Introduction

eduGAIN is a service that allows Participant Federations that serve the interests of education and research to interfederate. Interfederation allows end users whose Identity Provider exists in one Federation to easily authenticate to a Service Provider from a different Federation. This is enabled via the distribution of SAML metadata aggregates signed and distributed by eduGAIN. InCommon has a strong interest in joining eduGAIN as a Participant Federation.

The Interfederation Working Group of the InCommon Technical Advisory Committee has reviewed the eduGAIN Policy Framework, which describes the policies and practices of the eduGAIN service as well as the rights and responsibilities of Participant Federations. In order to join eduGAIN, InCommon (like all Participant Federations) is required to sign a declaration agreeing to the eduGAIN Policy Framework, which consist of three essential documents: 1) the eduGAIN Declaration, 2) the eduGAIN Constitution, and 3) the eduGAIN Metadata Profile. Agreement of a Participant Federation to the eduGAIN Policy Framework is in essence a unilateral agreement—the policy framework is set and, for the most part, non-negotiable.

This document contains the observations of the InCommon TAC Interfederation Working Group upon reviewing the eduGAIN Policy Framework. It contains only the clarifications and observations that the subcommittee deemed most noteworthy. Interested readers are invited to review the eduGAIN Policy Framework in its entirety. We organize these notes by the eduGAIN Policy Framework document to which they apply. We wish to acknowledge the participation and input of Ian Young from the UK Federation, which recently joined eduGAIN.

Declaration

Constitution

Metadata Profile

Conclusions

On the continuum between Stability, Assurance, & Centralized Control down the spectrum to Flexibility, Complete Freedom, and Decentralized Governance, the eduGAIN model is weighted toward the latter. In order to achieve maximal adoption among international federations, there are very few obligations placed on Participating Federations. As a consequence, there are also very few assurances for interoperability and stability. This is not a value judgment but simply today's balance point to get to a working model.

As such, the eduGAIN Policy Framework appears to present no philosophical barriers to InCommon participation. It should be noted, however, that there are some technical and operational issues that will need to be resolved in order to participate. The feeling of the Interfederation Working Group is that these are not insurmountable obstacles. Furthermore, the WG recognizes the significant benefits that would accrue to InCommon by participating in eduGAIN. eduGAIN provides a trust framework for participant federations as well as a service to allow interoperation with other identity federations in a relatively simple and scalable way. The Interfederation Working Group recommends to the TAC that participation in eduGAIN be actively pursued.