SALSA-NetAuth - FWNA conference call March 24, 2005

*Attendees*
Kevin Miller, Duke U. (co-chair)
Philippe, U. Tennessee (co-chair)
Dennis Ward, U. Michigan
Michael Griego, U. Texas - Dallas
Mark Linton, Penn State
Rich Crop, Penn State
Renee Frost, Internet2
Lisa Hogeboom, Internet2
Steve Olshansky, Internet2
Jessica Bibbee, Internet2 (scribe)

New *Action Items*
[AI] {Kevin} will post a summary of possible use cases to the {SALSA-FWNA} list.

[AI] {Dennis} will draft a use case highlighting an academic guest from a member institution.

[AI] {Philippe} will draft a use case focusing on shared facilities between two institutions.

Carry-over *Action Items*
[AI] {Chris}, {Philippe}, and {Kevin} will coordinate offline efforts to reformulate the project plan moving forward, and will bring their thoughts back to the next FWNA call.

[AI] {Chris} will discuss with Bluesocket the integration capabilities of web authentication gateways with 802.1x authentication.

*Discussion*
The Group will focus their immediate efforts on assembling practical use cases that exemplify the nature of FWNA work. {Kevin} shared three use cases prepared by the EduRoam folks, which he had sent out to the {SALSA - FWNA} mailing list (24-Mar-05). These use cases detailed local, national, and international AuthN cases. While these cases addressed the geographical context of federated wireless issues, they did not capture institutional aspects. The FWNA WG needs to consider use cases that incorporate aspects of AuthN, AuthZ, policy, and service provisioning. Covering these specifics will set in motion the next steps that FWNA needs to accomplish in this process. We need to formalize the broad architecture and rational for the work. We might find that it would benefit our work to branch out another WG that could build additional systems for this work to move forward.

Other considerations need to involve who the end user is - whether it is a guest from a member institution (academic scholars, etc.) or it might include a sensor node deployed at a remote location for gathering data that will be transmitted back to the university. There might be several kinds of actors - not so much people - but also devices that need to be accounted for. The situation may be semi-permanent (installed equipment), or it may require single-use attention (conference guest, visitor, etc.) What kinds of scenarios arise with groups like K-12, or guests from a national lab (.gov federation)?

There should also be a use case that accounts for horizontal relationships within institutions. For example, work between departments on the same campus. People from one department may need to access departmental resources elsewhere. This brings up AuthN issues that will be met within a single institution.

The idea of shared facilities presents additional challenges - two member institutions using a single facility where it is not desirable to have 2 networks, for the sake of interference. How can we design the infrastructure so that we use different spaces correctly?

Meeting the community's needs for wireless access is another interesting area. People may seek access for the sake of their cellular phone, not simply to join your WIFI. How do campuses deploy this?

When putting these use cases together, the Group also needs to ensure that all details are accounted for, such that someone unfamiliar with FWNA will understand. For example, it might not be obvious that a participant has a home location, as well as their remote location - and both of these locations must be a participant in the model. If the use cases are built from the bottom up, it would be ensure that issues are addressed at the user level, and would ultimately deal with the concerns that further development and policy. However, it may be better to hold off on these latter components until we are sure the technology is much more stable - the public will be more impressed with available and deliverable technology.

[AI] {Dennis} will draft a use case highlighting an academic guest from a member institution. [AI] {Philippe} will draft a use case focusing on shared facilities between two institutions. [AI] {Kevin} will post a summary of possible use cases to the {SALSA-FWNA} list. From this summary, the Group will condense the different scenarios possible, in order not to have overlap or gaps. {Anyone} who is interested in taking lead on developing and writing up one of these use cases should contact {Kevin}.

The Group briefly discussed the topic of single sign-on privileges that is facing every campus. Who is allowed access to where? In the case of access to libraries, is the system open or closed to the public? Which factors determine who can join the network? The easy solution simply asks the user to sign-on multiple times, though this is not desirable in the long run. This brings us to implementing caching, session tracking, etc. How relevant of an issue will this prove to be for FWNA?

The next SALSA-NetAuth - FWNA call will be on Thursday, April 7, 2005 at 11am ET.