IAWG Meeting Minutes 2011-04-13

These are draft minutes and have not yet been approved.

Attendees:

Voting:
John Bradley
Patrick Curry
Myisha Frazier-McElveen
Linda Goettler

Non-Voting:
Ken Dagg
Tom Smedinghoff
Mark Lizar
Ben Wilson

Apologies:
Joni Brennan
Richard Trevorah
Rich Furr
Bill Braithwaite

Staff:
Anna Ticktin

MINUTES:

 
1.  Administrative:

  • Roll Call — Quorum achieved
  • Reminder of Motion of Minutes Approval: 07 April 2011
  • A motion was not heard. The approval of these minutes will be carried over to next week's agenda.

Announcements:

  • Myisha will be unable to attend next week's telecon. Rich Furr will step in to lead the call.

Action Item Review: 

  • ACTION ITEM 20110406-01 RICHARD : GAF draft language. Progressed
  • ACTION ITEM 20110406-02 Anna : Voter's Feedback Matrix working page uploaded to the wiki. Completed.
  • ACTION ITEM 20110330-01 : Expiring Credentials Language update. Resource needed
  • ACTION ITEM 20110316-02 Anna : FAQs working page uploaded to the wiki. Completed.

 
*2. SAC ?Profile Guidance doc (Colin Wallis feedback*)*

  • ACTION ITEM 20110413-01 ANNA  will implement non-normative editorial changes and highlight those in a separate draft to the IAWG. Any substantive changes will be reviewed by the IAWG to determine their validity and whether to take immediate action or slate them for a future cycle.

3. General Assessment Framework (GAF) Language: Richard Wisher (email)

  • The structure and components of the IAF can be distilled into a higher-level set of objects, processes and relationships which can define a Generic Assurance Framework (GAF), of which the IAF would (of course) be a prime example. 
  • The GAF would be the model for other assurance frameworks, e.g. A(ttribute) AF, P(rivacy) AF, … 
  • It would (in his estimation) take someone about 10-20 hrs to provide a descriptive document which explained the components of the GAF and guidance on how to implement it as a specific application. 
  • The ‘metro-map’ description of the IAF might be a useful prompt for determining the essential components.

Comments:

  • Ben Wilson---suggests we focus on attribute assurance and pull anything "general" for separate consideration. . .
  • Patrick Curry---separating authorization vs authentication attributes could be a never-ending, complex task. . .

Next steps:

  • Where does this get slated in the IAWG roadmap?
  • Patrick suggests we seek partnership with the concurrent efforts of Rainer Hoerbe as well as Naspo / ANSI, with whom Patrick acts as liaison.
  • John suggests we're wise to piggyback other efforts, but remain careful not to be US-centric in our focus. A broader approach will allow for flexibility in augmentation down the road. . .

4. Expiring Credentials Language update

  • This work will be folded into the larger SAC "Sanity Check" project

5. SAC Sanity Check

  • This item will be carried over to the next agenda for a full discussion

6. Feedback Matrix / FAQs

  • Members are asked to begin adding their comments to the wiki space provided so that continued discussion may be had.

7. AOB

  • Munich Trust Framework Summit: 13 May
  • BoF session: TBD Sat or Sunday (Train ride)
  • Kantara F2F in Berlin: 16-18 May

Adjourned