Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

TitleGlobal FedLab
DescriptionLots of useful tools have been produced as part of FedLab - as seen in Roland's excellent presentation in Indianapolis.  There have also been other tools developed across the community to monitor and check information - such as MET, Code of Conduct monitor, Lukas's domain-checking tool for edugain, SMEV etc. etc.  Some of FedLab will be moved to production as part of the GN4 project under the Identity and Harmonisation Task, but this will only address specific GEANT Project use cases.  A pilot should be undertaken by REFEDS to look at global requirements and the best set of tools for our community.  In the longterm this may merge back with GEANT service offerings but it makes sense to run a pilot under REFEDS to address all possible features.
ProposerLicia Florio, Nicole Harris, Roland Hedberg
Resource requirementsFunding for hosting and coordinating testing and decisions around useful tools.  Development effort can be provided via GN4.
+1's<for others to voice their support - add your name here>Tom Barton
Title

EduGAIN Global incident handling/support framework

Description

As national federations continue to join eduGAIN the problem of supporting users across federation boundaries will increase. When a user has an issue attempting to access services provided in another federation how it will be resolved in this global federation of federations. Issues the end user may experience include;

  • Understanding where the cause of the problem is;
  • Language barriers;
  • Service providers unaware that their services is available in other federations;
  • Services providers unwilling to provide support to users in other federations;
  • Global scale and time zone difference challenges

The development of a global incident handling/support framework. This framework would build on each federation’s user support strategies and seek ongoing support of the framework from federation through a memorandum of understanding.

ProposerTerry Smith (AAF) and Sat Mandri (Tuakiri)
Resource requirements

1) Development of a service oriented approach eduGAIN Global Support Framework to provide seamless user experience, including:

i. Capability to log support request from anywhere (eduGAIN Support Zendesk)

ii. Incident Management process for National Federation on eduGAIN

iii. Incident Management process for Service Providers (Institutional, National, and International SPs)

2) A program of work to ingest (1) above into all national federations participating in eduGAIN.

Development and documentation of the framework Marketing of the framework and buy in for federations

Risk and Issues

eduGAIN to publish a register for participating members to log and manage Risk and Issues

+1'sHeath Marks (AAF), Wendy Petersen (CAF)

...

Title

Attribute authorities and group membership/role information

Description

Attribute authorities become interesting in VO world, where IdPs are not able to satisfy SP needs on additional attributes about the users especially group membership/roles. The main problem is when one SP wants to accept users from different VOs which use different attribute authorities. There is no common standard for representing group name/role in the attribute having VOs identification into account (just group name can lead to collision among different VOs).

Some examples how group names are used by current group mgmt systems:

  • Perun: {vo_name}:{group_name}:{sub_group_name}:...
  • SufConext: urn:collab:group:{group_provider}:{group_name}

Protocols which work with groups and theirs requirements on the group name:

  • VOOT: apart from id (usually UUID) it uses displayName which is a translatable string giving the group a human friendly name. The name is supposed to give a clear meaning for users setting up access control.
  • SCIM: apart from id (usually UUID) it uses displayName: A human readable name for the Group. 
ProposerMichal Prochazka (CESNET)
Resource requirementsSeveral conference calls should be enough for setting up the working group and produce recommendation on nameing schema for groups including VO identification.
+1'sScott Koranda, Wendy Petersen (CAF), Niels van Dijk (SURFnet), Heather Flanagan, Tom Barton

Group 3: (Operator) Best Practice

...