UC Identity Management Work Group
Meeting - 3/8/2004 - Agenda
Time: 8/8/2004, 10:00-3:00
Location: "Library" Room of the University Club, UC Irvine
- Review of project goals and timelines. (See the attached charge to this
group.)
- Review of the current state of campus authentication and
enterprise directories, along with projected use cases for the new
federated authentication infrastructure.
- Attributes that will be required by UCFY/YBO to identify the
user. These systems currently use the UCnetID to identify users,
but SSN is a possible alternative.
- Selection of technology. I think most of us are expecting
this will be Shibboleth, but we'll need a formal decision.
(See http://shibboleth.internet2.edu.)
- Solutions to the "Where are you from?" (WAYF) issue. Will
users start with a campus "login" page or browse directly to
UCFY/YBO? Should we use the InCommon WAYF service?
- Attributes required for access to CDL-licensed databases and
eduPerson. I believe everyone is already targeting eduPerson, so
this is probably a small issue. (See http://middleware.internet2.edu/dir/.)
- Attribute release policies. We need agreements on which
attributes can be released and under what circumstances. We also
need agreements on the allowable uses of attributes once they're
released.
- (Minimal) standards for intra-campus identity management,
registration, etc. Can we use InCommon as a basis for this?
(See http://incommon.internet2.edu/,
particularly the "InCommon Perspectus" that is linked from that page.)
- Division of labor. We need to develop a basic understanding
of who will be doing what. Here's a "straw man" proposal:
UCOP
- Software modifications to UCFY and YBO.
- Java federated authentication framework for use in other
applications.
- Provide assistance to campuses with origin deployment
Campuses
- Origin deployment (with integration to local authentication)
- Enterprise directory
- Coordination with campus libraries
- User education.