comanage-dev - [comanage-dev] Draft Minutes: COmanage-dev Call 18-Mar-2011
Subject: COmanage Developers List
List archive
- From: Emily Eisbruch <>
- To: CoMaNaGe-DeV <>
- Subject: [comanage-dev] Draft Minutes: COmanage-dev Call 18-Mar-2011
- Date: Mon, 21 Mar 2011 16:22:04 -0400
COmanage-dev Call 18-Mar-2011 Attending Ken Klingenstein, Internet2 (stand-in chair) RL Bob Morgan, U. Washington Keith Hazelton, U. Wisc Ann West, Internet2 Dan Pritts, Internet2 Steve Olshansky, Internet2Emily Eisbruch, Internet2 (scribe) Carry Over Action Items [AI] (Keith) will make sure that the COmanage glossary covers roles and groups accurately. https://spaces.internet2.edu/display/COmanage/Glossary [AI] (Ken) will provide a link to the French listing regarding applications and sets/bundles of attributes. [AI] (Keith) will add to the COmanage wiki use case library the case of bridging identity using social identity credentials. [AI] (Keith) will ask Roland and Leif to clarify how social identity assertions will be handled in their system. [AI] (Benn) will update the COmanage roadmap based on recent discussions with COs. [AI] (Benn and Keith) will talk about Bamboo's requirements for person registry. [AI] (Ken) will contact David Groep about VOMS GUMS. [AI] (Steven) will develop a one-page write-up on attribute aggregation. [AI] (Heather) will ask U. Chicago people to contribute an academic (intra-institutional) use case to the COmanage use case library. DISCUSSION VMs Danno has inquired recently on the list about the status of these VMs on the Amazon cloud: So far no one claimed ownership. SteveO will email Chris Hubing about them (DONE). VO CAMP
COmanage Demo
COmanage Team
GENI Update
The PKI Backend
Terminology
COmanage and GENI
Would it make sense for GENI to have two COmanage instances: 1. COmanage inside the GENI portal , as a place where various researchers would manage permissions and capabilities for their students and other researchers' students. and 2. Could there be a COmanage instance inside the GENI Project Office (GPO) functioning as a pseudo enterprise directory? This would involve embedding COmanage in the GENI management portal. All the attributes would be self asserted. RL "Bob" remarked that every organization can benefit from a Comanage instance as long as
Ken: Summer timeframe for having set this up within GENI. Ken raised a question about defining permissions to class members. Assume I create a class using GENI and all individuals in the class have the same sets of permissions. Would it look like a single group entry in COmanage? So that when you get to the portal you map to the group. and get the permissions from COmanage? OR would every individual in the class need their own entry in the COmanage person registry? Steven had indicated in the past that it would most likely be possible to put groups inside the person registry Ken saw a recent email discussing this ( PG PR registry ? ) Ken will send that email to the list if possible. RL "Bob" : Perhaps the question is whether there is justification for COmanage to be an IdM on its own with its own UI etc. ? Or should it just be the set of functionality embedded in something like Drupal Keith observed that with Grouper, both delivery approaches were used. Grouper was delivered with an admin UI. Then Grouper was delivered with web services to accomplish most of the Grouper functionality. That's the model -- get something useful out there (so need to develop some UI screens). Then pitch the idea to others to call functions from Grouper. InCommon News
Trust Issues Managing trust routes in GENI is challenging. Currently, accepting credentials from other clusters is problematic. They want a coordinated infrastructure. Does using a PKI attribute delivery mechanism simplify matters because they just can trust COmanage and Comanage will then deal with federation and metadata? Does it make sense to simplify trust at the PKI level by making Comanage the only CA that the various clusters need to know about? Ken: Is there parameterization that COmanage needs to go thru? A COmanage instance in InCommon needs to ingest the InCommon metadata. Is it doing that today? The COmanage demo has something called organizations. These provide identity. Keith will ask Benno what is behind the organization field at the 22-Mar-2011 COmanage/Bamboo demo intro session. The evolution of metadata has put InCommon and the Shib and SAML folks ahead of many federated organizations in terms of managing trust in scalable ways Bob re boarding process. if COmanage is an SP, accepting identities from IDPs, it would rely on its SAML software (Shibboleth) to do SAML processing of metadata. But how does it manage the IDPs that it is working with and their metadata? That could be a piece of application requirement we do not yet have standard functionality for. Ken: What about a listing of the various IDPs that could work for a particular COmanage instance? RL Bob: This listing is found in the discovery service that is embedded in the app. The way to find out if your organization is able to use an app, is to go to that app and looking at the list that pops up. There most likely is a requirement for exposing that for other purposes. This is part of dealing with the boarding process and making it easier. Dyonisius posted some interesting information on this on the MACE-Dir list on 3-Dec-2010. VO Updates
2011 Spring Member Meeting in Arlington, VA __________________ COmanage Working Group at SMM: Monday, April 18, 2011, 9:15 AM - 10:15 AM
Location: Salon A __________________ ALSO AT SMM: International Collaboration Platforms – SURFconext, COIP, COmanageMonday, April 18, 2011, 4:30 PM - 5:30 PMLocation: Salon D/E--------------- Supporting Research Communities: Collaborations in ActionTuesday, April 19, 2011, 1:15 PM - 2:30 PM
Location: Salon I/II/III--------------- Next COmanage-dev Call: 18-March-2011 Emily Eisbruch, Technology Transfer Analyst Internet2 office: +1-734-352-4996 | mobile +1-734-730-5749 Visit our website: www.internet2.edu Follow us on Twitter: www.twitter.com/internet2 Become a Fan on Facebook: www.internet2.edu/facebook |
- [comanage-dev] Draft Minutes: COmanage-dev Call 18-Mar-2011, Emily Eisbruch, 03/21/2011
Archive powered by MHonArc 2.6.16.