edugain-discuss AT lists.geant.org
Subject: An open discussion list for topics related to the eduGAIN interfederation service.
List archive
- From: "Cheng, Jonathan [ITS]" <jonathan.cheng AT polyu.edu.hk>
- To: "jiny92 AT kisti.re.kr" <jiny92 AT kisti.re.kr>
- Cc: "edugain-discuss AT lists.geant.org" <edugain-discuss AT lists.geant.org>, "Brook Schofield" <Brook.Schofield AT geant.org>
- Subject: RE: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership
- Date: Tue, 10 Oct 2017 04:40:36 +0000
- Accept-language: en-GB, en-US
- Authentication-results: prod-mail.geant.net (amavisd-new); dkim=pass (1024-bit key) header.d=polyu.edu.hk
- Authentication-results: spf=none (sender IP is ) smtp.mailfrom=jonathan.cheng AT polyu.edu.hk;
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
Hi Jinyong
Thank you very much for your feedback.
Our responses to your feedback are provided below in bolded purple texts in larger font. Please feel free to let us know if you have further questions or comments.
Cheers Jonathan
From:
振溶[Jinyong Jo] [mailto:jinyong.jo AT gmail.com]
Hello Jonathan,
My apologizes for late return. Korea's 10-day holidays just ended yesterday.
Comments/questions/recommendations:
1. 7-core attributes Does a Korea institution (namely, a foreign full member) have to provide at least 7-core attributes if it wants to federate with a HKAF associate member via eduGAIN?
No. The HKAF Federation Policy only mandates the Home Organizations (i.e. the HKAF Full Members) to collect or generate the 7 Core Attributes for their End Users in their IdPs. The policy does not mandate the HKAF Members to release all of the 7 Core Attributes in their IdPs. Furthermore, the 2nd rule in the HKAF Identity Provider Management Standard (https://www.hkaf.edu.hk/idp-management-standard) states that: “The Home Organization MAY ONLY release Attributes from its Identity Provider to a Service Provider, or another Identity Provider, with the permission of the End User.”
Furthermore, this policy only applies to the IdPs registered by HKAF Members, but not to the other IdPs connected via eduGAIN. For the scenario that you mentioned, the Korea institution just has to release (provide) the attributes that the Service Provider of the HKAF Associate Member requests via eduGAIN (of course with User Consent).
2. eduPersonAssurance Except for an example, it is hard to find any documents describing the format (a URN) of the attribute. Does HKAF use the same URN format as AAF has, and/or allow level 1 only?
We will register the HKAF Level-1 Identity Assurance Profile in the IANA LoA profile shortly in Oct 2017. It will be similar to the SWAMID Level-1 assurance profile.
It seems that HK has very similar data-protection/privacy-policy laws, including code of conducts, with Korea. For us, notifying items and getting user consent are essential before transmitting individual user information to domestic/foreign SPs. We leverage privacy policy statement to notify several items in [4.c.Information duty [1]] to end user. I hope HKAF encourages federation members to use the metadata element <mdui:PrivacyStatementURL>.
[1] HKAF Service Provider Management Standard, p. 5
We will definitely do so.
Cheers, Jinyong Jo KAFE/KISTI
2017-10-03 17:38 GMT+09:00 Cheng, Jonathan [ITS] <jonathan.cheng AT polyu.edu.hk>:
www.polyu.edu.hk/80anniversary This message (including any attachments) contains confidential information intended for a specific individual and purpose. If you are not the intended recipient, you should delete this message and notify the sender and The Hong Kong Polytechnic University (the University) immediately. Any disclosure, copying, or distribution of this message, or the taking of any action based on it, is strictly prohibited and may be unlawful. The University specifically denies any responsibility for the accuracy or quality of information obtained through University E-mail Facilities. Any views and opinions expressed are only those of the author(s) and do not necessarily represent those of the University and the University accepts no liability whatsoever for any losses or damages incurred or caused to any party as a result of the use of such information. |
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, 振溶 [Jinyong Jo], 02-Oct-2017
- RE: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Cheng, Jonathan [ITS], 03-Oct-2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, 振溶 [Jinyong Jo], 10-Oct-2017
- RE: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Cheng, Jonathan [ITS], 10/10/2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Anass Chabli, 10-Oct-2017
- RE: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Cheng, Jonathan [ITS], 11-Oct-2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Anass Chabli, 11-Oct-2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Nick Roy, 11-Oct-2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Peter Schober, 11-Oct-2017
- RE: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Cheng, Jonathan [ITS], 14-Oct-2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Anass Chabli, 11-Oct-2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Rhys Smith, 13-Oct-2017
- SV: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Pål Axelsson, 13-Oct-2017
- RE: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Cheng, Jonathan [ITS], 11-Oct-2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Anass Chabli, 10-Oct-2017
- RE: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Cheng, Jonathan [ITS], 10/10/2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, 振溶 [Jinyong Jo], 10-Oct-2017
- RE: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Cheng, Jonathan [ITS], 03-Oct-2017
- <Possible follow-up(s)>
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Eimantas Serpenskas, 10-Oct-2017
- Re: [eduGAIN-discuss] Assessment of Hong Kong/HKAF for eduGAIN membership, Brook Schofield, 27-Oct-2017
Archive powered by MHonArc 2.6.19.