGVuaWQubmV0%26rst%3D1%26tok%3DNTIjbzZ2YzJvNG5ydjhpaGkxZG5nMGwycmhmaHNAZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbTYwOWViMTJkYjVjMmJhY2I3OGU4YTkwNjlmYjEzMTFhNmY0NTc5NTU%26ctz%3DAsia%252FTokyo%26hl%3Den%26es%3D0&data=04%7C01%7CChris.Michael%40openbanking.org.uk%7Ccaae088f77da4e5288e508d8a1aa1cc2%7C3450fc49f14b45629b6a03faee2a42c4%7C0%7C0%7C637437099327557501%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=4%2FFjZCYcK%2BxeWzloCPfr0IbkOQXfvwjgk%2BOufBuhjaE%3D&reserved=0> - Maybe <https://gbr01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcalendar.google.com%2Fcalendar%2Fevent%3Faction%3DRESPOND%26eid%3Da3R2bG11b2Y3OTExZjJiMG10Mzltam5oZTdfMjAyMDEyMTZUMTQwMDAwWiBvcGVuaWQtc3BlY3MtZmFwaUBsaXN0cy5vcGVuaWQubmV0%26rst%3D3%26tok%3DNTIjbzZ2YzJvNG5ydjhpaGkxZG5nMGwycmhmaHNAZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbTYwOWViMTJkYjVjMmJhY2I3OGU4YTkwNjlmYjEzMTFhNmY0NTc5NTU%26ctz%3DAsia%252FTokyo%26hl%3Den%26es%3D0&data=04%7C01%7CChris.Michael%40openbanking.org.uk%7Ccaae088f77da4e5288e508d8a1aa1cc2%7C3450fc49f14b45629b6a03faee2a42c4%7C0%7C0%7C637437099327557501%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=m%2BX2zzwcXtVbrbvjxkR68GeDg0EUgFIYFoTeuj9flJ0%3D&reserved=0> - No <https://gbr01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcalendar.google.com%2Fcalendar%2Fevent%3Faction%3DRESPOND%26eid%3Da3R2bG11b2Y3OTExZjJiMG10Mzltam5oZTdfMjAyMDEyMTZUMTQwMDAwWiBvcGVuaWQtc3BlY3MtZmFwaUBsaXN0cy5vcGVuaWQubmV0%26rst%3D2%26tok%3DNTIjbzZ2YzJvNG5ydjhpaGkxZG5nMGwycmhmaHNAZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbTYwOWViMTJkYjVjMmJhY2I3OGU4YTkwNjlmYjEzMTFhNmY0NTc5NTU%26ctz%3DAsia%252FTokyo%26hl%3Den%26es%3D0&data=04%7C01%7CChris.Michael%40openbanking.org.uk%7Ccaae088f77da4e5288e508d8a1aa1cc2%7C3450fc49f14b45629b6a03faee2a42c4%7C0%7C0%7C637437099327567451%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=3dC%2FPZkzBOdFNIa%2B0bFakEH%2Fajif%2B4I%2Bw5hCWgsqwr8%3D&reserved=0>    more options » <https://gbr01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcalendar.google.com%2Fcalendar%2Fevent%3Faction%3DVIEW%26eid%3Da3R2bG11b2Y3OTExZjJiMG10Mzltam5oZTdfMjAyMDEyMTZUMTQwMDAwWiBvcGVuaWQtc3BlY3MtZmFwaUBsaXN0cy5vcGVuaWQubmV0%26tok%3DNTIjbzZ2YzJvNG5ydjhpaGkxZG5nMGwycmhmaHNAZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbTYwOWViMTJkYjVjMmJhY2I3OGU4YTkwNjlmYjEzMTFhNmY0NTc5NTU%26ctz%3DAsia%252FTokyo%26hl%3Den%26es%3D0&data=04%7C01%7CChris.Michael%40openbanking.org.uk%7Ccaae088f77da4e5288e508d8a1aa1cc2%7C3450fc49f14b45629b6a03faee2a42c4%7C0%7C0%7C637437099327567451%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=laowibWXaMs4j9NS6mAC6%2BB0YLB0zKku0JcWQGKoPnY%3D&reserved=0>
> Invitation from Google Calendar <https://gbr01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcalendar.google.com%2Fcalendar%2F&data=04%7C01%7CChris.Michael%40openbanking.org.uk%7Ccaae088f77da4e5288e508d8a1aa1cc2%7C3450fc49f14b45629b6a03faee2a42c4%7C0%7C0%7C637437099327577409%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=l336VXSsblR9V1IrPK1YXdjk4q0FwDvJaYVsa2IAct4%3D&reserved=0>
> You are receiving this courtesy email at the account openid-specs-fapi at lists.openid.net because you are an attendee of this event.
> 
> To stop receiving future updates for this event, decline this event. Alternatively you can sign up for a Google account at https://calendar.google.com/calendar/ and control your notification settings for your entire calendar.
> 
> Forwarding this invitation could allow any recipient to send a response to the organizer and be added to the guest list, or invite others regardless of their own invitation status, or to modify your RSVP. Learn More <https://gbr01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.google.com%2Fcalendar%2Fanswer%2F37135%23forwarding&data=04%7C01%7CChris.Michael%40openbanking.org.uk%7Ccaae088f77da4e5288e508d8a1aa1cc2%7C3450fc49f14b45629b6a03faee2a42c4%7C0%7C0%7C637437099327577409%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=eBpTcjTl7T1yhFm2TvSEqNs8ViYioUOPNza3ww5Zt5s%3D&reserved=0>.
> 
>  
> 
> 
> Please consider the environment before printing this email.
> 
> This email is from Open Banking Limited, Company Number 10440081. Our registered and postal address is 2 Thomas More Square, London, E1W 1YN. Any views or opinions are solely those of the author and do not necessarily represent those of Open Banking Limited. 
> 
> This email and any attachments are confidential and are intended for the above named only. They may also be legally privileged or covered by other legal rights and rules. Unauthorised dissemination or copying of this email and any attachments, and any use or disclosure of them, is strictly prohibited and may be illegal. If you have received them in error, please delete them and all copies from your system and notify the sender immediately by return email. You can also view our privacy policy (https://www.openbanking.org.uk/privacy-policy <https://www.openbanking.org.uk/privacy-policy>). _______________________________________________
> Openid-specs-fapi mailing list
> Openid-specs-fapi at lists.openid.net <mailto:Openid-specs-fapi at lists.openid.net>
> http://lists.openid.net/mailman/listinfo/openid-specs-fapi <http://lists.openid.net/mailman/listinfo/openid-specs-fapi>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-fapi/attachments/20201216/30f3e632/attachment-0001.html>


More information about the Openid-specs-fapi mailing list