These are the proposed top-level areas for the 2024 workplan, drawn from proposals crowdsourced in late 2023 / early 2024.
REF24-1: REFEDS Coordination and ManagementLead: Nicole Harris |
|---|
Aims:
|
| WORK ITEMS | DESCRIPTION | COMMENT | ASSIGNED TO | START DATE | END DATE | STATUS |
|---|---|---|---|---|---|---|
| REF24-1A | Maintain and develop the REFEDS blog, wiki, and website. | As normal. | Nicole Harris | 01/24 | 12/24 | |
| REF24-1B | REFEDS annual meetings. | TNC and one other meeting (TBD) | Nicole Harris | 01/24 | 10/24 | |
| REF24-1C | Manage REFEDS contracts with third parties. | These are contracts with external parties that support REFEDS such as Spherical Cow Consulting. | Nicole Harris | 01/24 | 12/24 | |
| REF24-1D | Manage REFEDS Sponsorships. | Current sponsor list. | Nicole Harris | 12/18 | 12/24 |
REF24-2: Specialist Working GroupsLead: Heather Flanagan |
|---|
Aim:
|
| WORK ITEMS | DESCRIPTION | ASSIGNED TO | START DATE | END DATE | GOALS | STATUS |
|---|---|---|---|---|---|---|
| REF24-2A | Peter Brand with support from Nicole Harris | 01/24 | 12/24 | This is an ongoing discussion group and as such has no specific goals. | ||
| REF24-2B | SPOG: SP Operators Group | Laura Paglione | 01/24 | 12/24 | This is an ongoing discussion group and as such has no goals. | |
| REF24-2C | eduID Operators Group | TBD | 01/24 | 12/24 | A group of NREN's offer an IdP service that is not bound to a specific organisation, for example as an IdP of last resort and IdP for home organisations that don't manage their own. My suggestion is to create an operator group so that have a place to discuss and exchange ideas and operational guidelines. A possible first outcome could be a position paper on how eduIDs perceive themselves (what unifies the eduID?) | |
| REF24-2D | MFA profile | TBD | 01/24 | 12/24 | Define a REFEDS profile for phishing-resistant multi-factor authentication Within its chosen scope, the existing MFA profile is great, but that scope leaves some space when it states: "Protection against active man-in-the-middle attacks is out of scope of this Profile." . There are protocols in the wild which do provide phishing resistance (most prominently, WebAuthn/FIDO2), and those are rolled out progressively by many big players. These new phishing-resistant MFA methods are a new level in the game of authentication assurance, and it feels wrong to put something like "password+TOTP generator (susceptible to phishing)" and "biometrics+cryptographic keypair (w/channel binding and phishing resistant)" into the same bucket. Phishing-resistant MFA deserves being recognised as its own class of authentication assurance, with a distinct REFEDS profile. | |
| REF24-2E | Entity Category Support | TBD | 01/24 | 12/24 | Define a REFEDS profile for registering support for entity categories or frameworks in metadata. Today all working groups need to define if and how an entity shall indicate in metadata that they support a specific REFEDS specification. To make that more generic I suggest that we create a working group that define a REFEDS framework on how this should be done. Today REFEDS entity categories and SIRTFI have this defined in their specifications but it would be good to have specific profile on how to do ths for all REFEDS framworks, profiles and entity categories. | |
| REF24-2F | Metadata about Federations | TBD | 01/24 | 12/24 | To find information about federations today require that you go to each one of them you're interested to and manually gather the information or go to eduGAIN technical site and look for what is manually registered there. I suggest a working group that discuss and may define a metadata extension that include information and policy links plus contact information that is published in the federation metadata feed so that others easy can aggregate this for example in MET and the technical eduGAIN site. The solution should be federation technology agnostic with examples for both SAML and Openid technology federations. | |
| REF24-2G | Browser Changes and Federation | Judith Bush, Zacharias Törnblom | 12/22 | 12/24 | Provide input to APIs under development by the browser community to implement new privacy controls managed by the browser. In FedCM ("A privacy preserving federated identity Web API" - quote from GitHub) several browser vendors are working to ensure users can still use buttons for "Sign in with <third party IdP vendor>..." even as the privacy-preserving practices around third-party cookies etc. are rolled out - privacy practices that would inevitably break the current login pattern. This baseline will enable us to continue offering our R&E community federated access as long as we take part in its development, and adapt our community's critical software stacks. | |
| REF24-2H | Update the MRPS | TBD | 01/24 | 03/24 | The current Metadata Registration Practice Statement is out of date but is still used by eduGAIN candidates. | |
| REF24-2I | OpenScience | Supporting Open Science Through Attributes Programs such as the US Government's Open Science initiative are likely to drive requirements for attributes beyond "researcher" and "member". Resource Providers will need additional information about a person’s qualifications in order to determine access to their services. This work item intends to
| ||||
| REF24-2J | VC Governance in R&E | Promote REFEDS for VC governance The "verifable credentials world" is about to reinvent many things REFEDS has developed for the international academic interfederation world for years. This covers e.g. federation standards, attribute specs and governance structures to manage all of that. We should try to figure out how to carry over those achievements to the "verifiable credentials world". | ||||
| REF24-2K | TrustInfo | TBD | 01/24 | 06/24 | Formalise SeamlessAccess trustinfo metadata as a REFEDS specification Trustinfo metadata has been developed by the SeamlessAccess team. A working document exists and code is in development (perhaps even deployed) in SeamlessAccess. This work item is to take the specification through the REFEDS standardization process, which should facilitate uptake by federation operators. |
REF24-3: Promotion and CommunicationLead: Nicole Harris |
|---|
Aims:
|
| WORK ITEMS | DESCRIPTION | ASSIGNED TO | START DATE | END DATE | STATUS |
|---|---|---|---|---|---|
| REF24-3A | Continue the monthly REFEDS Community chats. Topics for 2024 to include: REFEDS Survey results, working group updates, other topics as considered interesting by the community | Heather Flanagan | 01/24 | 12/24 | |
| REF24-3B | Maintain a liaison program between REFEDS Steering and FIM4R, FIM4L, and SeamlessAccess. | REFEDS Steering | 02/24 | 12/24 |
REF24-4: Standards and SpecificationsLead: Heather Flanagan |
|---|
Aims:
|
| WORK ITEMS | DESCRIPTION | ASSIGNED TO | START DATE | END DATE | STATUS |
|---|---|---|---|---|---|
| REF24-4A | Schema Editorial Board with support from Heather Flanagan | 01/24 | 12/24 | Work will focus on maintenance, considering updates as requested by the community | |
| REF24-4B | Standardizing REFEDS standards | Nicole Harris and Heather Flanagan | 01/24 | 12/24 | There are areas of REFEDS specification creation that could use improvements specifically:
This would help us step up as a standardisation body and give the sort of consistency seen in other areas. |
REF24-5: REFEDS ServicesLead: Nicole Harris |
|---|
Aims:
|
| WORK ITEMS | DESCRIPTION | ASSIGNED TO | START DATE | END DATE | STATUS |
|---|