IAWG Meeting Minutes 2011-04-13
These are draft minutes and have not yet been approved.
Attendees:
Voting:
John Bradley
Patrick Curry
Myisha Frazier-McElveen
Linda Goettler
Non-Voting:
Ken Dagg
Tom Smedinghoff
Mark Lizar
Ben Wilson
Apologies:
Joni Brennan
Richard Trevorah
Rich Furr
Bill Braithwaite
Staff:
Anna Ticktin
MINUTES:
1. Administrative:
- Roll Call — Quorum achieved
- Reminder of Motion of Minutes Approval: 07 April 2011
- A motion was not heard. The approval of these minutes will be carried over to next week's agenda.
Announcements:
- Myisha will be unable to attend next week's telecon. Rich Furr will step in to lead the call.
Action Item Review:
- ACTION ITEM 20110406-01 RICHARD : GAF draft language. Progressed
- ACTION ITEM 20110406-02 Anna : Voter's Feedback Matrix working page uploaded to the wiki. Completed.
- ACTION ITEM 20110330-01 : Expiring Credentials Language update. Resource needed
- ACTION ITEM 20110316-02 Anna : FAQs working page uploaded to the wiki. Completed.
*2. SAC ?Profile Guidance doc (Colin Wallis feedback*)*
- ACTION ITEM 20110413-01 ANNA will implement non-normative editorial changes and highlight those in a separate draft to the IAWG. Any substantive changes will be reviewed by the IAWG to determine their validity and whether to take immediate action or slate them for a future cycle.
3. General Assessment Framework (GAF) Language: Richard Wisher (email)
- The structure and components of the IAF can be distilled into a higher-level set of objects, processes and relationships which can define a Generic Assurance Framework (GAF), of which the IAF would (of course) be a prime example.
- The GAF would be the model for other assurance frameworks, e.g. A(ttribute) AF, P(rivacy) AF, …
- It would (in his estimation) take someone about 10-20 hrs to provide a descriptive document which explained the components of the GAF and guidance on how to implement it as a specific application.
- The ‘metro-map’ description of the IAF might be a useful prompt for determining the essential components.
Comments:
- Ben Wilson---suggests we focus on attribute assurance and pull anything "general" for separate consideration. . .
- Patrick Curry---separating authorization vs authentication attributes could be a never-ending, complex task. . .
Next steps:
- Where does this get slated in the IAWG roadmap?
- Patrick suggests we seek partnership with the concurrent efforts of Rainer Hoerbe as well as Naspo / ANSI, with whom Patrick acts as liaison.
- John suggests we're wise to piggyback other efforts, but remain careful not to be US-centric in our focus. A broader approach will allow for flexibility in augmentation down the road. . .
4. Expiring Credentials Language update
- This work will be folded into the larger SAC "Sanity Check" project
5. SAC Sanity Check
- This item will be carried over to the next agenda for a full discussion
6. Feedback Matrix / FAQs
- Members are asked to begin adding their comments to the wiki space provided so that continued discussion may be had.
7. AOB
- Munich Trust Framework Summit: 13 May
- BoF session: TBD Sat or Sunday (Train ride)
- Kantara F2F in Berlin: 16-18 May