Some data about the CBIC Federation

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

Federation management A mess? Nordunet Conference Mikael Linden CSC, the Finnish IT Center for Science.
Identity Network Ideals – Heterogeneity & Co-existence
Options for integrating the JANET Roaming Service (JRS) and Shibboleth Tim Chown University of Southampton (UK) JISC Access Management.
Eduserv Athens Federations David Orrell Eduserv Athens Technical Architect.
From Authentication to Privilege Management to the Attribute Economy: Marketing runs amok…
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
JISC Metaleth Project Athens, Shibboleth and the University of Bristol 29 th January 2007.
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
NJVid New Jersey Video Portal 1 Grant partners. NJVid New Jersey Video Portal 2 NJTrust - New Jersey Identity Trust Federation NJViD Advisory Board Meeting.
Administrative Information Systems Shibboleth: The Next Generation ISIS Technical Information Session for Developers Datta Mahabalagiri March
(Rev 1/11) UW System Identity and Access Management (IAM) Current Status and Roadmap Tom Jordan, IAM-TAG Chair Ty Letto, IAM Support Team Manager January,
Federated A(A(A))I Jens Jensen hepsysman, RAL,
SWITCHaai Team Federated Identity Management.
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
1 Multi Cloud Navid Pustchi April 25, 2014 World-Leading Research with Real-World Impact!
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
High-quality Internet for higher education and research AAI from the NREN perspective Schiphol, October 17, 2005
Neil Witheridge APAN29 Sydney February 2010 ARCS Authorisation Services Neil Witheridge Manager, ARCS Authorisation Services APAN29, Sydney, February 2010.
ShibGrid: Shibboleth access to the UK National Grid Service University of Oxford and STFC.
Federated Environments and Incident Response: The Worst of Both Worlds? A TeraGrid Perspective Jim Basney Senior Research Scientist National Center for.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
Shibboleth at Columbia Update David Millman R&D July ’05
MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters.
Comité Réseau des Universités News from CRU activities: Identity federation, eduroam, PKI, SCS, Sympa, security policies cru.fr 7th.
OGF22 25 th February 2008 OGF22 Demo Slides Prof. Richard O. Sinnott Technical Director, National e-Science Centre University of Glasgow, Scotland
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney Senior Research Scientist National Center for Supercomputing Applications University.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
PAPI: Simple and Ubiquitous Access to Internet Information Services JISC/CNI Conference - Edinburgh, 27 June 2002.
Refeds update TF-EMC2 Utrecht 3-Dec 2008 Mikael Linden CSC – the Finnish IT Center for Science.
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
National Computational Science National Center for Supercomputing Applications National Computational Science Integration of the MyProxy Online Credential.
Diego R. Lopez, RedIRIS TF-EMC2, Umea SIR, FedSSH and more to come…
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Attribute Delivery - Level of Assurance Jack Suess, VP of IT
Administrative Information Systems Shibboleth Install Session Technical Information Session for Developers Datta Mahabalagiri.
Jakob Gadegaard Bendixen, Shibboleth protected proxy servers a case study from the Danish library sector.
126/02/2016 META ACCESS MANAGEMENT SYSTEM A Ship on the Grid – Interoperability between Shibboleth and the Grid – Dr. Erik Vullings Programme Manager Macquarie.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Diego R. Lopez RedIRIS update Middleware activities at the South-western Border.
Shibboleth for Middle Schools James Burger -
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
AAI Interconnection with an European style Diego R. Lopez RedIRIS.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Shibboleth and eLibrary
User authentication on the e-Culture Science Gateway with Identity Federations and Identity Providers INDICATE Final Conference, Ankara,
Shibboleth Architecture
Federated Identity Management at Virginia Tech
LIGO Identity and Access Management
Mechanisms of Interfederation
Shibboleth Roadmap
Extending Authentication to Members of Social Networks
University of Texas System
John O’Keefe Director of Academic Technology & Network Services
e-Infrastructure Workshop 28th March 2006, University of Leeds
ESA Single Sign On (SSO) and Federated Identity Management
The French federation Eurocamp 2007 Helsinki
Topics The simple life The Simple Life GUI The full IdM life
Overview and Development Plans
What’s going on at your friendly neighbourhood
UK Federation 101 Ian A. Young EDINA, University of Edinburgh (and the UK Federation) Internet2 Fall Member Meeting, 7 Dec Shibboleth Development.
Federated Environments and Incident Response: The Worst of Both Worlds
IST346: Namespaces, Identity Management
Presentation transcript:

Some data about the CBIC Federation

Run by the National Council for Scientific Research (CSIC) Some basic facts Run by the National Council for Scientific Research (CSIC) With the support of RedIRIS Offered to centers belonging to CSIC Based on PAPI The Shibboleth protocol is used at several points In operation since July 2002 176 IdPs 109 SPs 65085 logins in 2006

Some Basic Facts

Based on federation-aware proxies The Service Providers Fully federated ones Access to CSIC library resources Library portal and meta-searcher (Metalib) Basic user administration and statistics Grid infrastructure helpdesk Based on federation-aware proxies Content providers DOI resolver for the proxied providers Conversations with providers to go Shib-enabled

The Identity Providers Central LDAP-based WAYF service May be directly integrated with the login process Based on the PAPI protocol Common Shibboleth gateway Identity is established through e-mail access credentials: POP(S), IMAP(S) It is recommended to use a LDAP-based attribute repository Though other (simpler?) methods are supported

Assertions and Schemas IdPs have to be able to provide data on Affiliation Center Currently using irisPerson20050202 SCHAC attributes planned for 3rd quarter this year Policies are explicitly the same that those applied by CSIC to enable access to other networking services Procedures explicitly mandated and audited by the CSIC Central Computing Service

No specific agreement required to participate Management Aspects No specific agreement required to participate IdPs are part of the CSIC network Outer SPs have signed agreements with the CSIC library services Steering Committee in charge of supervising operations and planning future developments Operations are responsibility of the CSIC Library Unit Developments are coordinated by the PAPI team at RedIRIS Users must explicitly require the service and authorize the exchange of their data