Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Number

Current Text

Proposed Text / Query

Proposer

Action

#1Existing TextYour Change ProposalNamePlease leave blank
1

5.3.3 The Identity Provider releases the eduPersonScopedAffiliation attribute.

Should this imply to release this attribute *always* to *all SPs*, including to publishers that are happy with only 'common-lib-terms'? Why should just the IdPs need to do something and not the SPs?
SPs that want to get the scopedAffiliation should either require this attribute in metadata or include a new (to-be-defined in this spec) EC value in metadata. 

Thomas Lenggenhager (SWITCH)
2http://refeds.org/category/academic-institutionGiven that the REFEDS website now does https by default, should this be https://refeds.org/category/academic-institutionGuy Halse (SAFIRE)
35.3.3 The Identity Provider releases the eduPersonScopedAffiliation attribute.How should the Identity Provider’s registrar perform this mandatory check? Would a statement by the IdP administrator be sufficient ?Thomas Lenggenhager (SWITCH)
43. The following URI is used as the attribute value for the Entity Category...

Under section 5 only requirements for Identity Providers are defined but normally an IdP uses Entity Support Category not Entity Category. Is this per design or only a mistake?

Comment from Rhys Smith: "normally an IdP uses Entity Support Category not Entity Category" - is correct, but only by coincidence. An entity that has a specific categorisation has an entity category. It just so happens that so far, all categorisations have been for SPs, and so the IdPs have the ESC. This is a categorisation about an IdP, so it's right the IdP has an EC. If there was a corresponding ESC, it would be assigned to the SP that supports that IdP EC.  Propose dropping ECS text.

Pål Axelsson (SWAMID)
55.3.3 The Identity Provider releases the eduPersonScopedAffiliation attribute.I would say that the behaviour of releasing euPersonScopedAffliliation to all SPs is not privacy by design as described in GDPR. It's a step away from data minimisation. euPersonScopedAffliliation is personal data even though it is not unique personal data.Pål Axelsson (SWAMID)
6Add to section 5

5.4. additional recommendations

5.4.1 It is RECOMMENDED that IdP releases a unique, persistent and not targeted ID to Service Providers that support and display in their metadata the Research and Scholarship Entity Category [R&S]

...

6. References

add:

[R&S] REFEDS Research and Scholarship Entity Category v1.3 Sept. 2016 see https://refeds.org/category/research-and-scholarship

Peter Geitz

(DAASI)


7Section 2is point 3 - "the institution is a research hospital, library or archive." meant to mean "research hospital, research library, or research archive", or what it says on the tin?Rhys Smith
(Jisc)

85.3.3how does a registrar check if an IdP releases ePSA?Rhys Smith
(Jisc)

9section 5. "Failure to do so MUST result in revocation of the entity’s membership in the category." Who makes the decision to revoke?"Failure to do so MUST result in the registrar revoking revocation of the entity’s membership in the category."Mikael Linden (CSC)

Other Comments / Observations

...