Leadership Council Teleconference - 2010-09-01
Minutes approved September 15, 2010
Kantara Leadership Council Teleconference
Date and Time
Date: Wednesday, September 1, 2010
Time: 3pm PDT | 6pm EDT | 22:00 UTC (Time Chart)
Teleconference Options:
Skype: +9900827043671716
US Dial-In: +1-201-793-9022 | Room Code: 3671716
NOTES:
Skype calls are toll-free, and you do NOT need to enter the Room Code.
International Numbers: http://kantara.atlassian.net/wiki/display/GI/Telco+Bridge+Info
Contact the Chair if you cannot use Skype and need a toll-free phone number (US or international)
Attendees
Voting:
User-Managed Access: Eve Maler
ULX: Phillipe Clement
Federation Interoperability: John Bradley
Japan WG: Toshihiro Suzuki
eGov: Colin Wallis
Privacy and Public Policy: Abbie Barbir
Non-Voting:
Identity Community Update: J. Trent Adams
Map the Gap: J. Trent Adams
Staff: Joni Brennan
Staff: Dervla O'Reilly
Guest: Drummond Reed
Apologies
Consumer ID: Bob Pinheiro
Agenda
Roll Call for Quorum Determination
Approval of prior meeting minutes
OIX Presentation - Drummond Reed
Reminder: Quarterly Reports
Call for Group Leaders to add 2010-Q2 Report and to back-fill prior reports
Add Reports to: Quarterly Reports
Using Report Template: Quarterly Report Template
Call for Paris Meeting Agendas
Proposal: Creation of a fellowship program supporting independent volunteers.
Action Item Reviews:
NASPO: LC Members interested in actively moving this work forward are asked to formalize a proposal and bring it to the LC for consideration.
United Identities: Colin will send the presentation around on the LC list, soliciting responses of interest.
AOB
Minutes
Roll Call for Quorum Determination
6 voting members, quorum reached
Approval of prior meeting minutes
MOTION: To approve the minutes as recorded for the Leadership Council Teleconference on 2010-08-04.
Moved by Colin, Motion Carried
Open Identity Exchange (OIX) Presentation
Introductory Notes:
Presented by Drummond Reed and John Bradley
ICF loaned Drummond to help bootstrap OIX
Drummond stepped down as ED of OIX after Catalyst, returning to ICF
Drummond is speaking as volunteer continuing to support the project
Don Thibeau now acting ED
John Bradley joined OIX as a volunteer Technical Advisor
General Overview:
OIX is primarily a registry, or "listing", of certified services (IdPs and RPs)
OIX "lists" operational trust frameworks
OIX and Kantara are symbiotic (as defined by the recent press release)
Kantara is one producer (among others) of frameworks that are listed and assessed against.
"Operational Certification" of each framework is defined by the framework producer (a.k.a. "framework authority")
OIX does not offer a certification service itself, it is a listing service on behalf of the "framework authority" (e.g. GSA/ICAM, Kantara, etc.)
OIX uses a "Rules & Tools" model to identify the difference between "process" (OIX) and "mechanism" (e.g. certification mechanism)
OIX builds on top of "Federation Operator Guidelines" that are both "Rules Based" and "Operational Based"
The term "profiles" is used to describe how a "framework authority" needs a specific technology to be implemented in order to be certified (and subsequently "listed" by OIX)
OIX is still solidifying methods for how "profiles" are created (e.g. by Kantara) and submitted to OIX for "listing"
OIX listings are technology neutral, not promoting any one specific technology.
There is an understood US-bias in many of the OIX foundational documents (many based on profiles from the US Gov), they are looking to expand further.
OIX carries some indemnifcation insurance
Q: If OIX "lists", but doesn't "certify", what is the actual process for getting "listed"?
A: This is still being defined, but the rough process is being formalized now.
Basic steps in "listing" a hypothetical new trust framework:
Example: LinkedOrg wants to submit a Trust Framework and have IdPs certified against it listed by OIX
For LinkedOrg to be a Trust Framework Authority, OIX requires:
they be a legal entity
they must be an OIX Member
LinkedOrg puts together a "Trust Framework Specification" comprised of:
Starting with with an "Implementation Profile" of Kantara IAF and...
... they add their own rules to it (e.g. a Privacy Profile)
They then define the same OpenID Profile used by ICAM for LOA 1.
To become an OIX Listed Trust Framework, OIX must verigy they are "compliant" by OIX General Counsel (currently Scott David):
Verify that it is an authetnic submission (i.e. all appropriate forms are filled out and steps followed) from an authentic member (i.e. an OIX member in good standing)
Verify that it meets all the requirements of the "OIX Trust Framework Requirements Document"
This is a proforma evaluation to ensure steps are followed, nothing about the contained details.
Verfification includes:
how assessors will do their job when certifying services for the proposed Trust Framework
that the submitted framework meets minimum bar from the "Principles of Openness" whitepaper:
The Trust Framework Authority must self-certify they agree to the principles.
Assesors for the LinkedOrg "Trust Framework Specification" must:
submit a "Trust Framework Participant Form"
meet requirements set out in the submitted "Trust Framework Specification"
They go through the Assesor Qualification Process to be "Listed"
They must be OIX Members (or a Kantara-certified assesor)
Participants (e.g. IDPs and RPs, etc.) go through a similar process to be "Listed"
They must also be OIX Members
NOTE: Kantara certified assesors are automatically accepted
Operation:
Listings will be queried using SAML-based signed metadata
Security will be matched to LOA (e.g. higher levels may require)
Much of this is still being worked out, in conjunction with input from the Fed Interop
Reminder: Quarterly Reports
Call for Group Leaders to add 2010-Q2 Report and to back-fill prior reports
Add Reports to: Quarterly Reports
Using Report Template: Quarterly Report Template
Call for Paris Meeting Agendas
Deadline for early-bird registration: September 17
Proposal: Creation of a fellowship program supporting independent volunteers.
Action Item Reviews:
NASPO: LC Members interested in actively moving this work forward are asked to formalize a proposal and bring it to the LC for consideration.
United Identities: Colin will send the presentation around on the LC list, soliciting responses of interest.
Meeting adjourned at 23:30
Next Teleconference
Date: Wednesday, September 15, 2010
Time: 9am PDT | 12pm EDT | 16:00 UTC (Time Chart)
Teleconference Options:
Skype: +9900827043671716
US Dial-In: +1-201-793-9022 | Room Code: 3671716
NOTES:
Skype calls are toll-free, and you do NOT need to enter the Room Code.
International Numbers: http://kantara.atlassian.net/wiki/display/GI/Telco+Bridge+Info
Contact the Chair if you cannot use Skype and need a toll-free phone number (US or international)