Scalable Trusted Federation
�Updates from InCommon Advisory Committees�
David Bantz, University of Alaska; Chair, Community & Trust Assurance Board
Jon Miner, University of Wisconsin; Co-chair, Community & Trust Assurance Board
Keith Wessel, University of Illinois; Chair, Technical Advisory Committee
Steven Premeau, University of Maine System
Albert Wu, Internet2
Today
InCommon Technical Advisory Committee (TAC) and Community Trust and Assurance Board (CTAB) have been working on several important initiatives to increase trusted interoperability among InCommon participants.
The first part of this session will describe the progress in these areas to date and how they will benefit scalable federation, including:
The second portion of this session will invite broad input on potential next directions to:
[ 2 ]
Community Trust and Assurance Board (CTAB)
CTAB Members
[ 4 ]
CTAB Updates
Baseline Expectations (“BE”)
Community-developed technical requirements for InCommon participants that foster collaboration and trusted access to resources. CTAB advocates and monitors community compliance, and listens for possible evolution of BE.��V1 (2020): maintain information about IdPs and SPs:� contact information for IdPs and SPs; � URLs for privacy policy & logo��V2 (2022): information security readiness:� TLS 2.0 for all end points in IdPs and SPs;� Explicit adherence to Security Incident Response Trust Framework for Federated Identity (SIRTFI)
[ 6 ]
[ 7 ]
Building the pyramid of trust and interoperability
8
Enable
basic collaboration
Support
high value resources
Protect
collaboration resources
Identity Providers
implement
Standard MFA
request/response
Identity assurance info
Release “Research & Scholarship” attributes
Reduce risk
Service Providers
implement
Basic security
Accurate & complete metadata �for good user experience
Everybody
implements
[ 9 ]
“Operationalizing” Baseline Expectations
[ 10 ]
SIRTFI Exercise
Continuing work on improving operational use of SIRTFI Framework.
[ 11 ]
Improving Trust with Clearer “Assurance” Guidance
REFEDS Assurance Framework v2
REFEDS MFA Profile v1.2
NIST 800-63-4
[ 12 ]
What's Next for CTAB in 2023 and Starting 2024 Work Plan
[ 13 ]
InCommon Technical Advisory Committee �(TAC)
What is the TAC?
[ 15 ]
Current Members
[ 16 ]
2023 TAC Work Plan
Theme: Future-proofing InCommon
Work plan items:
[ 17 ]
2023 TAC Work Plan
TAC also helps with or monitors the following community developments:
[ 18 ]
SAML 2.0 Deployment Profile Adoption
[ 19 ]
Entity Category Adoption
The working group invites your feedback:
Deployment Guidance for * Access Entity Categories (working draft)�https://docs.google.com/document/d/1B45F1GKHjUY0j3QNlQ_XojFziKN9W02xCuL49vdAQRk/
[ 20 ]
Federation Proxies
[ 21 ]
Federation Testing
[ 22 ]
Join Us
[ 23 ]
What's Next
What's do we do next? We want your feedback!
What's do we do next? We want your feedback!
What is important to you? What can we address to make the federation better and improve trust and interoperability? Are we looking at the right things? Are we including you? Can we?
Ideas
[ 25 ]
Leadership and �Advisory Groups
Drive the Bus!
Leadership opportunities for community members who contribute their insights, expertise, and talents within Identity & Access Management
Taking nominations now through October 1!
Please visit the Advisory Committee poster in TechEX foyer for more information and submit a nomination.
Otherwise, you may click this link to submit a nomination.
InCommon Steering Committee
InCommon Technical Advisory Committee (TAC)
InCommon Community Trust and Assurance Board (CTAB)
Community Architecture Committee for Trust and Identity (CACTI)
eduroam-US Advisory Committee
26