Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

FAPI & Post-quantum cryptography

Open
#736 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Documentation
Clarity
Needs clarification
Activity status
Quiet

Research direction

Review the FAPI 2.0 Security Profile section 5.4.1 and the referenced BCP195 guidance, then compare the TLS 1.2/1.3 and JWS/JWE post-quantum considerations described here. Done requires agreed FAPI Working Group guidance and a decision about whether and when the specification needs revision.

Written by the indexing model from the issue text.

Description

component: FAPI 1: Advanced migrated-from-bitbucket priority: major type: bug

Originally submitted by josephheenan (Joseph Heenan) on 2025-07-08

At some point we need to communicate the FAPI WG thoughts on post-quantum.

A quick set of thoughts:

  1. TLS 1.3 (or later) will be required for post-quantum so we probably want to add a recommendation around moving off TLS 1.2 at some point
  2. For TLS, FAPI2 already references BCP195 (TLS BCP) which you presume would be updated when good post-quantum advice is available, so we may not need to do anything other than keep an eye on the situation.
  3. For JWS/JWE there is post quantum work progressing at IETF (but I guess is at least a year away from becoming an RFC), we need to plan for updating https://openid.net/specs/fapi-security-profile-2_0-final.html#section-5.4.1 at some point - assuming the first step is allowing post-quantum in addition to existing algs I guess that would mean a FAPI 2.1 in maybe 2 years time. (I guess a version of FAPI that required the use of post-quantum, and hence disallowed the existing pre-quantum algs, would count as a breaking change so might need to be a FAPI 3.0 revision?)

‌


Bitbucket status: open

Bitbucket origin: issue 748

Dominant language
HTML
Stars
4
Forks
3
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from openid/fapi

All issues in openid/fapi

Similar issues

More Cryptography issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.