Click on the title of any column to reorder the list. # Name Document (if any) Issue Description Theme Scope for this group? Action Item 1 Warren Will publishing of InCommon IdPs and SPs into eduGAIN be opt-in or opt-out? opt-in/ In Scope for policy decision Key Issue. 2 Warren Will eduGAIN metadata feeds be aggregated into the InCommon feed or pulled separately by InCommon IdPs and SPs? Metadata practices Out of Scope; operational policy TAC 3 Warren Will InCommon simply publish the metadata as it arrives from eduGAIN, or will it add value, by, for instance: Metadata practices Minimally In scope TAC 4 Von Research SPs and making sure that the ease of obtaining attribute release that the Research and Scholarship category has enabled within InCommon expands to the international arena. R&S Out of Scope but Nota Bene; a related but not primary focus InC Ops/ 5 Ann FOPP Section 1. Add international context/role description Role Definition In Scope 6 Theresa FOPP Section 2. Organizational Structure: do we need a basic flow chart? Document Clarity Out of Scope Doc Editors 7 Bill FOPP Section 7.2 Relationship of Systems to Participant: Are ownership structures different in eduGain? Does that matter? Are their significant commercial or government systems influencing federations? [Warren's response] Legal/ Process In Scope ]]></ac:plain-text-body></ac:structured-macro> 8 Steven FOPP Update the IdP and SP definitions to better reflect the complexities of the environment. Participant System Definition In Scope with TAC support TAC 9 Bill FOPP Are the types of Identity Providers and Service Providers in eduGain substantially different entities than what we see in our federation? Are there different trust marks or certification marks than what we tend to use? If substantially different how will we inform our participants of what those entities are? [Warren's response] Participant System Definition In Scope with TAC support TAC 10 Ann FOPP Section 7.3.2 Metadata description needs to reflect interfederation InCommon Practices In Scope for draft; operational policy InC OPs/ TAC 11 Bill FOPP Do we need to include dispute resolution between federations? Dispute Resolution In Scope Key Issue ]]></ac:plain-text-body></ac:structured-macro> 12 Steven FOPP Section 9.2 InCommon must put in place processes to require the POP. Participant Practices; Nota Bene; AAC reviewing In Scope ]]></ac:plain-text-body></ac:structured-macro> 13 Theresa PA Disclaimer and Limitation: How will this be worded? Attorney's get really squeamish with these types of statements. Legal/ Process In Scope ]]></ac:plain-text-body></ac:structured-macro> 14 Ann FOPP Federation Technical Infrastructure will need mention of how eduGAIN is supported. InCommon Practices In Scope for Drafting 15 Ann PA Add description to section 1. Role Definition In Scope 16 Ann PA Update 6. Participant Requirements regarding governing law, accurate metadata, and documenting practices as needed for participant to support eduGAIN. Participant Requirements/ In Scope 17 Ann PA Section 7 InCommon Federation Services. Will be sharing metadata internationally as well. Upon request? opt-in/ In Scope 18 Bill PA Section 9. I suspect "privacy" rules are the biggest impact from a regulation standpoint. What are eduGains requirements from their participants in this area? [Donald's response] Privacy In Scope Key Issue 19 Ann PA Section 7: Federation Rules - Do we need to allude to other federations here or let the responsibility for applying those rules rest on InC to promulgate? [Bill's response] [Donald's response] Definition of Participants - Transparent about including international entities and what expectation we have for them. In Scope 20 Bill PA Section 12: Are eduGAIN insurance requirements similar, equitable? Does InCommon verify insurance contracts of participants? Insurance ]]></ac:plain-text-body></ac:structured-macro> 21 Theresa PA Section 15. Many public institutions are not allowed to agree to governance that is not within their state. Can this be reworded? Legal/ Process Out scope ]]></ac:plain-text-body></ac:structured-macro> 22 Group PA Participants have a choice and would sign a new agreement. Opt-out, we would send them the changes and propose a time when they would take effect. Either way, this the changes to this Agreement would be publicly vetted and discussed. opt-in/ In Scope 23 Ann PA Section 11: Is there an international impact on liability? Is there increased risk to the federation and participant? How should we proceed? Legal/ Process In Scope 24 Bill PA Section 10. Dispute Resolution: Should InCommon help with international disputes? Dispute Resolution In Scope ]]></ac:plain-text-body></ac:structured-macro> 25 Theresa PA Section 9. This is pretty ambiguous, can "as be required by federal and European law be added to the statement? [group] Need a broadly based statement that's based on the participant privacy statute and not limit it to federal and european law. Does it require the participant to understand the impact of releasing PII to the SPs? Privacy In Scope 26 All FOPP Section 10. Termination or Suspension: what does this mean in the international context? Include metadata tags included in the "phone book," but bad actors will be removed by InCommon and will notify other Participants; InC. will not policy but will administer best practices. In scope; further discussion anticipated 27 Steven Recommended attributes for interoperability: Includes SCHAC attributes. What does InCommon want to recommend to our members? Send to TAC; eduGAIN may want to review TAC 28 Steven eduGAIN uses two metadata fields that are not required or different from what we do. (isRequired and MDUI) What does InCommon want to recommend to our members? TAC 29 Bill Why is there an additional risk statement on the FOPP page? https://incommon.org/docs/policies/risk_assessment.html Can this be eliminated or incorporated into the policies in some way? From Participation agreement to FOPP, relationship InC. to eduGAIN In scope 30 Steven Should we be able to ask InCommon to filter out entities? Dispute Resolution, bundle with #26, In Scope
In particular, if we make publishing metadata into eduGAIN an opt-in activity, it seems to me we might be able to simply have separate agreements and operating procedures for those efforts. It also seems to me as though we can start asking those IdPs and SPs that choose to participate what added value might be of most benefit to them.
opt-out
a) filtering eduGAIN metadata (to remove malformed metadata or metadata that does not comply with InCommon standards/expectations, metadata from commercial enterprises entering through other federations, etc?)
b) negotiating attributes release policies, entity category tags, SAML versions, hash algorithms, etc with other eduGAIN participating federations.
c) interpreting legal obligations related to PII or other attribute release from other federations to make it easier for InCommon IdPs and SPs.
d) other similar value-adding activities.
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="2cf791d9-dcc2-4d43-84a0-3ba43a5e075a"><ac:plain-text-body><![CDATA[[John's response] Perhaps in an adjacent or linked document (TBD), InCommon Ops should publish our import filtering rules and export filtering rules in human readable format. Import filter will remove any tags we are authoritative for (e.g., InCommon Bronze, Silver), all certs <1024 bit key strength, duplicate md entries from eduGAIN sources, other filters...
]]></ac:plain-text-body></ac:structured-macro>
item C; operational policy
Wants to ensure that InCommon IdPs and SPs can participate in the international R&S standard. If we do come across any wording that would prevent participation in this program, we would address accordingly.
TAC
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="3a1e5dbe-31c8-4cab-8f3c-e50a3c7ddd39"><ac:plain-text-body><![CDATA[[Tracy's response] or a graphic?
]]></ac:plain-text-body></ac:structured-macro>
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="e88e0286-2d1e-4885-9076-6d1dbd3e9aaa"><ac:plain-text-body><![CDATA[[Susan response] What about a federal inquiry? How do we handle those things that aren’t an adjudicated order? Or sensitive research with an entity in a hostile nation that raises questions from the US Gov?
Need an explicit definition of IdP, SP and other entities. Add to PA too.
. eduGAIN itself does not add additional tags to metadata of this sort.
7.3.2.1 Certificate practices check.
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="dc3bb55d-d9b5-41e9-9381-4cfd8a2e47b9"><ac:plain-text-body><![CDATA[*[Tracy's response]* Could we get guidance from the Global Network at Berkman for international governance models?
]]></ac:plain-text-body></ac:structured-macro>
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="3f3ebf83-d159-41f3-abe2-fec234911bbf"><ac:plain-text-body><![CDATA[[John's response] This is dealt with in eduGAIN policy.
]]></ac:plain-text-body></ac:structured-macro>
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="332a9e83-8fc2-4daf-b3ed-2fde574e0a13"><ac:plain-text-body><![CDATA[*[group discussion] *Is InCommon going to help manage or not? We are facilitators not arbitrators of Interfederation. There are legal and non-legal ways of handling dispute resolution.
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="c11f174a-171f-4754-a055-e9c9ffa381f8"><ac:plain-text-body><![CDATA[[Bill's Comments] Section 9.2 talks about "communications" and "support" but seems to be mainly about support. It states documents and POPs are published on InCommon Website. Is that the only communication requirement? Where are POPs published? I am not real familiar with the Federation Manager, does it allow users to browse POPs?
]]></ac:plain-text-body></ac:structured-macro>
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="de4623bb-a9ff-4fa6-82b9-2e7554235979"><ac:plain-text-body><![CDATA[[Johns response] Do we need educate participants regarding international entities and lack of POP? Do we need require of InCommon IdPs/SPs before we export them to eduGAIN?
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="c5ce8a83-d5a8-4535-808f-eac10125e681"><ac:plain-text-body><![CDATA[[Group discussion] International implications
Practices
opt-out
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="b122b247-f4de-45b1-9245-da95cfe4f8b5"><ac:plain-text-body><![CDATA[[John] Yes, the provenance of each entity (i.e., the Federation responsible for each published IdP and SP) will be a "tag" that is stamped in each entity's metadata and retained when InCommon republishes each. In this way, InCommon participants will know which entities are based in InCommon and which are based in some other Federation's trust framework.
]]></ac:plain-text-body></ac:structured-macro>
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="641951a8-aa03-4abf-ade3-f537b2179dbb"><ac:plain-text-body><![CDATA[[Group] What's the definition of HE? InCommon has eligibility requirements. What are other federation eligibility requirements? If there was an institution we didn't like, could we ask InC to filter it out? Spawned dispute resolution # 31
]]></ac:plain-text-body></ac:structured-macro>
Possibly say less here, if InC is publishing metadata from another federation, InCommon will identify who is and who isn't an InCommon member.
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="16cccd3d-b0e3-45a7-9e9a-e4ba3a7dabac"><ac:plain-text-body><![CDATA[[Group] eduGAIN has no insurance requirements. Ann to check about InCommon insurance requirements
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="365d6e1b-107c-4673-915d-68e7367262a4"><ac:plain-text-body><![CDATA[[group] How do we determine the jurisdiction for the national agreement? We keep silent on this.
opt-out
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="3537a800-f9a0-445d-8a6d-a2a8423e2c05"><ac:plain-text-body><![CDATA[[John's comment] Liability:
]]></ac:plain-text-body></ac:structured-macro>
InCommon to Participant
InCommon to International Federations
Participant to Participant (external contract)
Participant to Participant (no contract)
Participant to International Federation Member (contract)
Participant to International Federation Member (no contract)
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="28f34efe-09e0-4104-8fa8-273e330ae525"><ac:plain-text-body><![CDATA[[group] Section 11: we provide a service with no implied warranties. Indemnification is off the table. Should not change, but is part of legal discussion. Dependent on how this comes out with governance issue/dispute resolution.
]]></ac:plain-text-body></ac:structured-macro>
Need to expand to all the entities.
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="167a90f8-288d-433b-b6ef-1fdf755e1bc0"><ac:plain-text-body><![CDATA[[Bill response] Sounds like a slippery slop to suggest international dispute resolution. I will confer with Scott David for an opinion.
]]></ac:plain-text-body></ac:structured-macro>
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="d0afcdbb-dc52-4bb6-919e-52e0cf340f8e"><ac:plain-text-body><![CDATA[[group] Does provide a process for how to do dispute resolution between organizations. If you have a disagreement, it's between those federations. eduGAIN is not a part.
This will be the single biggest hurdle.
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="2d2acf26-5fc0-4afe-bfdc-820e41e6f5ce"><ac:plain-text-body><![CDATA[[John] Suspension of Publishing Metadata. A fundamental question of how much power InCommon Participants would like to bestow to the Federation. Should InCommon import filter rules be minimal and necessary only for technical security reasons, or should InCommon act as a more active broker, with the power to drop international IdPs and SPs for a defined set of other reasons? Current federation policy is lean, increasing scalability and interoperability rather than a heavyweight policy enforcement role based on other non-technical issues. Is it important to consider certain minimal use cases such as international business treaties and hostile nation issues mentioned in #7?
]]></ac:plain-text-body></ac:structured-macro>
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="97cbcd54-7dfe-4085-9329-851a3be26208"><ac:plain-text-body><![CDATA[[group] What mechanisms do we use to review the process for exclusion? Who decides? What can InCommon staff do on behalf of the community? What needs further review?
]]></ac:plain-text-body></ac:structured-macro>
Process for appeal and reinstatement per approval of Steering Committee and dispute resolution, policy authority, included.
Send to TAC; Code of Conduct (Phase 2)
next steps of reinstatement.