REFEDS Assurance pilot telco
Tuesday 3rd April 2018 at 15:30 CEST/16:30 EEST/8:30 CDT
CERN’s Vidyo portal: https://www.nikhef.nl/grid/video/?m=rawg
Sami S, CSC
Timo T, Aalto
Daniel Y, Chicago
Jim B, XCEDE/CILogon
David G
Mikael L
Notes
- Changes to RAF/SFA spec draft after last call
- Assurance wg is considering a simpler approach to SFA: https://docs.google.com/document/d/1ZjpzyYWZhqjbTeIzxX9Vug9Whqb9YEkK29e1FBjL5VM/edit#
- test SPs around
- status IdPs and logins to test SPs
- Chicago
- IdP configuration pretty much done. There is some prior use of authentication context in Chicago – complicates switching to SFA/MFA
- Authentication Context goes and is properly picked up by CILogon SP
- ELIXIR displays ePAssurance attribute but just Authentication Context password.
- EGI cannot be integrated due to missing metadata in eduGAIN
- XSEDE
- now asserting MFA for all logins. Asserting IAP medium, too.
- ELIXIR displays ePAssurance but not AuthContext.
- EGI checkin not tested for the same reason as Chicago
- Aalto
- working on the logic to trigger MFA based on the requested Authentiation context – nearly there.
- Tested so far only using internal SPs.
- CSC
- no real news.
- Tested mostly using an internal test SP.
- ELIXIR test SP works for ePAssurance but not for authentication context
- This week going to test login to CILogon.
- Chicago
- updates to config samples?
- Jim and Timo to share their (new) IdP config findings
- next call: Monday 16th April 2018 at 15:30 CEST/16:30 EEST/8:30 CDT