October IM Forum meeting

Europe/London
    • 15:00 15:05
      Introduction 5m
    • 15:05 15:20
      UKRI IAM Project update 15m

      UKRI IAM Project
      Tim Kells, John Patrick

      Tim:

      • Nearing first deliverable for core funtionality, aiming for end of October - UKRI Greenfield
      • Low risk for users, with main change being taking the feed form UKRI to proofID
      • Main change will be joiner/leaver can be managed within the Greenfield service
      • Objective is one ID for SSO across STFC and all strategic partners
      • Timeline - go through next 6 weeks to work out implementation plan
        • Through to mid December
        • Understand routes and change plan
        • Implementation from January (Design, built test) through to ~ Sept 2023
        • Implement with considerations of Low Risks to Maximise Benefit
      • Slide to provide an overview due to be distributed end of next week

      John:

      • Collaboration is key - take the Impact and use case set and use these to build the test case set, so that those produced do represent the full case
      • Architect has full view, and keen to be engaged with the STFC side
      • Please raise questions as you have them

      Questions?

      • Paul Barrett - four data feeds? Thought there would be more
        • DLS HR (should this have been ISIS?), Oracle, UAS, Direct Web Interface
        • Current process for RFI, for example, is they send users and these are directly entered
        • One aspect of the minimal viable product would be an API for sending information in
        • DLS HR is to prevent any changes with that causing issues.
        • UAS covers extensions and expiry dates
        • From Tim, pasted:
          Establish trusted sources of identity data feed daily import
          into Identity Vault from
          o Oracle HR (file based)
          o Diamond Light Source – User Administration System
          (DLS UAS) (API based updates)
          o ISIS HR (API based updates
      • Users/Individuals, Identities and Roles giving different access levels
        • Will need mechanisms for a user to change an affiliation, and how data transfers with them
        • Need to understand models, including data ownership and how things may move and how this will fit within implementations
        • Some people may move around, and grants follow with them - and understanding how that complexity fits within use and test cases
        • Typically it has gone to a data steward or owner to establish ownership - this will require consideration to understand fully, and so as to consider business concerns
        • A person is an individual, and access should be layered on the person. The Identity Management system should support any data management flows, rather than having data management layered in this process
        • Information about a user that changes should be propagated as it changes
        • David - what is the primary key for a person, and then what are attributes attached
        • Need to understand the process of how a FedID and attributes may change when a user moves. Risks need to be considered, and future implementations will likely consider roles assigned to a user as opposed to their ID
        • Access needs to consider a number of different axis, not just an individual
        • Purpose should be to consider route to a newer, fine-grained, system rather than recreating "what-we-do-now"
        • Colin - need to get to a point where we can all do the same things.
        • John - large blob of use cases, which can grow and become more accurate. Matrix for understanding which are relevant to which group. Excel doc for mapping this.
    • 15:20 15:35
      Technical meeting topics 15m
      • What would we like in a technical meeting?

      What do we need from a Technical Meeting?

      • This would include the UKRI Architects - internal to UKRI, with the people developing. Considering the evolution migration
      • Already had a big discussion on attributes
      • Please get in contact over the next week if you have ideas after today
      • API Access for developers
      • High level design will be available January/February time for questions pertaining to that
        • Will need offline review, but understsading from a technical level that software using supports OAUTH2 and OpenID Connect - understand that it locks into what we're doing now
        • Considering the technical stakeholder perspective as well
        • Understanding the foundations, before considering high level
        • Tim - to make best use of time, would be good to collate questions and formulate responses
          Please send questions to thomas.dack@stfc.ac.uk
      • Jens - when sharing workflows to be supported, perhaps need to demo them or produce a write-up
      • Internal identities can be used to identify us internationally, through things such as eduGAIN
        • John Patrick will follow up with Jens to understand this, CC Tom
      • Tim - make sure Impact assessment with use cases represents starting positions - if people could review and feedback, changes can be made.
      • Start with a demonstration of the software with inital sent in questions, and then can iterate onwards.
         
    • 15:35 15:50
      Federated identity topics 15m
      • what would be useful to focus on
    • 15:50 16:00
      AOB and next meeting 10m