ACOnet Identity Federation Policy Experiences
Peter Schober
ACOnet
ACOnet Identity Federation Policy Experiences Peter Schober ACOnet - - PowerPoint PPT Presentation
ACOnet Identity Federation Policy Experiences Peter Schober ACOnet TERENA EuroCAMP @ 4 th GN3 Symposium 15-16 October 2012 Agenda 1. The Politics behind Federation Policies 2. Tales from a Federation Operator: On-boarding of prospective
ACOnet
◮ Policies reflect their political/contextual
◮ Also true for the policy template ◮ Your experience/context is probably still
◮ Eligibility: Be as “inclusive” or “neutral” as
◮ Don’t limit eligibility too early/narrowly:
◮ Aim for ubiquity from the beginning
◮ While still being a Trust Framework Provider
◮ Modular policy and approach
◮ There’s (academic) life beyond your Federation
◮ Create/modify local Policy by looking at others’ ◮ You’ll need to interop with them at some point
◮ Things we all need to deal with
◮ Laws (however different), Contracts with
◮ Constituency (examples from ACOnet):
◮ Service Providers (external) ◮ Home Orgs: NREN participants ◮ Attribute Authorities ?!
◮ How
◮ Require signed Service Agreement from * ◮ Signee must be able to legally bind org
◮ So far we didn’t have to deny any SPs ◮ But we may ask questions
◮ Esp. when required info was not provided ◮ Necessary (vs. optional) attributes ◮ Documentation regarding position of Signee
◮ Sometimes we consult with the community:
◮ SP: “We don’t require any attributes”. ◮ Turns out license terms only cover:
◮ students, staff, faculty, patrons
◮ Federation not really involved, still might want
◮ Policy Template now contains “SP responsible
◮ Making it easy to sign up (no new barriers):
◮ So don’t do that.
◮ Haka: IdM-Description ◮ JISC Identity Management Toolkit ◮ “What attributes are relevant for an SP”
◮ Kantara IAWG Federation Operator Guidelines ◮ GÉANT FOP(P) Template ?
◮ Not all SPs care about high(er) LoA ◮ ∃ Higher standard IdPs and lower standard IdPs ◮ How to match them up?
◮ By communicating those facts in an
◮ (Higher) LoA won’t need to cover all identities
◮ (Higher) LoA [probably] optional for HomeOrgs
◮ Work in progress
◮ Come back in a year
◮ Or stay for the panel discussion