Please Note that the above time is CONFIRMED.
13:15 SGT | Arrival & "Can you hear me now?" (see Connection Details) |
13:30 SGT | Welcome, Introductions & Agenda Agreement
|
13:45 SGT | Privacy and Member Contacts
|
14:00 SGT 8:00 CEST | Candidate, Member and Participant Requirements
|
See https://github.com/REFEDS/SAML-Profile/ for more info. | |
14:30 SGT 8:30 CEST | OIDC Federation
|
14:50 SGT 8:50 CEST | Future SG Meetings
|
14:55 SGT 8:55 CEST | Summary, Actions and Close (or we're running over time). |
15:00 SGT | Meeting Close. |
H323: https://call.lifesizecloud.com/otherways/2410313 H323:169.57.7.200##2410313
Phone: tel:+31858884440,2410313# or https://call.lifesizecloud.com/numbers
Current status - New members and candidates: See https://technical.edugain.org/status and work on progressing new members is underway.
Privacy and Member Contacts
Nicole highlighted the eduGAIN GDPR Impact Assessment and there will be a follow-up blog post summarising this advice. This is not a document for consultation/feedback - it is advice from the GÉANT project to the community.
Three options for the technical website:
It was decided that the best approach would be to ask eduGAIN-SG delegates and deputies to give consent to their information being published and told that not having this information public is an option.
Mailing list subscription.
At the moment the eduGAIN-SG mailing list is set to the default that subscriber information is not visible to other subscribers. It is proposed that SG members have a legitimate interest in seeing this information (particularly if details may not be shown on the public webpage) so this should be changed to being visible to subscribers.
SG members were asked to review federations that have a) been in the candidate
This comes with a caveat that there isn’t yet a decision by the eduGAIN SG on how to proceed.
Thomas Lenggenhager suggested that a period of 18 months of lack of activity for candidate federations would be a good starting point for reviewing candidate federations. There would need to be a clear definition of what constituted a lack of activity. Brook suggested that candidates should have produced a policy and a MRPS within this period of time.
Thomas W queried whether there was any real problem with candidates not having shown activity and it might force candidates to invent policies that were not suitable simply to show progress.
A simple measure of progress might be that the federation is still responding to email and that this would be sufficient.
For existing participants, there is no check currently in place to ensure that the requirements that existed at the point of joining are still fully in place. Nicole proposed that this information should be re-validated once every 12 months and if requirements are not being met, then federations may be asked to restart the membership process.
Chris asked if policies should be reviewed by the eduGAIN-SG if they have changed. It was suggested that it would be good practice for federations to self declare on the eduGAIN-SG if they change their policy or MRPS and invite members to comment. Changes revealed during the yearly check should also be communicated to the SG list.
Federation | Date of Application | Status | Decision |
---|---|---|---|
Albania - RASH | 2018-01-18 | Recent applicant. No Policy/MRPS. | |
China - CSTCloudFederation | 2017-11-10 | Recent applicant. Ready for assessment. | |
China - CARSI | 2017-08-01 | Declaration only. No Policy/MRPS. | |
Lebanon - LIFE | 2017-08-07 | MRPS required prior to assessment | |
Malawi - MAREN | 2016-06-08 | Declaration only. No Policy/MRPS. | |
Malaysia - SIFULAN | 2018-01-22 | Recent applicant. Ready for assessment. | |
Mexico - FENIX | 2017-10-25 | Declaration only. No Policy/MRPS. | |
Montenegro - eduID | 2015-06-16 | Policy under development. | |
Mozambique - CAFMoz | 2016-10-13 | Joining process underway. Response to feedback required. | |
Russia - RUNNET AAI | 2018-01-26 | Joining process underway. Responding to feedback. | |
Russia - фEDUrus | 2013-07-03 | Declaration only. No Policy/MRPS. | |
Serbia - iAMRES | 2015-04-01 | Declaration only. No Policy/MRPS. | |
Slovakia - safeID | 2015-06-16 | Recent activity. New SG deputy and work on Policy. |
Federation | Application Date | Joining Date | Status | Decision |
---|---|---|---|---|
Bulgaria - BIF | 2017-03-15 | 2017-10-27 | Operational Federation not Supplying Metadata | |
Cyprus - CyNet Identity Federation | 2017-05-18 | 2017-08-15 | Federation Production supported by GRNET | |
Italy - Grid Identity Pool | 2013-07-03 | 2016-08-11 | Operational Federation not Supplying Metadata | |
New Zealand - Tuakiri New Zealand Access Federation | 2013-11-26 | 2013-11-26 | Operational Federation not Supplying Metadata | |
Turkey - YETKİM | 2013-11-06 | 2013-11-26 | No Policy, No MRPS, No Metadata |
Participating Member Nits
Federation | Issue | Status | Decision |
---|---|---|---|
Argentina/MATE | No creationInstant available | ||
Finland/HAKA | No creationInstant available | ||
Greece/GRNET-AAI | SG deputy missing | ||
Ireland/Edugate | No creationInstant available | ||
Portugal/RCSTaai | No creationInstant available | ||
Spain/SIR | No creationInstant available |
Participating Member Problems
Federation | Issue | Status | Decision |
---|---|---|---|
Croatia/AAI@EduHr | Supplied English version of the Policy missing | Will be available by Tuesday 1 May 2018 |
Federation | MRPS Exists | MRPS Based on Template | Decision |
---|---|---|---|
Algeria/ARNaai | YES | YES | |
Argentina/MATE | YES | YES | |
Armenia/AFIRE | YES | YES | |
Australia/AAF | YES | YES | |
Austria/ACOnet Identity Federation | YES | YES | |
Belarus/FEBAS | YES | NO | |
Belgium/Belnet Federation | YES | NO | |
Brazil/CAFe | NO | N/A | |
Canada/Canada Access Federation | NO | N/A | |
Chile/COFRe | NO | N/A | |
Colombia/COLFIRE | YES | YES | |
Croatia/AAI@EduHr | NO | N/A | |
Czech Republic/eduID.cz | NO | N/A | |
Denmark/WAYF | NO | N/A | |
Ecuador/MINGA | NO | N/A | |
Estonia/TAAT | YES | YES | |
Finland/HAKA | NO | N/A | |
France/Fédération Éducation-Recherche | NO | N/A | |
Georgia/Grena Identity Federation | NO | NO | |
Germany/DFN AAI | NO | NO | |
Greece/GRNET | NO | NO | |
Hungary/eduId.hu | NO | NO | |
India/INFED | YES | NO | |
Iran/IR Fed | YES | YES | |
Ireland/Edugate | YES | NO | |
Israel/IUCC Identity Federation | YES | NO | |
Italy/IDEM | YES | NO | |
Japan/GakuNin | YES | NO | |
Korea/KAFE | YES | NO | |
Latvia/LAIFE | YES | NO | |
Lithuania/LITNET FEDI | NO | NO | |
Luxembourg/eduID Luxembourg | YES | YES | |
Macedonia/AAIEduMk | NO | NO | |
Moldova/LEAF | YES | YES | |
Norway/FEIDE | NO | NO | |
Oman/Oman KID | YES | YES | |
Poland/PIONIER.Id | YES | NO | |
Portugal/RCTSaai | NO | NO | |
Singapore/Singapore Access Federation - SGAF | YES | YES | |
Slovenia/ArnesAAI Slovenska izobrazecalno raziskovalna federacija | NO | NO | |
South Africa/SAFIRE | YES | YES | |
Spain/SIR | YES | NO | |
Sweden/SWAMID | YES | NO | |
Switzerland/SWITCHaai | YES | NO | |
The Netherlands/SURFconext | YES | NO | |
U.S./InCommon | YES | NO | |
Uganda/RIF | YES | YES | |
Ukraine/PEANO | YES | NO | |
United Kingdom/UK federation | YES | YES | |
Bulgaria/BIF | NO | NO | |
Cyprus/CyNet Identity Federation | YES | YES | |
Hong Kong/HKAF | YES | NO | |
Italy/Grid Identity Pool | NO | NO | |
New Zealand/Tuakiri New Zealand Access Federation | YES | NO | |
Turkey/YETKIM | NO | N/A |
The accuracy of the above table needs to be confirmed. There are 21 federations without any MRPS and of those with some joining practice documented there are 16 that have an MRPS template compatible version of their MRPS. Feedback on your particular federation welcome.
Step 1: MRPS for everyone.
Step 2: MRPS template compatible MRPS for everyone.
The deadline was set as 1st April 2018 for all federations to have an adequate MRPS.
Nicole highlighted that edugain-support had started looking at the requirements for incident response and asked for comments and suggestions on the proposed requirements review for central support for incident response at eduGAIN. This can be found at: eduGAIN Incident Management Coordination Role.
Future meetings: