AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)

Slides:



Advertisements
Similar presentations
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Advertisements

Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Authentication and Authorisation for Research and Collaboration Mikael Linden AARC all hands Milan Authentication and Authorisation.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No B2ACCESS LSDMA.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Networks ∙ Services ∙ People Mandeep Saini AARC/CORBEL Workshop Collaborative Organisation Platform as a Service June 1, 2016, Paris Product.
ELIXIR AAI Michal Procházka, Mikael Linden, EGI VC 15 March 2016.
The IGTF to eduGAIN Bridge
Building Trust for Research and Collaboration
Introduction to AAI Services
The EGI AAI “CheckIn” Service
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
Cross-sector and user-centric AAI
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS – Current status & Future Plans
Christos Kanellopoulos
CheckIn: the AAI platform for EGI
Check-in Nicolas Liampotis
An AAI solution for collaborations at scale
Boosting AAI for research and collaboration
Updates on Training Andrea Biancini (AARC2.AHM)2 NA2 WP leader
Bringing Harmonized Policy and Best Practice
Towards hamonized policies and best practices
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
AARC2 JRA1 Nicolas Liampotis
Minimal Level of Assurance (LoA)
Identity Management and Authorization
GÉANT project update eduTEAMS - AAI as a Service for Collaborative organisations Introduction Status Pilots New Features – input requested InAcademia –
Frameworks for harmonized policies and practices
Policy in harmony: our best practice
REFEDS Assurance Framework
Policy and Best Practice Harmonisation (‘NA3’)
Leveraging the IGTF authentication fabric for research
Leveraging the IGTF authentication fabric for research
Thursday pilot session: 7-minutes
Towards hamonized policies and best practices
EduTEAMS at a Glance Mandeep Saini Linz, Austria 30 May 2017.
OIDC Federation for Infrastructures
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
AAI For Researchers Licia Florio AARC Project Coordinator GÉANT DI4R
Updated (VO) Community Security Policies
AARC Blueprint Architecture and Pilots
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
OIDC Federation for Infrastructures
AARC2 JRA1 Update Nicolas Liampotis
AAI Architectures – current and future
RCauth.eu CILogon-like service in EGI and the EOSC
Community AAI with Check-In
JRA1: Integrated AAI Developments
REFEDS Assurance WG REFEDS meeting 16 June 2019
Authentication and Authorisation for Research and Collaboration
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
REFEDS Assurance Suite
Presentation transcript:

AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden) Authentication and Authorisation for Research and Collaboration Nicolas Liampotis (based on the work of Mikael Linden) JRA1, AARC2 GRNET AARC2 Kick-off meeting, Bad Herrenalb 7 June 2017

AAI alignment Platforms EGI CheckIn ELIXIR AAI EUDAT B2ACCESS GÉANT eduTEAMS

AAI alignment Main areas Technical architecture Infrastructure identifier(s) and attributes used Infrastructure identity’s cardinality and lifecycle Protocols and external account linking eduGAIN presence – principles and policies eduGAIN presence – technical Levels of Assurance

AAI comparative analysis results and suggestions Technical architecture EGI CheckIn, ELIXIR AAI and EUDAT B2ACCESS based on similar IdP- SP-Proxy model GÉANT eduTEAMS is a centralised Attribute Provider that IdP-SP- Proxies/Relying Parties can query for extra user attributes Suggestions None

AAI comparative analysis results and suggestions Infrastructure identifier(s) and attributes used All AAIs assign a unique, opaque, non-revocable, non-reassignable infrastructure identifier to users and deliver it to the Relying Parties as the primary user ID Suggestions align user identifier syntax investigate possibility to align Home Organisation affiliation attribute its name and syntax (can proxies assert scope they are not authoritative to?) how it is assigned if it cannot be retrieved from the home organisation IdP at least document the per-platform approaches attribute assurance needed align mapping of attributes to OIDC claims

AAI comparative analysis results and suggestions Infrastructure identity’s cardinality and lifecycle ELIXIR is the only AAI encouraging users to have only one identity; others let the users create multiple identities if they want to EGI and EUDAT identities have a single-valued Home Organisation attribute that is decided at the time of registration and presented to the Relying Parties. ELIXIR has a multi-valued Home Organisation attribute. All AAIs need fresh affiliation information; approaches vary Suggestions share approaches on data retention (EUDAT has documented approach)

AAI comparative analysis results and suggestions Protocols and external account linking All AAIs support SAML2 authentication EGI, ELIXIR and EUDAT support OAuth2/OIDC towards Authentication providers and Relying Parties eduTEAMS supports attribute queries based on SAML2 and VOOT EGI and EUDAT support IGTF X.509 certificates and locally managed passwords to authenticate the users EGI, ELIXIR and EUDAT support credential translation to X.509 certificates. Suggestions use common SAML profile (SAML2Int or successor) and OIDC profile towards Relying Parties

AAI comparative analysis results and suggestions eduGAIN presence – principles and policies All AAIs automatically trust IdPs from eduGAIN In the case of EGI, R&S and/or Sirtfi may affect the authenticating user’s LoA and service entitlements values eduTEAMS only automatically trusts REFEDS R&S and Sirtfi compliant SPs from eduGIAN Suggestions None

AAI comparative analysis results and suggestions eduGAIN presence – techincal All AAIs exposed in eduGAIN as SPs All AAIs satisfied with an eduGAIN IdP releasing the R&S attribute bundle ELIXIR requests only user’s unique identifiers and affiliation information from Identity Providers in eduGAIN EGI and EUDAT B2ACCESS request also their name, e-mail address eduTEAMS requests and supplies attributes in accordance with the R&S entity category eduTEAMS will also be exposed as Attribute Provider in eduGAIN Suggestions harmonisation of requested attributes from IdPs in eduGAIN (R&S attributes)

AAI comparative analysis results and suggestions Levels of Assurance Each AAI following different approach Suggestions harmonisation of LoA levels (separating things done internally in an infrastructure and the original IdPs) how to position social media identities? how to manage and rank the eduGAIN IdPs? make use of (endorse together?) REFEDS assurance profiles? many-to-one mapping in the platform and the related LoA calculus

mikael.linden@csc.fi