SlideShare ist ein Scribd-Unternehmen logo
1 von 16
OpenID Foundation
FAPI Certification Program
May 2019 Update
Joseph Heenan: FAPI Certification Program – May 2019 Update
Who Am I?
 Joseph Heenan, CTO at fintechlabs.io
 OpenID Certification Team member
 Software engineer & architect with over 25 years’ experience
 Active contributor to the OpenID Connect FAPI/MODRNA WG & specifications
 Team lead/product owner on the Open Banking Security Profile Conformance Suite
 Assisted many of the largest UK banks with achieving compliance to the OpenID
specification
https://www.linkedin.com/in/josephheenan/
Joseph Heenan: FAPI Certification Program – May 2019 Update
OIDF FAPI-RW Certification Program
 OP testing launched 1st April 2019
o Two implementors certified on day 1 & several more close to certifying
 RP testing in ‘pilot phase’
oRP Certification free until June 2019
 Visit https://openid.net/certification/instructions/ for details
Joseph Heenan: FAPI Certification Program – May 2019 Update
FAPI-RW Certification: Core goals
 Interoperability
 Security
 Correct deployment of certified software
However:
 Does not test all of OpenID Connect Core or OAuth
o ‘Pretty good’ coverage of relevant parts though
o Run python OpenID Connect Core tests as well
Joseph Heenan: FAPI Certification Program – May 2019 Update
Conformance Suite Design Goals
 Multi-party protocol testing
 Structured configuration
 Structured logging and results
 Separation of test logic & web frontend
 Deterministic, modular execution units
 Protect sensitive configuration and results data
 Transparent process
 Usable as part of CI
Joseph Heenan: FAPI Certification Program – May 2019 Update
Major differences vs current certification suite
 private_key_jwt client authentication
 Mutual TLS client authentication
 Signed request objects
 Certificate Bound access tokens
 Browser automation
 API
 Automated public regression test
 Automated regression testing of all source code changes
 Predictable fixed redirect URIs
 Two registered clients are required (to verify certificate binding etc)
 Resource server (with a trivial protected API) is required
 Extensible to support further profiles
o e.g. the UK OpenBanking profile of FAPI
Joseph Heenan: FAPI Certification Program – May 2019 Update
FAPI-RW: Help Wanted
 Conformance suite has automated regression tests
 Ensures that conformant implementations still pass the tests
 We need access to conformant implementations!
o In return, our team will let you know about any potential non-
compliances
 Only 1 OP vendor has signed up for ‘continuous conformance’
 RP testers also wanted
Joseph Heenan: FAPI Certification Program – May 2019 Update
CIBA Certification
 FAPI-CIBA OP tests
o Entering pilot phase imminently
o Spec still a little in flux
o Negative tests still being added
oDue to launch late June 2019
o Please email / talk to me if you have an implementation you’d like to
test!
 FAPI-CIBA RP tests
oEntering pilot phase July 2019
Joseph Heenan: FAPI Certification Program – May 2019 Update
Other available tests
 FAPI-R: Positive tests only
 FAPI-RW-OB: FAPI-RW tests that register intent prior to
authorization
o Intent registration APIs are specific to UK OB ecosystem
 HEART: Some tests available
 Certification program does not cover above
 Individual WGs should drive their tests & certification program
oCertification team can help/advise
o Fintechlabs.io can help
Joseph Heenan: FAPI Certification Program – May 2019 Update
Current roadmap
 June 2019: Full launch: FAPI-RW RP & FAPI-CIBA OP
 July 2019: Pilot launch: FAPI-CIBA RP
 September 2019: Full Launch: FAPI-CIBA RP
 Later (TBC):
o CIBA core OP tests
o FAPI-JARM OP tests
Joseph Heenan: FAPI Certification Program – May 2019 Update
Wrap up
 Conformance Suite source code etc publicly available on gitlab:
https://gitlab.com/openid/conformance-suite
Contributions welcome!
 Production deployment:
https://www.certification.openid.net/login.html
(Login with any google/gitlab/openid account)
 Contact me if you’d like some help:
o joseph.heenan@oidf.org or certification@oidf.org
o https://twitter.com/josephheenan
OpenID Foundation
OpenBanking UK Status
May 2019 Update
Joseph Heenan: FAPI Certification Program – May 2019 Update
A Quick Recap
 Largest 9 banks (the ‘CMA9’) in the UK were found to be having
an ‘adverse effect on competition’
 UK Government required these 9 banks to implement APIs
similar to PSD2
o 18 months ahead of PSD2 timelines
oUsing a standardised API
o Covering only current accounts
 Security profile derived from FAPI-RW specifications
Joseph Heenan: FAPI Certification Program – May 2019 Update
UK Banks
 Largest 9 banks (the ‘CMA9’) are using standards derived from
AIB, Barclays, BOI, Danske, HSBC, Lloyds, Nationwide, RBS,
Santander
 Further UK banks due to deploy same standards
o Sainsbury’s, Creation, Cynergy, ClearBank, Cumberland BS, Yorkshire
BS, Vanquis, …
 Currently banks are not returning customer identity
 CMA9 have all passed an older (pre-FAPI) version of the FAPI
conformance tool
 Banks aligning to FAPI standard within the next year
 CIBA is allowed but not required
Joseph Heenan: FAPI Certification Program – May 2019 Update
UK API Consumers
 >23 API-consuming services live with end-users as of March
2019
 >38 million API calls in March 2019
 Uses vary
o Account aggregation
oAffordability checks
o Credit scoring
o Financial forecasting
Joseph Heenan: FAPI Certification Program – May 2019 Update
The End
Thank you!

Weitere ähnliche Inhalte

Was ist angesagt?

OpenID Certification Program Update - 2018-04-02
OpenID Certification Program Update - 2018-04-02OpenID Certification Program Update - 2018-04-02
OpenID Certification Program Update - 2018-04-02MikeLeszcz
 
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License PresentantionOpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License PresentantionMikeLeszcz
 
OIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification UpdateOIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification UpdateOpenIDFoundation
 
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group UpdateOpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group UpdateMikeLeszcz
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group UpdateOIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group UpdateOpenIDFoundation
 
OpenID Foundation RISC WG Update - 2017-10-16
OpenID Foundation RISC WG Update - 2017-10-16OpenID Foundation RISC WG Update - 2017-10-16
OpenID Foundation RISC WG Update - 2017-10-16MikeLeszcz
 
OpenID Foundation RISC WG Update - 2018-04-02
OpenID Foundation RISC WG Update - 2018-04-02OpenID Foundation RISC WG Update - 2018-04-02
OpenID Foundation RISC WG Update - 2018-04-02MikeLeszcz
 
OpenID Foundation MODRNA WG Update
OpenID Foundation MODRNA WG UpdateOpenID Foundation MODRNA WG Update
OpenID Foundation MODRNA WG UpdateBjorn Hjelm
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...OpenIDFoundation
 
Getting Started with API Standardization in SwaggerHub
Getting Started with API Standardization in SwaggerHubGetting Started with API Standardization in SwaggerHub
Getting Started with API Standardization in SwaggerHubSmartBear
 
9 Months and Counting with Jeff Borek of IBM OpenAPI Meetup 2016 09 15
9 Months and Counting with Jeff Borek of IBM OpenAPI Meetup 2016 09 159 Months and Counting with Jeff Borek of IBM OpenAPI Meetup 2016 09 15
9 Months and Counting with Jeff Borek of IBM OpenAPI Meetup 2016 09 15Open API Initiative (OAI)
 
IATA Open Air: How API Standardization Enables Innovation in the Airline Indu...
IATA Open Air: How API Standardization Enables Innovation in the Airline Indu...IATA Open Air: How API Standardization Enables Innovation in the Airline Indu...
IATA Open Air: How API Standardization Enables Innovation in the Airline Indu...SmartBear
 
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...SmartBear
 
Effective API Lifecycle Management
Effective API Lifecycle Management Effective API Lifecycle Management
Effective API Lifecycle Management SmartBear
 
How LISI Automotive Accelerated Application Delivery with SwaggerHub
How LISI Automotive Accelerated Application Delivery with SwaggerHubHow LISI Automotive Accelerated Application Delivery with SwaggerHub
How LISI Automotive Accelerated Application Delivery with SwaggerHubSmartBear
 
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...apidays
 
[WSO2 API Day Chicago 2019] Sustainable Competitive Advantage
[WSO2 API Day Chicago 2019] Sustainable Competitive Advantage [WSO2 API Day Chicago 2019] Sustainable Competitive Advantage
[WSO2 API Day Chicago 2019] Sustainable Competitive Advantage WSO2
 
Can virtualization transform your API lifecycle?
Can virtualization transform your API lifecycle?Can virtualization transform your API lifecycle?
Can virtualization transform your API lifecycle?TEST Huddle
 

Was ist angesagt? (19)

OpenID Certification Program Update - 2018-04-02
OpenID Certification Program Update - 2018-04-02OpenID Certification Program Update - 2018-04-02
OpenID Certification Program Update - 2018-04-02
 
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License PresentantionOpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
 
OIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification UpdateOIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification Update
 
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group UpdateOpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group UpdateOIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
 
OpenID Foundation RISC WG Update - 2017-10-16
OpenID Foundation RISC WG Update - 2017-10-16OpenID Foundation RISC WG Update - 2017-10-16
OpenID Foundation RISC WG Update - 2017-10-16
 
OpenID Foundation RISC WG Update - 2018-04-02
OpenID Foundation RISC WG Update - 2018-04-02OpenID Foundation RISC WG Update - 2018-04-02
OpenID Foundation RISC WG Update - 2018-04-02
 
OpenID Foundation MODRNA WG Update
OpenID Foundation MODRNA WG UpdateOpenID Foundation MODRNA WG Update
OpenID Foundation MODRNA WG Update
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
 
Getting Started with API Standardization in SwaggerHub
Getting Started with API Standardization in SwaggerHubGetting Started with API Standardization in SwaggerHub
Getting Started with API Standardization in SwaggerHub
 
9 Months and Counting with Jeff Borek of IBM OpenAPI Meetup 2016 09 15
9 Months and Counting with Jeff Borek of IBM OpenAPI Meetup 2016 09 159 Months and Counting with Jeff Borek of IBM OpenAPI Meetup 2016 09 15
9 Months and Counting with Jeff Borek of IBM OpenAPI Meetup 2016 09 15
 
API Docs with OpenAPI 3.0
API Docs with OpenAPI 3.0API Docs with OpenAPI 3.0
API Docs with OpenAPI 3.0
 
IATA Open Air: How API Standardization Enables Innovation in the Airline Indu...
IATA Open Air: How API Standardization Enables Innovation in the Airline Indu...IATA Open Air: How API Standardization Enables Innovation in the Airline Indu...
IATA Open Air: How API Standardization Enables Innovation in the Airline Indu...
 
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
 
Effective API Lifecycle Management
Effective API Lifecycle Management Effective API Lifecycle Management
Effective API Lifecycle Management
 
How LISI Automotive Accelerated Application Delivery with SwaggerHub
How LISI Automotive Accelerated Application Delivery with SwaggerHubHow LISI Automotive Accelerated Application Delivery with SwaggerHub
How LISI Automotive Accelerated Application Delivery with SwaggerHub
 
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
 
[WSO2 API Day Chicago 2019] Sustainable Competitive Advantage
[WSO2 API Day Chicago 2019] Sustainable Competitive Advantage [WSO2 API Day Chicago 2019] Sustainable Competitive Advantage
[WSO2 API Day Chicago 2019] Sustainable Competitive Advantage
 
Can virtualization transform your API lifecycle?
Can virtualization transform your API lifecycle?Can virtualization transform your API lifecycle?
Can virtualization transform your API lifecycle?
 

Ähnlich wie OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certification Update

OpenID FAPI Certification Program Update - EIC - May 2019
OpenID FAPI Certification Program Update - EIC - May 2019OpenID FAPI Certification Program Update - EIC - May 2019
OpenID FAPI Certification Program Update - EIC - May 2019Joseph Heenan
 
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program UpdateOIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program UpdateOpenIDFoundation
 
OpenChain - Today and Tomorrow - Korean Work Group
OpenChain - Today and Tomorrow - Korean Work GroupOpenChain - Today and Tomorrow - Korean Work Group
OpenChain - Today and Tomorrow - Korean Work GroupShane Coughlan
 
OpenChain China Workshop # 1
OpenChain China Workshop # 1OpenChain China Workshop # 1
OpenChain China Workshop # 1Shane Coughlan
 
Expert Panel: The Future of Community Association Management
Expert Panel: The Future of Community Association ManagementExpert Panel: The Future of Community Association Management
Expert Panel: The Future of Community Association ManagementAppFolio
 
Enterprise E-Commerce Webinar #3: Bringing Your API to Market
Enterprise E-Commerce Webinar #3: Bringing Your API to MarketEnterprise E-Commerce Webinar #3: Bringing Your API to Market
Enterprise E-Commerce Webinar #3: Bringing Your API to MarketNikita Sharma
 
#APIOps- Agile API Development powered by API Connect
#APIOps- Agile API Development powered by API Connect#APIOps- Agile API Development powered by API Connect
#APIOps- Agile API Development powered by API Connectpramodvallanur
 
API Fortress - Evolving from API Testing to API Monitoring
API Fortress - Evolving from API Testing to API MonitoringAPI Fortress - Evolving from API Testing to API Monitoring
API Fortress - Evolving from API Testing to API MonitoringPatrick Poulin
 
OpenAPI Intro (1).pdf
OpenAPI Intro (1).pdfOpenAPI Intro (1).pdf
OpenAPI Intro (1).pdfPostman
 
Evolving API Testing into API Monitoring by Patrick Poulin
Evolving API Testing into API Monitoring by Patrick PoulinEvolving API Testing into API Monitoring by Patrick Poulin
Evolving API Testing into API Monitoring by Patrick PoulinQA or the Highway
 
OpenChain Work Team Meeting Agenda 08-19-2019
OpenChain Work Team Meeting Agenda 08-19-2019OpenChain Work Team Meeting Agenda 08-19-2019
OpenChain Work Team Meeting Agenda 08-19-2019Shane Coughlan
 
Improving the software integration with the use of REST API
Improving the software integration with the use of REST APIImproving the software integration with the use of REST API
Improving the software integration with the use of REST APIIlya Beketov
 
5 Things Community Association Managers Need To Do In 2020
5 Things Community Association Managers Need To Do In 20205 Things Community Association Managers Need To Do In 2020
5 Things Community Association Managers Need To Do In 2020AppFolio
 
apidays LIVE New York 2021 - The State of Banking APIs 2021 by Mark Boyd
apidays LIVE New York 2021 - The State of Banking APIs 2021 by Mark Boydapidays LIVE New York 2021 - The State of Banking APIs 2021 by Mark Boyd
apidays LIVE New York 2021 - The State of Banking APIs 2021 by Mark Boydapidays
 
API Fortress - API Monitoring - A False Sense of Security
API Fortress - API Monitoring - A False Sense of SecurityAPI Fortress - API Monitoring - A False Sense of Security
API Fortress - API Monitoring - A False Sense of SecurityPatrick Poulin
 
Atagg2015 Testing QA transformation trends - capgemini’s 2015 world quality r...
Atagg2015 Testing QA transformation trends - capgemini’s 2015 world quality r...Atagg2015 Testing QA transformation trends - capgemini’s 2015 world quality r...
Atagg2015 Testing QA transformation trends - capgemini’s 2015 world quality r...Agile Testing Alliance
 
OpenChain Tooling Work Group Meeting #1 - Agenda Slides
OpenChain Tooling Work Group Meeting #1 - Agenda SlidesOpenChain Tooling Work Group Meeting #1 - Agenda Slides
OpenChain Tooling Work Group Meeting #1 - Agenda SlidesShane Coughlan
 
APIdays Helsinki 2019 - API Security Risk Management with Bug Bounties with L...
APIdays Helsinki 2019 - API Security Risk Management with Bug Bounties with L...APIdays Helsinki 2019 - API Security Risk Management with Bug Bounties with L...
APIdays Helsinki 2019 - API Security Risk Management with Bug Bounties with L...apidays
 
Overcoming Test Automation Obstacles
Overcoming Test Automation ObstaclesOvercoming Test Automation Obstacles
Overcoming Test Automation ObstaclesPerfecto by Perforce
 
Using OpenChain for Practical Open Source Software Supply Chain Management (O...
Using OpenChain for Practical Open Source Software Supply Chain Management (O...Using OpenChain for Practical Open Source Software Supply Chain Management (O...
Using OpenChain for Practical Open Source Software Supply Chain Management (O...Shane Coughlan
 

Ähnlich wie OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certification Update (20)

OpenID FAPI Certification Program Update - EIC - May 2019
OpenID FAPI Certification Program Update - EIC - May 2019OpenID FAPI Certification Program Update - EIC - May 2019
OpenID FAPI Certification Program Update - EIC - May 2019
 
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program UpdateOIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
 
OpenChain - Today and Tomorrow - Korean Work Group
OpenChain - Today and Tomorrow - Korean Work GroupOpenChain - Today and Tomorrow - Korean Work Group
OpenChain - Today and Tomorrow - Korean Work Group
 
OpenChain China Workshop # 1
OpenChain China Workshop # 1OpenChain China Workshop # 1
OpenChain China Workshop # 1
 
Expert Panel: The Future of Community Association Management
Expert Panel: The Future of Community Association ManagementExpert Panel: The Future of Community Association Management
Expert Panel: The Future of Community Association Management
 
Enterprise E-Commerce Webinar #3: Bringing Your API to Market
Enterprise E-Commerce Webinar #3: Bringing Your API to MarketEnterprise E-Commerce Webinar #3: Bringing Your API to Market
Enterprise E-Commerce Webinar #3: Bringing Your API to Market
 
#APIOps- Agile API Development powered by API Connect
#APIOps- Agile API Development powered by API Connect#APIOps- Agile API Development powered by API Connect
#APIOps- Agile API Development powered by API Connect
 
API Fortress - Evolving from API Testing to API Monitoring
API Fortress - Evolving from API Testing to API MonitoringAPI Fortress - Evolving from API Testing to API Monitoring
API Fortress - Evolving from API Testing to API Monitoring
 
OpenAPI Intro (1).pdf
OpenAPI Intro (1).pdfOpenAPI Intro (1).pdf
OpenAPI Intro (1).pdf
 
Evolving API Testing into API Monitoring by Patrick Poulin
Evolving API Testing into API Monitoring by Patrick PoulinEvolving API Testing into API Monitoring by Patrick Poulin
Evolving API Testing into API Monitoring by Patrick Poulin
 
OpenChain Work Team Meeting Agenda 08-19-2019
OpenChain Work Team Meeting Agenda 08-19-2019OpenChain Work Team Meeting Agenda 08-19-2019
OpenChain Work Team Meeting Agenda 08-19-2019
 
Improving the software integration with the use of REST API
Improving the software integration with the use of REST APIImproving the software integration with the use of REST API
Improving the software integration with the use of REST API
 
5 Things Community Association Managers Need To Do In 2020
5 Things Community Association Managers Need To Do In 20205 Things Community Association Managers Need To Do In 2020
5 Things Community Association Managers Need To Do In 2020
 
apidays LIVE New York 2021 - The State of Banking APIs 2021 by Mark Boyd
apidays LIVE New York 2021 - The State of Banking APIs 2021 by Mark Boydapidays LIVE New York 2021 - The State of Banking APIs 2021 by Mark Boyd
apidays LIVE New York 2021 - The State of Banking APIs 2021 by Mark Boyd
 
API Fortress - API Monitoring - A False Sense of Security
API Fortress - API Monitoring - A False Sense of SecurityAPI Fortress - API Monitoring - A False Sense of Security
API Fortress - API Monitoring - A False Sense of Security
 
Atagg2015 Testing QA transformation trends - capgemini’s 2015 world quality r...
Atagg2015 Testing QA transformation trends - capgemini’s 2015 world quality r...Atagg2015 Testing QA transformation trends - capgemini’s 2015 world quality r...
Atagg2015 Testing QA transformation trends - capgemini’s 2015 world quality r...
 
OpenChain Tooling Work Group Meeting #1 - Agenda Slides
OpenChain Tooling Work Group Meeting #1 - Agenda SlidesOpenChain Tooling Work Group Meeting #1 - Agenda Slides
OpenChain Tooling Work Group Meeting #1 - Agenda Slides
 
APIdays Helsinki 2019 - API Security Risk Management with Bug Bounties with L...
APIdays Helsinki 2019 - API Security Risk Management with Bug Bounties with L...APIdays Helsinki 2019 - API Security Risk Management with Bug Bounties with L...
APIdays Helsinki 2019 - API Security Risk Management with Bug Bounties with L...
 
Overcoming Test Automation Obstacles
Overcoming Test Automation ObstaclesOvercoming Test Automation Obstacles
Overcoming Test Automation Obstacles
 
Using OpenChain for Practical Open Source Software Supply Chain Management (O...
Using OpenChain for Practical Open Source Software Supply Chain Management (O...Using OpenChain for Practical Open Source Software Supply Chain Management (O...
Using OpenChain for Practical Open Source Software Supply Chain Management (O...
 

Mehr von OpenIDFoundation

OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...OpenIDFoundation
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...OpenIDFoundation
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...OpenIDFoundation
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation UpdateOIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation UpdateOpenIDFoundation
 
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...OpenIDFoundation
 
OIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group Update
OIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group UpdateOIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group Update
OIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group UpdateOpenIDFoundation
 
OpenID Connect "101" Introduction -- October 23, 2018
OpenID Connect "101" Introduction -- October 23, 2018OpenID Connect "101" Introduction -- October 23, 2018
OpenID Connect "101" Introduction -- October 23, 2018OpenIDFoundation
 
OpenID Foundation Research & Education Working Group Update - October 22, 2018
OpenID Foundation Research & Education Working Group Update - October 22, 2018OpenID Foundation Research & Education Working Group Update - October 22, 2018
OpenID Foundation Research & Education Working Group Update - October 22, 2018OpenIDFoundation
 
OpenID Foundation iGov Working Group Update - October 22, 2018
OpenID Foundation iGov Working Group Update - October 22, 2018OpenID Foundation iGov Working Group Update - October 22, 2018
OpenID Foundation iGov Working Group Update - October 22, 2018OpenIDFoundation
 
OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018OpenIDFoundation
 

Mehr von OpenIDFoundation (10)

OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation UpdateOIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
 
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
 
OIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group Update
OIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group UpdateOIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group Update
OIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group Update
 
OpenID Connect "101" Introduction -- October 23, 2018
OpenID Connect "101" Introduction -- October 23, 2018OpenID Connect "101" Introduction -- October 23, 2018
OpenID Connect "101" Introduction -- October 23, 2018
 
OpenID Foundation Research & Education Working Group Update - October 22, 2018
OpenID Foundation Research & Education Working Group Update - October 22, 2018OpenID Foundation Research & Education Working Group Update - October 22, 2018
OpenID Foundation Research & Education Working Group Update - October 22, 2018
 
OpenID Foundation iGov Working Group Update - October 22, 2018
OpenID Foundation iGov Working Group Update - October 22, 2018OpenID Foundation iGov Working Group Update - October 22, 2018
OpenID Foundation iGov Working Group Update - October 22, 2018
 
OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018
 

Kürzlich hochgeladen

How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfhans926745
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 

Kürzlich hochgeladen (20)

How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 

OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certification Update

  • 1. OpenID Foundation FAPI Certification Program May 2019 Update
  • 2. Joseph Heenan: FAPI Certification Program – May 2019 Update Who Am I?  Joseph Heenan, CTO at fintechlabs.io  OpenID Certification Team member  Software engineer & architect with over 25 years’ experience  Active contributor to the OpenID Connect FAPI/MODRNA WG & specifications  Team lead/product owner on the Open Banking Security Profile Conformance Suite  Assisted many of the largest UK banks with achieving compliance to the OpenID specification https://www.linkedin.com/in/josephheenan/
  • 3. Joseph Heenan: FAPI Certification Program – May 2019 Update OIDF FAPI-RW Certification Program  OP testing launched 1st April 2019 o Two implementors certified on day 1 & several more close to certifying  RP testing in ‘pilot phase’ oRP Certification free until June 2019  Visit https://openid.net/certification/instructions/ for details
  • 4. Joseph Heenan: FAPI Certification Program – May 2019 Update FAPI-RW Certification: Core goals  Interoperability  Security  Correct deployment of certified software However:  Does not test all of OpenID Connect Core or OAuth o ‘Pretty good’ coverage of relevant parts though o Run python OpenID Connect Core tests as well
  • 5. Joseph Heenan: FAPI Certification Program – May 2019 Update Conformance Suite Design Goals  Multi-party protocol testing  Structured configuration  Structured logging and results  Separation of test logic & web frontend  Deterministic, modular execution units  Protect sensitive configuration and results data  Transparent process  Usable as part of CI
  • 6. Joseph Heenan: FAPI Certification Program – May 2019 Update Major differences vs current certification suite  private_key_jwt client authentication  Mutual TLS client authentication  Signed request objects  Certificate Bound access tokens  Browser automation  API  Automated public regression test  Automated regression testing of all source code changes  Predictable fixed redirect URIs  Two registered clients are required (to verify certificate binding etc)  Resource server (with a trivial protected API) is required  Extensible to support further profiles o e.g. the UK OpenBanking profile of FAPI
  • 7. Joseph Heenan: FAPI Certification Program – May 2019 Update FAPI-RW: Help Wanted  Conformance suite has automated regression tests  Ensures that conformant implementations still pass the tests  We need access to conformant implementations! o In return, our team will let you know about any potential non- compliances  Only 1 OP vendor has signed up for ‘continuous conformance’  RP testers also wanted
  • 8. Joseph Heenan: FAPI Certification Program – May 2019 Update CIBA Certification  FAPI-CIBA OP tests o Entering pilot phase imminently o Spec still a little in flux o Negative tests still being added oDue to launch late June 2019 o Please email / talk to me if you have an implementation you’d like to test!  FAPI-CIBA RP tests oEntering pilot phase July 2019
  • 9. Joseph Heenan: FAPI Certification Program – May 2019 Update Other available tests  FAPI-R: Positive tests only  FAPI-RW-OB: FAPI-RW tests that register intent prior to authorization o Intent registration APIs are specific to UK OB ecosystem  HEART: Some tests available  Certification program does not cover above  Individual WGs should drive their tests & certification program oCertification team can help/advise o Fintechlabs.io can help
  • 10. Joseph Heenan: FAPI Certification Program – May 2019 Update Current roadmap  June 2019: Full launch: FAPI-RW RP & FAPI-CIBA OP  July 2019: Pilot launch: FAPI-CIBA RP  September 2019: Full Launch: FAPI-CIBA RP  Later (TBC): o CIBA core OP tests o FAPI-JARM OP tests
  • 11. Joseph Heenan: FAPI Certification Program – May 2019 Update Wrap up  Conformance Suite source code etc publicly available on gitlab: https://gitlab.com/openid/conformance-suite Contributions welcome!  Production deployment: https://www.certification.openid.net/login.html (Login with any google/gitlab/openid account)  Contact me if you’d like some help: o joseph.heenan@oidf.org or certification@oidf.org o https://twitter.com/josephheenan
  • 12. OpenID Foundation OpenBanking UK Status May 2019 Update
  • 13. Joseph Heenan: FAPI Certification Program – May 2019 Update A Quick Recap  Largest 9 banks (the ‘CMA9’) in the UK were found to be having an ‘adverse effect on competition’  UK Government required these 9 banks to implement APIs similar to PSD2 o 18 months ahead of PSD2 timelines oUsing a standardised API o Covering only current accounts  Security profile derived from FAPI-RW specifications
  • 14. Joseph Heenan: FAPI Certification Program – May 2019 Update UK Banks  Largest 9 banks (the ‘CMA9’) are using standards derived from AIB, Barclays, BOI, Danske, HSBC, Lloyds, Nationwide, RBS, Santander  Further UK banks due to deploy same standards o Sainsbury’s, Creation, Cynergy, ClearBank, Cumberland BS, Yorkshire BS, Vanquis, …  Currently banks are not returning customer identity  CMA9 have all passed an older (pre-FAPI) version of the FAPI conformance tool  Banks aligning to FAPI standard within the next year  CIBA is allowed but not required
  • 15. Joseph Heenan: FAPI Certification Program – May 2019 Update UK API Consumers  >23 API-consuming services live with end-users as of March 2019  >38 million API calls in March 2019  Uses vary o Account aggregation oAffordability checks o Credit scoring o Financial forecasting
  • 16. Joseph Heenan: FAPI Certification Program – May 2019 Update The End Thank you!

Hinweis der Redaktion

  1. EU regulators ask for conformance results as part of PSD2 complliance
  2. (vendor is authlete)
  3. The smaller banks are effectively required to adopt an established standard by PSD2, as doing otherwise is essentially impossible due to the requirement to prove to the relevant regulator “'is widely used and is easy for TPPs to use’”, a requirement that’s almost impossible for a small bank that few TPPs are keen to integrate with. https://www.fca.org.uk/publications/policy-statements/ps18-24-approach-final-regulatory-technical-standards-and-eba-guidelines-under-revised-payment Banks are actually aligning to a OB specific profile of API with a few extra requirements, however (unlike the previous Open Banking Security Profile) it is now a true profile, nothing conflicts with or weakens FAPI.