<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">Hi all,</div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">As part of my work with the Canadian Access Federation that CANARIE operates, I have implemented native support for F-TICKS[1] logging for Shibboleth V3 and have opened a feature enhancement ticket to suggest it be part of the Shibboleth distribution so others may be able to benefit from it's inclusion in the distro:</div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><a href="https://issues.shibboleth.net/jira/browse/IDP-840" class="">https://issues.shibboleth.net/jira/browse/IDP-840</a></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">One aspect that is hard to describe for the ticket (beyond my observations) is interest in such a feature being in the core.  </div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">As it is not a code update, but a configuration, it's not a big change, but is a change nonetheless.  I have already described a few aspects of the use of F-TICKS in the ticket but if I have missed your federation or site use of the extra logging format, please voice your support either in the ticket or on the users list.  By doing so I hope the request will have more information than just my observations on what it would mean to include it in the Shibboleth distro in a useful and sustainable fashion that would benefit the most users of the IdP software.</div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><div class=""><br class=""></div><div class="">Many thanks to those who helped out on this and for the Shibboleth team to have a framework in v3 that made this much easier  to accomplish all without coding.   </div><div class=""><br class=""></div><div class="">For those who need a bit more background on F-TICKS keep scrolling to see more detail..</div></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">Thanks!</div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">Chris</div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><div class=""><div class="">___________________________________________________________________________________________</div><div class="">Chris Phillips </div><div class="">Technical Architect, Canadian Access Federation | CANARIE| <a href="mailto:chris.phillips@canarie.ca" class="">chris.phillips@canarie.ca</a> |GPG: 0x0380811D </div></div><div class=""><br class=""></div></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><b class="">What is F-TICKS?</b></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">F-TICKS[1] is a log format that masks user identifying sign in information to allow for statistical collection of access logs while protecting personally identifiable information.  While F-TICKS is used widely in eduroam[2], other higher education federations also use it in the SAML space.</div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">Having F-TICKS support in Shibboleth v2.x was slightly tedious and had more dependancies than desired but is a key operational aspect to assist with logging and deriving access metrics in the federated sign on space.  The difficulty to implement on v2 prevented more widespread adoption  of the technique.</div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""> </div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">In Shibboleth v3 it was much easier to refactor it into the logging infrastructure and leverage the bean support to accomplish the same thing with no external dependancies. (hurray!)  Having this available to any Idp operator I think would be very beneficial and allow tools like the UK's Raptor[3], SWAMID's FLOG tools[4] to work more seamlessly than before and potentially simplify deployments.</div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">[1] <a href="https://tools.ietf.org/html/draft-johansson-fticks-00" class="">https://tools.ietf.org/html/draft-johansson-fticks-00</a></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">[2] <a href="https://monitor.eduroam.org/f-ticks/" class="">https://monitor.eduroam.org/f-ticks/</a></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">[3] <a href="http://iam.cf.ac.uk/trac/RAPTOR" class="">http://iam.cf.ac.uk/trac/RAPTOR</a></div><div style="font-family: Calibri, sans-serif; font-size: 14px;" class="">[4] <a href="https://github.com/SUNET/flog" class="">https://github.com/SUNET/flog</a></div><div class=""><br class=""></div></body></html>