Dear all,
I hope this email finds you all well.
I would like to share some updates on the TIIME event. Several of you were there, so you can correct/add anything as needed. There are notes for the unconference sessions here: https://surfdrive.surf.nl/s/HccGjF8BnWMfMc7
There were a lot of discussions on wallets (not a surprise), OIDC fed, zero knowledge, etc. A (possibly) new topic goes under the name AARC for education see below.
Some take aways:
(i) as you know by the end of 2026, all European Union Member States must provide a certified EU Digital Identity (EUDI) Wallet to citizens, enabling secure storage of digital documents and ID. However the roll out of wallets in the education sector will take more than 1 year.
The nordics are working together on a wallet pilot.
(ii) When talking about wallets we also talk about OIDC Fed, as the trusted and scalable foundation that allows educational institutions to issue and verify digital credentials (like diplomas and student IDs) within wallets.
OIDC Fed 1.0 specs are out! A journey that lasted 10y! There is also a nice post on LinkedI: https://self-issued.info/?p=2813
(iii) As you know AARC community was established following the first cycles of EC funding in 2019; one of the main results was the AARC Blueprint architecture that defines patterns for research collaboration AAIs. To date the AARC BPA has become the community best practice for those that want to deploy an interoperable AAI for research collaboration globally (US, Australia, and EU research collaborations AAI follow the the AARC BPA). The BPA under AARC TREE project (which ends in a few days) has been evolved to support user centric technologies, such as wallets.
Comments on the AARC BPA 2025 are welcome - I’ll share the link in a few days.
(iv) The university alliances are gaining momentum (in addition to Erasmus+) and they are also getting some support from the EC. One of the things that are needed to support the alliances is a way to authN users and identify that they belong to an alliance. This is conceptually similar to the use-case of a researcher that wishes to access resources based on their role in a specific reattach collaboration, hence the idea of expanding AARC to support education as well.
One of the first things to do, is to create an inclusive group that brings together the NRENs as well as the alliances and other existing players and discuss how the NRENs can provide the necessary identity infrastructure to support the alliances.
There was discussion to organise a nordic meeting with the nordic alliances - what do you think? Does it make sense?
I think it would be good to have a call in the before Easter and sync, I’ll send a doodle to find a slot.
Best,
Licia
------
Licia Florio - Senior Strategy and Policy Officer, NORDUnet
Phone: +31653928443
Data protection policy: https://nordu.net/privacy-policy/
Legal notice: https://nordu.net/legal-notice/
Dear all,
This is an high level agenda for the call today.
The call will take place at 2 pm. Today
1. GN project updates:
(i) current project Licia
(ii) and preparation for the new one (GN5-3) Jan
2. Updates on Nordic activities
(i) Nordic wallet pilot
(ii) anything else?
3. International activities
4. Anything else you would like to report/discuss?
Best,
Licia
------
Licia Florio - Senior Strategy and Policy Officer, NORDUnet
Phone: +31653928443
Data protection policy: https://nordu.net/privacy-policy/
Legal notice: https://nordu.net/legal-notice/
Dear all,
We will have our next call on Monday 19th at 2 PM CET.
Thanks to you all for filling in the poll.
The invite is on its way. I’ll share an agenda on Friday. If anybody would want to share updates please let me know!
Best,
Licia
------
Licia Florio - Senior Strategy and Policy Officer, NORDUnet
Phone: +31653928443
Data protection policy: https://nordu.net/privacy-policy/
Legal notice: https://nordu.net/legal-notice/
Dear all,
I was hoping to find a time to send a poll to find a date for a call in January.
Sadly, there ware a few things that came in between and I did not manage. I think at this point it’s easier if I send something in Jan.
I take this opportunity to wish you all a relaxing Christmas and an healthy new year!!
Best,
Licia
------
Licia Florio - Senior Strategy and Policy Officer, NORDUnet
Phone: +31653928443
Data protection policy: https://nordu.net/privacy-policy/
Legal notice: https://nordu.net/legal-notice/
Hi everyone,
I’m looking for input on how we can better handle the following situation:
IGTF Personal Certificates are used for user authentication in collaborations between CERN and Norwegian universities. To enable certificate issuance, Identity Providers in eduGAIN must release certain attributes—most importantly, eduPersonPrincipalName, which GEANT requires for IGTF Personal Certificates [1].
However, HARICA does not currently require this attribute, and Feide cannot release attributes that are not explicitly required. As a result, Sikt is unable to provide IGTF Personal Certificates to our customers.
The latest update we received from HARICA (on September 19) was:
"This change is already in our plans, but we are also looking to introduce the 'subject-ID' attribute, which appears to be the optimal one for identity mapping. We are discussing internally how to prioritize this over other requested features."
For now, we are implementing a workaround for Norwegian universities, but it’s disappointing that a certificate provider operating under a GEANT contract does not already support this.
How can we apply more pressure on HARICA to prioritize this change?
[1] https://wiki.geant.org/pages/viewpage.action?spaceKey=TCSNT&title=TCS+2025+…
Thanks for any ideas—and wishing you all a great weekend ahead!
Hildegunn