EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.

Slides:



Advertisements
Similar presentations
David Groep Nikhef Amsterdam PDP & Grid Evolving Assurance – IGTF LoA generalisation David Groep Interoperable Global Trust Federation IGTF Documents at.
Advertisements

INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Policy Issues for Identity Management (and other attributes) EGI Technical.
Updates from the EUGridPMA David Groep, Oct 11 th, 2011.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Updates from the EUGridPMA David Groep, July 16 st, 2007.
David Groep Nikhef Amsterdam PDP & Grid Evolving Assurance – going where? Collaborative, distributed, and generalized assurance beyond just identity authentication.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Summary of Poznan EUGridPMA32 September EUGridPMA Poznan 2014 meeting – 2 David Groep – Welcome back at PSNC.
Welcome to Amsterdam EUGridPMA35 September EUGridPMA Amsterdam 2015 meeting – 2 David Groep – Welcome back in Amsterdam.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
Building Trust for Research and Collaboration
EUGridPMA Status and Current Trends and some IGTF topics April 2017 TAGPMA I2GS April Meeting David Groep, Nikhef & EUGridPMA.
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
Policy and Best Practices … the Story So Far
Policy and Best Practice Harmonisation
EUGridPMA CAOPS-WG and IGTF Issues March 2013 Charlottesville, VA, USA David Groep, Nikhef, EUGridPMA, and EGI.
Christos Kanellopoulos
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
Policy and Best Practices … the Story So Far
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Federated Identity Management for Researchers (FIM4R)
EUGridPMA Status and Current Trends and some IGTF topics March 2017 APGridPMA Spring Meeting David Groep, Nikhef & EUGridPMA.
Boosting AAI for research and collaboration
Bringing Harmonized Policy and Best Practice
Towards hamonized policies and best practices
EUGridPMA Status and Current Trends and some IGTF topics October 2016 TAGPMA24 meeting David Groep, Nikhef & EUGridPMA.
Minimal Level of Assurance (LoA)
EUGridPMA Status and Current Trends and some IGTF topics March 2016 Taipei, TW David Groep, Nikhef & EUGridPMA.
EUGridPMA Status and Current Trends and some IGTF topics October 2017 APGridPMA Autumn Meeting David Groep, Nikhef & EUGridPMA.
Frameworks for harmonized policies and practices
Policy in harmony: our best practice
EUGridPMA Status and Current Trends and some IGTF topics March 2014 Taipei, TW David Groep, Nikhef & EUGridPMA.
Assessing Combined Assurance
Assessing Combined Assurance
Policy and Best Practice Harmonisation (‘NA3’)
Leveraging the IGTF authentication fabric for research
Leveraging the IGTF authentication fabric for research
“RaaS” – towards RCauth.eu as a Service
Towards hamonized policies and best practices
WP3: Policy and Best Practice Harmonisation
OIDC Federation for Infrastructures
Updated (VO) Community Security Policies
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
OIDC Federation for Infrastructures
AARC2 JRA1 Update Nicolas Liampotis
AAI Architectures – current and future
RCauth.eu CILogon-like service in EGI and the EOSC
43rd EUGridPMA May 23-25, 2018 Karlsruhe, DE
WP3: Policy and Best Practice Harmonisation
David Groep for the entire AARC Policy Team I2TechEX18 meeting
EUGridPMA Status and Current Trends and some IGTF topics August 2018 APGridPMA Auckland Meeting David Groep, Nikhef & EUGridPMA.
David Groep for the entire AARC Policy Team AARC2 AHM4 meeting
AAI in EGI Status and Evolution
Federated Incident Response
Presentation transcript:

EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA

Recent EUGridPMA topics PMA membership and reviews Infrastructure Policy Alignment & Snctfi Up Next: AAI for research and collaboration Policy and technology Bridging using infrastructure proxies Bridging trust: assurance, security, and uniqueness in RCauth OIDC Federation at the IGTF for Research and e-Infrastructures See also the EUGridPMA42 summary: https://www.eugridpma.org/meetings/2018-01/

Geographical coverage of the EUGridPMA 26 of 28 EU member states (all except LU, MT) + AE, AM, CH, DZ, EG, GE, IR, IS, JO, MA, MD, ME, MK, NO, KE, PK, RS, RU, SY, TR, UA, CERN (int), TCS (EU), RCauth.eu (EU/NL), QV (BM) Active progress ZA 47+4

Membership and other changes Responsiveness challenges for some members PLEASE take care to renew your trust anchors in time, as well as your CRLs Identity providers: both reduction and growth Grid-FR now hosted within French government PKI infrastructure RCauth.eu distributed operations (GRNET, STFC, Nikhef) Self-audit review Cosmin Nistor as review coordinator Self-audits progressing on schedule for most CAs

Upcoming events EUGridPMA 43, Karlsruhe May 23 – 25, 2018 I2GS, TAGPMA May 6-10 (incl 10th!), San Diego, CA, USA TNC18 and REFEDS June 10, 11-14, Trondheim, NO PEARC18 July 22-26, Pittsburg, PA, USA TechEx Oct 15-18, Orlando, FL, USA

AAI in a wider context IGTF traditionally well-linked to research and e-Infrastructures support for research use cases user-centric authentication based on a ‘bottom-up’ approach In Europe, the AARC project supports evolution of ‘traditional’ R&E federations towards this research and collaboration use common Blueprint Architecture promoting SP-IdP Proxies harmonised policy supporting production use of federations (Sirtfi and “R&S”, non-reassigned identifiers and assurance) help communities express ‘common’ qualities through Snctfi allow newer technologies (OIDC) on the Infrastructure side

Assurance and trust frameworks Identity Assurance Profiles for Infrastructure risk scenarios https://igtf.net/ap/loa/ BIRCH - good quality (federated) identity, DOGWOOD - identifier-only with traceability (R&S+Sirtfi+a few bits) RFC 6711 Registry: https://iana.org/assignments/loa-profiles technology-specific ‘trust anchor’ distribution services Supporting research and e-Infrastructure use cases technology bridges: TCS, RCauth.eu, IGTF-eduGAIN bridge, … behind Infrastructure Proxies OIDC gains prominence: OIDC Fed for RP pilot Policy framework for Relying Parties (‘SP-IdPs-Proxies’) Snctfi - Community Trust Framework in Federated Infras https://igtf.net/snctfi Policy Development Kit

Snctfi: aiding Infrastructures achieve policy coherency  allow SP-IdP-Proxies to assert ‘qualities’, based on assessable trust  Develop recommendations for an Infrastructure’s coherent policy set Snctfi Scalable Negotiator for a Community Trust Framework in Federated Infrastructures Complements Sirtfi with requirements on internal consistent policy sets for Infrastructures Aids Infrastructures assert existing categories R&S, Sirtfi, CoCo Support communities and infrastructures with a policy kit and Acceptable Use Policy alignment Graphics inset: Ann Harding and Lukas Hammerle, GEANT and SWITCH https://igtf.net/snctfi

Trust for global e-Science infrastructures “establish common policies and guidelines that enable interoperable, global trust relations between providers of e-Infrastructures and cyber-infrastructures, identity providers, and relying parties” EGI HPCI PRACE PRAGMA GEANT WLCG RedCLARA XSEDE . . . OSG