Final Draft - OIX AXWG Trust Framework Specification 1.0 7-2-13;

8 views
Skip to first unread message

David Coxe

unread,
Jul 2, 2013, 11:53:27 AM7/2/13
to oix-ax-wor...@googlegroups.com
To  OIX AXWG members:

Congratulations!  Attached is the final draft of the OIX AXWG Trust Framework Specification version 1.0.  After considerable effort, edits, redrafts and good hard work, we are almost finished with Version 1.0 

Please take the next couple of days to provide feedback on this final draft.  Send all comments to DC...@iddataweb.com.  

We will be submitting this document, along with any edits or suggestions for improvement, to the OIX Board for processing this Friday at around noon EST.  

We believe that this has turned into a significant and meaningful piece of work, and that this will be well received by the community.  We will be providing a final briefing about this work at the Ping Cloud Identity Summit next Monday.

Thanks again for all of your contributions, participation and hard work.

Regards,


Dave Coxe  &  Pete Graham

Co-Chairs
  
OIX AXN Trust Framework Specification 1.0 - 7-2-2013.docx

Dale Rickards

unread,
Jul 2, 2013, 1:58:59 PM7/2/13
to oix-ax-wor...@googlegroups.com
Dave and team,

Here are my comments/changes.   I have removed a section from the privacy area (AXN Operational Privacy Principles – An Example) which should be placed somewhere else as it was not an outcome of the privacy group.   It would probably be better in the technical implementation.

Also my personal opinion is that the technical implementation guide should be a separate document not embedded into this one.  

Take Care,


Dale Rickards, CISSP, CISM

Regulatory Affairs, Audit and Compliance, Universal Identity Services | Verizon Enterprise Solutions

Tel: +1 416-626-2435 | Mob: +1 416-729-2116

email: dale.r...@verizon.com

mobile email: dale.r...@rogers.com

---

Visit us at www.VerizonEnterprise.com



--
You received this message because you are subscribed to the Google Groups "OIX AX Working Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to oix-ax-working-g...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.
 
 
OIX AXN Trust Framework Specification 1.0 - 7-2-2013 (dr comments).docx

Furr, Richard

unread,
Jul 2, 2013, 2:08:45 PM7/2/13
to oix-ax-wor...@googlegroups.com

Dale,

 

In going thru this (still on-going) I note they only talk about issuing OpenID credentials - The user is issued an OpenID[FR1]  credential by an IDP, such as a government agency, bank, e-mail or social network provider with whom they have an established online relationship

 

They didn’t number pages or paragraphs so this is in the AX Business Frameworks section

 

Rich Furr

Identity, Regulatory Affairs, Audit, and Compliance Consultant

Verizon Enterprise Solutions

704-575-1680

4300 Sharon Rd, #343

Charlotte,  NC 28211


 [FR1]Only OpenID?  What about credentials issued by other certified IdPs?

Andrew Nash

unread,
Jul 2, 2013, 2:08:54 PM7/2/13
to oix-ax-wor...@googlegroups.com
I agree completely with Dale on the technical implementation guide, both from an audience perspective and saving the trees

Although maybe acceptable in government contexts, 127 pages will lose internet focused readers

--Andrew

Scott Rice

unread,
Jul 2, 2013, 2:10:45 PM7/2/13
to oix-ax-wor...@googlegroups.com

I had understood this was a request by OIX to have a single document.   But as the person who tried to jam the TIG into the main document I agree a separate document would be better if OIX is ok with that.

 

Scott

 

 

From: oix-ax-wor...@googlegroups.com [mailto:oix-ax-wor...@googlegroups.com] On Behalf Of Andrew Nash


Sent: Tuesday, July 02, 2013 11:09 AM
To: oix-ax-wor...@googlegroups.com

Pamela Dingle

unread,
Jul 2, 2013, 2:30:36 PM7/2/13
to oix-ax-wor...@googlegroups.com
+1 for a separate document for the technical guide.  Only a small portion of the audience of the main document will need to see the technical implementer's guide, and right now the size of the combined document is intimidating and may turn people off from even attempting to start to read the less technical parts.
Pamela Dingle  |  Sr. Technical Architect
PingIdentity  |   www.pingidentity.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
O: 303-999-5890   M: 303-999-5890
Email: pdi...@pingidentity.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Connect with Ping
Twitter: @pingidentity
LinkedIn Group: Ping's Identity Cloud    
Facebook.com/pingidentitypage
Connect with me
Twitter: @pamelarosiedee

Dave Coxe ID

unread,
Jul 2, 2013, 3:03:41 PM7/2/13
to oix-ax-wor...@googlegroups.com

Dale,

We had agreed to leave the section of Operational Privacy Principles in that section per your last set of edits.  I think it provides context and belongs in this section as an example of what could be available to support the privacy principles as outlined.  Pete, Don and I discussed this a couple of weeks ago, along with the topic of including the TIG.  We would like to leave these sections in the doc, even though the TIG adds to the length.  The TIG can be extracted by technical folks who want to continue to evolve the guide.

Dave

David Coxe, CEO

ID/DataWeb, Inc.

DC...@IDDataWeb.com

571-332-2740 cell

571-723-4310 office

 

From: oix-ax-wor...@googlegroups.com [mailto:oix-ax-wor...@googlegroups.com] On Behalf Of Dale Rickards


Sent: Tuesday, July 02, 2013 1:59 PM
To: oix-ax-wor...@googlegroups.com

Graham, Peter M

unread,
Jul 2, 2013, 3:30:31 PM7/2/13
to oix-ax-wor...@googlegroups.com

This is consistent with our discussions to date and at this point we are in danger of “loving the document to death”.  I could see the TIG as a separate document but as we discussed this previously and made the decision to include it we should allow it to stand, ditto for the privacy section of the doc.

Peter Mark Graham

Senior Identity Strategist | Verizon Enterprise Solutions

Tel: 520-762-9518 | Mob: 520-576-7083

 

MC15244-a-DBIR_Email-Signature
cid:image002.jpg@01CE0456.D8B0FF60  cid:image003.jpg@01CE0456.D8B0FF60  cid:image004.jpg@01CE0456.D8B0FF60  cid:image005.jpg@01CE0456.D8B0FF60

Dale Rickards

unread,
Jul 2, 2013, 3:42:20 PM7/2/13
to oix-ax-wor...@googlegroups.com
Okay

As discussed the privacy table in section "Appendix B" will stay but I still think that "AXN Operational Privacy Principles – An Example" should be removed Privacy policy framework section as it was not developed by the PWG.   

Take Care,


Dale Rickards, CISSP, CISM

Regulatory Affairs, Audit and Compliance, Universal Identity Services | Verizon Enterprise Solutions

Tel: +1 416-626-2435 | Mob: +1 416-729-2116

email: dale.r...@verizon.com

mobile email: dale.r...@rogers.com

---

Visit us at www.VerizonEnterprise.com


Andrew Nash

unread,
Jul 2, 2013, 3:56:18 PM7/2/13
to oix-ax-wor...@googlegroups.com

Hey Pete
.sorry I missed that conversation - I would have pushed on a few points in particular - not meaning to second guess you guys now

I would observe however that if it is actually to be used then the technical guide will iterate a lot based on implementors experience

--Andrew

image001.gif
image002.jpg
image004.jpg
image003.jpg
image005.jpg
Reply all
Reply to author
Forward
0 new messages