Minutes

Attending:
Walter Hoehn, Michael Gettes, Tom Barton, Steve Carmody, Keith Hazelton, Scott Cantor, Janemarie Duh, Mark Scheible, Kim Milford, Jim Jokl, Albert Wu, Tom Mitchell

With:
Mike Zawacki, Nick Roy, Paul Caskey, Ann West, Steve Zoppi, Kevin Morooney, IJ Kim, Mike LaHaye, David Walker

Action Items

(AI) Nick Roy will write up strawman incident response proposal for handling vulnerable deployments listed in metadata, enumerating types of vulnerability classifications and the incident procedures for each, share with TAC for review.  Note that this strawman should include an education component and also any supporting material


(AI) A communications plan is needed for the incident response plan, and, more generally, to promote standards. This should include an email campaign to explain in stark technical terms why the v3 upgrade needs to happen and encourage community transparency.

(AI) TAC formed a working group to review the TAC work list, fill in the details, adjust things for clarity, and assign rank/priorities. Volunteers are Mark Scheible, Steve Carmody, and Jim Jokl. The working group will complete its work in two weeks (June 3)

(AI) Steve Zoppi will create accounts (at bugs.internet2.edu) for members of TAC and include them in the relevant project(s).

Shib v2 to v3 Discussion

There was discussion among a smaller group, then the full TAC, concerning ramifications of IdPs not upgrading to Shib v3 and InCommon’s role in encouraging upgrades. For example, should outdated IdP software cause any security or other types of threats, what is the federation’s plan?

It appears that the FOPP allows InCommon to develop an incident response policy that includes circumstances under which federating software may have its entity descriptor(s) removed from federation metadata (see the PA and "Software Guidelines" in the wiki). However there is a question whether the FOPP does allow this, or if it would need to change to accommodate this.

The TAC has asked that InCommon staff develop an incident response process to address the removal of software entity descriptors and/or compromised key material from the InCommon metadata when their continued presence presents a substantial risk to other Participants. (AI) Nick Roy will write up strawman incident response proposal for handling this kind of situation, enumerating types of vulnerability classifications and the incident procedures for each, and share with TAC for review. Note that this strawman should include an education component and also any supporting material
.

(AI) A communications plan is needed for this and, more generally, to promote standards. This should include an email campaign to explain in stark technical terms why the v3 upgrade needs to happen and encourage community transparency.

Other thoughts from the IdPv2 to IdPv3 discussion:

Joint Steering, TCIC Meeting

The day prior to the TAC meeting included a joint meeting of the InCommon Steering Committee and the TIER Community Investor Committee (TCIC).

“Deep Dive” - Kevin provided an overview of a recently held “deep dive,” which involved four community members meeting with the trust/identity leadership. The meeting was intended to validate processes and resource needs and gaps. That review produced good momentum and next steps.

One key outcome is developing and communicating a holistic view of of everything T&I has on its plate - from campuses, to national, and international connections (including talking honestly about positives and challenge.

There also seems to be increased clarity on the importance of Shib and the connection now among TIER, InCommon and Shib. There may still be confusion about how the Shib Consortium works and how funding for Shib works.

Kevin and Klara Jelinkova will put together the next intensive review, solution paths, funding opportunities, resource priorities, and other follow up. That will happen prior to the beginning of July. A smaller group will then develop those findings into a plan. Kevin will also follow up with “deep dive” attendees to gauge their thoughts/activities between then and now.

Comments include:

TAC Work Items

There was a discussion about evaluating and prioritizing the 2016 TAC work items, in relationship to the other processes, including TIER and InCommon overall priorities and how the landscape has changed. It will also be helpful to understand resource availability when setting priorities. Note there are two lists referred to below. One is the InCommon Priority Worksheet, developed by InCommon staff. The other is the draft TAC work list.

Some comments:

Given the lack of time to review each work item in detail and assign priorities, TAC formed a working group to review the TAC work list, fill in the details, adjust things for clarity, and assign rank/priorities. Volunteers are Mark Scheible, Steve Carmody, and Jim Jokl. The working group will complete its work in two weeks (June 3).

There was a discussion about the requirements for tools to manage this type of work.

  1. Need to differentiate requirements vs. features and include that determination in decision making process

  2. Need a rigorous prioritization process

  3. Need to communicate the work plan, including:

    1. Deadlines

    2. Whether efforts are opportunistic or strategic

    3. General work flow

Job 1: the process:

  1. Someone gets an idea

  2. We track the idea

  3. Rate the idea

  4. Prioritize compared against all the other ideas
  5. Consider sequencing of the ideas in the collective

  6. Once you have the natural order of things determine the size

  7. Bring to bear the resources to be applied (if available)
  8. Solicit for additional/external resources if needed


Job II: The Response (solution/tool): https://bugs.internet2.edu (Kanban)

The point of this approach is to tell a story of things we need to accomplish, to aggregate tasks into a narrative form, make that process visible to outside stakeholders, and show progress.

(AI) Steve Zoppi will create accounts (at bugs.internet2.edu) for members of TAC and include them in the relevant projects.

Next meeting

Thursday, May 26, 1 pm ET