InCommon Assurance Community Wiki
Baseline Expectations for Trust in Federation
Assurance Community Call - Oct. 5, 2016
InCommon MFA Interoperability Profile Working Group
InCommon Silver with Active Directory Domain Services Cookbook for 1.2 Released
The final version of the InCommon Silver with Active Directory Domain Services Cookbook is available now! For an overview of the important bits, see the May 2014 webinar recording.
Reading Bronze: Understanding the InCommon Profile (recordings available)
InCommon sponsored a community reading of the Bronze InCommon Assurance Profile to aid in the understanding and intent of the requirements. There were four calls during Dec. 2013 and Jan. 2014. The calls have now concluded. Thanks to all who participated for the excellent comments and questions.
- Identity Assurance Assessment Framework; Version 1.2 Feb 2013 [PDF]
- Identity Assurance Profiles; Version 1.2 Feb 2013 [PDF]
- Alternative Means; Multi-factor Authentication for Silver certification
- DIFFS with 1.1: Framework and Profiles
- Deprecated Versions
Guidance for Supporting SHA-2 Signed Assertions
In August 2014, InCommon released Migrating to SHA-2 to help certified campuses support SHA-2 signed assertions.
In June 2014, InCommon Steering approved the (now expired) "Alternative Means for Bronze and Silver Requirement to Discontinue SHA-1 Encryption for SAML Assertions" to ease the transition for Identity Provider Operators that had been certified by the InCommon Assurance Program or were wishing to apply for certification by January 15, 2015.
Multi-Context Broker Model
The Multi-Context Broker (MCB) was released in February of 2014 to improve support for multi-factor authentication and assurance profiles in version 2.x of the Shibboleth IdP. MCB functionality is also in the more recent Shibboleth IdP version 3.x. See Multi-Context Broker for more more background and information on how to configure and deploy the MCB for either version of the Shibboleth IdP.
- Assurance Technical Implementation Considerations - Draft Guidance for IdPs and SPs.
- See Implementation Examples
- Bronze and Silver AuthnContext Schema
- Check out the AD and Silver Cookbook, Multi-factor Considerations, and case studies.
- Assurance Implementation Example from Virginia Tech
- Harvard University Executive Summary of achieving Bronze Certification, Bronze Self-Certification Document, and Enhancing the Harvard Authentication System to Support InCommon Bronze
- Add your Approach to Supporting the Federal Privacy Requirements
- more community contributions
Webinars and Presentations
- Baseline Expectations – Last Call for Comments, Aug. 3, 2016 (link to slides and recording)
- Baseline Expectations for Trust in Federation, July 6, 2016 (link to slides and recording)
- Sirtfi for Security Incidents in a Federated Context, May 4, 2016 (link to slides and recording)
- Multifactor Authentication Interop Profile Working Group Update, April, 6, 2016 (link to slides and recording)
Developments in Assurance: Insights from Across the Pond, Feb. 3, 2016 (link to slides and recording)
- Assurance Survey Results and Baseline Standards to replace the POP, at Nov. 2015 Assurance call (link to slides and recording)
- Duo with Shibboleth v3, from U. Chicago and Unicon, at Sept 2015 Assurance call (link to slides and recording)
- Flexible Vetting: using a point system to verify identity, at May 2015 Assurance call. (link to slides and recording)
- Password Reset practices, at April 2015 Assurance call. (link to slides and recording)
- InCommon Bronze Approaches from GW and Harvard, recorded March 4, 2015. See recorded Webinar. See slides (PDF).
- InCommon Bronze and Security, IAM Online with two Bronze case studies (Todd Haddaway, UMBC and Sharon Welna, University of Nebraska Medical Center), (webinar recorded October 15, 2014 and slide deck)
- Successful Security Practices: Counting Failed Login Attempts, PDF slide Deck, Webinar recorded Sept. 3, 2014
- Better Practices Build Better Systems: Identity Assurance, recorded presentation by Ann West, Internet2, and Ron Thielen, U. Chicago, at EDUCAUSE Security Professionals Conference, May 2014
- Open for Business: InCommon Identity Assurance Program (PDF Silde Deck. Webinar recorded February 29, 2012)
- Grab the Bronze and Silver Ring: Identity Assurance Progress (PDF Slide Deck. Webinar recorded June 15, 2011)
InCommon Assurance News
Confluence Syndication Feed
|Baseline Expectations – Last Call for Comments is topic of Aug. 3 Assurance Call|