...
logs of ETLR servers (contain IPaddress, MAC address, outer-identity, CUI, ON, ...)
Geant central ops | NROs | IdPs | SPs | |
Dataset description: | Logs from the European top level servers | Logs from the national radius servers | Logs from the IdP radius server | Logs from the SP radius server |
Purpose of processing: | Troubleshooting issues and resolving security incidents. | Troubleshooting issues and resolving security incidents. Recommendation by the eduroam service definition. Logs of all authentication requests and responses SHOULD be kept. The minimum log retention time is six months, unless national regulations require otherwise. The information in the requests and responses SHOULD as a minimum include:
| Troubleshooting issues and resolving security incidents. Requirement by the eduroam service definition. fff
| Troubleshooting issues and resolving security incidents. Requirement by the eduroam service definition. Sufficient logging information MUST be kept to be able to correlate between a client’s layer 2 (MAC) address and the layer 3 (IP) address that was issued after login if public addresses are used. This requirement is void if NAT is used. |
Data source: | Data is logged in the ETLR servers when an RADIUS authentication or response passes. (user access eduroam in another country) | Data is logged in the FTLR server(s) when an RADIUS authentication or response passes. (user accesses eduroam in another institution) | Data is logged in the IdP RADIUS server(s) when an RADIUS authentication or response passes. (user accesses eduroam anywhere) | Data is logged in the SPs RADIUS server(s) when an RADIUS authentication or response passes. (user accesses eduroam at that SPs location) |
Data storage and access: | Data is stored in the ETLR servers | Depending on the NRO practices, data can be kept and stored by NRO as well. | ||
Data transfer: | F-ticks data are not transferred to any other party or system. | F-ticks data are sent to the eduroam core operations. | ||
Data retention: | F-ticks data are kept permanently. | Depends on the NRO practices if they keep a copy and for how long. | Depends on the local policies. eduroam service definition recommendation is: The minimum log retention time is six months, unless national regulations require otherwise. | |
Personal data processed: | Yes | Yes |
eduroam F-ticks
Data is processed by GEANT central ops and NROs.
...