You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 15 Next »


Click on the title of any column to reorder the list.

#

Name

Document (if any)

Issue Description

Theme

Scope for this group?

Action Item

1

Warren

 

Will publishing of InCommon IdPs and SPs into eduGAIN be opt-in or opt-out? 
In particular, if we make publishing metadata into eduGAIN and pulling metadata from eduGAIN opt-in activities, it seems to me we might be able to simply have separate agreements and operating procedures for those efforts. It also seems to me as though we can start asking those IdPs and SPs that choose to participate what added value might be of most benefit to them.

opt-in/
opt-out

In Scope for policy decision

Key Issue.

2

Warren

 

Will eduGAIN metadata feeds be aggregated into the InCommon feed or pulled separately by InCommon IdPs and SPs?

Metadata practices

Out of Scope

TAC

3

Warren

 

Will InCommon simply publish the metadata as it arrives from eduGAIN, or will it add value, by, for instance:
   a) filtering eduGAIN metadata (to remove malformed metadata or metadata that does not comply with InCommon standards/expectations, metadata from commercial enterprises entering through other federations, etc?)
   b) negotiating attributes release policies, entity category tags, SAML versions, hash algorithms, etc with other eduGAIN participating federations.
   c) interpreting legal obligations related to PII or other attribute release from other federations to make it easier for InCommon IdPs and SPs.
   d) other similar value-adding activities.

Metadata practices



Minimally In scope
item C

TAC

4

Von

 

Research SPs and making sure that the ease of obtaining attribute release that the Research and Scholarship category has enabled within InCommon expands to the international arena.

R&S

Out of Scope but Note Bene

InC Ops/
TAC

5

Ann

FOPP

Section 1. Add international context/role description

Role Definition

In Scope

 

6

Theresa

FOPP

Section 2. Organizational Structure: do we need a basic flow chart?
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="942f6f37-cf10-4f83-b626-c3507f6c30b2"><ac:plain-text-body><![CDATA[[Tracy's response] or a graphic?

Document Clarity

Out of Scope
]]></ac:plain-text-body></ac:structured-macro>

Doc Editors

 

 

7

Bill

FOPP

Section 7.2 Relationship of Systems to Participant: Are ownership structures different in eduGain? Does that matter? Are their significant commercial or government systems influencing federations? 

[Warren's response] 

Ownership would be defined by each participating federation in eduGAIN. I've only got insight into a couple (UK, Canada) but they seem essentially the same.

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="9aacad36-46bd-4a9d-a21e-78ce4e2bd80d"><ac:plain-text-body><![CDATA[[Susan response] What about a federal inquiry? How do we handle those things that aren’t an adjudicated order? Or sensitive research with an entity in a hostile nation that raises questions from the US Gov?

Legal/ Process

In Scope

 

]]></ac:plain-text-body></ac:structured-macro>

8

Steven

FOPP

Update the IdP and SP definitions to better reflect the complexities of the environment.

 

 

 

9

Bill

FOPP

Are the types of Identity Providers and Service Providers in eduGain substantially different entities than what we see in our federation? Are there different trust marks or certification marks than what we tend to use? If substantially different how will we inform our participants of what those entities are? 

[Warren's response]

 For the most part, the IdPs and SPs are very analogous to what we have in InCommon. They are mostly university ID management systems and services. Individual federations in eduGAIN might have certifications or trust marks that they use internally - we are free to ignore them and should do so in general
. eduGAIN itself does not add additional tags to metadata of this sort.

 

 

 

10

Ann

FOPP

Section 7.3.2 Metadata description needs to reflect interfederation

InCommon Practices

 

 

11

Bill

FOPP

Do we need to include dispute resolution between federations?  
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="601f2bdc-789e-4df4-9222-1818c4e4fd84"><ac:plain-text-body><![CDATA[*[Tracy's response] *Could we get guidance from the Global Network at Berkman for international governance models?

 

 

 

]]></ac:plain-text-body></ac:structured-macro>

12

Steven

FOPP

Section 9.2 InCommon must put in place processes to require the POP.

Note Bene

 

 

13

Theresa

PA

Disclaimer and Limitation: How will this be worded? Attorney's get really squeamish with these types of statements.

 

 

 

14

Ann

FOPP

Federation Technical Infrastructure will need mention of how eduGAIN is supported.

InCommon Practices

 

 

15

Ann

PA

Add description to section 1.

Role Definition

 


 

 

16

Ann

PA

Update 6. Participant Requirements regarding governing law, accurate metdata, and documenting practices as needed for participant to support eduGAIN.

Participant Requirements/
Practices

 

 

17

Ann

PA

Section 7 InCommon Federation Services.  Will be sharing metadata internationally as well. Upon request?

opt-in/
opt-out 

 

 

18

Bill

PA

Section 9. I suspect "privacy" rules are the biggest impact from a regulation standpoint. What are eduGains requirements from their participants in this area?

[Donald's response] 

Based on what is written in the "Discussion of the issues" document, it seems eduGAIN does not have strict standards for membership however the community members appear to self govern (http://www.edugain.org/technical/status.php). I looked at a few of the member statements on privacy/security and they seem similarly worded to the InCommon requirements. I may look at this as any other agreement between providers in that if I really want to federate with another organization I am going to research their policies and procedures even if they are a member. I think federation simply makes it easier to do so.

Privacy

 

 

19

Ann

PA

Section 7: Federation Rules - Do we need to allude to other federations here or let the responsibility for applying those rules rest on InC to promulgate?

[Bill's response] 

I think this is a key issue. As an InCommon Participant I do want to understand "who" are registered and "where" they are registered, which could impact "what" I register. But I realize that comes with a price of additional administration because the "where" could be international. InC providing the brokering services would be valuable in my mind.

[Donald's response] 

I agree with Bill that InCommon could broker this whether it be through an attribute that identifies the eduGAIN entities, and may also keep from having to maintain separate metadata for eduGAIN members. Could this also resolve the opt in/opt out question?

 

 

 

20

Bill

PA

Section 13: Are edGAIN insurance requirements similar, equitable? Does InCommon verify insurance contracts of participants?

 

 

 

21

Theresa

PA

Section 15. Many public institutions are not allowed to agree to governance that is not within their state. Can this be reworded?

 

 

 

22

Group

PA

Participants have a choice and would sign a new agreement. Opt-out, we would send them the changes and propose a time when they would take effect. Either way, this the changes to this Agreement would be publicly vetted and discussed.

opt-in/
opt-out

 

 

23

Ann

PA

Section 11: Is there an international impact on liability? Is there increased risk to the federation and participant? How should we proceed?

 

 

 

24

Bill

PA

Section 10. Dispute Resolution: Should InCommon help with international disputes?

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="095cef27-4e43-4e31-bd34-b0569dadae5f"><ac:plain-text-body><![CDATA[[Bill response] Sounds like a slippery slop to suggest international dispute resolution. I will confer with Scott David for an opinion.

 

 

 

]]></ac:plain-text-body></ac:structured-macro>

25

Theresa

PA

Section 9. This is pretty ambiguous, can "as be required by federal and European law be added to the statement?

privacy

 

 

26

All

FOPP

Section 10. Termination or Suspension: what does this mean in the international context?

 

 

 

27

Steven

 

Recommended attributes for interoperability: Includes SCHAC attributes. What does InCommon want to recommend to our members?

 

 

 

28

Steven

 

eduGAIN uses two metadata fields that are not required or different from what we do. (isRequired and MDUI) What does InCommon want to recommend to our members?



 

 

29

Steven

 

What configuration should we recommend to our IdPs and SPs?



 

 

30

Bill

 

Why is there an additional risk statement on the FOPP page?  

https://incommon.org/docs/policies/risk_assessment.html

 Can this be eliminated or incorporated into the policies in some way?

Trust?

 

 

  • No labels