edugain-discuss - Re: [eduGAIN-discuss] Question about federations' IdP members

Re: [eduGAIN-discuss] Question about federations' IdP members

  • From: Leif Johansson <leifj AT>
  • To: edugain-discuss AT
  • Subject: Re: [eduGAIN-discuss] Question about federations' IdP members
  • Date: Wed, 17 Nov 2021 22:08:29 +0100

On 2021-11-17 20:16, Valeriu Vraciu wrote:
> Hello,
> Please help us understand and act the best possible way in the following
> matter, maybe there are/were similar cases in other federations:
> EduGain is a service supported by GEANT, gathering identity federations
> established mainly by NRENs, so a reasonable conclusion is that beneficiary
> IdP institutions are members of NRENs or have some
> sort of relation with NREN. Please correct me if it is a wrong assumption.

Yeah mostly, although in some countries the NREN remit extend a bit beyond
higher education to include related govt agencies, k12 etc.

> We have a request to join eduGain as an IdP from an accredited by the
> Ministry of Education private university, with which we did not have any
> relation (until this request). They are not connected to
> our network and do not use any service from us, so first reaction seems to
> be a no go. Any information regarding how other federations deal with such
> cases can help us to decide further.
> Our policy does not cover this case, maybe an update will be worth too.

In Sunet we would probably take a similar approach: the SWAMID federation is
part of
the NREN service infra and as such requires that the customer is connected to
network. I would not go as far as saying that there would *never* be a case
when we
might bend that rule... but that would then probably be a decision at the
board level
in our case.

As always ymwv, hope this helps.

Cheers Leif

