SALSA NetAuth Conference Call May 12, 2005

*Action Items*
New
[AI] {Eric and Kevin} will revise the diagram in the Futures (architecture) document and send the document to the WG as version 3.
[AI] {Group} will reread Kevin Miller’s notes from the Spring I2 Member Meeting and prepare to discuss them on the next call.

Carry Over
[AI] {Chris} will arrange vendor discussions for a subsequent call.
[AI] {Chris} will contact Bob Morgan to discuss whether there may be IETF activities that would be open to or in alignment with NetAuth efforts.
[AI] {Jeff} will send the presentation for EDUCAUSE Mid-Atlantic regional meeting in January and review it for possible case study possibility
[AI] {Chris} will post message to the NetAuth and FWNA lists soliciting volunteers to develop an outline of issues for NetAuth in a federated environment.
[AI] {Chris} will solicit from the WG contributions about NetAuth vendor solutions currently being used.
[AI] {Mike} will provide a brief summary of ESnet collaborative trust domain commonalities.
[AI] {Individuals} will send in case studies for potential use in the Strategies document.
[AI] {Group} will review slides posted for EDUCAUSE regional group meeting.
[AI] {Group} will review information to be used as the appendix for the Strategies document.
[AI] {Chris} will find editors to help with the appendix of the Strategies document.
[AI] {Chris and Mark} will develop the NetAuth approach to NAT devices as a discussion topic for submission to the Effective Practices WG.
[AI] {SteveO} will post I2 document standard links to the WG’s website.

*Participants*
Chris Misra, University of Massachusetts (chair)
Kevin Miller, Duke University
Mike Wiseman University of Toronto
Robert Brentrup, Dartmouth University
Eric Gauthier, Boston University
Robert Lowe, Lawrence University
Terrie Clark, Internet2 (scribe)
Renee Frost, Internet2
Steve Olshansky, Internet2

*Discussion*
Both the NetAuth/FWNA BoF and general sessions at the Spring I2 Member Meeting were well attended. These sessions gave the working group the opportunity to discuss the Strategies and Futures documents. The joint SALSA NetAuth/FWNA sessions highlighted discussions about Eduroam and related efforts, including in Australia.

The Futures document will undergo a few minor changes. It will be sent to the list, reviewed by the group and published as draft 3. Once published it will be vetted among other groups such as SALSA, ResNet and FWNA. The final state box will be changed to reflect the state of a device that has successfully connected to the network, but is being monitored for policy violations. The diagram will also reflect the enforcement states of remediation and isolation as transitional states, not end states.

Efforts to collaborate with the EDUCAUSE Effective Practices group for case study development have been suspended for now. The NetAuth group decided to develop effective practice-like use cases to support to Strategies document, and to develop an applicability section for the Futures document to reflect deployed NetAuth solutions discussed in the Futures document. The timing for development of the applicability section is yet to be determined.

The ResNet 2005 conference will be held in June, 2005 at Georgia Institution of Technology. For more information please see: http://resnet2005.gatech.edu/.

NERCOMP will hold a network security strategy workshop on May 17, 2005 at the University of Massachusetts in Amherst. For more information please see: http://www.nercomp.org/sigs/0405/051705NetworkSec/NetworkSched.html.

A Joint Techs workshop will be held in Vancouver, British Columbia from July 17 – 21, 2005. The efforts of the SALSA, including those of the NetAuth working group, will be of interest to attendees and will be presented at the workshop. For info on Joint Techs see http://jointtechs.es.net/Vancouver20051.htm.

The WG’s revised document roadmap has been published and is available on the WG’s website.

Many vendors have expressed interest in developing products enhancing network security. The two most notable are Cisco Network Admission Control (NAC) and Microsoft Network Access Protection (NAP). While these companies differ in network security approaches, the group agreed that it would be useful to solicit input and provide feedback to vendors wishing to serve the Research and Education community. The group has identified contacts within Cisco and Microsoft, and will soon decide how to proceed. It was also discussed that input from IETF on NetAuth and NetAuth related efforts would be useful.

The next call is Thursday, May 26, 2005 at 12:00 PM ET. An agenda with the call in number will be sent out to the WG via the list prior to the call.