Currently the XSEDE SSO Hub requires XSEDE Kerberos authentication. CAN-6 states, "The authentication mechanism MUST be able to federate with other mechanisms such as those used by OSG, PRACE, EGI, and InCommon." Migrating the SSO Hub to Globus Auth will give users the option of using InCommon authentication (via CILogon) when logging in. Note that the XSEDE SSO Hub will likely be migrating to Globus Auth due to Globus Toolkit retirement (XCI-127).
Per Jim: "This activity should NOT be launched until the Globus Auth SSH is ready for testing or at least until we have more details on the Globus Auth SSH design. Maybe the activity should just be "Integrate Globus Auth SSH with SSO Hub"? "This gap will be addressed in the activity to integrate Globus Auth SSH with the SSO Hub."