As part of the eduGAIN Strategy, we are committed to improving the basic standards of security, authenticity, accuracy and interoperability of metadata within eduGAIN and to providing greater consistency in information held about entities in eduGAIN.
For this to be achieved, a GOAL was set to improve the baseline standards for security, data protection and assurance across all entities published to eduGAIN.
As part of the proposed roadmap for delivery the eduGAIN Strategy, a phased approach has been proposed to improve the quality of data in metadata.
| Requiurement | Security | Privacy | Assurance |
|---|---|---|---|
| 1 | Require security contacts and commitment to incident response for federations | Require privacy notice and completion of mdui:PrivacyStatementURL for all enties | require expression of RAF information / ability to assert https://refeds.org/assurance for all Identity Providers.
|
| 2 | Require security contacts and commitment to incident response for all entities | require expression of identifier uniqueness / ability to assert: https://refeds.org/assurance/ID/unique | |
| 3 | Require Sirtfi for all entities | require minimum RAF level - TBD. |
Proposed Approach
| Phase | Requirement | Deadline | Comments |
|---|---|---|---|
| 1 | Require security contacts and commitment to incident response for federations | 31st December 2025 | Complete, target achieved |
| 2 | Require security contacts and commitment to incident response for all entities Require privacy notice and completion of mdui:PrivacyStatementURL for all entities Require expression of RAF information / ability to assert https://refeds.org/assurance for all Identity Providers. | 31st December 2026 | Proposed - is it too much to include RAF in this year? Could be rolled to 2027 I think we can discuss this. I would not dilute it too much though. Maybe we could move RAF base requirement to 2027-Q1? (Davide) |
| 3 | Require Sirtfi for all entities Require expression of identifier uniqueness / ability to assert: https://refeds.org/assurance/ID/unique | 31st December 2027 | +1 (Davide) |
| 4 | Require minimum RAF level - TBD. | This still needs significant scoping work |
Process
- Requirements will be announced by the Secretariat and appropriate amendments made the SAML Technical Profile.
- Federations will be asked to remove all entities that do not meet these standards by the deadline or (or they will be filtered by eduGAIN OT?).