(Historical page content from old UK Federation website. Please see also the Federation Documents page for the current versions...)
Consultation Documentation
The deadline for submitting feedback closed on 26 October 2006.
UKERNA has been asked by the Joint Information Systems Committee (JISC) and Becta to provide and operate a UK Access Management Federation for FE, HE and Schools. Federation services will be launched on 30th November 2006 . This consultation process sets out to elicit comment and feedback, and to promote discussion in relation to the framework and specification of the federation. This consultation process runs from the 6th to the 26th of October 2006.
Five draft documents as described below are presented as the basis of federation services. The first document, Rules of Membership for the federation sets out the contractual framework of trust that binds together members of the federation. Members are required to provide accurate data, observe best practice in relation to the exchange and processing of data, and abide by the technical specification for the service. There are two points to draw your attention to in this document:
- The nature of federated access management devolves all responsibility for authentication and authorisation to Identity Providers within the federation. This means that individual Identity Providers can bring the whole federation into disrepute if their internal policies or procedures are inadequate. In order to help proactively maintain standards of operation and give confidence in the operation of the federation to service providers, a programme of auditing will be established.
- Although the right has been reserved to charge for federation services in future, there are no current plans to do this and charging would only be implemented following consultation and a period of notice.
The second document in the series provides recommendations for use of personal data. The federation is designed to protect the privacy of the user while giving service providers and member organisations sufficient assurance that requirements such as licenses and acceptable use policies can be enforced. The Shibboleth architecture, chosen for the federation, is designed to protect user privacy.
The third document, Technical Recommendations for Participants, specifies the federation technical architecture in detail, including the rationale behind some of the technical choices made.
The fourth document in this series outlines the technical specifications for the federation. This sets out the trust fabric that is used within the federation based on PKI technology, using digital certificates.
The final document, Federation Operator Procedures, sets out details on enrolment, certificate authority qualification and support services being provided by the federation operator.
It is planned to release further documents to help sites implement their federation systems. These will be published on the federation web site in due course. A draft of the first of these on identity providers is included as part of this consultation exercise.
To provide feedback, please send comments to Mark Tysom at UKERNA (m.tysom@ukerna.ac.uk) by noon on 26th October 2006.
Consultation documents
