This is a static archive of the previous Open Grid Forum Redmine content management system saved from host redmine.ogf.org file /projects/voms-proc-wg/wiki/Wiki at Thu, 03 Nov 2022 23:16:02 GMT Wiki - VOMS-PROC WG - Open Grid Forum

Mission

There are currently multiple implementations validating VOMS credentials, and all of these have had to make uncoordinated choices in how to interpret bags of attributes. For security and integrity reasons alone it is needed that the interpretation of attributes is consistent. The scope is deliberately limited to writing two specific documents in a narrow subject space, for which insufficient guidance exists but where active work is ongoing.

Documents

Published GFDs

none yet

Documents currently under consideration by the CAOPS-WG

  • determining the effective attribute set for collated VOMS attributes as presented in a hierarchical chain of identity credentials
  • order in which attributes are to be interpreted
  • how to determine the set of valid attributes in case one out of a bag of VOMS ACs at the same level has expired
  • Understanding parsing rules for collated VOMS SAML space (not available yet)
  • how validation parsing rules should be applied for collated VOMS attributes when used in a SAML environment
  • how to different forms of delegation in SAML (e.g. who confirms the subject) impact the way attributes are to be interpreted
This is a static archive of the previous Open Grid Forum Redmine content management system saved from host redmine.ogf.org file /projects/voms-proc-wg/wiki/Wiki at Thu, 03 Nov 2022 23:16:02 GMT