Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...


Line Number / ReferenceProposed Change or QueryProposer / AffiliationAction / Decision (please leave blank)
125"continual trust improvements" this phrase is not very clear to me. What is a "trust improvement"?Hannah Short/CERN
229the majority of the requirements are SAML independent, is there any reason to tie this to SAML? It might be more useful for future OIDC fed efforts if it were genericHannah Short/CERN



337/51/64should these contacts also cover security issues as well as operational?Hannah Short/CERN
439/53I suppose it's intentional that Sirtfi is not mentioned? Is it intended that the "security practices" be the ones from Sirtfi? It may be worth clarifying somehow, though I appreciate the value of keeping the docs independentHannah Short/CERN
5additional requirementProposed addition: "Any Federation services must support the exchange / storage and processing of personal information compliant with GDPR”Andreas Matheus, Secure Dimensions
6NARe: the comment on line 5 of this consultation table- many jurisdictions in which R&E federations operate are not subject to GDPR. I'd suggest something much more general such as "respect the privacy rights of individuals".Nic Roy, InCommon
710Typo of "interfederatons" for "interfederations"Andrew Cormack/Jisc
830Maybe clearer to explicitly add, "Those organisations are referred to as XXX Operators."Andrew Cormack/Jisc
937[IdP3] feels like "You publish contact information and respond in a timely fashion to operational issues", rather than "Your IdP must have contact information..."?Andrew Cormack/Jisc
1051

[SP3] feels like "You publish contact information and respond in a timely fashion to operational issues", rather than "Your Service must have contact information..."?

Andrew Cormack/Jisc
1158typo of "respects" for "respect".Andrew Cormack/Jisc
1258/9"unless governed by an applicable contract" seems odd, better maybe "requirements may be set out in an applicable contract"?Andrew Cormack/Jisc
1362typo "be" for "are"Andrew Cormack/Jisc
1464[FO2] feels like "You publish contact information and respond in a timely fashion to operational issues", rather than "Your Service must have contact information..."?Andrew Cormack/Jisc
15GeneralDo we have an expectation on any parts of the required information to be published in English?  If so should that be made explicit? While this is perhaps not  a requirement on an federation level, it would sure help when wanting to compare baseline between federations as may be needed for eduGAIN now or at some later time?Niels van Dijk / SURF
1624/75The reference named IFBE is the document itself. Did you mean the repository for this document and supporting material? Then better name it as repository.Thomas Lenggenhager / SWITCH
1729Move SAML specific references to a dedicated section or appendix. That allows to later add OIDC specifics.
In the SAML section refer to the two Kantara Federation Interoperability Profiles (Implementation and Deployment).
Thomas Lenggenhager / SWITCH