UMA telecon 2012-09-27

UMA telecon 2012-09-27

Date and Time

  • All-hands meeting on Thursday, 27 September 2012, at 9am PT (time chart)
    • Skype: +99051000000481
    • US: +1-805-309-2350 (other international dial-in lines available) | Room Code: 178-2540

Agenda

  • Roll call
  • Review all open AIs
  • Review Q4 plans and October focus meeting schedule (see below)
  • Educational
    • Webinar plans: Oct 17?!
    • Case study review
  • Trust
    • Binding Obligations status
  • Technical
    • Prioritize open issues
  • Interop
    • Feature tests status/review and known-implementation review
  • AOB

Minutes

Roll call

Quorum was reached.

New meeting schedule discussion

Is the new paradigm working? Is it too confusing? It may impose more mental work on everybody, but that's not necessarily a bad thing. Sal thinks he might attend IIW, but we know of no others. So let's definitely plan on having an all-hands call during IIW week.

AI:

  • Eve: Post all informal notes in minutes area of wiki

Webinar plans: Oct 17 8am PT

Let's confirm this time for our webinar! Maciej et al. are flexible in general. The theme will be UMA and higher education. We'll plan to do a live demo of the Cloud Identity solution, and also probably highlight the Fraunhofer effort with slides, demos, or screenshots.
AIs:
  • Eve: Ask Joni to set up the WebEx and a registration page, and ensure that we can record it.
  • Eve: Alert Joni and Kantara about publicizing the webinar.
  • Eve, Maciej, et al.: Publicize the webinar on Twitter, blogs, etc. and put all associated events on the calendar.
  • Eve, Maciej: Alert Joni that Cloud Identity will be sponsoring the webinar.
  • Alam: Check with Mario about doing a short demo during the webinar or supplying screenshots or slides.
  • Eve, Maciej: Plan out webinar slide content and associated case study. They and Thomas will do an ad hoc meeting on Oct 8 to work on content. (We also have next week's focus meeting on educational topics.)

Review all open AIs

 

Date

Who

Status

Action

Topic area

Comments

2012-02-02-4

Thomas, Sal, Eve

Open

Capture business-oriented use cases.

Educational

We think Mike S.'s efforts on writing a case study will get us the closest to this goal.

2012-07-19-3EveOpenPut feature tests on the OSIS wiki.InteropEve made progress on the offline version of these. Up through Section 2, these are nominally done; Section 3 is partially done based on Trey's and Martin's work.
2012-08-02-2EveOpenSend UMA use case information to PMRM group.EducationalWe will just point them to our published case studies when we have them.
2012-08-02-3Sal, TreyOpenLiaise with others as appropriate on potential alignment opportunities for host/AM introduction-type patterns.TechnicalSal will reach out to the AXN winners of the NSTIC grant, cc'ing Eve. He has also asked for the pilot proposals to be made public; we expect they will, eventually.
2012-08EveOpenHelp dyn-client-reg spec progress in the OAuth WG.TechnicalEve has reached out to Evan Prodromou and Nat Sakimura to find out their interest and status, but we still don't have an active spec editor. Thomas and Eve will meet with Nat and sort things out.

Case study review

Alam will have an ACM article published on their UMA implementation shortly. And Maciej et al. have prepared a paper on their use case and implementation as well. From this, Eve got the idea of standardizing a case study document template, so that potential users and deployers of UMA can pick and choose.

The new Case Studies page on the wiki has the template. Here are updated notes on the currently planned case studies, with a bit of prioritization:

  1. Verified student data sharing (Maciej/Thomas as reviewer)
  2. Enterprise management of scope authorization (Mike: OxAuth issue, draft swimlane)
  3. Street Identity++ (Maciej/Eve/Sal as reviewer)
  • Self-contained app (Eve/Neil as reviewer, for eGov open data?: writeup)
  • Parent-group sharing of child information (Thomas: writeup)
  • Online personal loan (Domenico)
  • EU-compliant user data-sharing control (Luk/Sampo/Kevin as reviewer)

AI:

  • Maciej: Try to get the Google Talk video released one more time.

Binding Obligations status

Eve shared the progress we achieved on discussing the Binding Obligations document. George points out the the plain meaning of delegation is that you are transferring authority you have; you can't transfer authority you don't have. So maybe obligation R1b is overthinking things. If someone has admin authority (e.g., R/W entitlement but not the instance of the entitlement), then they should be able to delegate a R/W entitlement instance. Thomas points out that the Kerberos concept of proxiable and forwardable tickets causes no end of strife! Let's take out R1b. We can always pick it up later when we have a valid use case for it. It's the "sore thumb" obligation.

Attendees

As of 12 July 2012 (pre-meeting), quorum is 7 of 13.

  1. Catalano, Domenico
  2. D'Agostino, Sal
  3. Fletcher, George
  4. Hardjono, Thomas
  5. Machulak, Maciej
  6. Maler, Eve
  7. Mohammed, Alam
  8. Moren, Lukasz

Non-voting participants:

  • Kevin Cox

Next Meetings

  • Focus meeting on Thursday, 4 October 2012, at 9am PT (time chart) – educational
  • Focus meeting on Thursday, 11 October 2012, at 9am PT (time chart) – interop
  • Focus meeting on Thursday, 18 October 2012, at 9am PT (time chart) – technical
  • All-hands meeting on Thursday, 25 October 2012, at 9am PT (time chart) - IIW XV week