...
ROOM:
TOPIC:
CONVENER:
SCRIBE: Joost
# of ATTENDEES: Roland, Lalla, Motonori, Schuko, Joost, Roland vR-D, Marina, Klaas.
MAIN ISSUES DISCUSSED
- Does it make sense to move from Identity Providers to Attribute Providers?
- We can expect that more users are going to want to use social logins instead of university login (bring your own identity).
- This means that Home Organisations can "outsource" authentication to social login providers, and only do identity vetting and issue attribute statements to relying parties.
- What's in it for:
- Home organisations: lose responsibility for authentication, securely storing passwords
- End users: need not use different identities in different domains, or lose their identities when leaving the home organisation
- Reling parties: obtain some attributes more easily (e.g. self asserted attributes), richer sets of attributes, (VOs?)
- As discussed on day 1 of TF-EMC2:
- what AP pattern fits different use cases best?
- How to differentiate between attributes obtained from different sources (e.g. self-asserted vs HO-asserted)
- We need use-cases to answer these questions
- first get clear what the problem is
- Some use-cases will have alternative solutions ,e.g. transition prestudent-student-leave people from outside the federation
- VOs
ACTIVITIES GOING FORWARD / NEXT STEPS
...