wiki:Taskforces/AAI/Meetings/2014-05-12

Version 1 (modified by Dieter Van Uytvanck, 6 years ago) (diff)

--

Submitted by Martin Matthiesen on 15 May 2014

Participants

  • Kristóf Bajnok (SZTAKI)
  • Mihály Héder (SZTAKI)
  • Zsuzsanna Magyar (SZTAKI)
  • Martin Matthiesen (CSC)
  • Jozef Misutka (LINDAT)
  • Oliver Schonefeld (IDS)
  • István Tétényi (SZTAKI)
  • Dieter van Uytvanck (CLARIN)
  • Kai Zimmer (BBAW)

SPF: Welcome Sander, status, issues (15 min)

Status

Issues

  • Metadata distribution / how to deal with the complexity
    • details will be worked out with individual federations
    • we hope to make use of eduGAIN. Problem: with opt-out IdPs are automatically part of eduGAIN metadata but a lot of them are misconfigured, eg in Brazil.
    • with 24+ federations we need an aggregated Metadata feed, no SP will want to configure all national federation's feeds. Martin, Oliver and Sander will look into this.

Virtual Organisations Access control systems (20 min total)

Q&A HEXAA (Istvan) (~10 min)

Istvan presented Hexaa. Hexaa is software that enables VO maintainers to maintain additional SAML attibutes and user profiles for their VO. Details:

Q&A REMS (Martin, see attachment, ~10 min)

REMS stands for Resource Entitlement Management System. Users can apply for resources which can be approved in a distributed way. Martin briefly introduced the application approval process in REMS Details:

General discussion

We discussed the issue of non-persistent or missing attributes and their use in the systems described above. We agreed to organize a webinar, Dieter and Sander will prepare it.

The need for attractive, accessible content (10 min)

  • BNC is willing to join SPF/eduGAIN
    • This content would be attractive to demonstrate the need for international AAI interconnect like eduGAIN/SPF. Martin will help with the setup.
  • Dariah is embracing the Data protection Code of Conduct and implementing on its services.

Interoperability: The UFAL SP-Validator (Jozef) (15 min)

Jozef presented a tool with which SPs can validate themselves against possible IdPs. The script "only" detects missing login screens, but that covers quite a lot of interconnect issues. It is compatible with Nagios for continuous testing. That needs to be communicated to the targets so they don't get worried by regular probes. The tool can be adjusted to emulate a different valid SP (tested on Weblicht) The tool was recieved with great appreciation. Dieter, Sander and Jozef will promote the tool.

Action points

This topic includes the unchecked ones from the last meeting.

  • Dieter, Sander: Webinar HEXAA/REMS
  • Martin, Oliver, Sander: Metadata aggretation SPF
  • Dieter, Sander, Jozef: Promote the IdP-Validator
  • Thomas: Hook up BAS with the SPF
  • Martin: https://wiki.edugain.org/CLARIN; Contact Feide to accept the CoC.
  • Dieter: Promote the SPF in Zürich.; Contat Feide to opt-in to the SPF.

Next meeting

In about a month. Martin will send out invitations.