Tuesday, April 20, 2021

Baseline Expectations office hours

55 participants


Resources 

Baseline Expectations Overview

Baseline Expectations:

Implementation and Guidance Guide:

DavidB provided an overview of Baseline Expectations


Overview

Discussion

Question : When will BEv2 verification start?

Answer: BEv2 starts July 19, so enforcement begins then.

Question: How is it determined if we comply with SIRTFI?  https://refeds.org/sirtfi

Answer:

Comment: our organization (an SP) reviewed the BEv2 requirements and determined we are in compliance.  

Question: Is there a need to publish compliance to other members,
as was done for the InCommon Federation POP (Participant Operating Practices)  prior to Baseline Expectations? 

Answer: There is no need to publish a compliance statement. 

Timing for BEv2:

TLS Endpoint question

  Answer:  there can be grace periods depending on circumstances

Comment: Concerned about SHALL in upper case in implementation guide.

Reply: Your colleagues and peers will look at mitigation proposals

ChrisB and ScottCa :  Or campus deals with many service providers who need to  get metadata from our IDP, some of those SPs are not members of the Federation. Some are using an older version of SSL protocol for consuming metadata. We can’t turn of older SSL 1.0 on our IDP.    We can never get better than a B grade on SSL labs grading

Andy :

ChrisB : An option that does not require us to contact all the SP operators and get them to change something would be welcome. 

Andy: there may some intermediary approach

Les: 

TomB: The precise extent to which any of the specifications are implemented is a risk management decision of an organization. Must be made with the priorities of the organization in mind.  It’s not just a strict compliance framework.

Albert: Saw on a thread: Case where a commercial login company is putting out login pages, that look like campus login pages, and they use justification that the user has given consent.  

Comment: it’s a phishing scheme 

Note difference between Baseline Expectations and Guidance doc

  1. Normative text of Baseline Expectations, short statements
  2. Guidance doc is meant to be implementation guide, to provide clarity


TLS Endpoint issue and possible approach

Comment: our company has many parts. Verifying that the BE only applies to those parts of our company that interacts with InCommon Participants.  

Answer: Yes, that’s correct

Comment: thanks to the whole InCommon team for working towards improved security

SSL Labs Testing

Thanks to all for participating