Attendees: Romain, Maarten, Brian, DavidC, Hannah, AndreaC
Notes:
- Maybe organise face-to-face call Friday week of 22nd
- We should consider data that is taken from users and used to generate DNs from RCAuth
- RCAuth currently requires consent rather than relying on legitimate interest. Could change in future.
- This will certainly not be a final privacy statement
- RCAuth privacy statement https://rcauth.eu/privacy
- Do we want to keep data for ever, based on legitimate interest of academic traceability? Send to Management Board for input. VOMS is not necessarily the source of truth for who is in an experiment.
- We need to support the right to be forgotten?
- HR keeps VO information, that should be the source of truth
- Is LoA personal information? General consensus is No
- Checkin deployment
- Accessed to CERN OpenStack and installed VM
- IAM
- Deployment help
- What do we want from the pilots?
- Deployed at CERN
- Privacy policies approved by HR and HR DB view integrated in pilot deployment
- Ask us when you have Qs :)
- Nicolas has added content on LoA. Difficulty is that multi factor authentication is not included in RAF.
- Discussion on how we include it in tokens
- Need additional time to consider whether this should be a base claim or only in the authorisation token
- BIG TOPIC, we need to clarify confusion between the different tokens
Actions:
- Hannah -ping Mischa/Brian/Paul/Nicolas to clarify Qs on JWT Catalogue
-
Hannah - ask Dave and Mischa how to handle this potential conflict between RCAuth providing certificate DNs vs RCAuth taking information from IdPs to generate DNs
-
Romain - in Tuesday meeting ask management board on importance of keeping user records in WLCG AAI indefinitely (may also be possible to keep a subset of data that won't change?)
-
Hannah - change "Experiment computing role of the person (e.g. "production manager")" to roles and groups
-
Hannah - make changes to privacy statements and send to HR
-
Hannah - make summary slides for Tuesday
-
Pilots - deploy within CERN
-
Hannah - send around a doodle for the week of the 22nd, likely Friday afternoon