SlideShare a Scribd company logo
What is REFEDS Interested In?


                 Nicole Harris
  UK Access Management Focus, JISC Advance
                 @nicoleharris
Slides: http://www.slideshare.net/nicolevharris
Me




•   UK Access Management Focus;
•   Advisor to UK federation;
•   REFEDS Coordinator;
•   PEER Project Manager;
•   Shibboleth Consortium Manager;
•   Generally opinionated about access and identity.
What does the R&E Federation space
            look like?
R&E Federations Status (1)
R&E Federations Status (2)
•   27 Federations plus 2 confederations.
•   4753 entities within those federations.
•   1815 Identity Providers.
•   2755 Service Providers.
•   Plus several ‘others’ (don’t worry about it).
                                  (November 2011)
Top resources?
• In 14 federations:
  – Czech Medical Atlas and Microsoft Dreamspark.
• In 12:
  – Web of Knowledge, Scopus, ScienceDirect.
• In 11:
  – IEEE, EBSCO.
• In 10:
  – Springer, OVID.
So it’s all working, right?
For SPs, Federation Sucks
    I know because I wrote a paper on it!
Barriers
•   Multiple registry of entity data.
•   Multiple legal documents.
•   One-off clauses.
•   Interpretation of data protection.
•   Sponsorship letters.
•   Fees.
•   Technical Barriers.
https://refeds.terena.org/index.php/Barriers_for_Ser
vice_Providers
Registering Entity Data
• Federations are just big metadata (xml) files.
• Entity = your chunk of that data.
• It goes a bit like this:
How does it work?
Federation A

Federation B
                              You
Federation C
What we need is a place where this
can be centrally registered and then
     called on by federations…
PEER




http://beta.terena-peer.yaco.es/
Legal Contracts
                                                                                                                                                                                                                                 F ED
                                                                                                                                                                                                                                                 ERA
                                                                                                                                                                                                                                                                 T IO
                                                                                                                                                                                                                            T he
                                                                                                                                                                                                                                                                               N       RU L
                                                                                                                                                                                                                                    A
                                                                                                                                                                                                                          fr am u st r al
                                                                                                                                                                                                                                   e            ia
                                                                                                                                                                                                                        t r u st w o r k an n A cc e
                                                                                                                                                                                                                                                                                                        ES
                                                                                                                                                                                                                                  e                            ss F
                                                                                                                                                                                                                      w it h d el ect d su p p                      ed e
                                                                                                                                                                                                                                                                          r at
                                                                                                                                                                                                                               in an          r on            o
                                                                                                                                                                                                                     in st             d b           ic co r t in fr as io n p r
                                                                                                                                                                                                                            it u t
                                                                                                                                                                                                                                   io n s et w een m m u n                  t r u ct o vi d e
                                                      TERMO DE COMPROMISSO PARA ADESÃO À FEDERAÇÃO CAFe                                                                                                                                                              ic at           u            sa
                                                                                                                                                                                                                   T h is                 in A             u
                                                                                                                                                                                                                                                 u st r n iv er si           io n r e t o fa
                                                                                                                                                                                                                            d                            al ia        t ies s an d                 ci
                                                                                                                                                                                                                 t o b o cu m e                                 an d           an d         co ll li t at e
                                                                                                                                                                                                                        em               nt o                        o ve             r           ab
                                                                                                                                                                                                                ser vi         et               u t li                      r se as e se ar ch o r at io n
                                                                                                                                                                                                                        ce p b y p ar                  nes
                                                                                                                                                                                                                                                              th                     .
                                            Pelo presente, a organização identificada neste Termo, ora denominada PARTICIPANTE,                                                                                                 r o vi
                                                                                                                                                                                                                                       d er
                                                                                                                                                                                                                                              t ic ip
                                                                                                                                                                                                                                                       at in e r u les
                                                                                                                                                                                                              T h is                        s.               g id           an d
                                            adere a este documento e assume a responsabilidade pela utilização dos serviços                                                                                          d o cu                                       en t              o b li
                                                                                                                                                                                                             Par                                                       it y
                                            disponibilizados pela Comunidade Acadêmica Federada, doravante denominada                                                                                            t icip m en t                                                an d         gat io
                                                                                                                                                                                                                         an t s         su p                                                      ns
                                            simplesmente CAFe, ciente da “Política de Uso da Federação CAFe: provedores de                                                                                                                   e r se
                                            serviço”, e da “Política de Uso da Federação CAFe: provedores de identidade”,
                                                                                                                                                                                                            24 M                                      d es
                                                                                                                                                                                                                                                             t he
                                                                                                                                                                                                                   ay 2                                           Fed
                                            conforme adiante descrito.                                                                                                                                                     011                                          er at
                                                                                                                                                                                                                                                                                io n
                                                                                                                                                                                                                                                                                       Ru le
                                                                                                                                                                                                                                                                                             s fo
                                                                                                                                                                                                                                                                                                   r
                                            PARTICIPANTE: [nome da instituição], com sede na [endereço], neste ato representada
                                            por [nome completo], [função], doravante denominada [sigla da instituição]


                                            O presente Termo considera que:


                                               a) A Federação CAFe é composta por um conjunto de instituições que, sobre uma
                                                  infraestrutura de autenticação e autorização multidomínios, estabelece uma rede de
                                                  confiança que simplifica o acesso a serviços federados oferecidos;

                                               b) A RNP tem como atribuição o gerenciamento dos processos de disponibilidade,
                                                  confiabilidade e melhoria continua do Serviço da CAFe, além de apoiar a
                                                  homologação visando a adesão de novos Provedores de Identidade e Provedores de
                                                  Serviço na federação CAFe, bem como o suporte a atualizações e melhorias
                                                  contínuas;

                                               c) a RNP e a PARTICIPANTE têm interesse comum na manutenção e desenvolvimento
                                                  da Federação CAFe com o objetivo de simplificar o processo de Autenticação e
                                                  Autorização entres as instituições participantes;                                                                                                                                                                                          ©A
                                                                                                                                                                                                                                                                                               ustr
                                                                                                                                                                                                                                                                                                    alian
                                                                                                                                                                                                                                                                                                          Acces
                                               d) a PARTICIPANTE tem interesse em integrar a Federação CAFe como Provedor de                                                                                                                                                                                   s Fe
                                                                                                                                                                                                                                                                                                                   dera
                                                  [Identidade ou Serviço], para benefício da comunidade de educação, pesquisa e                                                                                                                                                                                        tion
                                                                                                                                       RedIRIS Identity Service                                        Conditions of Use for Identity Providers                                                                               Inc.
                                                  cultura.


                                            Para tanto, a PARTICIPANTE dá ciência e se compromete ao que se segue:                     RedIRIS Identity Service
                                                                                                                                       Conditions of Use for Identity Providers
                                            1 - DO OBJETO
                                                                                                                                       Version 1.0 – 20080220
                                            1.1 – O presente Termo tem por objeto estabelecer as diretrizes de participação, a serem
                                            realizadas com o apoio recíproco, na CAFe;
                                                                                                                                       ___________________________________________________________________, as applicant for
                                                                                                                                   1   the identity transfer services provided by the RedIRIS Identity Service (SIR), to be used by the identity
                                                                                                                                       provider identified by its URL, unique ID, and public key included at the end of this document
                                                                                                                                       (referred in the rest of this document as “the Applicant”) declares that:

                                                                                                                                           1. Knows and accepts the rules, procedures and technical requirements for the connection of
                                                                                                                                              their identity management system with the RedIRIS Identity Service, as specified at
                                                                                                                                              http://www.rediris.es/sir/. Applicants accept the appropriate changes that may take place, and
                                                                                                                                              that shall be communicated with sufficient time through the service website, and directly to the
UK Access Management Federation for                                                                                                           RedIRIS Official Liaisons (“Personas de Enlace con RedIRIS”, referred as “PERs” in the rest
                                                                                                                                              of this document) of the corresponding affiliated institution.
            Education and Research
                                                                                                                                           2. Knows that breaking these conditions can imply the discontinuation of the service.

                                                                                                                                           3. Declares that data included in this document are accurate, apart error or omission in good
                                                                                                                                              faith.


       Rules of Membership                                                                                                                 4. Commits to permanently update the information included in this document, informing the
                                                                                                                                              PERs of any change that takes place.

                                                                                                                                           5. Assumes that RedIRIS, in all procedures related to service provision, will act according to the
                                                                                                                                              data provided in this document.

                                                                                                                                           6. Knows and accepts that any falsity or error in the data included in this document can be
                         1st August 2011                                                                                                      cause of the discontinuation of the service.

                                                                                                                                           7. Knows and accepts that once the service is active it can be revoked in case of violation of the
                                                                                                                                              requirements.

                                                                                                                                           8. Knows and assumes that the service can be revoked in case of serious technical negligence.

                                                                                                                                           9. Declares that, according to their best knowledge, the connection of the identity provider
                                                                                                                                              identified below with the RedIRIS Identity Service does not harm the rights of any third party.

                                                                                                                                           10. Knows and accepts that the service is provided by RedIRIS in non-commercial terms for its
                                                                                                                                               users in the research and academic community, and that RedIRIS shall not be held liable for
                                                                                                                                               any damage caused, directly or indirectly, by the usage of the service.

                                                                                                                                           11. Knows and assumes that RedIRIS will perform personal data processing according to Ley
                                                                                                                                               Orgánica 15/1999 on Personal Data Protection and the regulations developing it.

                                                                                                                                           12. Knows and assumes that the rights to access and rectification can be exercised according to
                                                                                                                                               the above mentioned regulations. The rights to cancellation and opposition can only be
                                                                                                                                               exercised after the discontinuation of the service, since personal data processing by Red.es is
                                                                                                                                               required for the use of the RedIRIS Identity Service.




                             Version 2.1
                    ST/AAI/UKF/DOC/001


                                                                                                                                                                                                                                                       1/2
Wouldn’t it be great if these were
 standardised and simplified?
REFEDs Policy Review
• Painstakingly taking apart every clause in
  every federation policy.
• Mapping these to generic content ‘blocks’ and
  ‘elements’ within each block.
• Making recommendations about structure
  and unnecessary language.
• NOT a legal review.
Isn’t there an easier way?
Full Interfederation
• The ability of federations to exchange
  metadata about their entities.
• Normally an additional legal agreement
  between the 2 federations.
• Full technical and policy integration.
• Bi-lateral (UK and Edugate) or via groups
  (eduGain and Kalmar2).
eduGain (1)




www.edugain.org
eduGain (2) – Drawbacks
• At least one of the federations you are a
  member of needs to have signed up for
  eduGain.
• Opt-in: you have to ask to be included in an
  aggregate.
• Not always clear which entities are
  interfederated – are your customers there?
eduGain (3) Benefits
• Only have to have a relationship with 1
  federation.
• Technically, as an SP, you can chose with
  federation that is.
A quick note on Barriers to Users
Login Interfaces Suck
 I know this because I’ve tried to use them
How Bad?
New UK federation WAYF
Foodle and DiscoJuice
MDUI
• Currently being used by DiscoJuice and
  Shibboleth Embedded Discovery Service /
  Central Discovery Service.
• OASIS Standard for IdP Discovery:
  – http://docs.oasis-
    open.org/security/saml/Post2.0/sstc-saml-idp-
    discovery.pdf.
MDUI for SPs (Shibboleth Recs)
Non Logo elements
• <mdui:DisplayName>Recommended required
  <mdui:Description>Recommended 100 chars max
• <mdui:Keywords> Not used
• <mdui:InformationURL> Available
• <mdui:PrivacyStatementURL> Available
Logo elements
• Shibboleth - must be specified using an HTTPS URL
• Shibboleth - logo size should be between 64px by 350px wide and
  64px by 146px high
• Shibboleth - logos should have transparent backgrounds
• Shibboleth - logos look better if they have a landscape rather than a
  portrait aspect ratio

             https://refeds.terena.org/index.php/MDUI_-_Software_recommendations
MDUI for IdPs (Shibboleth Recs)
Non Logo elements
<mdui:DisplayName>Recommended, 33 chars max Strongly recomended <mdui:Description>
Supporting the Display Name function with more details
<mdui:Keywords> Used Used for incremental search
<mdui:InformationURL> Not used at present
<mdui:PrivacyStatementURL>Not used at present – see Attribute WG recs
<mdui:IPHint>Not used Planned for future release
<mdui:DomainHint> Not used Planned for future release
<mdui:GeolocationHint> Not used Heavily used. Strongly recomended.


Logo elements
•   Shibboleth - The URL specifying the logo must be https protected.
•   Shibboleth - One logo should be provided of size approximately 80px(width) by 60px (height). A
    larger logo may be provided but the aspect ratio should be maintained (logos are selected based on
    apsect ration).
•   Shibboleth - One logo should be provided of size 16px by 16px.
•   Shibboleth - Logo backgrounds should be transparent.



                https://refeds.terena.org/index.php/MDUI_-_Software_recommendations
Thank you for listening

More Related Content

PDF
Travel Weekly Magazine travelweekly The 30th Issue (12 Aug, 2010)
PDF
Water Related Expertise In Toronto Region July09 Final
PDF
2010 Honda Insight Hybrid Portland
PDF
2010 Honda Insight Hybrid
PDF
2010 Honda Insight Hybrid Los Angeles
PDF
2010 Honda Insight Hybrid Virginia Beach
PDF
Austin Honda Insight Brochure 2010
PDF
Dave Folio
Travel Weekly Magazine travelweekly The 30th Issue (12 Aug, 2010)
Water Related Expertise In Toronto Region July09 Final
2010 Honda Insight Hybrid Portland
2010 Honda Insight Hybrid
2010 Honda Insight Hybrid Los Angeles
2010 Honda Insight Hybrid Virginia Beach
Austin Honda Insight Brochure 2010
Dave Folio

What's hot (13)

PPT
Kevin Ashley Mid Con Aade Presentation.Rev
PDF
2010 Honda Insight Hybrid San Leandro
PPT
Dental amalgam
PDF
2010 Honda Insight Hybrid Jackson
PDF
Open Source Success: jQuery
PDF
IWB in the Prep Classroom
PDF
Visual Resume
PDF
Spiral Of Knowledge - 1965
PDF
2010 Honda Insight Hybrid Los Angeles
PPT
Fringe eu procurement - sara piller
PDF
2010 Honda Insight Boston
PDF
2010 Honda Insight Hybrid Boston
PDF
rijkhof design package design samples
Kevin Ashley Mid Con Aade Presentation.Rev
2010 Honda Insight Hybrid San Leandro
Dental amalgam
2010 Honda Insight Hybrid Jackson
Open Source Success: jQuery
IWB in the Prep Classroom
Visual Resume
Spiral Of Knowledge - 1965
2010 Honda Insight Hybrid Los Angeles
Fringe eu procurement - sara piller
2010 Honda Insight Boston
2010 Honda Insight Hybrid Boston
rijkhof design package design samples
Ad

Viewers also liked (8)

PDF
Edisi keduabelas
PDF
Edisi 3
PPT
Refeds ferpa v0 02
PDF
REFEDS Overview
PDF
Edisi 1
PPT
Licia Florio REFEDS Prague 2011
PDF
Edisi 10
PDF
Edisi 15
Edisi keduabelas
Edisi 3
Refeds ferpa v0 02
REFEDS Overview
Edisi 1
Licia Florio REFEDS Prague 2011
Edisi 10
Edisi 15
Ad

Similar to REFEDS MET, PEER and MDUI Presentation (20)

KEY
CloudTunnel Atlanta Ruby Users Group October 2012
PDF
Constituent elements of mainframe processing
PDF
VocaLight Infrared Classroom Amplification Brochure
PPTX
Making federations work together more effectively - Nicole Harris, JISC Adva...
PDF
Enterprise Collaboration: Can You Connect Social Learning and Business Perfor...
PDF
Personal Branding for Corporate Success
PDF
CM10 Design for Change Patricia Sears
PDF
CM10 Design for Change Patricia Sears
PDF
Bookbuzz Strategy
PDF
Exerpt From Exec Overview
PDF
the 37 Issues of Travel Weekly
PDF
The 35th Travelweekly Digital Issue
PDF
AAF Nissan Plans Book
PDF
A af plansbook2012
PDF
Park Design
PDF
JecoGuides: how to in just 3 steps
PDF
Heartland Sundance 2013 Brochure
PDF
120125 tridti p2_resized
PPS
Mobile Marketing May 2011
CloudTunnel Atlanta Ruby Users Group October 2012
Constituent elements of mainframe processing
VocaLight Infrared Classroom Amplification Brochure
Making federations work together more effectively - Nicole Harris, JISC Adva...
Enterprise Collaboration: Can You Connect Social Learning and Business Perfor...
Personal Branding for Corporate Success
CM10 Design for Change Patricia Sears
CM10 Design for Change Patricia Sears
Bookbuzz Strategy
Exerpt From Exec Overview
the 37 Issues of Travel Weekly
The 35th Travelweekly Digital Issue
AAF Nissan Plans Book
A af plansbook2012
Park Design
JecoGuides: how to in just 3 steps
Heartland Sundance 2013 Brochure
120125 tridti p2_resized
Mobile Marketing May 2011

Recently uploaded (20)

PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Enhancing emotion recognition model for a student engagement use case through...
PPT
What is a Computer? Input Devices /output devices
PDF
August Patch Tuesday
PPTX
Chapter 5: Probability Theory and Statistics
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PDF
Web App vs Mobile App What Should You Build First.pdf
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
A contest of sentiment analysis: k-nearest neighbor versus neural network
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
2021 HotChips TSMC Packaging Technologies for Chiplets and 3D_0819 publish_pu...
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
STKI Israel Market Study 2025 version august
PDF
project resource management chapter-09.pdf
NewMind AI Weekly Chronicles - August'25-Week II
Enhancing emotion recognition model for a student engagement use case through...
What is a Computer? Input Devices /output devices
August Patch Tuesday
Chapter 5: Probability Theory and Statistics
cloud_computing_Infrastucture_as_cloud_p
NewMind AI Weekly Chronicles – August ’25 Week III
Web App vs Mobile App What Should You Build First.pdf
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
A contest of sentiment analysis: k-nearest neighbor versus neural network
TLE Review Electricity (Electricity).pptx
Hindi spoken digit analysis for native and non-native speakers
gpt5_lecture_notes_comprehensive_20250812015547.pdf
2021 HotChips TSMC Packaging Technologies for Chiplets and 3D_0819 publish_pu...
Assigned Numbers - 2025 - Bluetooth® Document
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
STKI Israel Market Study 2025 version august
project resource management chapter-09.pdf

REFEDS MET, PEER and MDUI Presentation

  • 1. What is REFEDS Interested In? Nicole Harris UK Access Management Focus, JISC Advance @nicoleharris Slides: http://www.slideshare.net/nicolevharris
  • 2. Me • UK Access Management Focus; • Advisor to UK federation; • REFEDS Coordinator; • PEER Project Manager; • Shibboleth Consortium Manager; • Generally opinionated about access and identity.
  • 3. What does the R&E Federation space look like?
  • 5. R&E Federations Status (2) • 27 Federations plus 2 confederations. • 4753 entities within those federations. • 1815 Identity Providers. • 2755 Service Providers. • Plus several ‘others’ (don’t worry about it). (November 2011)
  • 6. Top resources? • In 14 federations: – Czech Medical Atlas and Microsoft Dreamspark. • In 12: – Web of Knowledge, Scopus, ScienceDirect. • In 11: – IEEE, EBSCO. • In 10: – Springer, OVID.
  • 7. So it’s all working, right?
  • 8. For SPs, Federation Sucks I know because I wrote a paper on it!
  • 9. Barriers • Multiple registry of entity data. • Multiple legal documents. • One-off clauses. • Interpretation of data protection. • Sponsorship letters. • Fees. • Technical Barriers. https://refeds.terena.org/index.php/Barriers_for_Ser vice_Providers
  • 10. Registering Entity Data • Federations are just big metadata (xml) files. • Entity = your chunk of that data. • It goes a bit like this:
  • 11. How does it work? Federation A Federation B You Federation C
  • 12. What we need is a place where this can be centrally registered and then called on by federations…
  • 14. Legal Contracts F ED ERA T IO T he N RU L A fr am u st r al e ia t r u st w o r k an n A cc e ES e ss F w it h d el ect d su p p ed e r at in an r on o in st d b ic co r t in fr as io n p r it u t io n s et w een m m u n t r u ct o vi d e TERMO DE COMPROMISSO PARA ADESÃO À FEDERAÇÃO CAFe ic at u sa T h is in A u u st r n iv er si io n r e t o fa d al ia t ies s an d ci t o b o cu m e an d an d co ll li t at e em nt o o ve r ab ser vi et u t li r se as e se ar ch o r at io n ce p b y p ar nes th . Pelo presente, a organização identificada neste Termo, ora denominada PARTICIPANTE, r o vi d er t ic ip at in e r u les T h is s. g id an d adere a este documento e assume a responsabilidade pela utilização dos serviços d o cu en t o b li Par it y disponibilizados pela Comunidade Acadêmica Federada, doravante denominada t icip m en t an d gat io an t s su p ns simplesmente CAFe, ciente da “Política de Uso da Federação CAFe: provedores de e r se serviço”, e da “Política de Uso da Federação CAFe: provedores de identidade”, 24 M d es t he ay 2 Fed conforme adiante descrito. 011 er at io n Ru le s fo r PARTICIPANTE: [nome da instituição], com sede na [endereço], neste ato representada por [nome completo], [função], doravante denominada [sigla da instituição] O presente Termo considera que: a) A Federação CAFe é composta por um conjunto de instituições que, sobre uma infraestrutura de autenticação e autorização multidomínios, estabelece uma rede de confiança que simplifica o acesso a serviços federados oferecidos; b) A RNP tem como atribuição o gerenciamento dos processos de disponibilidade, confiabilidade e melhoria continua do Serviço da CAFe, além de apoiar a homologação visando a adesão de novos Provedores de Identidade e Provedores de Serviço na federação CAFe, bem como o suporte a atualizações e melhorias contínuas; c) a RNP e a PARTICIPANTE têm interesse comum na manutenção e desenvolvimento da Federação CAFe com o objetivo de simplificar o processo de Autenticação e Autorização entres as instituições participantes; ©A ustr alian Acces d) a PARTICIPANTE tem interesse em integrar a Federação CAFe como Provedor de s Fe dera [Identidade ou Serviço], para benefício da comunidade de educação, pesquisa e tion RedIRIS Identity Service Conditions of Use for Identity Providers Inc. cultura. Para tanto, a PARTICIPANTE dá ciência e se compromete ao que se segue: RedIRIS Identity Service Conditions of Use for Identity Providers 1 - DO OBJETO Version 1.0 – 20080220 1.1 – O presente Termo tem por objeto estabelecer as diretrizes de participação, a serem realizadas com o apoio recíproco, na CAFe; ___________________________________________________________________, as applicant for 1 the identity transfer services provided by the RedIRIS Identity Service (SIR), to be used by the identity provider identified by its URL, unique ID, and public key included at the end of this document (referred in the rest of this document as “the Applicant”) declares that: 1. Knows and accepts the rules, procedures and technical requirements for the connection of their identity management system with the RedIRIS Identity Service, as specified at http://www.rediris.es/sir/. Applicants accept the appropriate changes that may take place, and that shall be communicated with sufficient time through the service website, and directly to the UK Access Management Federation for RedIRIS Official Liaisons (“Personas de Enlace con RedIRIS”, referred as “PERs” in the rest of this document) of the corresponding affiliated institution. Education and Research 2. Knows that breaking these conditions can imply the discontinuation of the service. 3. Declares that data included in this document are accurate, apart error or omission in good faith. Rules of Membership 4. Commits to permanently update the information included in this document, informing the PERs of any change that takes place. 5. Assumes that RedIRIS, in all procedures related to service provision, will act according to the data provided in this document. 6. Knows and accepts that any falsity or error in the data included in this document can be 1st August 2011 cause of the discontinuation of the service. 7. Knows and accepts that once the service is active it can be revoked in case of violation of the requirements. 8. Knows and assumes that the service can be revoked in case of serious technical negligence. 9. Declares that, according to their best knowledge, the connection of the identity provider identified below with the RedIRIS Identity Service does not harm the rights of any third party. 10. Knows and accepts that the service is provided by RedIRIS in non-commercial terms for its users in the research and academic community, and that RedIRIS shall not be held liable for any damage caused, directly or indirectly, by the usage of the service. 11. Knows and assumes that RedIRIS will perform personal data processing according to Ley Orgánica 15/1999 on Personal Data Protection and the regulations developing it. 12. Knows and assumes that the rights to access and rectification can be exercised according to the above mentioned regulations. The rights to cancellation and opposition can only be exercised after the discontinuation of the service, since personal data processing by Red.es is required for the use of the RedIRIS Identity Service. Version 2.1 ST/AAI/UKF/DOC/001 1/2
  • 15. Wouldn’t it be great if these were standardised and simplified?
  • 16. REFEDs Policy Review • Painstakingly taking apart every clause in every federation policy. • Mapping these to generic content ‘blocks’ and ‘elements’ within each block. • Making recommendations about structure and unnecessary language. • NOT a legal review.
  • 17. Isn’t there an easier way?
  • 18. Full Interfederation • The ability of federations to exchange metadata about their entities. • Normally an additional legal agreement between the 2 federations. • Full technical and policy integration. • Bi-lateral (UK and Edugate) or via groups (eduGain and Kalmar2).
  • 20. eduGain (2) – Drawbacks • At least one of the federations you are a member of needs to have signed up for eduGain. • Opt-in: you have to ask to be included in an aggregate. • Not always clear which entities are interfederated – are your customers there?
  • 21. eduGain (3) Benefits • Only have to have a relationship with 1 federation. • Technically, as an SP, you can chose with federation that is.
  • 22. A quick note on Barriers to Users
  • 23. Login Interfaces Suck I know this because I’ve tried to use them
  • 27. MDUI • Currently being used by DiscoJuice and Shibboleth Embedded Discovery Service / Central Discovery Service. • OASIS Standard for IdP Discovery: – http://docs.oasis- open.org/security/saml/Post2.0/sstc-saml-idp- discovery.pdf.
  • 28. MDUI for SPs (Shibboleth Recs) Non Logo elements • <mdui:DisplayName>Recommended required <mdui:Description>Recommended 100 chars max • <mdui:Keywords> Not used • <mdui:InformationURL> Available • <mdui:PrivacyStatementURL> Available Logo elements • Shibboleth - must be specified using an HTTPS URL • Shibboleth - logo size should be between 64px by 350px wide and 64px by 146px high • Shibboleth - logos should have transparent backgrounds • Shibboleth - logos look better if they have a landscape rather than a portrait aspect ratio https://refeds.terena.org/index.php/MDUI_-_Software_recommendations
  • 29. MDUI for IdPs (Shibboleth Recs) Non Logo elements <mdui:DisplayName>Recommended, 33 chars max Strongly recomended <mdui:Description> Supporting the Display Name function with more details <mdui:Keywords> Used Used for incremental search <mdui:InformationURL> Not used at present <mdui:PrivacyStatementURL>Not used at present – see Attribute WG recs <mdui:IPHint>Not used Planned for future release <mdui:DomainHint> Not used Planned for future release <mdui:GeolocationHint> Not used Heavily used. Strongly recomended. Logo elements • Shibboleth - The URL specifying the logo must be https protected. • Shibboleth - One logo should be provided of size approximately 80px(width) by 60px (height). A larger logo may be provided but the aspect ratio should be maintained (logos are selected based on apsect ration). • Shibboleth - One logo should be provided of size 16px by 16px. • Shibboleth - Logo backgrounds should be transparent. https://refeds.terena.org/index.php/MDUI_-_Software_recommendations
  • 30. Thank you for listening