Participants

Proposers
NameOrganisation
SUNET
Nicole RoyInternet2
GN4-3 project team
NameOrganisationRole
DFN-LRZScrum Master
Martin van Es SURFTeam Member, Development
GRnetTeam Member, Development


Stakeholders
Name

Organisation

Role 
GARReduGAIN service owner



Stakeholder engagements
DateName(s)OrganisationNotes
18.11.19

Davide Vaghetti

GARRInitial stakeholder kick-off
17.12.19--Sprint Demo 2.1
19.03.20--Sprint Demo 2.3
30.06.20--Sprint Demo 2.6








Activity overview

Description

Metadata is at the heart of the trust fabric of current R&E Identity Federations. For the trust to properly propagate, this metadata is first collected from and then distributed by the federation towards the federation members. Generally speaking this is the same for both national as well as inter-federations like eduGAIN.

The current models for distributing metadata are strained. The most widely used model that distributes a per federation file with entities suffers from file size issues and comes with a risk on long delays for changes to propagate. The MDQ model is more dynamic and resolves both aforementioned issues, but mandates a centralized service to be available at all time. This is a spof not only technically, but may also be a policy control point.

This activity investigates a new proposal from Leif Johansson, called "push MDQ" which introduces a new, potentially highly scalable way of distributing metadata.

Activity goals
  • Extend the existing proposal from Leif Johansson to include concrete examples, and identify potential challenges
  • Discuss the extended proposal with a group of community experts
  • Describe how this new protocol could be implemented and operationalized into the current trust fabric of R&E federations. Which roles and responsibilities are needed; who would cover them? Which product(s) may be used to implement the protocol. How to deal with backwards compatibility?
  • Draft an RFC based on the proposal in such way that the proposal may be implemented into a technical solution
  • If so appropriate, submit the RFC to a relevant body for standardization
  • Create at minimum 1 'server'  and 1 'client' implementation of the specification using existing IdP, SP or MDQ software

Activity Details

Technical details

This activity will define a new standard for exchanging metadata. It will extent at least 1 existing product to demonstrate the protocol can be used for metadata updates.

The fist version of the "Push MDQ" proposal can be found here: https://docs.google.com/document/d/1wc2MPME-hl6Izt9-x-UHyy880qmNpx3iVrI24TxMMI4/edit?usp=sharing

Business case

If the idea works as proposed, it would improve the scalability and freshness of metadata exchange tremendously, in its turn improving the ability for IdPs and SPs to interact in a much more secure and less error prone way

Risks
  • There might be technical restraints that prevent the use within the R&E community
  • During the initial expert discussion, it might turn out that the concept is not appreciated by the community.


Data protection & Privacy

No personal data needs to be exchanged


Definition of Done (DoD)

The activity is completed when:

  • The existing proposal from Leif Johansson is extended and discussed and written into an RFC
  • An accompaniment document is delivered describing how the protocol could be implemented into the current R&E federation trust framework
  • At minimum 1 'server'  and 1 'client' implementation of the specification using existing (open source) IdP, SP or MDQ software was created


Sustainability
  • If so appropriate, submit the RFC to a relevant body for standardization
  • The changes to software will be donated to the software projects
  • All results of the push MDQ analysis and the POC are transferred to the eduGAIN service task.

Activity Results

Meetings

Date

Activity

Owner

Minutes





















Documents

  File Modified
PDF File Push-MDQ.pdf Oct 24, 2019 by Michael Schmidt
File scenarios.odg Dec 17, 2019 by Niels van Dijk
PDF File scenarios.pdf Dec 17, 2019 by Niels van Dijk
PDF File PushMDQ implementation guidance for Federations.pdf Aug 25, 2020 by Michael Schmidt
PDF File Using public websub hubs for PushMDQ.pdf Aug 25, 2020 by Michael Schmidt


  • No labels