<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><div dir="ltr">Hi,</div><div dir="ltr"><br><blockquote type="cite">Am 05.06.2020 um 10:20 schrieb Daniel Fett via Openid-specs-fapi <openid-specs-fapi@lists.openid.net>:<br><br></blockquote></div><blockquote type="cite"><div dir="ltr">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<p>Hi all,</p>
<p>I prepared a first (rough) draft of the FAPI 2 Advanced profile
and would welcome your feedback: <a href="https://bitbucket.org/openid/fapi/src/c28fc020e7ab9377d96501f2b4daa9a9da8f2128/FAPI_2_0_Advanced_Profile.md?at=danielfett%2Ffapi2%2Fadvanced">https://bitbucket.org/openid/fapi/src/c28fc020e7ab9377d96501f2b4daa9a9da8f2128/FAPI_2_0_Advanced_Profile.md?at=danielfett%2Ffapi2%2Fadvanced</a></p>
<p>One open question is whether we can give recommendations
regarding resource request and response signing. We currently have
<a href="https://bitbucket.org/openid/fapi/src/master/Financial_API_HTTP_Signing.md">https://bitbucket.org/openid/fapi/src/master/Financial_API_HTTP_Signing.md</a>
which lists "typical requirements" but does not give concrete
advice.</p>
<p>eTSI is developding JAdES </p></div></blockquote><div>is the current spec publicly available?</div><blockquote type="cite"><div dir="ltr"><p>and there is some work ongoing in the
IETF HTTP group as well.</p></div></blockquote>I think this work is in early stage, I don’t think we should be waiting for it getting stable.<br><blockquote type="cite"><div dir="ltr">
<p>What are other options that we should take a look at?</p></div></blockquote>(1) JWS in its traditional form or as (2) detached signature with unencoded payload - as far as I remember, UK OB wanted to use (2) but reverted to (1). I would appreciate if someone involved in UK OB would comment.<div><br></div><div>best regards,</div><div>Torsten.<br><blockquote type="cite"><div dir="ltr">
<p>-Daniel<br>
</p>
<span>_______________________________________________</span><br><span>Openid-specs-fapi mailing list</span><br><span>Openid-specs-fapi@lists.openid.net</span><br><span>http://lists.openid.net/mailman/listinfo/openid-specs-fapi</span><br></div></blockquote></div></body></html>