edugain-discuss AT lists.geant.org
Subject: An open discussion list for topics related to the eduGAIN interfederation service.
List archive
RE: [eduGAIN-discuss] [Spam]Re: Assessment of Morocco/eduIDM.ma for eduGAIN membership
Chronological Thread
- From: "Samia El Haddouti" <elhaddouti AT cnrst.ma>
- To: "'Terry Smith'" <t.smith AT aaf.edu.au>, "'Brook Schofield'" <brook.schofield AT geant.org>
- Cc: <edugain-discuss AT lists.geant.org>, <team AT eduidm.ma>
- Subject: RE: [eduGAIN-discuss] [Spam]Re: Assessment of Morocco/eduIDM.ma for eduGAIN membership
- Date: Mon, 9 Jul 2018 17:25:44 +0100
- Authentication-results: prod-mail.geant.net (amavisd-new); dkim=pass (1024-bit key) header.d=cnrst.ma header.b=EB4yLiYK; dkim=pass (1024-bit key) header.d=cnrst.ma header.b=s9jXylJd
- Dkim-filter: OpenDKIM Filter v2.7.1 mta.cnrst.ma 3030FA2EE1
- Dkim-filter: OpenDKIM Filter v2.7.1 mta.cnrst.ma 60211DFA2F
Feedback from the AAF... Terry, thank you very much for your feedback and your interesting remarks and suggestions…
Metadata Registration Practice Statement (MRPS) If you suggest that these definitions should be generic, we propose to modify them as following:
I don't think this document is the right place to declare can be a member, maybe something more along the lines of the template - "An organisation that has joined the Federation by agreeing to be bound by the Federation Policy in writing", then in your federation policy you define the criteria for organisations joining. o eduIDM Member: An institution that has joined eduIDM Federation by agreeing to be bound by the eduIDM Federation Policy and by signing the eduIDM Federation Member Request.
Not sure if this definition helps to clarify wrt the metadata registration practice, the federation registry is just used to registry metadata and it's run by the federation operator.
Try and keep these definitions as generic as possible. o eduIDM Registry: a system to register metadata of entities. This system is run by the operator of eduIDM Federation – MARWAN.
The URL should be versioned. e.g. http://www.eduidm.ma/mrps-eduidm-v1.0.pdf The URL will be changed as you have suggested. http://www.eduidm.ma/mrps-eduidm-v1.0.pdf
We will add the following statement: “Updates to the documentation SHALL be accurately reflected in the federation metadata.”
This document will change over time, you practices need to cater for these changes. The paragraph relating to the statements above, as is mentioned on the template, will be added:
“An entity that does not include a reference to a registration policy MUST be assumed to have been registered under an historic, undocumented registration practice regime. Requests to re-evaluate a given entity against a current MRPS MAY be made to the eduIDM helpdesk via team AT eduidm.ma”
We will add the reference to the procedure for becoming a member of eduIDM as following: “The procedure for becoming an eduIDM federation member is documented here: https://www.eduidm.ma/adhesion/”
During the verification process, we rely on the information received officially from the institution and that are approved by the legal representative
The URL should have a version number. This will be changed as you have suggested <mdrpi:RegistrationPolicy xml:lang="en"> </mdrpi:RegistrationPolicy>
Need to allow for entities to be modified and deleted as these events do occur. The statement will be changed as following: “Once a member has joined the eduIDM Federation, any number of entities MAY be added, modified or removed by the Registered Representatives.”
Federation Policy
Should this apply to all entities not just the Federation Operator. It is the IdPs and SPs that will be handling users personal data. Should they also agree to be bound by the legal requirements of your nation with respect to personal data. Fully agree. We will add this obligation on the “Obligations and Rights of Federation Members”
The is very vague, is there a set of attributes that IdP must / should collect for use by SPs? If so these should be listed within the rules. This will help organisations when setting up their IdPs and services will have less issues if they know what attribute they can expect from IdPs.
The set of attributes, that IdPs must collect for use by SPs, they are specified in the IdP Memebership Agreement https://www.eduidm.ma/files/IdP-Membership-Agreement.pdf. This latter is the document that members sign when they join eduIDM policy.
Your eligibility may limit you, particularly when connecting services to your federation. Many services come from commercial companies that provide resources to academic institutions.
The eduIDM team has decided to add commercial companies and organizations that don’t belong to MARWAN community as partners. In this case, the “Eligibility” section will be changed as following:
“All institutions and organizations connected to MARWAN network or other academic institutions can join eduIDM federation as members. These institutions can apply, at any time, for membership as Identity Providers and/or Service Providers at any time. Commercial companies and organizations that don’t belong to the MARWAN community, and they would like to contribute to the eduIDM Federation by providing services, can join the eduIDM Federation as Partners.”
We will add the definition of “eduIDM Partners” on the “Definitions and Terminology section” section.
Thanks, Terry. Thank you again for the time you have put in reviewing our submission!
-- Terry Smith | Technical Engagement and Support Manager | Australian Access Federation Inc Mob: 0414 692 424 | Email: t.smith@aaf.edu.au | Address: Lvl 21, 179 Turbot St, Brisbane QLD 4000 | Web: www.aaf.edu.au | Support: support.aaf.edu.au | Twitter: twitter.com/ausaccessfed |
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- [eduGAIN-discuss] Assessment of Morocco/eduIDM.ma for eduGAIN membership, Brook Schofield, 04-Jul-2018
- Re: [eduGAIN-discuss] Assessment of Morocco/eduIDM.ma for eduGAIN membership, Rhys Smith, 05-Jul-2018
- Re: [eduGAIN-discuss] Assessment of Morocco/eduIDM.ma for eduGAIN membership, Terry Smith, 06-Jul-2018
- RE: [eduGAIN-discuss] [Spam]Re: Assessment of Morocco/eduIDM.ma for eduGAIN membership, Samia El Haddouti, 07/09/2018
- Re: [eduGAIN-discuss] Assessment of Morocco/eduIDM.ma for eduGAIN membership, Brook Schofield, 30-Jul-2018
- <Possible follow-up(s)>
- Re: [eduGAIN-discuss] Assessment of Morocco/eduIDM.ma for eduGAIN membership, Samia El Haddouti, 09-Jul-2018
- Re: [eduGAIN-discuss] Assessment of Morocco/eduIDM.ma for eduGAIN membership, Novosad Andrey, 11-Jul-2018
Archive powered by MHonArc 2.6.19.