Kantara FIWG Teleconference 

Approved by quorum on 2019-06-05 call

Date and Time

  • Date: 15 May, 2019
  • Time: 16:30 EDT


  • Nick Roy v
  • Scott Cantor v
  • Vlad Mencl nv
  • Keith Wessel v
  • Judith Bush v
  • Andrew Morgan nv
  • Alan Buxey v
  • Colin Wallis nv
  • Eric Goodman nv
  • Regrets


  1. Roll call
    1. Quorum achieved
    2. Here is the  group participation agreement, AI: anyone who wants to vote should fill it out and indicate that they want to have voting status.
  2. Agenda bash
  3. Approval of previous meeting's minutes: https://kantarainitiative.org/confluence/display/fiwg/Meeting+Minutes+01+May+2019
    1. Approved
  4. Review of previous AIs:
    1. Need to get an update on this next time (May 29)
    1. [DONE]
    2. Could contact people at vendors who we know maintain their federated SSO, ask them if they want to provide input.
    3. Reaching out personally to people could work, but what is the input we want? Research projects of the world have had many opportunities to provide input. Vendor side of things is a different problem space that is not consistent with the goals of this doc, with the exception of targeted outreach to collaborative space (Internet2 NET+). Rest is about other sectors like government, which is mostly what Kantara consists of now. Would have to have direct outreach for that.
    4. There is an IDPro Slack org, Judith could post to SAML, gov identity, general channels. Proposed message:
      1. Kantara has a SAML interoperability working group that has reconstituted to approve a new version of SAML2int that aspires to address existing interoperability issues and look ahead to improved crypto. The draft is at https://kantarainitiative.github.io/SAMLprofiles/saml2int.html We’d love your input into the revision of the original SAML2int. If you want to get involved, please take a look here for meeting times, mailing list, and how to become a voting member: https://kantarainitiative.org/confluence/display/fiwg/Home  
    5. A few early e-gov people were around this WG before Rainer got involved. Maybe we should check with Colin to see if he can drum up some eGov type people.
    6. AI: Keith reach out to Colin Wallis about eGov people to contact [DONE]
    7. Free to do whatever we want, even if that’s due diligence, ask for feedback, do one last round of editing, call for a vote.
    8. Need to frame the ask on feedback, because people focused on pragmatics are not going to understand what we’re trying to do.
    9. Discussion of vendors in Internet2 NET+ program as part of feedback.
    10. Want to expose others to this, get some buy-in.
    11. AI: Nick reach out Sara Jeanes to gauge NET+ (Sara, vendor architects) interest in reviewing/feedback.
    12. There is a hope that InCommon could give sponsored partners a discount because they do certain things in alignment with the profiles.
    13. Reaching out to eGov/etc is also a form of evangelizing. At least awareness-building.
    14. Colin sent the solicitation to the eGov list. Will seek additional ideas from Colin on getting feedback.
    1. Walter: formatting revisions
    2. Keith: email to solicit more participation
  5. Resume discussion of next steps
    1. Most of the spec sounds reasonable to Vlad
    2. Avoiding nameID was surprising - Shibboleth IdPv3 upgrade in New Zealand, moved away from eduPersonTargetedID, to persistent nameID
      1. The move away from ePTID and persistent nameID is because applications don’t treat identifiers case sensitively, so we are facing a security problem with those identifiers. This is all covered in the subject ID specification (https://docs.oasis-open.org/security/saml-subject-id-attr/v1.0/saml-subject-id-attr-v1.0.html)
      2. The new identifiers look useful, this is not a dissenting opinion, it’s more of a ‘sigh, we have to change again, but there’s a good reason for it.’
    3. No other comments at this point.
    4. Nick will spin up a feedback wiki page in the Kantara wiki when we start to get dissenting opinions.
    1. Wait and see what happens with broader participation, revisit on May 29.
    1. Want to extend this meeting to a full hour?
      1. 5:30 US ET is OK with Scott and Judith
      2. Don’t need another 15 minutes at the moment, could extend later if needed.
      3. Not a problem with Alan to go to an hour either.
      4. Leaving length at 45 minutes for now.
    1. Picking up where we left off last week, we need to start a document to record dissenting opinions.
    2. We also need to get some dormant attendees to rejoin to actually have dissenting opinions to document.
    3. Discuss where to go from here
  6. Meeting adjourned - next meeting 29 May 2019, same time/place

 Call ended at 50 min.