SlideShare a Scribd company logo
1 of 14
Download to read offline
OIDF Research and Education WG
UPDATE
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
Who is participating to the R&E WG?
+ a bunch of people
from Internet2 (Keith
“MACE-Dir” Hazelton),
NRENs, IGTF, CERN,
etc
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
Why we've created a R&E WG in the OIDF?
● Research and Education sector has been doing IAM and FIM (Federated
Identity Management) for many years.
● Standards, specifications and profiles has been created around two major
technologies: LDAP and SAML.
● Meet the raising demand for OIDC and OAuth2 in the current R&E IAM and
FIM landscape.
● We want to work with the industry to create a set of specs and profiles that
will ease the use of OIDC and OAuth2 in the R&E sector.
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
Work planning: specifications, schedule,
commitment
R&E profiles for OpenID
Connect
R&E claims and scopes
for OpenID Connect
Entity metadata
extension for OpenID
Connect
Intermediate steps and
time frame
Community feedback
and engagement
When is it done?
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
Work done so far
R&E profiles for OpenID
Connect
R&E claims and scopes
for OpenID Connect
Entity metadata
extension for OpenID
Connect
Intermediate steps and
time frame
Community feedback
and engagement
When is it done?
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
What is missing in the OIDC specs?
● User identification use cases tailored to R&E.
● Affiliation, groups and role information.
● A set of claims and scopes to specifically support the schemas currently
employed in R&E: eduPerson, SCHAC, and the derived profiles and bundles
of user information, such as the Research and Scholarship Entity Category.
R&E claims and scopes for OpenID Connect
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
Done so far
● Started leveraging the REFEDS SAML-OIDC mapping white paper:
https://wiki.refeds.org/x/BYBRAg
● Spent some time defining claims for:
○ affiliation, based on eduPersonScopedAffiliation (plain string)
○ group, based on isMemberOf and AARC’s URN notation (plain or URN string)
○ entitlements, based on eduPersonEntitlements, URN (URN string)
● Drafted use cases for user identifiers:
○ anonymous identifier: used by many academic journals along with specific entitlements.
○ pseudo-anonymous identifier (i.e. pair-wise).
○ globally unique persistent identifier.
● Drafted synthetic ways to represent an OIDC public identifier for account linking:
○ as a string: iss!sub
○ as a compact JWT: { “iss”:”https://donotoverload.this”, “sub”:”compact JWT”}
R&E claims and scopes for OpenID Connect
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
R&E claims and scopes for OpenID Connect
What’s next?
1. A first draft of the version will be out before the end of the summer.
2. We will ask for feedbacks and comments in two main places: inside the
OpenID Connect community, and in the REFEDS and eduGAIN
communities.
3. Implement the due changes to the spec.
4. Repeat point 2 and 3 in short cycles --- at least two other times (by the
charter).
5. Finally publish the draft.
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
Entity metadata extension for OpenID Connect
Why we need to extend the OIDC entities metadata?
● No way to specify contact types: contacts is a simple list/array of string, while in R&E we
have administrative, technical contact types plus a security incident response one.
● No way to declare that an entity belong to a specific category, nor that an entity supports
and recognizes an entity category.
● Implementing the most common policy frameworks used in the R&E federated identity
context [R&S EC, CoCo, SIRTFI] is far from being and easy task, if possible anyway.
● The final target is to extend the set of claims used to describe entities in a standard and
community blessed way --- not just the R&E community.
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
Entity metadata extension for OpenID Connect
Work done so far
● Considered two different approaches:
1. An extension claim that will host a structured JSON Object.
2. Create new claims as they are currently needed to implement the R&E
policy frameworks.
What’s next?
● Cannot work it in parallel with the other spec, so it has been paused until the
R&E claims and scopes spec is published.
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
WG tools: repositories, wikis, trackers
https://github.com/daserzw/oidc-edu-wg/
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
References
● The R&E WG web-page on the OpenID Foundation site
https://openid.net/wg/rande
● R&E WG presentation at OIDF Workshop at VMWare (Oct 22 2018):
https://bit.ly/2JPT30Z
● Wrap-up of R&E OIDC Panel Session at Internet2 TechEx 2018:
https://bit.ly/2SUPDOC
● Who proposed this working group and why:
https://bit.ly/2PNu8Az
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
Thanks
Davide Vaghetti, davide.vaghetti@garr.it, GARR
Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019

More Related Content

What's hot

20090620 CWID EDI-gateway (EDI) Identity Management (IDM) US
20090620 CWID EDI-gateway (EDI) Identity Management (IDM) US20090620 CWID EDI-gateway (EDI) Identity Management (IDM) US
20090620 CWID EDI-gateway (EDI) Identity Management (IDM) USKim Holm
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...OpenIDFoundation
 
OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17
OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17
OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17Shane Coughlan
 
OpenID Foundation MODRNA WG Update
OpenID Foundation MODRNA WG UpdateOpenID Foundation MODRNA WG Update
OpenID Foundation MODRNA WG UpdateBjorn Hjelm
 
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...OpenIDFoundation
 
OpenChain Automotive Work Group Meeting #2 - Lyon
OpenChain Automotive Work Group Meeting #2 - LyonOpenChain Automotive Work Group Meeting #2 - Lyon
OpenChain Automotive Work Group Meeting #2 - LyonShane Coughlan
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...OpenIDFoundation
 
OpenID Progress EEMA Conference
OpenID Progress EEMA ConferenceOpenID Progress EEMA Conference
OpenID Progress EEMA Conferenceevidos
 
Mohannad hussain community track - siim dataset & dico mweb proxy
Mohannad hussain   community track - siim dataset & dico mweb proxyMohannad hussain   community track - siim dataset & dico mweb proxy
Mohannad hussain community track - siim dataset & dico mweb proxyDevDays
 
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...Shane Coughlan
 
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group UpdateOpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group UpdateMikeLeszcz
 
IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...
IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...
IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...MicheleNati
 
MODRNA WG Update - Dec 2021
MODRNA WG Update - Dec 2021MODRNA WG Update - Dec 2021
MODRNA WG Update - Dec 2021Bjorn Hjelm
 
Furore devdays 2017- oai
Furore devdays 2017- oaiFurore devdays 2017- oai
Furore devdays 2017- oaiDevDays
 
OpenID Foundation MODRNA WG Overview
OpenID Foundation MODRNA WG OverviewOpenID Foundation MODRNA WG Overview
OpenID Foundation MODRNA WG OverviewBjorn Hjelm
 
Hungarian Electronic Public Administration Interoperability Framework (MEKIK)...
Hungarian Electronic Public Administration Interoperability Framework (MEKIK)...Hungarian Electronic Public Administration Interoperability Framework (MEKIK)...
Hungarian Electronic Public Administration Interoperability Framework (MEKIK)...Csaba Krasznay
 
OpenChain & OpenUK Future Leaders Group Presentation (Reduced)
OpenChain & OpenUK Future Leaders Group Presentation (Reduced)OpenChain & OpenUK Future Leaders Group Presentation (Reduced)
OpenChain & OpenUK Future Leaders Group Presentation (Reduced)Shane Coughlan
 
The importance of corda architect certification in students life
The importance of corda architect certification in students lifeThe importance of corda architect certification in students life
The importance of corda architect certification in students lifeBlockchain Council
 

What's hot (20)

20090620 CWID EDI-gateway (EDI) Identity Management (IDM) US
20090620 CWID EDI-gateway (EDI) Identity Management (IDM) US20090620 CWID EDI-gateway (EDI) Identity Management (IDM) US
20090620 CWID EDI-gateway (EDI) Identity Management (IDM) US
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
 
OIDC4VP for AB/C WG
OIDC4VP for AB/C WGOIDC4VP for AB/C WG
OIDC4VP for AB/C WG
 
OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17
OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17
OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17
 
OpenID Foundation MODRNA WG Update
OpenID Foundation MODRNA WG UpdateOpenID Foundation MODRNA WG Update
OpenID Foundation MODRNA WG Update
 
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
 
OpenChain Automotive Work Group Meeting #2 - Lyon
OpenChain Automotive Work Group Meeting #2 - LyonOpenChain Automotive Work Group Meeting #2 - Lyon
OpenChain Automotive Work Group Meeting #2 - Lyon
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
 
OpenID Progress EEMA Conference
OpenID Progress EEMA ConferenceOpenID Progress EEMA Conference
OpenID Progress EEMA Conference
 
Mohannad hussain community track - siim dataset & dico mweb proxy
Mohannad hussain   community track - siim dataset & dico mweb proxyMohannad hussain   community track - siim dataset & dico mweb proxy
Mohannad hussain community track - siim dataset & dico mweb proxy
 
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
 
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group UpdateOpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
 
IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...
IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...
IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...
 
MODRNA WG Update - Dec 2021
MODRNA WG Update - Dec 2021MODRNA WG Update - Dec 2021
MODRNA WG Update - Dec 2021
 
Furore devdays 2017- oai
Furore devdays 2017- oaiFurore devdays 2017- oai
Furore devdays 2017- oai
 
OpenID Foundation MODRNA WG Overview
OpenID Foundation MODRNA WG OverviewOpenID Foundation MODRNA WG Overview
OpenID Foundation MODRNA WG Overview
 
Hungarian Electronic Public Administration Interoperability Framework (MEKIK)...
Hungarian Electronic Public Administration Interoperability Framework (MEKIK)...Hungarian Electronic Public Administration Interoperability Framework (MEKIK)...
Hungarian Electronic Public Administration Interoperability Framework (MEKIK)...
 
OpenChain & OpenUK Future Leaders Group Presentation (Reduced)
OpenChain & OpenUK Future Leaders Group Presentation (Reduced)OpenChain & OpenUK Future Leaders Group Presentation (Reduced)
OpenChain & OpenUK Future Leaders Group Presentation (Reduced)
 
640 822
640 822640 822
640 822
 
The importance of corda architect certification in students life
The importance of corda architect certification in students lifeThe importance of corda architect certification in students life
The importance of corda architect certification in students life
 

Similar to OIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group Update

OpenChain Japan Work Group - Meeting 27
OpenChain Japan Work Group - Meeting 27OpenChain Japan Work Group - Meeting 27
OpenChain Japan Work Group - Meeting 27Shane Coughlan
 
Research Data Alliance in a nutshell - Fotis Karayannis
Research Data Alliance in a nutshell - Fotis KarayannisResearch Data Alliance in a nutshell - Fotis Karayannis
Research Data Alliance in a nutshell - Fotis KarayannisBlue BRIDGE
 
Immersion Program Presentation Web2
Immersion Program Presentation   Web2Immersion Program Presentation   Web2
Immersion Program Presentation Web2Rick Reo
 
IIIF at the Getty: Vision & Tactics
IIIF at the Getty: Vision & TacticsIIIF at the Getty: Vision & Tactics
IIIF at the Getty: Vision & TacticsStefano Cossu
 
OpenChain-Monthly-Meeting-2022-11-15
OpenChain-Monthly-Meeting-2022-11-15OpenChain-Monthly-Meeting-2022-11-15
OpenChain-Monthly-Meeting-2022-11-15Shane Coughlan
 
Lloyd Green (IEEE): Standardization Needs and Efforts in VR/AR
Lloyd Green (IEEE): Standardization Needs and Efforts in VR/ARLloyd Green (IEEE): Standardization Needs and Efforts in VR/AR
Lloyd Green (IEEE): Standardization Needs and Efforts in VR/ARAugmentedWorldExpo
 
Get Into Open Source
Get Into Open SourceGet Into Open Source
Get Into Open SourceJoe Sepi
 
OpenChain Monthly Meeting 2022-11-01
OpenChain Monthly Meeting 2022-11-01OpenChain Monthly Meeting 2022-11-01
OpenChain Monthly Meeting 2022-11-01Shane Coughlan
 
SR-R-nKAnwar_PPM_Penulisan_ProposalLPDP.pdf
SR-R-nKAnwar_PPM_Penulisan_ProposalLPDP.pdfSR-R-nKAnwar_PPM_Penulisan_ProposalLPDP.pdf
SR-R-nKAnwar_PPM_Penulisan_ProposalLPDP.pdfHabibAbda
 
5th Content Providers Community Call
5th Content Providers Community Call5th Content Providers Community Call
5th Content Providers Community CallOpenAIRE
 
IEEE Digital Senses Initiative - Standards Activities 3/30/2017
IEEE Digital Senses Initiative - Standards Activities   3/30/2017IEEE Digital Senses Initiative - Standards Activities   3/30/2017
IEEE Digital Senses Initiative - Standards Activities 3/30/2017yymedia
 
Rda in a_nutshell_february_2017_updated
Rda in a_nutshell_february_2017_updatedRda in a_nutshell_february_2017_updated
Rda in a_nutshell_february_2017_updatedResearch Data Alliance
 
A Survey on Knowledge Base: An Internal Platform to Exchange Technical Questi...
A Survey on Knowledge Base: An Internal Platform to Exchange Technical Questi...A Survey on Knowledge Base: An Internal Platform to Exchange Technical Questi...
A Survey on Knowledge Base: An Internal Platform to Exchange Technical Questi...IRJET Journal
 

Similar to OIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group Update (20)

Rda in a_nutshell_june_2017
Rda in a_nutshell_june_2017Rda in a_nutshell_june_2017
Rda in a_nutshell_june_2017
 
RDA in a Nutshell - May 2017
RDA in a Nutshell - May 2017RDA in a Nutshell - May 2017
RDA in a Nutshell - May 2017
 
OpenChain Japan Work Group - Meeting 27
OpenChain Japan Work Group - Meeting 27OpenChain Japan Work Group - Meeting 27
OpenChain Japan Work Group - Meeting 27
 
Research Data Alliance in a nutshell - Fotis Karayannis
Research Data Alliance in a nutshell - Fotis KarayannisResearch Data Alliance in a nutshell - Fotis Karayannis
Research Data Alliance in a nutshell - Fotis Karayannis
 
Immersion Program Presentation Web2
Immersion Program Presentation   Web2Immersion Program Presentation   Web2
Immersion Program Presentation Web2
 
IIIF at the Getty: Vision & Tactics
IIIF at the Getty: Vision & TacticsIIIF at the Getty: Vision & Tactics
IIIF at the Getty: Vision & Tactics
 
D2.2 Workflow Guidelines
D2.2  Workflow Guidelines D2.2  Workflow Guidelines
D2.2 Workflow Guidelines
 
OpenChain-Monthly-Meeting-2022-11-15
OpenChain-Monthly-Meeting-2022-11-15OpenChain-Monthly-Meeting-2022-11-15
OpenChain-Monthly-Meeting-2022-11-15
 
Lloyd Green (IEEE): Standardization Needs and Efforts in VR/AR
Lloyd Green (IEEE): Standardization Needs and Efforts in VR/ARLloyd Green (IEEE): Standardization Needs and Efforts in VR/AR
Lloyd Green (IEEE): Standardization Needs and Efforts in VR/AR
 
Rda in a_nutshell_january_2017
Rda in a_nutshell_january_2017Rda in a_nutshell_january_2017
Rda in a_nutshell_january_2017
 
Get Into Open Source
Get Into Open SourceGet Into Open Source
Get Into Open Source
 
OpenChain Monthly Meeting 2022-11-01
OpenChain Monthly Meeting 2022-11-01OpenChain Monthly Meeting 2022-11-01
OpenChain Monthly Meeting 2022-11-01
 
H2020 ICT calls
H2020 ICT callsH2020 ICT calls
H2020 ICT calls
 
SR-R-nKAnwar_PPM_Penulisan_ProposalLPDP.pdf
SR-R-nKAnwar_PPM_Penulisan_ProposalLPDP.pdfSR-R-nKAnwar_PPM_Penulisan_ProposalLPDP.pdf
SR-R-nKAnwar_PPM_Penulisan_ProposalLPDP.pdf
 
5th Content Providers Community Call
5th Content Providers Community Call5th Content Providers Community Call
5th Content Providers Community Call
 
IEEE Digital Senses Initiative - Standards Activities 3/30/2017
IEEE Digital Senses Initiative - Standards Activities   3/30/2017IEEE Digital Senses Initiative - Standards Activities   3/30/2017
IEEE Digital Senses Initiative - Standards Activities 3/30/2017
 
Rda in a_nutshell_february_2017_updated
Rda in a_nutshell_february_2017_updatedRda in a_nutshell_february_2017_updated
Rda in a_nutshell_february_2017_updated
 
A Survey on Knowledge Base: An Internal Platform to Exchange Technical Questi...
A Survey on Knowledge Base: An Internal Platform to Exchange Technical Questi...A Survey on Knowledge Base: An Internal Platform to Exchange Technical Questi...
A Survey on Knowledge Base: An Internal Platform to Exchange Technical Questi...
 
Rda in a_nutshell_september_2017
Rda in a_nutshell_september_2017Rda in a_nutshell_september_2017
Rda in a_nutshell_september_2017
 
Dii Toolkit Initiative
Dii Toolkit InitiativeDii Toolkit Initiative
Dii Toolkit Initiative
 

More from OpenIDFoundation

OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program UpdateOIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program UpdateOpenIDFoundation
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group UpdateOIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group UpdateOpenIDFoundation
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...OpenIDFoundation
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...OpenIDFoundation
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...OpenIDFoundation
 
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...OpenIDFoundation
 
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...OpenIDFoundation
 
OIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification UpdateOIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification UpdateOpenIDFoundation
 
OpenID Connect "101" Introduction -- October 23, 2018
OpenID Connect "101" Introduction -- October 23, 2018OpenID Connect "101" Introduction -- October 23, 2018
OpenID Connect "101" Introduction -- October 23, 2018OpenIDFoundation
 
OpenID Foundation Connect Working Group Update - October 22, 2018
OpenID Foundation Connect Working Group Update - October 22, 2018OpenID Foundation Connect Working Group Update - October 22, 2018
OpenID Foundation Connect Working Group Update - October 22, 2018OpenIDFoundation
 
OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018OpenIDFoundation
 

More from OpenIDFoundation (11)

OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program UpdateOIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
OIDF Virtual Workshop -- 5/21/2020 -- OpenID Certification Program Update
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group UpdateOIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
 
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
 
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
 
OIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification UpdateOIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification Update
 
OpenID Connect "101" Introduction -- October 23, 2018
OpenID Connect "101" Introduction -- October 23, 2018OpenID Connect "101" Introduction -- October 23, 2018
OpenID Connect "101" Introduction -- October 23, 2018
 
OpenID Foundation Connect Working Group Update - October 22, 2018
OpenID Foundation Connect Working Group Update - October 22, 2018OpenID Foundation Connect Working Group Update - October 22, 2018
OpenID Foundation Connect Working Group Update - October 22, 2018
 
OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018
 

Recently uploaded

Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfMounikaPolabathina
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embeddingZilliz
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 

Recently uploaded (20)

Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdf
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embedding
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 

OIDF Workshop 4/29/2019 -- OpenID Research & Education Working Group Update

  • 1. OIDF Research and Education WG UPDATE Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 2. Who is participating to the R&E WG? + a bunch of people from Internet2 (Keith “MACE-Dir” Hazelton), NRENs, IGTF, CERN, etc Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 3. Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 4. Why we've created a R&E WG in the OIDF? ● Research and Education sector has been doing IAM and FIM (Federated Identity Management) for many years. ● Standards, specifications and profiles has been created around two major technologies: LDAP and SAML. ● Meet the raising demand for OIDC and OAuth2 in the current R&E IAM and FIM landscape. ● We want to work with the industry to create a set of specs and profiles that will ease the use of OIDC and OAuth2 in the R&E sector. Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 5. Work planning: specifications, schedule, commitment R&E profiles for OpenID Connect R&E claims and scopes for OpenID Connect Entity metadata extension for OpenID Connect Intermediate steps and time frame Community feedback and engagement When is it done? Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 6. Work done so far R&E profiles for OpenID Connect R&E claims and scopes for OpenID Connect Entity metadata extension for OpenID Connect Intermediate steps and time frame Community feedback and engagement When is it done? Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 7. What is missing in the OIDC specs? ● User identification use cases tailored to R&E. ● Affiliation, groups and role information. ● A set of claims and scopes to specifically support the schemas currently employed in R&E: eduPerson, SCHAC, and the derived profiles and bundles of user information, such as the Research and Scholarship Entity Category. R&E claims and scopes for OpenID Connect Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 8. Done so far ● Started leveraging the REFEDS SAML-OIDC mapping white paper: https://wiki.refeds.org/x/BYBRAg ● Spent some time defining claims for: ○ affiliation, based on eduPersonScopedAffiliation (plain string) ○ group, based on isMemberOf and AARC’s URN notation (plain or URN string) ○ entitlements, based on eduPersonEntitlements, URN (URN string) ● Drafted use cases for user identifiers: ○ anonymous identifier: used by many academic journals along with specific entitlements. ○ pseudo-anonymous identifier (i.e. pair-wise). ○ globally unique persistent identifier. ● Drafted synthetic ways to represent an OIDC public identifier for account linking: ○ as a string: iss!sub ○ as a compact JWT: { “iss”:”https://donotoverload.this”, “sub”:”compact JWT”} R&E claims and scopes for OpenID Connect Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 9. R&E claims and scopes for OpenID Connect What’s next? 1. A first draft of the version will be out before the end of the summer. 2. We will ask for feedbacks and comments in two main places: inside the OpenID Connect community, and in the REFEDS and eduGAIN communities. 3. Implement the due changes to the spec. 4. Repeat point 2 and 3 in short cycles --- at least two other times (by the charter). 5. Finally publish the draft. Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 10. Entity metadata extension for OpenID Connect Why we need to extend the OIDC entities metadata? ● No way to specify contact types: contacts is a simple list/array of string, while in R&E we have administrative, technical contact types plus a security incident response one. ● No way to declare that an entity belong to a specific category, nor that an entity supports and recognizes an entity category. ● Implementing the most common policy frameworks used in the R&E federated identity context [R&S EC, CoCo, SIRTFI] is far from being and easy task, if possible anyway. ● The final target is to extend the set of claims used to describe entities in a standard and community blessed way --- not just the R&E community. Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 11. Entity metadata extension for OpenID Connect Work done so far ● Considered two different approaches: 1. An extension claim that will host a structured JSON Object. 2. Create new claims as they are currently needed to implement the R&E policy frameworks. What’s next? ● Cannot work it in parallel with the other spec, so it has been paused until the R&E claims and scopes spec is published. Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 12. WG tools: repositories, wikis, trackers https://github.com/daserzw/oidc-edu-wg/ Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 13. References ● The R&E WG web-page on the OpenID Foundation site https://openid.net/wg/rande ● R&E WG presentation at OIDF Workshop at VMWare (Oct 22 2018): https://bit.ly/2JPT30Z ● Wrap-up of R&E OIDC Panel Session at Internet2 TechEx 2018: https://bit.ly/2SUPDOC ● Who proposed this working group and why: https://bit.ly/2PNu8Az Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019
  • 14. Thanks Davide Vaghetti, davide.vaghetti@garr.it, GARR Davide Vaghetti - Consortium GARR and GEANT davide.vaghetti@garr.it, OpenID Foundation Workshop - April 29th 2019