FAPI & Post-quantum cryptography
Open
Nobody has claimed this yet.
component: FAPI 1: Advanced
migrated-from-bitbucket
priority: major
type: bug
- Dominant language
- HTML
- Stars
- 3
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
Originally submitted by josephheenan (Joseph Heenan) on 2025-07-08
At some point we need to communicate the FAPI WG thoughts on post-quantum.
A quick set of thoughts:
- TLS 1.3 (or later) will be required for post-quantum so we probably want to add a recommendation around moving off TLS 1.2 at some point
- For TLS, FAPI2 already references BCP195 (TLS BCP) which you presume would be updated when good post-quantum advice is available, so we may not need to do anything other than keep an eye on the situation.
- For JWS/JWE there is post quantum work progressing at IETF (but I guess is at least a year away from becoming an RFC), we need to plan for updating https://openid.net/specs/fapi-security-profile-2_0-final.html#section-5.4.1 at some point - assuming the first step is allowing post-quantum in addition to existing algs I guess that would mean a FAPI 2.1 in maybe 2 years time. (I guess a version of FAPI that required the use of post-quantum, and hence disallowed the existing pre-quantum algs, would count as a breaking change so might need to be a FAPI 3.0 revision?)
Bitbucket status: open
Bitbucket origin: issue 748
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review the FAPI 2.0 Security Profile section 5.4.1 and the referenced BCP195 guidance, then compare the TLS 1.2/1.3 and JWS/JWE post-quantum considerations described here. Done requires agreed FAPI Working Group guidance and a decision about whether and when the specification needs revision.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100