FAPI & Post-quantum cryptography
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Documentation
- Clarity
- Needs clarification
- Activity status
- Quiet
- Domain
- cryptography, documentation, security
Research direction
Review the FAPI 2.0 Security Profile section 5.4.1 and the referenced BCP195 guidance, then compare the TLS 1.2/1.3 and JWS/JWE post-quantum considerations described here. Done requires agreed FAPI Working Group guidance and a decision about whether and when the specification needs revision.
Written by the indexing model from the issue text.
Description
Originally submitted by josephheenan (Joseph Heenan) on 2025-07-08
At some point we need to communicate the FAPI WG thoughts on post-quantum.
A quick set of thoughts:
- TLS 1.3 (or later) will be required for post-quantum so we probably want to add a recommendation around moving off TLS 1.2 at some point
- For TLS, FAPI2 already references BCP195 (TLS BCP) which you presume would be updated when good post-quantum advice is available, so we may not need to do anything other than keep an eye on the situation.
- For JWS/JWE there is post quantum work progressing at IETF (but I guess is at least a year away from becoming an RFC), we need to plan for updating https://openid.net/specs/fapi-security-profile-2_0-final.html#section-5.4.1 at some point - assuming the first step is allowing post-quantum in addition to existing algs I guess that would mean a FAPI 2.1 in maybe 2 years time. (I guess a version of FAPI that required the use of post-quantum, and hence disallowed the existing pre-quantum algs, would count as a breaking change so might need to be a FAPI 3.0 revision?)
Bitbucket status: open
Bitbucket origin: issue 748
- Dominant language
- HTML
- Stars
- 4
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openid/fapi
-
component: FAPI 1: Advanced migrated-from-bitbucket priority: major type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
migrated-from-bitbucket priority: trivial type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
-
component: Certification component: FAPI2: Advanced Authorization
Difficulty 5/5 Over a week Newbie friendliness 35/100
-
component: Certification component: FAPI2: Security Profile
Difficulty 4/5 3-5 days Newbie friendliness 35/100
Similar issues
-
Platform Platform Reconnect Platform Virtual Map
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
hiero-ledger/hiero-consensus-node#27313 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
branch: 4.1 branch: master help wanted triaged: bug waiting-for: contributor response
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
chinabugotech/hutool#4326 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
w3c/vc-di-quantum-resistant#44 · 1 reaction ·