Revamping IdP in the Cloud pilot activities

Slides:



Advertisements
Similar presentations
Cancún - Mexico, Andrea Biancini Towards a Federation as a Service From IdP in the Cloud project to FaaS.
Advertisements

AAF Middleware update February Presented by Terry Smith Technical Manager and Heath Marks Manager.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Connect communicate collaborate GÉANT3plus Enabling Users Pilots Lukas Hämmerle Task Leader "Enabling Users"
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
Authentication and Authorisation for Research and Collaboration Pilots on the Integrated R&E AAI Paul van Dijk, Activity Lead Pilots.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Niels van Dijk AARC General Meeting Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Authentication and Authorisation for Research and Collaboration Mikael Linden AARC all hands Milan Authentication and Authorisation.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Authentication and Authorisation for Research and Collaboration David Groep AARC All Hands meeting Milano Policy and Best Practice.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
CERN IT Department CH-1211 Genève 23 Switzerland t CERN IT Monitoring and Data Analytics Pedro Andrade (IT-GT) Openlab Workshop on Data Analytics.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Possibilities for Grouper in a cross/inter organizational use Andrea Biancini, Consortium GARR GN3+ F-2-F meeting Stockholm, April.
CMS Experience with the Common Analysis Framework I. Fisk & M. Girone Experience in CMS with the Common Analysis Framework Ian Fisk & Maria Girone 1.
INDIGO – DataCloud CERN CERN RIA
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Testing and Release Procedures/Tools Cristina Aiftimiei (INFN-CNAF) Mario David (LIP)
EPAM Cloud Orchestration
Authentication and Authorisation for Research and Collaboration On behalf of the MJRA1.2 scribes J Jensen.
WLCG Update Hannah Short, CERN Computer Security.
Boosting AAI for research and collaboration
ESA EO Federated Identity Management Activities
Web application hosting with Openshift, and Docker images
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
Web application hosting with Openshift, and Docker images
EGI Updates Check-in Matthew Viljoen – EGI Foundation
Campus IdP Status and plans GARR Mario Reale
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS – Current status & Future Plans
eduTEAMS Roadmap and Timeline,
Wrap up Licia Florio AARC Coordinator
Identity Management and Authorization
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Supporting Services for Campus Identity Providers Plans
GÉANT 4-2 JRA3 T1 Something with Federations and Campus VC
EGI-Engage Engaging the EGI Community towards an Open Science Commons
An AAI solution for collaborations at scale
Boosting AAI for research and collaboration
Updates on Training Andrea Biancini (AARC2.AHM)2 NA2 WP leader
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
Minimal Level of Assurance (LoA)
Identity Management and Authorization
GÉANT 4-2 JRA3 T1 and T2 Federations and Campus (CaFe) e-Infrastructures and Service Providers (RASP) Daniela Pöhn JRA3 T1 LRZ/DFN-AAI Technology Exchange.
CV0-002 VCE Dumps
Solutions for federated services management EGI
Policy in harmony: our best practice
ESA Single Sign On (SSO) and Federated Identity Management
Thursday pilot session: 7-minutes
Policy and Best Practice … in practice
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
AAI For Researchers Licia Florio AARC Project Coordinator GÉANT DI4R
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
AARC2 JRA1 Update Nicolas Liampotis
AAI Architectures – current and future
Technical Outreach Expert
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Revamping IdP in the Cloud pilot activities Proposal for the forthcoming months Mario Reale, Maria Laura Mantovani, Davide Vaghetti, Marco Malavolti AARC JRA1, SA1, NA2 GARR AARC All Hands F2F CERN Geneva November 30, 2016

IdP in the Cloud in the Blueprint Architecture Agenda IdP in the Cloud as an answer for AARC Requirements and Policy assurance IdP in the Cloud in the Blueprint Architecture The current existing solution - Proposal for a new implementation Required developments for the pilot Estimated efforts and timeline Outcome

Requirements addressed by IdP in the Cloud Availability of well-configured, secure and schema compliant IDPs in the federation SIRTFI enforcement (Operational Security, Incident Response, Traceability, Participant Responsibilities) Entity Category (R&S, CoCo) support/Attribute release enforcement Ease the implementation of predefined assurance profiles (LoA) Reduce required effort to interface additional components possibly needed by SPs in the Federation Attribute Authorities Step-Up Authentication Provisioning of IDPs to poorly skilled/attended Home Organizations Enrollment of new identities in the Federation (guest users zero target) Best Practices Step-up AuthN Attribute Release Persistent Unique Id Attribute Aggregation Levels of Assurance Incident Response User Managed Information Guest Users

IdP in the Cloud in the Blueprint Architecture

Proposal for improvement of current GARR IdP in the Cloud (1/2) IdP in the Cloud Features version 1 (current) version 2.0 (pilot) version X (evolution) Cloud Infrastructure Openstack Any docker-enabled cloud infrastructure Openstack (private cloud) Public cloud (Azure, AWS, etc.) Cloud Infrastructure integration manual Juju, Vagrant Container support (none) Docker (with persistent storage for DB, custom config, and logs) Kubernetes Deploy management Puppet Ansible OpSys Ubuntu 12.04.5 Debian (latest) Ubuntu CentOS IdP SW Shibboleth v3.2.1(latest) Shibboleth v3.3.x (latest) Flavours IdP only IdP + IDM IdM+Directory+IdP

Proposal for improvement of current GARR IdP in the Cloud (2/2) IdP in the Cloud Features version 1 (current) version 2.0 (pilot) version X (evolution) IdM OpenLDAP+phpLDAPadmin (mySQL) OpenLDAP+phpLDAPadmin OpenLDAP+PERUN OpenLDAP+midPoint OpenLDAP+Apache Syncope System monitoring Nagios, collectd Zabbix System security - Fail2ban or alternatives Statistics and accounting PHP script based on loganalysis script Added values Entity category support Managed Attribute filter Federation integration Managed LoA

Pilot tasks breakout Setup docker environment Development of Ansible playbooks to Create the HomeOrg IdP including all required customizations Spawn and management of IdPs through Docker containers Support for english and local language (according to partners’ participation) We will evaluate other container types (e.g. LXC/LXD) and other Linux distributions (e.g. Ubuntu, CentOS) if of interest for pilot participants/community Set up of a testbed, possibly involving different infrastructures / hosting environments We encourage the participation of 1-2 AARC additional partners to the pilot Publish ansible playbooks and Docker recipes on public repos Publish the Docker image on Docker Hub

Draft estimated effort and timeline Setup of required clusters at the sites (0.5 week , 2 persons) Creation of test Docker environment (0.5 week, 2 persons) Writing Ansible playbooks to carry out required tasks (4 weeks, 2 persons) Including local language support Tests against test SP-instances (1 week, 1 person) Writing comprehensive guide for providers, in collaboration with NA2 (2 weeks , 1 person) Writing Leaflet for HO, in collaboration with NA2 (1 week, 1 person) Showcasing everything on the SA1 wiki / Cockpit panel (2 weeks, 1 person) Timeline: Start : January 1, 2017 - End: March 31, 2017

Outcome Demonstrate feasibility and effectiveness of providing IdP in the Cloud via containers deployable, possibly on different cloud infrastructures Production of an handbook for Cloud providers in order to offer the service Leaflet for Home Organizations about needs and benefits of the IdP in the Cloud solution

AARC vs GN4-2 approach in supporting IdP deployment AARC NA2/SA1 proposed activities GN4-2 JRA3 Task 1 planned / ongoing activities Demonstrate feasibility for IdP in the Cloud Howto handbook for Cloud providers Leaflet for Home Organizations about needs and benefits of the IdP in the Cloud solution On-going survey on NRENs/Feds requirements around IdPs and level of appreciation for a Cloud-based solution Cost-Benefit Analysis to be provided for a Campus IdP platform .Its goal is supporting a GEANT decision on future transition to service for a Deployment toolkit NREN/GEANT hosted Cloud IdP platform Sketching an initial design for a comprehensive platform aimed at Providing IdP MD management Spawning IdPs on Containers Plugging private cloud infrastructures

mario.reale@garr.it marialaura.mantovani@garr.it davide.vaghetti@garr.it marco.malavolti@garr.it