...
Document | Comments |
---|---|
eduGAIN Declaration | The eduGAIN Declaration achieves the goal of being broadly agnostic and the language used in this should be reflected throughout the document suite (e.g. AAI endpoints). The use of the term "federation" as equal to joining organisation may need further discussion (most federations don't exist as legal entities). |
eduGAIN constitution | The constitution is heavily based on the assumption of use of SAML and use of the MDS as the trust broker. Two options exist here: have a constitution per technology / operational model OR update the constitution to reflect a more agnostic approach. If the constitution is to be updated, the following issues would need to be address:
CHANGES TO SG: Federations should ensure that representatives can represent all technology profiles. Federations may vote on all constitutional changes and new profiles but my only vote on changes to technical profiles they use. Delete bullet 7. CHANGES TO EXEC: The edugain executive comprises representatives from organisations that fund edugain operations. The current exective is documented (on the edugain website). Change bullet 2 to changes to service scope and cost of service changes. Add designate an edugain operator as a bullet. Add Federation Operator definition. A document highlighting areas where the constitution would need to change is available: https://docs.google.com/document/d/1zqq1BRloo0gwxnNtX0X189sMXbODTflLKJzzOxYui34/edit. This is not intended to be a proposed amended document for ratification, but simply highlights the problem areas. |
eduGAIN metadata profile, attribute profile, SAML 2.0 WebSSO profile. | These documents are all explicitly SAML profiles - may be cleaner to move these into one SAML profile document and replicate with "moonshot" profile etc. etc. |
GÉANT Data Protection Code of Conduct | The CoCo is for SAML implementations only and its current status is a bit unclear and causes some confusion, particularly as it is broadly about entity implementation and blurs the lines between instructions to federations / instructions to entities. May be better to pull this out into a section of "best practice endorsed by eduGAIN SG" OR point specifically to documentation for how federations should implement CoCo. |