Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

WORKITEMSDESCRIPTIONASSIGNED TOSTART DATEEND DATESTATUS                    
REF19-2A

FOG: Federation Operators Group

Peter Schober with support from Nicole Harris01/201912/2019
REF19-2B

OIDC(re): OpenID Connect for Research and Education

Niels van Dijk with support from Heather Flanagan01/201912/2019Proposed addition to the charter: OIDCre federations are moving into pilot phases and discussions on how to run hybrid SAML/OIDC federations are happening now. Rather than having to go back and try and normalize the policies for OIDCre federations, let's take a look at what we think the policy space should look like and create the necessary templates.
REF19-2CSIRTFITom Barton with support from Nicole Harris01/201912/2019

 SIRTFI

Activity to investigate and report on the various ways Identity Federations have implemented incident response handling internally.

The result should provide national federations with insight on what to expect when contacting a peer, and opportunity for alignment and improvement. In addition it could support Sirtifi and eduGAIN e-Science support activities within AARC GEANT projects.

Template for federation operators.

Scoping tools to automate Sirtfi response testing and compliance.

REF19-2DIdPs of Last ResortPete Birkinshaw with support from Heather Flanagan01/201912/2019

Continue on work to define ways of tagging IdPs of Last Resort and defining a specification for minimum requirements of such an IdP within federation environment.


REF19-2EAssuranceMikael Linden with support from Heather Flanagan01/201912/2019

The REFEDS Assurance suite was approved in October 2018. 2019 will focus on encouraging adoption of the profiles.

REF19-2FEntity Category SupportNicole Harris01/201912/2019

Conduct a post-mortem for entity categories in general.

Work for REFEDS R&S next steps: R&S2, affiliation, academia

Abstract attributes

 - define approaches to abstract attributes to allow groups of attributes to be used.

 - feed into proposals to produce guidelines on attribute release for edugain.

 - create registry of attributes if appropriate.

Exchanging entity attributes outside of those with global definitions (e.g. R&S, Sirtfi etc) creates a potential for mounting conflict; part of handling this is orchestration and handling. There may also be tags that are defined within a federation, but not cross federation. This creates a vocabulary control challenge. Who handles the responsibilities among the fed ops to consider this and does this need managing? This work area will initially focus on discussion here (best practice), clarifying use cases and create a matrix to inform the discussion.  Recommendations on future steps to support this (including potential registries, rules for stripping using MDQ etc.) will be made.

The existing identifier complexity is maddening. Possibly push for adoption of the Subject-ID spec everywhere an identifier is needed, to reduce complexity for all involved going forward. Replaces eduPersonTargetedID, SAML 2.0 persistent NameID, eduPersonUniqueID and (partially) eduPersonPrincipalName. Might help align with private/public identifiers in OIDC.

REF19-2G

Federation Trust 2.0

Tom Barton and Judith Bush with support from Heather Flanagan01/201912/2019

Design, resource, and deploy a global metadata distribution infrastructure for both per-entity and aggregate metadata serving needs, for all federations to use, at global scale.

Per-entity metadata and dynamic federation ideas force a rethinking of how Federations Operators signify their validation or endorsement of certain metadata statements, and consequently a rethinking of much of the process of operating a federation. Deliverables:

  1. Define workflows that endow trust in dynamic federation metadata, ie, work out operational aspects of Roland's paper.
  2. Define an architecture or design in which it is easy for each recipient to validate dynamic metadata.
  3. List ramifications for standard federation operating procedures in a dynamic metadata environment.

...