130 likes | 252 Vues
This document provides an update on the EduGAIN project, detailing its purpose, timeline, and policy structure. EduGAIN aims to create a confederation that interconnects existing federations, with technical pre-pilot starting in April 2010 and a planned production launch in April 2011. The document outlines proposed bodies, the policy enforcement mechanism, requirements for federations, and aspects of data protection. Stakeholders are encouraged to provide feedback and participate in discussions to enhance the EduGAIN initiative.
E N D
EduGAIN policy (working draft) Status update REFEDs 30th May 2010 Mikael.linden@csc.fi
eduGAIN project in general • Purpose of eduGAIN, (a.k.a. GÉANT3 Service Activity 3, Task 3) • Create a confederation interconnect existing federations • Timeline • 4/2010 technical pre-pilot started • 10/2010 pilot starts • 4/2011 production starts, policy signed • 4/2013 project ends • For details, listen to TNC speak on Wednesday 11-12.30 • Task leader: Valter Nordh • Policy sub-task: Mikael Linden
Proposed eduGAIN bodies • NREN PC • As defined by Geant network and project • Technical Steering Group (TSG) • On delegate from each participant federation • Operational Team (OT) • Daily technical issues
1. Agreement • Joining federation signs • Unilateral declaration where joining federation commits to the terms
2. Constitution • Eligibility to join • GN3 project partners • Other federations if approved by NREN PC • Requirements for joining federations • Primarily from research and education • Ensure Providers conform to policy • Provide helpdesk • Incident handling
2. Policy Enforcement In case of a severe policy violation, OT • issues a notice to the TSG, or • propose to NREN PC a temporary quarantine period, or • propose to NREN PC a disqualification of the participant federation from the confederation.
2. Other issues • Branding: leave the door open for eduID • Audits: No audits for federations or IdPs • Profiles supplementing the constitution • NREN PC approves, if REQUIRED • TSG approves, if RECOMMENDED or OPTIONAL
3. Technical profiles • Metadata profile (REQUIRED) • A SAML2 metadata profile • SAML 2.0 profile (RECOMMENDED) • Saml2int.org ver 0.2 ?
3. Attribute syntax and semantics important RECOMMENDED webSSO attribute profile • RECOMMENDED attributes (cn, mail, eP(S)A, schacHomeOrganization, schacHomeOrganizationType) • ePA semantics (if needed, define a new attribute) • SAML2 persistentID RECOMMENDED • ePPN MAY be used
3. Data Protection OPTIONAL data protection profile • Helps to conform to directive 95/46/EC on data protection • SPs have two categories: PII and non-PII • Defines IdPs’ and SPs’ coordinated functionality • For minimal disclosure, informing the end user, legal grounds for processing, release to 3rd countries… • Relies on SAML2 metadata tags
3. Quality of IdP-side Identity management • IdPs must ensure that attributes released are up-to-date • (some interest in expressing Level of Assurance in the assertion)
Got interested? • Provide your comments • Face to face • By mail to edugain-policy@geant.net • In our vc every second Thursday at 10.00 CEST on connect.sunet.se/edugain • The next one is in 10th June