20th FIM4R Workshop

Europe/London
Palmer Building, University of Reading

Palmer Building, University of Reading

Pepper Ln, Reading RG6 6EW, UK
David Groep (Nikhef National institute for subatomic physics (NL)), David Kelsey (Science and Technology Facilities Council STFC (GB)), Hannah Short (CERN), Maarten Kremers (SURF), Peter Gietz, Tom Barton
Description

20th FIM4R Workshop
Monday March 31st 2025, 13:00 – 17:00 BST in Reading, UK

This workshop will be cohosted with the TIIME unconference.

More information and registration for this workshop: https://tiime-unconference.eu/

The workshop will be held in the same location as TIIME unconference at Palmer Building of the University of Reading.

    • 12:00 13:00
      FIM4R Welcome Lunch 1h
    • 13:00 13:05
      Welcome and opening remarks 5m
      Speaker: Mr Maarten Kremers (SURF)
    • 13:05 13:10
      Welcome & Logistics from our local host 5m

      Includes info on the the no-host dinner :-)

      Speaker: Ian Collier
    • 13:10 14:10
      Review of FIM4Rv2 Paper – What’s Solved, What’s Still Open? 1h
      • Moderator-led discussion with 5 provocative statements/questions
      • Open floor for participant feedback and debate
      Speaker: Hannah Short (CERN)
      • Many of the requirements have been worked around or are no longer a priority e.g. non-web, a dev eduGAIN environment
      • Many are still valid, e.g. attribute release, logos
      • Many have not progressed at all e.g. service catalogue, deprovisioning, IdP deployment profile
      • Many have progressed in the way we hoped e.g. security incident reponse & blocking
    • 14:10 14:25
      FIM4L 15m
      Speaker: Peter Gietz
    • 14:25 14:35
      Group picture 10m

      All participants gather for a group photo

      Speaker: Mr Maarten Kremers (SURF)
    • 14:35 15:05
      Break 30m
    • 15:05 15:50
      Discussion on the Federation Proxy Report 45m
      Speaker: Mr Maarten Kremers (SURF)
      • There was a working group in Incommon on Federation Proxies and what their roles and responsibilities are
        • This was triggered by some concern that proxies required 2FA or requested attributes for services that didn't need it (because they operate others that did need it)
        • The payment model of some federations may also contribute to suspicion over SP proxies (i.e. if SPs have to pay or not)
      • For now it is paused
      • There was a feeling in the room that this was written from the perspective of federation operators trying to control Federation Proxies, rather than federations trying to connect users to services that happen to be behind gateways that provide single sign on to a set of related services 
      • More discussion is needed
    • 15:50 16:20
      Risk assesment 30m
      Speaker: David Crooks
      • General agreement that the stepped approach to the risk assessment is nice
      • Issue is that communities typically don't have enough people and just want to do their research
      • As a low investment approach we could ask framing questions in the AARC Compendium E.g.
        • "Before you start, it's important to fully describe the goals of your community and to identify its primary assets. This may both impact your AAI design choices and optionally complete a full risk assessment." 
        • "Who is authorized to make decisions (legal or otherwise) for your community? Ensure you know this before starting as it will be important for defining several highly recommended policies."
    • 16:15 16:35
      Support for small communities 20m
      Speakers: David Kelsey (STFC - Science & Technology Facilities Council (GB)), David Kelsey (Science and Technology Facilities Council STFC (GB))
      • One of the aims of AARC TREE is to provide guidance to communites of 10 - 100 people 
      • In general everything is getting more complex, but we aim to hide it from the communities
      • In the Compendium deliverable from AARC TREE we need to cater for them. We must assume that they will not have a dedicated person, even part time
      • There are already community-as-a-service providers (many!) 
        • We should collect use cases 
      • There also communities that may want to move from existing username/password infra to full federation
      • No consensus really on what a good approach is
    • 16:35 16:45
      Open Discussion / TBD 10m
      Speakers: David Groep (Nikhef National institute for subatomic physics (NL)), David Kelsey (Science and Technology Facilities Council STFC (GB)), Hannah Short (CERN), Mr Maarten Kremers (SURF)
    • 16:50 17:00
      Wrap-up 10m
      Speaker: Mr Maarten Kremers (SURF)