GÉANT 4-2 JRA3 T1 and T2 Federations and Campus (CaFe) e-Infrastructures and Service Providers (RASP) Daniela Pöhn JRA3 T1 LRZ/DFN-AAI Technology Exchange.

Slides:



Advertisements
Similar presentations
EduGAIN – Are we there yet? Lukas Hämmerle (ghost writer, Brook Schofield) FIM4R, Helsinki – 2 October 2013.
Advertisements

Copyright JNT Association 20051OptionalCopyright JNT Association 2007 Overview of the UK Access Management Federation Josh Howlett.
SWITCHaai Team Federated Identity Management.
Innovation through participation Interfederation through eduGAIN - steps and challenges eduGAIN interfederation service Federated Identity Systems.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Test your IdP
Federation as a Service Marina Vermezović, AMRES Federated Identity Technology Workshop Sofia, Bulgaria, 20. Jun 2014.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Innovation through participation eduGAIN policy: A worm report TF-EMC2 Vienna Mikael Linden, CSC The worm farmer.
Networks ∙ Services ∙ People Nicole Harris, GÉANT GN4 Project Update “SA5”, or Identity Stuff Internet2 Technology Exchange 2015.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Authentication and Authorisation for Research and Collaboration David Groep AARC All Hands meeting Milano Policy and Best Practice.
Growth. Interfederation PKI is globally scalable Unfortunately, its not locally deployable… Federation is locally deployable Can it.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Understanding deployment issues on the Supply Chain Ann Harding, SWITCH, Nicole Harris, TERENA Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Ann Harding eduGAIN Town Hall eduGAIN in the GÉANT Project Activity Leader GÉANT Trust and Identity.
Progress Report on the U.S. NSTIC Efforts Jack Suess – Delegate for Research, Development, Education & Innovation
Networks ∙ Services ∙ People Andrea Biancini #TNC15, Porto, Portugal Implementing Grouper to federate user authorization Federated Authorization.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Géant-TrustBroker Dynamic inter-federation identity management Daniela Pöhn TNC2014 Dublin, Ireland May 19 th, 2014.
Innovation through participation Data Protection Code of Conduct (DP CoC) TNC2013 conference, 4 June 2013 Mikael Linden, CSC – IT Center for Science
Introduction to AAI Services
Releasing Attributes for Science!
WLCG Update Hannah Short, CERN Computer Security.
Explorer Post Renewal Instructions
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
Cross-sector and user-centric AAI
International Growth of Federations & eduGAIN
On Monitoring, Diagnostics and Measurement in eduGAIN and Beyond
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
Presented by Martine Deprez Head of Unit, EC - SG/A1 – Development and Advice Carine Smets Team Leader e-TrustEx Business – EC - SG/A1 – Development.
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
Identity Federations - Overview
Géant-TrustBroker Dynamic inter-federation identity management
Christos Kanellopoulos
CheckIn: the AAI platform for EGI
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
GÉANT 4-2 JRA3 T1 Something with Federations and Campus VC
Boosting AAI for research and collaboration
Incident Response for Federated Identities
Updates on Training Andrea Biancini (AARC2.AHM)2 NA2 WP leader
GEANT Code of Conduct and REFEDS Research and Scholarship compared
Minimal Level of Assurance (LoA)
Policy in harmony: our best practice
ESA Single Sign On (SSO) and Federated Identity Management
Policy and Best Practice … in practice
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
OIDC Federation for Infrastructures
AAI Architectures – current and future
RCauth.eu CILogon-like service in EGI and the EOSC
Community AAI with Check-In
REFEDS Report: Fall 2017 Nicole Harris Internet2 Technology Exchange
GÉANT 4-2 JRA3 Daniela Pöhn JRA3 T1 LRZ/DFN-AAI
Tom Barton (WG Chair) University of Chicago and Internet2
Baseline Expectations for Trust in Federation
GEANT Data protection Code of Conduct 2.0 REFEDS meeting 16 June 2019
Federated Incident Response
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

GÉANT 4-2 JRA3 T1 and T2 Federations and Campus (CaFe) e-Infrastructures and Service Providers (RASP) Daniela Pöhn JRA3 T1 LRZ/DFN-AAI Technology Exchange 2016, Miami 2016-09-26

Code of Conduct European Parliament and Council: data protection reform  legal and federation consultation  analysis of eduGAIN’s policies focused on attribute release  effective 25 May 2018 2.0 draft should cover attribute release out of EU/EEA as well Work with DLA Piper  analysis of policies Possible to craft a single Code of Conduct that will work globally? Roadmap: Fall 2016: Prepare a draft of a new, GDPR compliant Code of Conduct Spring 2017: Community consultation within REFEDS community Iterate 25 May 2018 submit to the data protection authorities for approval

Metadata and attribute release management Attribute release: typical conversion rules stored centrally? Metadata management: scalable metadata release KPI monitoring Monitoring and Statistics Web page with all available tools Standardize F-Ticks format eduGAIN F-Ticks service Ticks by every IdP Aggregated per federation/inter-federation Public stats and internal stats

IdP as a Service Look at GARR IDEM, UK Federation,… TIER Business models, security,… As Extension of Federation as a Service

eduGAIN incident management development SIRTFI Security contacts in Metadata Validated Look at requirements from AARC Probe Overview/Monitoring page Self-assessment tool Management tool? Monitoring page added to technical eduGAIN

RASP – Research Infrastructures and Service Providers Task Leader: Lukas Hämmerle

eduGAIN Connectivity Check Service (ECCS) technical.edugain.org/eccs/ Checks for each eduGAIN IdP if it is properly "connected" to eduGAIN I.e. it loads eduGAIN metadata and displays a login page when a user tries to access an eduGAIN SP For each eduGAIN IdP do the following check: Initiate a login process from two eduGAIN SPs (except for disabled IdPs) Check if a reasonable login page is returned Classify error messages (Error = Red, Warning = Yellow) Display results on a public web page IdPs can be excluded from checks (=disabled IdPs) Check is not 100% accurate for non-Shib/non-SSP IdPs with custom authentication mechanisms InCommon Federation (August 8th) 30 red IdPs with errors, 48 yellow IdPs with warnings, 333 Ok IdPs

Effect of ECCS Announcement of ECCS

eduGAIN IsFederated Check Service (EIFCS) technical.edugain.org/isFederatedCheck/ Find out if people and organisations are federated and eduGAIN-ready yet. Has a complete list of all IdPs and organisations of production federations world wide as well as of eduGAIN.

eduGAIN Access Check Service (EACS) access-check.edugain.org Test federated access via an eduGAIN IdP using a set of short-term test identities (student, staff, researcher, incomplete attributes, R&S) Use of test identities limited to owner of SP (metadata contact) ******* test-student Research DB X Create service-specific test accounts with different profiles Use them for login on own service only Check if access works and attributes are available

Upcoming: eduGAIN Attribute Release Check Service (EARCS) Work in Progress Check to see if IdP conforms to attribute release recommendations (i.e. R&S, CoCo) Any user from an IdP can take test Results will be public

Simple SP Registration Process wiki.edugain.org/How_to_Join_eduGAIN_as_Service_Provider Generic (federation-independent) guide on how to register an SP in eduGAIN Refers to guides of individual member federations UK Access Management Federation (in a pilot) to act as a "federation-of- last-resort" in case SP does not know with which federation to register