Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Embedded SCA Support #121

Open
cyberphone opened this issue Jan 6, 2024 · 1 comment
Open

Embedded SCA Support #121

cyberphone opened this issue Jan 6, 2024 · 1 comment

Comments

@cyberphone
Copy link

cyberphone commented Jan 6, 2024

11d. Berlin Group openFinance API Framework - Core-PSD2 Compliance V2 Suite - Consent API 20231005.pdf
"NOTE: The embedded SCA Approach where all PSU credentials are transported via the API is very specific."

Indeed. Making "very specific" stuff a part of a general purpose API was a HUGE mistake.

Although I would love to use Adorsys' xs2a software for embedded SCA, Berlin Group's take on the matter makes it easier to start from scratch. Here is the overarching plan.: https://cyberphone.github.io/doc/research/revised-open-banking-architecture.pdf
ob2 li

It is obviously missing one thing: there must be a way for application services to reuse the bank's login in order to permit self-initiation of payment credentials. I don't think PIISP is this.

@cyberphone
Copy link
Author

cyberphone commented Jan 7, 2024

11c. Berlin Group openFinance API Framework - Core-PSD2 Compliance V2 Suite - Protocol Functions and Security Measures 20231005.pdf

"7.1.4 Signing the body using EMV_AC
Not supported for the current version of the openFinance Framework. Support will be added as part of future versions."

This obviously does not belong in a framework. That EMV support was proposed early 2020 but never happened verifies the huge drawbacks with moving "applications" down into the "kernel".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant