wiki:Taskforces/AAI/Meetings/2016-10-15

Version 1 (modified by Dieter Van Uytvanck, 6 years ago) (diff)

--

Submitted by Martin Matthiesen on 03 July 2015

Participants: Jozef Mišutka, Dieter Van Uytvanck (12:50-13:10), Sander Maijers (via Skype), Daan Broeder, Paul Meurer,  Martin Matthiesen (chair & minutes),

Time: 11:45-13:10

Agenda

  1. Formalia: Agreeing on agenda, secretary
  2. Action points from last meeting (10 min)
  3. Meta: Scheduling meetings (10 min)
  4. AAI TF and CLARIN+ AAI task (10 min, Martin)
    1. Central Monitoring (10 min, Martin)
  5. User survey in Clarin (10 min, Jozef)
  6. Attribute release developments (10 min, Martin)
  7. AARC: Developments, Clarin's role (10 min, Martin)
  8. Summary for SCCTC
  9. Action points for next meeting (5 min)
  10. Next meeting

1 Formalia

Agenda and Martin as secretary were ok.

2 Action points from last meeting (10 min, All)

  • SP Signing: Mitchell and Oliver make sure the SPF XML is signed.
    • 15.10.: Done: Metadata now signed.
  • Setup Trac for manual login tests across federations.
    • Progress. Documentation split.
    • Todo: We need more volunteers.
    • 15.10.: Krista Liin volunteers for U Tarto, Estonia.
  • Meeting on Central Monitoring: Martin prepares a meeting, Jozef and Kai will at least join.
    • Now part of Clarin+, see below.
  • Documentation for SPs: Martin relays feedback to Sander/Dieter.
    • Ongoing, also part of Clarin+
  • Martin contacts Dieter/Sander on SLAs.
    • Done: SLA template according to fitsm.eu sent.
  • SP Survey (Jozef)
    • Done.
  • Publish eduGAIN encouragement letter, including information on ECs (from point 3) (Martin, Jozef)
    • Yet to be done.
  • Low Priority APs
    • Feide opt-in to SPF

3 Meta: Scheduling our meetings (10 min, Martin)

We decided to try Doodle for the next meeting preparation. There was also a general sense that we would like to meet more often, but shorter and but with a specific topic.

4 AAI TF and CLARIN+ AAI task (10 min, Martin)

There is overlap between issues we try to advance in the Taskforce and the Clarin+ AAI task. Clarin+ AAI seems to be our Taskforce with proper funding. This is a good development, but we should avoid unneccessary overlap.

Main tasks of CLARIN+ AAI:

  • Improve Clarin IdP (availability, security)
  • Improve SPF-SAML aggregation workflow
  • Set up monitoring
  • Collect login statistics and improve availability for Clarin SPs
  • Make {infra,discovery}.clarin.eu redundant to improve availability.

Clarin+ AAI and this task force should work together closely. Jozef's next step will be to present and discuss a Clarin AAI requirements document here.

4.1 Central Monitoring (10 min, Jozef)

This is pushed forward within Clarin+, see above. Currect requirements can be found here:

https://trac.clarin.eu/wiki/Monitoring#Requirements.

5 User survey in Clarin (10 min, Jozef)

https://docs.google.com/spreadsheets/d/17THRllM2VKuV-NDivSoJZmUDpmtAJM-nOMihnPv74JU/edit#gid=1619541889

Conclusions and suggestions:

  1. CLARIN should explicitly mention the fact that SPF/eduGAIN contain IdPs not meeting the "traceable to real person" requirement.
  2. CLARIN should explicitly mention that SPF maintains list of such IdPs (from SPF) which should be filtered out - we have identified one such IdP.
  3. CLARIN should explicitly mention that in order to filter such IdPs out SPs must take additional action.

6 Attribute release developments (10 min, Martin)

Something is moving in Germany: U Tübingen releases now attributes to all CLARIN SPs, even without Data Protection Code of Conduct (CoCo) as requirement, since they interpret the laws in a way that european public institutions are to be treated equall to German public institutions and can therefore receive attributes. The downside is that the registration process is still manual. DFN-AAI has suggested to maintain an EC for CLARIN SPs that fulfil the "public institution" requirement.

On the downside North-Rhine-Westphalia (specifically U Cologne) cannot release attributes just because of CoCo because of a different clause in their law. I have not yet presented the Tübingen case to them, as of writing this agenda.

7 AARC: Developments, Clarin's role (10 min, Martin)

Martin was interviewed by Mikael Linden for AARC. Would Clarin want to have a more active role within AARC, influence things?

15.10.: We discussed that we would indeed like to be more involved. The next opportunity is at the FIM4R Meeting in Vienna. Martin (for this TF), Jozef (for Clarin+ AAI) and Daan (for AARC) are planning to go. We would like to emphasize the pros and cons of eduGAIN vs. SPF, formulate requirements and discuss with eduGAIN representatives what eduGAIN would be willing to take on.

8 Summary for SCCTC

Content of the slide so far:

•Testing AAI (from CZ,DK,FI,DE,NL)•User survey done by Lindat•Following developments in eduGAIN•Tübingen found a way to release attributes to CLARIN•AAI part of CLARIN+

9 Action points next meeting (5 min)

  • Jozef: Prepare CLARIN AAI requirements
  • Daan,Jozef,Martin: Prepare FIM4R
  • Dieter: Will talk with Koenraad de Smedt to Feide to convince them of a more flexible opt-in policy, eg like the Dutch policy: 1-time opt-in per IdP for the whole block of CLARIN SPs, including those added in the future.
     

10 Next meeting

End of November, before FIM4R meeting in Vienna.