Campus IdP Status and plans GARR Mario Reale

Slides:



Advertisements
Similar presentations
TF-EMC2 February 2006, Zagreb Deploying Authorization Mechanisms for Federated Services in the EDUROAM Architecture (DAME) -Technical Project Proposal-
Advertisements

Cancún - Mexico, Andrea Biancini Towards a Federation as a Service From IdP in the Cloud project to FaaS.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
1 Our Expertise and Commitment – Driving your Success An Introduction to Transformation Offering November 18, 2013 Offices in Boston, New York and Northern.
Mantychore Oct 2010 WP 7 Andrew Mackarel. Agenda 1. Scope of the WP 2. Mm distribution 3. The WP plan 4. Objectives 5. Deliverables 6. Deadlines 7. Partners.
COMP-14: Automating your deployments using ANT Gary S Clink Business Consultant.
ETICS2 All Hands Meeting VEGA GmbH INFSOM-RI Uwe Mueller-Wilm Palermo, Oct ETICS Service Management Framework Business Objectives and “Best.
Portal for ArcGIS An Introduction
Authentication and Authorisation for Research and Collaboration Pilots on the Integrated R&E AAI Paul van Dijk, Activity Lead Pilots.
Géant-TrustBroker project overview Slides assembled by the Géant-TrustBroker team at Leibniz Supercomputing Centre, Germany for a short presentation by.
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
PDS4 Project Report PDS MC F2F University of Maryland Dan Crichton March 27,
INDIGO – DataCloud WP5 introduction INFN-Bari CYFRONET RIA
International Planetary Data Alliance Registry Project Update September 16, 2011.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI IPv6 Report for HEPiX CERN October 5, 2012 CERN 1
HEPiX Virtualisation working group Andrea Chierici INFN-CNAF Workshop CCR 2010.
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
WACREN EduID Fostering Identity Federations in West and Central Africa 3rd Sci-GaIA Workshop Dar es Salaam, Tanzania – 5 th September Omo Oaiya.
Bob Jones EGEE Technical Director
On Campus Internship Work Plan Creation
ESA EO Federated Identity Management Activities
Multi Point VPN Service
AARC Update What’s been happening in AARC which matters for GÉANT
WHY? - Found initiative while case statement preparation
Overall Roadmap and Timeline
SA1 Execution Plan Status and Issues
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS Roadmap and Timeline,
Software Configuration Management
Global Grid Forum GridForge
Wrap up Licia Florio AARC Coordinator
InCommon Steward Program: Community Review
Supporting Services for Campus Identity Providers Plans
Revamping IdP in the Cloud pilot activities
GÉANT 4-2 JRA3 T1 Something with Federations and Campus VC
Neil Witheridge’s slides
Infrastructure Area EMI All Hands Summary.
Hyper-V Cloud Proof of Concept Kickoff Meeting <Customer Name>
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
Identity Management and Authorization
Description of Revision
Get Microsoft Exam PDF Braindumps With Verified Question Answers By Realexamdumps.com
SQL Server BI on Windows Azure Virtual Machines
SQL Server OLTP with Microsoft Azure Virtual Machines
ESA Single Sign On (SSO) and Federated Identity Management
Thursday pilot session: 7-minutes
Leigh Grundhoefer Indiana University
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
Multi-Domain User Applications Research (JRA3)
ESS Vision 2020: ESS.VIP Validation
SISAI STATISTICAL INFORMATION SYSTEMS ARCHITECTURE AND INTEGRATION
AARC2 JRA1 Update Nicolas Liampotis
AAI Architectures – current and future
Academy Hub An eUnomia Factory Solution.
Björn Erik Abt :: Paul Scherrer Institut
X-DIS/XBRL Phase 2 Kick-Off
Supporting Institutions Towards a Shibbolized Infrastructure
New Assessment & Test Methods
Technical Outreach Expert
Server Management and Automation Windows Server 2012 R2
Academy Hub An eUnomia Factory Solution.
DSG Governance Group Recommendations.
NMDWS Internship Portal
Executive Sponsor: Tom Church, Cabinet Secretary
Presentation transcript:

Campus IdP Status and plans GARR Mario Reale GN4.2 JRA3 All-Hands - F2F - December 12-13, 2016

Agenda Goals and implementation Survey Market Analysis Deliverable (D9.1) Cost Benefit Analysis Requirements for the Campus IdP platform Initial design Roadmap ahead and timeline ( milestones, deliverables ) Discussion - People’s involvement

Goals Develop a Campus IDP platform to support the deployment of Identity Providers at Campuses Bring it to production level for possible endorsement and adoption by GEANT Pursue integration with current existing GEANT FaaS service (“add the last mile..”) Exploit possible synergies/collaborations with Internet2 TIER project From the GN4.2 DoW: “Based on findings from AARC, TIER (Internet2) and NREN developments, develop a campus IdP extension to the FaaS service for sites and regions who currently do not have the ability to support or offer a cloud IdP-type of service to campuses” Reference products: Jagger Other FaaS components: HSM, DS, MDA Cloud IDP ( Some NRENs already offer a Cloud IdP solutions to customers )

Implementation Write a Market Analysis with assessment of existing Cloud IdP solutions by NRENs Produce a Costs-Benefits analysis Provide it to GEAN PLM Team Design an initial architecture for an integrated solution: Campus IdP + FaaS platform Start a pilot service Review CBA periodically Go through all steps required by SA2 T1 Services transition to production procedures Write all required Service Templates: SDP, Requirements, Documentation Fill all required Service Templates

The scenario: options to provide supporting services for Campus IdP GEANT / NRENs Hosted Campus IDP Cloud Service integrated with FaaS Design Implementation Pilot Service Transition to Production Collection of community requirements Hosted Cloud Campus IdP platform integrated with FaaS components Assessment of existing solutions Market Analysis document Toolkit deploying Cloud IdP for Campus Costs Benefits Analysis document Cloud Campus IdP service catalogue

GEANT NREN Survey on Cloud IdP Survey on Cloud IdP circulated to the Fed Operators list - early October Aimed at better understanding the Campus IdP problem definition: Community Requirements, Potential for Cloud-based Campus IdP solutions Got 17 answers from the following NRENs: ARNES, CANARIE, CESNET, GARR, GRNET, GEANT, HEANet, Internet2, JANET, RedIRIS, RENATER, SURFnet, SWITCH A relevant outcome: there is high desire but little or none internal ability for institutions to deliver identity provider services to their users ( ~ 40 % of answers) Survey Still online on http://tinyurl.com/z33jond Detailed answers report available at http://tinyurl.com/zdr9gf5

Survey Results 1/2 Q2:What is the desire and ability of institutions to deliver Identity Provider services Q3:What are the main barriers to adoption of federated Identity services?

Survey Results 2/2 Q8: How interested would your individual institutions be in outsourcing the provisioning of a local IdP to a managed service provider? Q11:Principle advantages of a GEANT provided and managed Cloud based solution for the IDP?

Market Analysis for Supporting Services for Campus IdPs Deliverable D9.1 - Market Analysis for Supporting Services for Campus Identity Providers - due by end of December: Deliverable needs to be completed in its overview of current Cloud IdP solutions by NRENs Pending FInalize description of Cloud IDP offers by some NRENs (ARNES, JISC, HEANet, SWITCH...) Injection of outcome of Cloud IDPs NRENs survey Complete the use cases requirements for Campuses and Federations with and without FaaS GEANT role section Currently in progress at https://docs.google.com/document/d/1bWN8wyHO-PyyOBAu5aSqR2Hrbuurv0eJgwSyWtKzdkg/edit?usp=sharing Delayed by 1 month due to need to define boundaries towards AARC activities on Cloud IdP

Cost Benefit Analysis We need to deliver a CBA Analysis for the Campus IDP - Milestone for Month 6 - Approved by M8 CBA should highlight relevant economical aspects related to the proposal of Campus IDP service An empty skeleton - shared google doc - is available at http://tinyurl.com/hx9uyth It is now really time to write it :-) Including the associated CBA Excel file We should be able to get an empty template for it

CBA document structure - GN4 CBA template Executive Summary Background and Objectives Considerations and recommendation ( Available options and recommended one ) Summary information Business Model Values users Value proposition / Community need Value creation Value chain Value capture KPIs and critical success factors Risks Costs Benefits Cost/Benefits summary Excel documentation - Embed the CBA excel file Product/Service description Technical Requirements Operational Requirements Timescales Conclusion and next step References Glossary

Requirements for the Campus IdP platform Due to spread in NRENs currently adopted technologies, be as portable as possible ( independent of specific private cloud platform and infrastructure deployment model ) Security : Secure way to interface the LDAP/AD backend ( LDAPS - disable LDAP) Ensure secure AuthZ approach towards MD-backend integration ( JSON Web Token ( JWT) ) Different levels of GUI management profiles: basic ( all defaults) skilled manager ( access to more advanced options) Plug in JAGGER Resource Registry, but more general - design a general solution Possibility to integrate configuration management via Ansible ( and Puppet ? ) Provide both: Ansible playbooks for automated IdP deployment on Docker Integration of Openstack: automated spawning on IdPs on Openstack via Docker container Longer Term requirements to be addressed Provide High Availability for the IdP instances Consider integration with eduROAM GUI and a unique management interface for both

Functionality to be provided by the Campus IdP platform Generic Docker templates Archive and management of the IdP metadata Private Docker repository SAML SSO support to the Platform (registry) Service Provider (.i.e.: the Platform itself will be a federation SP e.g. using FaaS) Configuration of the IdP instances Define source of user registry Attributes mapping Defining source of signed metadata Locally defined attribute release policy and/or define remote attribute release policy Customized login page Upload of required configuration files from the platform instance to the IdP ones, including public certificates Bulk configuration, patches, security updates management for all IdP instances through the generation of automated scripts ( eg: Ansible playbooks, Puppet recipes..) Build versioned docker template based on current configuration and upload to private docker repository Spawn of new IdP instances according to Docker containers

Initial draft architecture

Roadmap Finalise the market analysis deliverable D9.1 (december/january) Write the CBA document (january) Develop further a detailed design for the Gn4.2 solution for IdP Compile a shopping-list of required individual components and related developments Analyse in detail the required bits to interface FaaS Pledge resources to start setting up a development testbed

Suggested Discussion items today Agree on the goals Detail the work to do in a breakdown of specific work items Assign people to work items according to personal skills / taste Resources Common tools for remote collaboration on the work items Shall we schedule periodic joint remote-working sessions ?