You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Next »

These are the proposed top-level areas for the 2024 workplan, drawn from proposals crowdsourced in late 2023 / early 2024. 



REF24-1: REFEDS Coordination and Management

Lead: Nicole Harris

Aims:

  • To progress REFEDS position as an important player within the access and identity management space internationally.  
  • To build on established relationships with GÉANT project and other federation-related activities around the world. 
WORK ITEMSDESCRIPTIONCOMMENTASSIGNED TOSTART DATEEND DATESTATUS                    
REF24-1AMaintain and develop the REFEDS blog, wiki, and website.

As normal.

Nicole Harris 01/24 12/24


REF24-1BREFEDS annual meetings.TNC and one other meeting (TBD)Nicole Harris 01/24 10/24


REF24-1CManage REFEDS contracts with third parties.These are contracts with external parties that support REFEDS such as Spherical Cow Consulting.Nicole Harris 01/24 12/24


REF24-1DManage REFEDS Sponsorships.Current sponsor list.Nicole Harris 12/18 12/24


REF24-2: Specialist Working Groups

Lead: Heather Flanagan

Aim:

  • To provide infrastructure and support for evolving ideas and areas in the REFEDS community. 
WORK ITEMSDESCRIPTIONASSIGNED TOSTART DATEEND DATEGOALS                   STATUS
REF24-2A

FOG: Federation Operators Group

Peter Brand with support from Nicole Harris01/2412/24This is an ongoing discussion group and as such has no specific goals.
REF24-2BSPOG: SP Operators GroupLaura Paglione01/2412/24This is an ongoing discussion group and as such has no goals.
REF24-2CeduID Operators GroupTBD01/2412/24

A group of NREN's offer an IdP service that is not bound to a specific organisation, for example as an IdP of last resort and IdP for home organisations that don't manage their own. My suggestion is to create an operator group so that have a place to discuss and exchange ideas and operational guidelines.

A possible first outcome could be a position paper on how eduIDs perceive themselves (what unifies the eduID?)


REF24-2DMFA profileTBD01/2412/24

Define a REFEDS profile for phishing-resistant multi-factor authentication

Within its chosen scope, the existing MFA profile is great, but that scope leaves some space when it states: "Protection against active man-in-the-middle attacks is out of scope of this Profile." . There are protocols in the wild which do provide phishing resistance (most prominently, WebAuthn/FIDO2), and those are rolled out progressively by many big players. These new phishing-resistant MFA methods are a new level in the game of authentication assurance, and it feels wrong to put something like "password+TOTP generator (susceptible to phishing)" and "biometrics+cryptographic keypair (w/channel binding and phishing resistant)" into the same bucket. Phishing-resistant MFA deserves being recognised as its own class of authentication assurance, with a distinct REFEDS profile.


REF24-2EEntity Category SupportTBD01/2412/24

Define a REFEDS profile for registering support for entity categories or frameworks in metadata.

Today all working groups need to define if and how an entity shall indicate in metadata that they support a specific REFEDS specification. To make that more generic I suggest that we create a working group that define a REFEDS framework on how this should be done. Today REFEDS entity categories and SIRTFI have this defined in their specifications but it would be good to have specific profile on how to do ths for all REFEDS framworks, profiles and entity categories.


REF24-2FMetadata about FederationsPål Axelsson01/2412/24

To find information about federations today require that you go to each one of them you're interested to and manually gather the information or go to eduGAIN technical site and look for what is manually registered there. I suggest a working group that discuss and may define a metadata extension that include information and policy links plus contact information that is published in the federation metadata feed so that others easy can aggregate this for example in MET and the technical eduGAIN site. The solution should be federation technology agnostic with examples for both SAML and Openid technology federations.


REF24-2GBrowser Changes and FederationJudith Bush, Zacharias Törnblom12/2212/24

Provide input to APIs under development by the browser community to implement new privacy controls managed by the browser. In FedCM ("A privacy preserving federated identity Web API" - quote from GitHub) several browser vendors are working to ensure users can still use buttons for "Sign in with <third party IdP vendor>..." even as the privacy-preserving practices around third-party cookies etc. are rolled out - privacy practices that would inevitably break the current login pattern. This baseline will enable us to continue offering our R&E community federated access as long as we take part in its development, and adapt our community's critical software stacks.


REF24-2HUpdate the MRPSTBD01/2403/24The current Metadata Registration Practice Statement is out of date but is still used by eduGAIN candidates.
REF24-2IOpenScience


Supporting Open Science Through Attributes

Programs such as the US Government's Open Science initiative are likely to drive requirements for attributes beyond "researcher" and "member". Resource Providers will need additional information about a person’s qualifications in order to determine access to their services. This work item intends to

  1. Capture use cases for open access/open science in order to identify the various classes of problems that will need to be addressed
  2. Collate and compare existing community efforts that may be able to support these use cases and authorization decisions
  3. Make recommendations for how the identified problems could be addressed.

REF24-2JVC Governance in R&E



Promote REFEDS for VC governance

The "verifable credentials world" is about to reinvent many things REFEDS has developed for the international academic interfederation world for years. This covers e.g. federation standards, attribute specs and governance structures to manage all of that. We should try to figure out how to carry over those achievements to the "verifiable credentials world".


REF24-2KTrustInfo
TBD01/2406/24

Formalise SeamlessAccess trustinfo metadata as a REFEDS specification

Trustinfo metadata has been developed by the SeamlessAccess team. A working document exists and code is in development (perhaps even deployed) in SeamlessAccess. This work item is to take the specification through the REFEDS standardization process, which should facilitate uptake by federation operators.


REF24-3: Promotion and Communication

Lead: Nicole Harris

Aims:

  • To provide materials and support mechanisms to help federations promote effective approaches to IdPs and SPs.
  • To provide feedback on documents produced by other groups to support clarity of messages.
  • To reach out to target groups where specific messaging could be beneficial.
WORK ITEMSDESCRIPTIONASSIGNED TOSTART DATEEND DATESTATUS                    
REF24-3AContinue the monthly REFEDS Community chats. Topics for 2024 to include: REFEDS Survey results, working group updates, other topics as considered interesting by the community


Heather Flanagan01/2412/24
REF24-3BMaintain a liaison program between REFEDS Steering and FIM4R, FIM4L, and SeamlessAccess.REFEDS Steering02/2412/24

REF24-4: Standards and Specifications

Lead: Heather Flanagan

Aims:

  • To provide support for the development of standards and specifications under the REFEDS banner.
  • To pilot specification work to support implementation requirements.
  • To put in place structures to ensure specification and schema sustainability.
WORK ITEMSDESCRIPTIONASSIGNED TOSTART DATEEND DATESTATUS                    
REF24-4A

Schema management

Schema Editorial Board with support from Heather Flanagan01/2412/24

Work will focus on maintenance, considering updates as requested by the community

REF24-4B

Standardizing REFEDS standards

Nicole Harris and Heather Flanagan01/2412/24

There are areas of REFEDS specification creation that could use improvements specifically:

  • to ensure that repeatables elements within specifications are standardised and worded in the same way for consistency and user support
  • to create a standard way of editing and managing changes to specifications within working groups (e.g github?)

This would help us step up as a standardisation body and give the sort of consistency seen in other areas.

REF24-5: REFEDS Services

Lead: Nicole Harris

Aims:

  • To support the basic REFEDS infrastructure needs (website, wiki, and mailing lists). 
WORK ITEMSDESCRIPTIONASSIGNED TOSTART DATEEND DATESTATUS                    




  • No labels