openid / openid/fapi

FAPI & Post-quantum cryptography

Open
#736 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

component: FAPI 1: Advanced migrated-from-bitbucket priority: major type: bug
Dominant language
HTML
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Originally submitted by josephheenan (Joseph Heenan) on 2025-07-08

At some point we need to communicate the FAPI WG thoughts on post-quantum.

A quick set of thoughts:

  1. TLS 1.3 (or later) will be required for post-quantum so we probably want to add a recommendation around moving off TLS 1.2 at some point
  2. For TLS, FAPI2 already references BCP195 (TLS BCP) which you presume would be updated when good post-quantum advice is available, so we may not need to do anything other than keep an eye on the situation.
  3. For JWS/JWE there is post quantum work progressing at IETF (but I guess is at least a year away from becoming an RFC), we need to plan for updating https://openid.net/specs/fapi-security-profile-2_0-final.html#section-5.4.1 at some point - assuming the first step is allowing post-quantum in addition to existing algs I guess that would mean a FAPI 2.1 in maybe 2 years time. (I guess a version of FAPI that required the use of post-quantum, and hence disallowed the existing pre-quantum algs, would count as a breaking change so might need to be a FAPI 3.0 revision?)


Bitbucket status: open

Bitbucket origin: issue 748

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the FAPI 2.0 Security Profile section 5.4.1 and the referenced BCP195 guidance, then compare the TLS 1.2/1.3 and JWS/JWE post-quantum considerations described here. Done requires agreed FAPI Working Group guidance and a decision about whether and when the specification needs revision.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.