Terms and Conditions of Service
1 Definitions
1.1 The IDEM-Tester Service
IDEM-Tester is a modular, independent web application that can be queried via REST API.
The service is accessible at https://idemtester.garr.it
Users possessing credentials from the IDEM AAI Federation have access to all functionalities provided by the service, such as testing SAML entity metadata, viewing results on the web app, and using the REST API. In cases where an Organization is finalizing the membership process and the User does not yet possess credentials, the service will be usable in a limited version via a voucher, subject to express authorization from IDEM GARR staff.
IDEM-Tester is developed and managed by Consortium GARR.
1.2 Data
The service acquires and manages two types of data: test metadata and the User's personal information.
"Test metadata" is defined as SAML entity metadata entered into the service via URL when completing a test request form. The metadata in question are public data and belong to the originating Organizations; IDEM-Tester uses them solely for the purpose of testing the content.
Personal information refers to data characterizing the User's identity, such as first and last name, username, any content encryption passwords, the affiliated Organization, and the IP addresses used to access the service. Personal data is extracted from information provided by the IDEM Federation Identity Providers and is used for authentication, authorization, and monitoring purposes.
1.3 Actors
The main roles that individuals may hold when interacting with IDEM-Tester are listed in the following table. Certain service procedures and related technical documents may introduce and define more detailed sub-roles involved in specific process activities.
| Acronym | Role | Description |
|---|---|---|
| Administrative Roles | ||
| AG | GARR Administration | Manages the contractual and administrative relations between the IDEM-Tester subscribing organizations (via their Administrative Representative) and the GARR Consortium. |
| Technical Roles | ||
| UT | IDEM-Tester User | The individual who accesses IDEM-Tester, uploads service metadata (via web app or REST API), and views the results. |
| SI | IDEM-Tester Service Support | The expert group managing IDEM-Tester. They provide Tier 1 and Tier 2 support, handle test requests from unauthenticated users, and issue vouchers. |
2 Service Features
IDEM-Tester is accessible via the Internet, both through a web interface (https://idemtester.garr.it) and via REST API. The service allows users to test the content of single SAML entity metadata in an automated manner, based on the rules specified in the Technical-Operational Profile. The service is characterized by maintaining its own servers, managed by GARR, within the Italian territory. IDEM-Tester is designed as an automation tool for verifying the metadata content of Organizations intending to join the IDEM AAI Federation and maintaining its validity over time.
3 Operation
3.1 Access
IDEM-Tester can only be used by users possessing digital identity credentials from a member of the IDEM Federation or those authorized by IDEM-Tester Service Support through the assignment of a voucher. The authorization request is made by filling out a form where it is necessary to provide a reference email and a URL to the metadata to be tested; a voucher associated with this information will allow access to the service with limited functionality.
3.2 User Management and Reporting
Users possessing federated credentials do not need to register for the service; they only need to authenticate through their Identity Provider independently to access all functionalities. When a User leaves their affiliated organization, the organization will remove the credentials from its systems. Anonymous users can access limited service functionalities through the issuance of a voucher, the issuance and management of which is the responsibility of IDEM-Tester Service Support.
The revocation of an Organization's membership in the IDEM Federation formally implies the revocation of access to the service.
3.3 Data Location
The servers hosting the data that users upload through the service are located in Italy within the GARR infrastructure, which also manages maintenance and operations. Users accessing the service through the local networks of Organizations reach the data via the GARR network; in all other cases, access to the servers occurs via the Internet.
3.4 User Support
Users have access to FAQs and online manuals.
For any problems, needs for clarification, or suggestions, users may contact IDEM-Tester Service Support, which will take charge of analyzing the incident encountered or evaluating the request made. Contact channels for IDEM-Tester Service Support are described on the service website.
4 Terms of Use
4.1 Application of Terms
The provisions of the following documents in their most recent version are applicable to the use of IDEM-Tester:
- For users belonging to a member of Consortium GARR: Consortium GARR Statute and Acceptable Use Policy (AUP);
- For users belonging to a Conventioned Entity of Consortium GARR: Convention and related attachments, specifically the AUP;
- For Organizations that have signed a framework agreement with Consortium GARR: terms of the agreement, implementing agreements, and AUP;
- For all users: the “Terms and Conditions of Use” described in this document.
In case of conflicting statements, this document prevails over the provisions of the other aforementioned documents. GARR reserves the right to modify the terms and conditions of use at any time. Organizations and users will be appropriately informed of any changes.
4.2 Admissible Use
IDEM-Tester can be used to test single SAML entity metadata and view the results. It can be used by affiliates of a subscribing Organization and by unregistered users who receive a sharing link as described in Section 3.1.
Any use of the service is admissible only to the extent that such use does not conflict with this service description, GARR’s AUP, the law, or the rights of third parties. It is the User's responsibility to decide which files and directories to upload, synchronize, modify, download, or share through the service.
4.3 User Responsibility for Content
Users and Organizations have exclusive responsibility for their conduct, use, and the content they upload to the service. It is not permissible to use the IDEM-Tester service in any way that may conflict with this service description or the rules indicated in the AUP.
The activities that third-party users can perform on shared data are varied (e.g., copying files, modifying them, sharing them with third parties, publishing them, etc.).
It is not permissible to use the IDEM-Tester service in any way that may cause offense, defamation, or harm to third parties—for example, using the service to disseminate obscene or indecent material, or material that causes any form of anxiety or defamation, or in any way that violates laws or regulations.
It is not permissible to use the IDEM-Tester service to disseminate advertising material.
Furthermore, it is forbidden to transfer one's User credentials to third parties.
GARR declines all responsibility for actions taken voluntarily or involuntarily by users regarding content.
4.4 Misuse of the Service
The illegitimate use of the service is governed by the provisions in sections 4.2, 4.3, 4.4, 4.5, and 4.10 of this document.
In case of reasonable suspicion that the service is being used in violation of laws, regulations, or the rules contained in this paragraph 4, GARR reserves the right to block access to the content in question immediately (e.g., pirated copies or illegal content), disabling the accounts holding the content, deleting any shares, and moving the content to quarantine. Affected users and their affiliated Organizations will not have the right to assert any claims for compensation following measures taken by IDEM-Tester Support Service against misuse of the service.
Furthermore, in all cases of service misuse, GARR reserves the right to cooperate with competent authorities where required by law or deemed necessary. In this context, GARR will offer all requested cooperation to the competent authority, providing all information necessary to prosecute illegal actions. Users and their organizations agree to cooperate with GARR to promptly stop the misuse and ascertain its causes. User and organization responsibilities are discussed in section 4.10.
4.5 Notifications of Misuse
Should a User identify illegal content or content that constitutes misuse of the service, the User is required to inform GARR by sending a report to the IDEM-Tester Support Service according to the methods indicated on the service website. The report must contain the following information: a) name and address of the User, b) description of the identified improper content, c) explanation of how the content harms the User, the service, or third parties based on the criteria established in section 4.4, d) URL or links where the content is reachable, e) date and time the content or misuse was identified, f) screenshots to help better understand the location and access conditions of the content.
GARR will evaluate on a case-by-case basis the actions to be taken in response to a report from users.
4.6 Passwords and Data Backup
The User is responsible for protecting the passwords used to access the service. The User agrees not to disclose them to third parties. The User is responsible for every activity carried out through their account or through the use of their passwords.
Excluding the service backups described in paragraph 3.4, GARR will not create any backup of User content for long-term preservation purposes. IDEM-Tester is designed for managing active data and is therefore not suitable for mass backup purposes, such as User workstations.
4.7 Personal Data Protection
The User determines the scope within which their data content is made accessible to third parties at the time of sharing. Organizations, through their Technical Contact Persons, have the responsibility to ask their users to respect the terms and conditions applicable to the processing of personal data within the content.
During registration, the service uses User information provided according to the methods and constraints imposed by the IDEM Identity Federation. While accessing the service, GARR tracks certain information (IP address, date and time, username) for service maintenance and improvement purposes. GARR tracks the number of User accounts and storage assigned in aggregate form to subscribing Organizations.
4.8 Warranties and Security
GARR guarantees that data is stored on its own infrastructure in Italy. GARR applies best practices regarding network and service protection but does not guarantee a specific level of security (QoS) or a specific level of availability (SLA).
4.9 GARR's Liability
The responsibilities and related limitations of GARR in managing the IDEM-Tester service are in addition to any constraints regulated by agreements and conventions entered into individually or collectively between the Organizations and GARR. The aforementioned agreements shall be considered prevailing if they conflict with the rules of this document.
4.10 Responsibility of Organizations and Users in Case of Misuse
Subscribing Organizations and users are entirely responsible, to the extent provided by law, for damages suffered by GARR due to misuse of the service and for other indirect damages. Each User and their affiliated Organization are personally and at their own expense responsible for violations of copyright or intellectual property and/or violations of current legal provisions regarding the protection of personal data caused by content uploaded to the service.
The User and the subscribing Organization respectively agree to indemnify and hold GARR harmless from any and all claims, damages, prejudices, costs, or expenses (including costs for legal assistance and those resulting from any judicial measures issued against GARR) that GARR may incur as a result of the violation by the User or the Organization of any of the rules contained or referred to in this document.