Skip to Content.
Sympa Menu

interfed - [inc-interfed] Mar 12 notes / Mar 26 agenda

Subject: Interfederation

List archive

[inc-interfed] Mar 12 notes / Mar 26 agenda


Chronological Thread 
  • From: Jim Basney <>
  • To: <>
  • Subject: [inc-interfed] Mar 12 notes / Mar 26 agenda
  • Date: Tue, 12 Mar 2013 13:30:40 -0500
  • Authentication-results: sfpop-ironport05.merit.edu; dkim=neutral (message not signed) header.i=none
  • Openpgp: id=0A33BE15; url=http://www.ncsa.illinois.edu/~jbasney/pgp.asc

Thanks Steven for leading us today in a productive discussion of the
Code of Conduct work. My call notes are included below.

We decided there will be no inc-interfed call next week (March 19).
We'll meet again on March 26. Please let me know if you have agenda
items for the next call. Otherwise, I propose we continue to focus on
the InCommon SP + "foreign" IdP use case, discuss anything blocking the
LIGO+Cardiff pilot, then discuss what it would take to expand the LIGO
pilot to include additional IdPs.

-Jim

-----
attending: JimB, TomS, IJK, IanY, ScottC, SteveC, JohnK, MarkS
No call next week (March 19). Next call March 26.
Today's topic: Data Protection Code of Conduct for interfederation
Steven sent notes to our email list.
Varying opinions on EU privacy directive. For example: Danish
centralized consent service would be considered illegal by data
regulators in other countries.
SP is data controller or processor depending on contract with IdP.
Assumes bilateral contract between IdP and SP.
Accepting either ePPN or ePTID trips this up?
CoC entity attribute added to metadata.
IdP commits to CoC? SP can accept optional attributes if IdP did consent.
When is user informed? Before attributes are released to specific SP.
Pilot effort with CLARIN VO. German federation active participant.
URL to "signed copy of CoC"? Just metadata tag is OK.
Current REFEDs work item to extend CoC to US.
CoC doesn't currently apply outside EU.
issue: InCommon doesn't support isrequired=true on requested attributes.
Google OAuth / OpenID Connect not doing targeted IDs?
Cardiff IDP and LIGO SP example. Ian says this is OK because user has
requested the service / consented to release. Example of differing
interpretations of privacy directive.
next REFEDS meeting in early June. Need US input on CoC.
Could LIGO agree to CoC today? Let's ask ScottK.
CoC work needs more IdP input. Mostly driven by SPs now.



Archive powered by MHonArc 2.6.16.

Top of Page