...
13:15 SGT | Arrival & "Can you hear me now?" (see Connection Details) |
13:30 SGT | Welcome, Introductions & Agenda Agreement
|
13:45 SGT | Privacy and Member Contacts
|
14:00 SGT 8:00 CEST | Candidate, Member and Participant Requirements
|
See https://github.com/REFEDS/SAML-Profile/ for more info. | |
14:30 SGT 8:30 CEST | OIDC Federation
|
14:50 SGT 8:50 CEST | Future SG Meetings
|
14:55 SGT 8:55 CEST | Summary, Actions and Close (or we're running over time). |
15:00 SGT | Meeting Close. |
...
Federations in Attendance (xx)
- SWITCHaai
- FÉR
Attendees (xx)
- Brook Schofield, GÉANT
- Casper Dreef, GÉANT
- Nicole Harris, GÉANT
- Thomas Lenggenhager, SWITCH
- Terry Smith, AAF
- Chris Phillips, CANARIE
- Arnout Terpstra, SURFconext
- Maja, P
- Zenon Mousmoulas, GRNET
- Sten Aus, EENet / TAAT (Estonia)
- Sven Hüsson, EENet / TAAT (Estonia)
- Alex
- Anass Chabli, FÉR
- Jonathan Cheng, HKAF
- Nicholas Mbonimpa
- Pål Axelsson, SWAMID
- Pascal P, Belnet
- Saeed Khademi, IRFedxxxx, Hitsa
- ...
- Gerrit Bahlman, APAN Chair
- Erik K., NORDUnet
- Toby Chan, HKAF
- William Wan, CARSI
- xxx, Bangladesh
- Peter Kopac, safeID
- Justin Knight, Jisc
- Guy Halse, SAFIRE (with Donald Coetzee)
- Davide Vaghetti, GARR
Apologies (x)
- Wolfgang Pempe, DFN
- Peter Schober, ACOnet
- ...
...
Current status - New members and candidates: See https://technical.edugain.org/status and work on progressing new members is underway.
Privacy and Member Contacts
- Technical website email addresses.
- Mailing list membership visibility.
Nicole highlighted the eduGAIN GDPR Impact Assessment and there will be a follow-up blog post summarising this advice. This is not a document for consultation/feedback - it is advice from the GÉANT project to the community.
Three options for the technical website:
- Default name + email address listed (current situtation).
- Default name with hidden email address.
- Neither name nor email address.
It was decided that the best approach would be to ask eduGAIN-SG delegates and deputies to give consent to their information being published and told that not having this information public is an option.
- ACTION20180327-01: Nicole to ask all the SG delegates and deputies to opt-in to having their data published on the eduGAIN website, and make them aware that email can be hidden.
Mailing list subscription.
At the moment the eduGAIN-SG mailing list is set to the default that subscriber information is not visible to other subscribers. It is proposed that SG members have a legitimate interest in seeing this information (particularly if details may not be shown on the public webpage) so this should be changed to being visible to subscribers.
- ACTION20180327-02: Brook to propose a change in the mailing list settings to allow subscribers of the eduGAIN-SG to see other subscribers and give them a window to object.
Candidate, Member and Participant Requirements
SG members were asked to review federations that have a) been in the candidate
This comes with a caveat that there isn’t yet a decision by the eduGAIN SG on how to proceed.
Thomas Lenggenhager suggested that a period of 18 months of lack of activity for candidate federations would be a good starting point for reviewing candidate federations. There would need to be a clear definition of what constituted a lack of activity. Brook suggested that candidates should have produced a policy and a MRPS within this period of time.
Thomas W queried whether there was any real problem with candidates not having shown activity and it might force candidates to invent policies that were not suitable simply to show progress.
A simple measure of progress might be that the federation is still responding to email and that this would be sufficient.
- ACTION20180327-04: Brook to propose email response as a simple bar for measuring responsiveness of candidate federations.
For existing participants, there is no check currently in place to ensure that the requirements that existed at the point of joining are still fully in place. Nicole proposed that this information should be re-validated once every 12 months and if requirements are not being met, then federations may be asked to restart the membership process.
- ACTION20180327-05: eduGAIN-OT to implement a yearly check of basic requirements for member federations. If requirements are not being met by any member federation, these issues will be brought to the next eduGAIN-SG for review.
Chris asked if policies should be reviewed by the eduGAIN-SG if they have changed. It was suggested that it would be good practice for federations to self declare on the eduGAIN-SG if they change their policy or MRPS and invite members to comment. Changes revealed during the yearly check should also be communicated to the SG list.
Long term candidacy
Federation | Date of Application | Status | Decision |
---|---|---|---|
Albania - RASH | 2018-01-18 | Recent applicant. No Policy/MRPS. | |
China - CSTCloudFederation | 2017-11-10 | Recent applicant. Ready for assessment. | |
China - CARSI | 2017-08-01 | Declaration only. No Policy/MRPS. | |
Lebanon - LIFE | 2017-08-07 | MRPS required prior to assessment | |
Malawi - MAREN | 2016-06-08 | Declaration only. No Policy/MRPS. | |
Malaysia - SIFULAN | 2018-01-22 | Recent applicant. Ready for assessment. | |
Mexico - FENIX | 2017-10-25 | Declaration only. No Policy/MRPS. | |
Montenegro - eduID | 2015-06-16 | Policy under development. | |
Mozambique - CAFMoz | 2016-10-13 | Joining process underway. Response to feedback required. | |
Russia - RUNNET AAI | 2018-01-26 | Joining process underway. Responding to feedback. | |
Russia - фEDUrus | 2013-07-03 | Declaration only. No Policy/MRPS. | |
Serbia - iAMRES | 2015-04-01 | Declaration only. No Policy/MRPS. | |
Slovakia - safeID | 2015-06-16 | Recent activity. New SG deputy and work on Policy. |
...
Federation | MRPS Exists | MRPS Based on Template | Decision |
---|---|---|---|
Algeria/ARNaai | YES | YES | |
Argentina/MATE | YES | YES | |
Armenia/AFIRE | YES | YES | |
Australia/AAF | YES | YES | |
Austria/ACOnet Identity Federation | YES | YES | |
Belarus/FEBAS | YES | NO | |
Belgium/Belnet Federation | YES | NO | |
Brazil/CAFe | NO | N/A | |
Canada/Canada Access Federation | NO | N/A | |
Chile/COFRe | NO | N/A | |
Colombia/COLFIRE | YES | YES | |
Croatia/AAI@EduHr | NO | N/A | |
Czech Republic/eduID.cz | NO | N/A | |
Denmark/WAYF | NO | N/A | |
Ecuador/MINGA | NO | N/A | |
Estonia/TAAT | YES | YES | |
Finland/HAKA | NO | N/A | |
France/Fédération Éducation-Recherche | NO | N/A | |
Georgia/Grena Identity Federation | NO | NO | |
Germany/DFN AAI | NO | NO | |
Greece/GRNET | NO | NO | |
Hungary/eduId.hu | NO | NO | |
India/INFED | YES | NO | |
Iran/IR Fed | YES | YES | |
Ireland/Edugate | YES | NO | |
Israel/IUCC Identity Federation | YES | NO | |
Italy/IDEM | YES | NO | |
Japan/GakuNin | YES | NO | |
Korea/KAFE | YES | NO | |
Latvia/LAIFE | YES | NO | |
Lithuania/LITNET FEDI | NO | NO | |
Luxembourg/eduID Luxembourg | YES | YES | |
Macedonia/AAIEduMk | NO | NO | |
Moldova/LEAF | YES | YES | |
Norway/FEIDE | NO | NO | |
Oman/Oman KID | YES | YES | |
Poland/PIONIER.Id | YES | NO | |
Portugal/RCTSaai | NO | NO | |
Singapore/Singapore Access Federation - SGAF | YES | YES | |
Slovenia/ArnesAAI Slovenska izobrazecalno raziskovalna federacija | NO | NO | |
South Africa/SAFIRE | YES | YES | |
Spain/SIR | YES | NO | |
Sweden/SWAMID | YES | NO | |
Switzerland/SWITCHaai | YES | NO | |
The Netherlands/SURFconext | YES | NO | |
U.S./InCommon | YES | NO | |
Uganda/RIF | YES | YES | |
Ukraine/PEANO | YES | NO | |
United Kingdom/UK federation | YES | YES | |
Bulgaria/BIF | NO | NO | |
Cyprus/CyNet Identity Federation | YES | YES | |
Hong Kong/HKAF | YES | NO | |
Italy/Grid Identity Pool | NO | NO | |
New Zealand/Tuakiri New Zealand Access Federation | YES | NO | |
Turkey/YETKIM | NO | N/A |
...
Step 2: MRPS template compatible MRPS for everyone.
The deadline was set as 1st April 2018 for all federations to have an adequate MRPS.
TODO: Policies that don't follow the federation template? What is the importance of this?
General activity and incident response requirements
...
- ACTION20180327-06: Brook / Nicole to contact all of the federations that do not have an adequate MRPS to discuss a plan for implementing a MRPS.
Incident response requirements
Nicole highlighted that edugain-support had started looking at the requirements for incident response and asked for comments and suggestions on the proposed requirements review for central support for incident response at eduGAIN. This can be found at: eduGAIN Incident Management Coordination Role.
- ACTION20180327-07: All to review the requirements for the eduGAIN Incident Management Coordination Role.
Future meetings: