Skip to content

Updated to generify across InC services, v.1.3 #2

Merged
merged 1 commit into from
Sep 5, 2019
Merged

Updated to generify across InC services, v.1.3 #2

merged 1 commit into from
Sep 5, 2019

Conversation

nroy
Copy link
Contributor

@nroy nroy commented Jul 15, 2019

This is a proposed new version of the InCommon Incident Handling Framework that accommodates the framework being applied to other InCommon services beyond just the federation.

@nroy nroy self-assigned this Jul 15, 2019
@nroy nroy requested review from awu and a user July 15, 2019 19:58
@awu
Copy link

awu commented Jul 16, 2019

I believe much of this is already being addressed in Slack. though I thought I'd mention it here:

By removing the word "Federation", this document can now be interpreted as to cover all aspects of InCommon activities. The issue: what is "InCommon"? Is it operations under InCommon LLC's control? If so, I think that means InCommon Cert Service is, but eduroam is not... If the word "InCommon" does not refer to InCommon LLC, then we should define what it means here.

Regarding Cert Service, we outsource its entire operation to Sectigo. Isn't that the same as us outsourcing eduroam to anyroam? A compromise to Sectigo's infrastructure (including its management app) poses similar risks to the community as anything else we cover. I am not sure I understand the rationale to exclude Cert Svc when we are including eduroam.

@nroy
Copy link
Contributor Author

nroy commented Aug 19, 2019

Need to consider removing/replacing "participants" in this - are eduroam connectors participants?

@nroy
Copy link
Contributor Author

nroy commented Aug 19, 2019

eduroam connectors sign a connector agreement, not the InCommon PA. SP-only connectors sign a different connector agreement directly with Anyroam.

@nroy
Copy link
Contributor Author

nroy commented Aug 19, 2019

Create new governing language that is contract-agnostic, send to KXM for approval/adoption.

@nroy nroy merged commit 37c8dfd into master Sep 5, 2019
Sign in to join this conversation on GitHub.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants