Date

Attendees

Goals

Discussion items

TimeItemWhoNotes
15 min

Administrivia

  • Org financial health
  • 2025 contracts
  • SC nomination for 2025-2027
Nicole Harris
  • No concerns re:org financial health
  • This is Pål's last meeting. Thank you for your service!
15 min

REFEDS 49 Prep

Heather Flanagan

Reminder: meeting venue will be FULL

Agenda topics pulled from last meeting

30 minValue Proposition and REFEDS' Future, cont'd

From the 16 September meeting:

  • How can we get the rest of the world to recognize the experience we have to make identity federation (including wallets) work at scale?
    • It's about showing up in more communities.
  • If we want REFEDS to focus on governance and standards, we need additional resources. To get additional resources, we need a much clearer value proposition and a way to ask for funding (and a plan to do something with that funding). It's not so much that REFEDS needs the resources; it's the federations that need the resources. Which means we either build infrastructure for them or build and maintain tools they can deploy.


It's less about REFEDS as an entity as more about what we have to do in the next five years.

  • Curate specifications that only R&E is concerned about. These specs are more about user experience than transport; maybe transport needs to be considered more. There are also questions about how to deploy and support the specs. The creation function is entirely different from the enforcement function. Might be ok?
  • What do we consider our community? Just because an entity publishes metadata, they may be technically compatible and policy incompatible.
    • eduGAIN draws this line because they have an enforcement function
    • other standards orgs only act as enforcement when there is a certification body to review a test suite. Testing and validation are required.
    • also, promotion of specs is another challenge that needs to happen. Right now, that depends entirely on what time and effort volunteers have to push this forward.
  • Should REFEDS be a standards body at all? It has other functions, such as being a community/talking shop.

What would we lose if REFEDS went away?

  • GEANT could do the enforcement, but it lacks a connection to the rest of the world. It matters if we can implement our use cases, and for that we need standards and trust. If REFEDS go away, we lose the standards and trust.

Are we as much a community convener as a we are a creator of new spaces? See how FIM4R, FIM4L, TIIME reboot have formed. The enthusiasm is there when we're in the room, but it's hard to see that between the twice a year meetings. There are other ways of creating community.

If we say we need to be standards, worth noting that AEGIS and OpenID Foundation have gone different directions. What gap are we filling? Is that gap actually necessary to fill? Maybe we need to narrow down our scope.

  • Different funding sources tend to create their own communities.
  • People feel more comfortable with "their" kind of people (e.g., research operators, librarians). It does make sense on a national level, but why was it needed at a global level?
  • Communities are proving to be better at the immediate problems, but the longer-term issues still need space (and it is harder for that space to exist when funding is hard). If you stop shy of building something (e.g., a specification) before it's real, then it won't be successful. Example: wallets aren't real, yes, and no one is making the call as to whether we want to focus on it OR wait and see how it turns out. We don't have a forward-looking roadmap that includes what and how. Until we decide we're going to lead, we're going to continue to see fragmentation; people with problems to solve can't wait all day.

REFEDS needs to lead in:

  • committing to participating in other standards organizations where those SDOs have clear ownership of protocols we need (e.g., OpenID Foundation federation)
    • "layering interpretation and meaning on existing standards to establish a common, shared understanding of what these mean for R&E"
    • semantics of the identity information exchange
    • educational credentials (there is a protocol war underway in this space)
    • trust framework (OpenID Federation is promising)
  • testing and validation services
    • trust should be recognized as both technical trust and contractual/governance trust
      • see the passport and/or visa model - there is both technical trust and a governance trust, but it is also a one-service model where it only has to do one thing: get you into a country. For a MET-like tool to play around with, see https://www.passportindex.org/byRank.php
        • One could argue we have everything we need to interoperate effectively, similar to passport/visa model. So why can't we solve the last piece of agreeing to what the standard is? Maybe this is what we need to pursue: what builds technical trust vs what builds organizational trust? Do we have sufficient, modern technical trust that we can solely focus on organizational trust?
        • Maybe the gap is implementation guidance, case studies, or something to help respond to issues during implementation. How do we help entities and operators adopt the specs? We need meaningful-to-the-implementers engagement.
    • enforcement may need to distributed to the individual federations
      • REFEDS says, IF I do it, I do it in this way; Federations decide to enforce. What's missing is the agreement on what things we're all going to do together. This leads back to the issues that eduGAIN is having as well, which sees its role as distributing metadata, when it may need to be more than that.


If we ever do decide to shut REFEDS down, we must find a proper home for the material we've created.

Action items

  •