Attendees
Susan Brooker-Gross
Mary Dunker
Frank Galligan
Greg Kroll
Ismael Alaoui
Karen Herrington
Agenda
- Responses to TechSupport e-mail regarding focus group meetings.
- Review InCommon Silver profile requirements. See Standards for Identity Assurance
- Are we done discussing Establishing existing relationships?
- See 20100617 meeting notes.
- Are we done discussing Concept for exception retrieval of escrowed keys?
- See 20100617 meeting notes.
- Background Questions 6, 12, 17, 20, 24 are pending or unanswered.
Meeting Notes
- Responses to TechSupport e-mail regarding focus group meetings.
- See the list of names of those that responded on the page linked above.
- We will call this first meeting an initial or introductory meeting and invite everyone that responded. An analysis of this initial meeting will determine whether smaller focus group meetings are warranted.
- Action item: Greg will schedule this meeting ASAP.
- One question to ask participants is: Who needs external trust, i.e., root key signing?
- Review InCommon Silver profile requirements.
- What level of identity proofing do we need? Does it need to be the same for Faculty/Staff versus students?
- As long as we are going to have to define and follow a process we might as well conform to a standard.
- Identity proofing requirements using an "existing relationship" via the Hokie Passport may be a possibility.
- Action item: Karen will talk to the Hokie Passport office and report back on the process they use to issue a Hokie Passport.
- Communications regarding our process (i.e., our sales pitch) needs to be well written and clear so the inconvenience of a face-to-face identity proofing is tolerable.
- InCommon silver requirements:
- identity proofing
- logging of process and credentials used
- documentation on our process
- Internal Audit must sign-off on our processes and send a report to InCommon in order to receive/be approved for silver status.
- We plan to strive for InCommon silver but if that presents a show stopper then it is not the end of the world, i.e., would be nice but not required.
- "Out of band" = No regular pre-defined process to get it done. A special case.