Thursday pilot session: 7-minutes

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

SWITCHaai Team Federated Identity Management.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Mikael Linden AARC all hands Milan Authentication and Authorisation.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No B2ACCESS LSDMA.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
ELIXIR AAI Michal Procházka, Mikael Linden, EGI VC 15 March 2016.
eduroam-as-a-service
Introduction to AAI Services
WLCG Update Hannah Short, CERN Computer Security.
Boosting AAI for research and collaboration
EGI Updates Check-in Matthew Viljoen – EGI Foundation
Campus IdP Status and plans GARR Mario Reale
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
eduTEAMS platform for collaboration Niels Van Dijk
eduTEAMS – Current status & Future Plans
eduTEAMS Roadmap and Timeline,
Identity Management and Authorization
Géant-TrustBroker Dynamic inter-federation identity management
Christos Kanellopoulos
Jens Jensen, STFC Sep EUGridPMA Manchester
CheckIn: the AAI platform for EGI
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Revamping IdP in the Cloud pilot activities
Update on FIM4R David Kelsey
EGI-Engage Engaging the EGI Community towards an Open Science Commons
An AAI solution for collaborations at scale
Boosting AAI for research and collaboration
SA1 Update at AARC2 All Hands Meeting, Amsterdam November 2017
Updates on Training Andrea Biancini (AARC2.AHM)2 NA2 WP leader
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
IDN Variant TLDs Program Update
The AARC Project Licia Florio AARC Coordinator GÉANT
Minimal Level of Assurance (LoA)
Identity Management and Authorization
Identity Management and Authorization
Policy in harmony: our best practice
Policy and Best Practice … in practice
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
Updated (VO) Community Security Policies
AARC Blueprint Architecture and Pilots
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
OIDC Federation for Infrastructures
AARC2 JRA1 Update Nicolas Liampotis
AAI Architectures – current and future
Mapping ELIXIR projects to EGI VOs
EGI EPOS Competence Center
Björn Erik Abt :: Paul Scherrer Institut
Community AAI with Check-In
Community Engagement & Competence Centre
AAI in EGI Status and Evolution
Technical Outreach Expert
UmbrellaID in the EOSC era ?
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Thursday pilot session: 7-minutes 6 Presentations Show us what work will take place within SA1 (action points, timelines) Show (high-level) architecture/components 7 minutes each No deviations! Order: CTA (Alessandro) WLCG (Hannah) LIGO (Paul H.) EPOS (Mariusz) EISCAT_3D (Ingemar) DARIAH-EGI (David H.)

6: DARIAH – EGI (1/3) Pilot consists of two parts Pilot 1: Implementation of a SP/IdP-proxy in the DARIAH AAI Compliant with the AARC Blueprint Architecture Implementation of AARC recommendations & guidelines Based on Shibboleth Pilot 2: Interoperability pilot between EGI and DARIAH Initial use case: DARIAH users can use EGI services (e.g. deployment of VMs, operational tools) through EGI check-in Mapping from DARIAH group memberships to EGI entitlements for EGI services at EGI check in Plan: make the workflow simple for DARIAH users (i.e. avoid noticeable registration at EGI check in, if possible)

6: DARIAH – EGI (2/3) Initial call took place in October F2F meeting yesterday to discuss use cases and status Pilot 1 (DARIAH AAI proxy) already running in a “PoC version” Timeline: Until Feb. 18: implement AARC recommendations in proxy March 18: connect to development Instance of EGI check-in April 18: define group mappings, test attribute release, paperwork May 18: move to production EGI check-in and test fed. Cloud access

6: DARIAH – EGI (3/3) Implementation based on concept (see below) almost done Technology: Shibboleth IdP & SP with some “glue code” Will be extended (according to timeline) to fulfill AARC recommendations on identifiers, group memberships, LoA

EUDAT-PRACE Pilot

Scenario PRACE LDAP – B2ACCESS synchronization gridFTP PRACE LDAP – B2ACCESS synchronization Entity/identity provisioning in B2ACCESS based on LDAP search filter (branch, attributes) Only users who accepted terms and conditions Assigning to B2ACCESS groups based on LDAP filter Still the admin may manually assign an entity to additional group, define attribute or disable it Users processed in bulk periodically B2ACCESS – B2STAGE/B2SAFE synchronization B2SAFE account provisioning and DN mapping (1-1) on demand Assigning to B2SAFE groups based on B2ACCESS group membership Support for certificates: Used as B2ACCESS credentials (e.g. IGTF) Generated by B2ACCESS Single user processed online, just before the standard authorization

PRACE LDAP B2ACCESS PRACE gridFTP B2STAGE

Status The work in progress was presented to EUDAT during developers meeting in October The work was in general accepted and decided to be put in production Some enhancements were suggested (regarding efficiency in particular) Deployment agenda was agreed Implementation (including suggestions) finished in mid November Documentation in progress Deployment in a couple of production services planned until the end of December It is planned be shown in EUDAT final conference in January Real life tests, corrections, enhancements…

Interfaces The pilot works with gridFTP B2STAGE The mechanism is general, so it can be plugged into HTTPS B2STAGE -planned

Group management in EUDAT Group for each service instance Group for each community Normally the groups are managed manually by service/community admins The pilot is able to add users to some groups (e.g. PRACE) automatically

User consent Expressing user’s agreement on terms and conditions, processing personal data, etc. to be compliant with Geant Data Protection Code of Conduct and local policies – we assume it is done on PRACE side and expressed in „EUDAT” LDAP attribute.

Lifescience AAI Pilot

Different AAI components to be delivered by EGI, EUDAT and GÉANT. Aim Build an AAI that follows AARC blueprint and that serves multiple lifescience communities First domain-specific AAI infrastructure At the moment to serve 11 lifescience infrastructures Different AAI components to be delivered by EGI, EUDAT and GÉANT.

31st of Jan 2018 to complite Phase 1 of the pilot: Plan LS AAI Pilot 31st of Jan 2018 to complite Phase 1 of the pilot: key pilot components operational 3 first relying services from the research infrastructures integrated to the pilot Two main milestones: M1 (22nd Dec 2017) : Test environment ready, connections between SB proxies and NB proxies and PERUN, using dummies SPs and IdPs M2 (end Jan 2018 ): Pilot available for LS. Connect real IdPs and 3 LS SPs. Pilot to start on 24th Nov 2017