Conveners
Incident Response in eduGAIN: BoF
- Davide Vaghetti (GARR)
- Tobias Dussa (DFN-CERT)
- Daniel Kouřil (CESNET)
Description
In this Birds of a Feather session, we invite participants interested in the security aspects of federated authentication and authorization. We will open the session with a brief introduction to the eduGAIN CSIRT and an overview of its role and capabilities.
To stimulate discussion, we will present several real-world incidents that the team has handled in recent years, along with the lessons we learnt. These cases span a range of challenges, including large‑scale misuse of compromised identities, problematic behavior of services weakening the overall security, and problems caused by insecure configurations. These cases also trigger a review of the eduGAIN security baseline, which represents the minimum capabilities that the relevant security teams, consisting of eduGAIN CSIRT and the federations security contacts, needs to meet.
The goal of the session is to exchange experiences, compare different approaches to incident handling in distributed environments, and identify common challenges across the federated ecosystem. We aim to discuss expectations and requirements for incident response in eduGAIN from the perspectives of all involved actors, i.e., service operators, identity providers, and individual federations.
All information presented or discussed in this session is strictly for the attending participants and must not be disclosed further (TLP:AMBER+STRICT).