Bring the WLCG federation Home

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
WebFTS as a first WLCG/HEP FIM pilot
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
New Developments in Authentication and Access Management Alan Robiette JISC Development Group JISC-NSF-DLI2 Meeting, 2002.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
WebFTS File Transfer Web Interface for FTS3 Andrea Manzi On behalf of the FTS team Workshop on Cloud Services for File Synchronisation and Sharing.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
David Groep Nikhef Amsterdam PDP & Grid Bring the WLCG federation Home Extending your trust options beyond bottom-up identity by collaborating with global.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Kipper – a Grid bridge to Identity Federation Andrey Kiryanov.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Operating Systems & Information Services CERN IT Department CH-1211 Geneva 23 Switzerland.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
PRACE user authentication and vetting Vincent RIBAILLIER, 29 th EUGridPMA meeting, Bucharest, September 9 th, 2013.
Authentication and Authorisation for Research and Collaboration Hannah Short (CERN) DI4R Authentication and Authorisation for Research.
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
Building Trust for Research and Collaboration
Key management issues in PGP
Introduction to AAI Services
Accessing the VI-SEEM infrastructure
WLCG Update Hannah Short, CERN Computer Security.
Law Enforcement Information Sharing Program (LEISP) Federated Identity Management Pilot February 27, 2006.
Applying eduGAIN to network operations The perfSONAR case
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
Cross-sector and user-centric AAI
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
EGI Updates Check-in Matthew Viljoen – EGI Foundation
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
Case Studies in Federated Identity Management for Research Communities
Ian Bird GDB Meeting CERN 9 September 2003
Gaming e-Infrastructures to improve Interfederation Readiness
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Federated Identity Management for Researchers (FIM4R)
GÉANT International Networking and Collaboration
Boosting AAI for research and collaboration
The AARC Project Licia Florio AARC Coordinator GÉANT
Minimal Level of Assurance (LoA)
Policy in harmony: our best practice
ESA Single Sign On (SSO) and Federated Identity Management
Assessing Combined Assurance
Assessing Combined Assurance
Leveraging the IGTF authentication fabric for research
Leveraging the IGTF authentication fabric for research
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
OIDC Federation for Infrastructures
RCauth.eu CILogon-like service in EGI and the EOSC
Community AAI with Check-In
Shibboleth 2.0 IdP Training: Introduction
AAI in EGI Status and Evolution
ORCID: ADDING VALUE TO THE GLOBAL RESEARCH COMMUNITY
Baseline Expectations for Trust in Federation
Protecting Privacy with Federated AA
Federated Incident Response
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Bring the WLCG federation Home Extending your trust options beyond bottom-up identity by collaborating with global Research and Scholarship With support from the Authentication and Authorization for Research and Collaboration project Trust Anchor Distribution evolution supported by EGI ENGAGE

You all remember the bad old days …

And now we have this! WLCG FIM4R pilot background: eduGAIN connected federations as of November 2014 – Brooke Schofield, TERENA

Evolution of Trust – from 1995 to 2020? Every institute trusts only its own database you can trace everyone, but you get to manage all the accounts passwords are all over - and users pick the same everywhere Distributed global trust – independent third parties identification and identity vetting by CAs, a limited number but accessible to all users everywhere on their own inititiative Easing trust building – mixing assurance from different places extend identification by also leveraging your home organisation www.igtf.net/ap/iota

Evolving for 2020! Getting to distributed global trust for open innovation, open science, open to the world how far can we push federated authentication? A single account for all your services, single sign-on for everything: from data analysis to wikis, and from file sending, and date picking to expense claims But … institutions vary a lot is your home university ready to identify you to the world? does it even want to tell WLCG who you are? ready to help you already today? Or does it need work? is it ready to help the others, sites and operators, in case of incidents? www.refeds.org, FIM4R https://cdsweb.cern.ch/record/1442597

#1: Leverage the CERN User Office Your trusty CA distribution as of next month: now with the CERN LCG IOTA CA supporting the WebFTS pilot https://webfts.cern.ch

More than a pilot – a new way of life! wLCG leverages major open science infrastructures it must work alongside more dynamic communities on the same infrastructure without separating services besides the ‘CERN LCG IOTA CA’ there will be more generic identity providers from all over the world services must be able to trust just-a-unique-name CAs for only highly-managed VOs like LCG, but not for other VOs This needs a decision in software – on CA+VO combination this software is getting there for many areas you all should encourage software providers to implement and deploy such new software in production ASAP http://www.nikhef.nl/grid/tmp/WLCG-CERN-IOTA-statement-MB-20151028.pdf

Open Science, Open to the World? Ready? Old innovations now just seem a given: think of eduroam™ On the way…it may be bumpy! Federated access means you’ll rely on your institute a lot more Some things become easier (web) others more complicated (CLI) Meanwhile, there’ll be lot of bridging and new things to learn But: aligning with the world will bring usability benefits, and enable scenarios that for next years’ students will be their ‘natural habitat’! www.aarc-project.eu

But What Should I Do?? Ask your home organisation to join or opt-in to eduGAIN still no federation? In an eduGAIN country? Ask your local IT to join the national federation, or set up identity management! Ask them to release attributes there’s a basic set that is needed, called “Research and Scholarship” they should join that scheme Ask them to collaborate in incident response and tell us so by joining the SirTFi programme – it’s self- asserted, and we will trust them if they say so – but it means that sites and response teams know they’re able to act OK https://refeds.org/category/research-and-scholarship, https://wiki.refeds.org/display/GROUPS/SIRTFI