OIDC Federation for Infrastructures

Slides:



Advertisements
Similar presentations
David Groep Nikhef Amsterdam PDP & Grid Evolving Assurance – IGTF LoA generalisation David Groep Interoperable Global Trust Federation IGTF Documents at.
Advertisements

Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
David Groep Nikhef Amsterdam PDP & Grid Evolving Assurance – going where? Collaborative, distributed, and generalized assurance beyond just identity authentication.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
Building Trust for Research and Collaboration
Introduction to AAI Services
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
Bring the WLCG federation Home
Policy and Best Practices … the Story So Far
eduTEAMS platform for collaboration Niels Van Dijk
Policy and Best Practice Harmonisation
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
Building Interoperable Global Trust
AARC Strategy and Approach
Policy and Best Practices … the Story So Far
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Check-in Nicolas Liampotis
Boosting AAI for research and collaboration
Bringing Harmonized Policy and Best Practice
Towards hamonized policies and best practices
Minimal Level of Assurance (LoA)
The RCauth.eu CILogin-like TTS Pilot in EGI
Sustainability for the AARC CILogin-like TTS Pilot
EUGridPMA Status and Current Trends and some IGTF topics October 2017 APGridPMA Autumn Meeting David Groep, Nikhef & EUGridPMA.
Frameworks for harmonized policies and practices
Policy in harmony: our best practice
Assessing Combined Assurance
Assessing Combined Assurance
Policy and Best Practice Harmonisation (‘NA3’)
Leveraging the IGTF authentication fabric for research
Leveraging the IGTF authentication fabric for research
“RaaS” – towards RCauth.eu as a Service
Towards hamonized policies and best practices
WP3: Policy and Best Practice Harmonisation
AARC Athens AHM meeting – NA3 session
OIDC Federation for Infrastructures
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
Updated (VO) Community Security Policies
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
RCauth.eu CILogon-like service in EGI and the EOSC
WP3: Policy and Best Practice Harmonisation
David Groep for the entire AARC Policy Team I2TechEX18 meeting
EUGridPMA Status and Current Trends and some IGTF topics August 2018 APGridPMA Auckland Meeting David Groep, Nikhef & EUGridPMA.
Community AAI with Check-In
David Groep for the entire AARC Policy Team AARC2 AHM4 meeting
AAI in EGI Status and Evolution
WISE Information Security for collaborating e-Infrastructures David Kelsey (STFC-RAL, UK Research and Innovation) ISGC2019, Taipei, 2 April 2019 In collaboration.
JRA1: Integrated AAI Developments
Authentication and Authorisation for Research and Collaboration
Federated Incident Response
WISE, SCI & policy templates David Kelsey (STFC-RAL, UK Research and Innovation) FIM4R & TIIME, Vienna, 11 February 2019.
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

OIDC Federation for Infrastructures leveraging the IGTF global infrastructure trust framework with OIDC technology David Groep co-supported by the Dutch National e-Infrastructure coordinated by SURF, by EOSC-HUB, and by AARC

Trust for global e-Science infrastructures “establish common policies and guidelines that enable interoperable, global trust relations between providers of e-Infrastructures and cyber-infrastructures, identity providers, and relying parties” EGI OSG PRACE HPCI GEANT WLCG PRAGMA RedCLARA XSEDE . . . 24 December 2018 Interoperable Global Trust Federation 2005 - 2018

Assurance and trust frameworks Identity Assurance Profiles for R/E-Infra risk scenarios (https://igtf.net/ap/loa/) “BIRCH” - good quality (federated) identity, “DOGWOOD” - identifier-only, but with traceability (R&S+Sirtfi+a few bits) RFC 6711 Registry: https://iana.org/assignments/loa-profiles technology-specific ‘trust anchor’ distribution services Policy framework for Relying Parties (‘SP-IdPs-Proxies’) Snctfi - Community Trust Framework in Federated Infras https://igtf.net/snctfi How can we help support RI and e-Infrastructure use cases? technology bridges: TCS, RCauth.eu, IGTF-eduGAIN bridge, … behind the Infrastructure Proxies for research & collaboration, OIDC gains prominence 24 December 2018 Interoperable Global Trust Federation 2005 - 2018

Snctfi: aiding Infrastructures achieve policy coherency  allow SPIdP Proxies to assert ‘qualities’, categories, based on assessable trust  Develop recommendations for an Infrastructure’s coherent policy set Snctfi Scalable Negotiator for a Community Trust Framework in Federated Infrastructures Derived from SCI, the framework on Security for Collaboration among Infrastructures Complements Sirtfi with requirements on internal consistent policy sets for Infrastructures Aids Infrastructures to assert existing categories to IdPs REFEDS R&S, Sirtfi, DPCoCo, … https://igtf.net/snctfi Graphics inset: Ann Harding and Lukas Hammerle, GEANT and SWITCH

OIDC Fed use cases for research and e-Infrastructures EOSC-HUB registration of clients goal for EGI and EUDAT is a scalable and trusted form of OIDC usage. Today < O(50) clients; next year maybe O(100-1000)? cloud-based services (containers, microservices) could push that to millions CILogon (and XSEDE) use cases see need for a set of policies and practices that support a 'trust anchor distribution'-like service targeting OIDC OPs and RPs and where RPs that are ‘in the community’ can be identified as such ELIXIR (and the Life Sciences) AAI expect growth in # OIDC RPs as AAI extends beyond just ELIXIR and into other biomedical RIs – potentially dynamically created All of these need a policy framework, on both the (infrastructure) OPs and on the RPs This is the community that traditionally also relied on the IGTF trust anchor distribution https://www.eugridpma.org/meetings/2018-01/summary-eugridpma-2018-01-prague.txt 24 December 2018 Interoperable Global Trust Federation 2005 - 2018

IGTF OIDC Federation Task Force The IGTF task force for OIDC Federation will identify specific objectives – I2 TechEx scope needs and requirements for R/E infrastructure OIDC Fed – Prague EUGridPMA 42 verify compatibility of IGTF Assurance Profile framework for ‘technology-agnosticity’ with OpenID Providers (proxies) and RPs test an OIDCFed scenario e.g. starting with use cases: WLCG, RCauth.eu, ELIXIR/LS, EGI CheckIn, … assess structure and needed meta-data in a ‘trust anchor service’, how to address RPDNC links it with (dynamic) client registration liaise with OIDC Fed efforts in AARC and GN*-*, and Roland Hedberg

OIDC Fed pilots Based on the spec by Roland Hedberg scoped to the RP + Proxy case is not very complex, actually Infrastructures can use trusty shortcuts that would be too costly at the general R&E scale leverage existing policy and trust framework ‘pilot’ RPs and proxies will be using scripting and glue to get integration with existing services, based on assessed trust framework we can leverage existing trust

Can we do without a single one to rule them all? today the RIs and EIs trust the IGTF trust anchors and may (but do rarely) add their own Can the ‘federation’ be the community and import a commonly trusted set? Can the IGTF allow devolved registration provided that the trusted organisations implement the same policy controls Snctfi and the proper Assurance Profiles? 24 December 2018 Interoperable Global Trust Federation 2005 - 2018

For the benefit of Research Infras … IGTF membership process and Snctfi jointly give you the trust of Infra SPs (RPs) use peer-reviewed (self-)assessment as foundation of the ‘scientific process’ of trust technical details on how the IGTF FedOp will sign and distribute meta-data statements – subject to discussion at TIIME, AARC, and IGTF meetings new communities and (proxy) operators can join IGTF any time there is no fee or something like that but we request participation in the peer-review and assessment process … 24 December 2018 Interoperable Global Trust Federation 2005 - 2018

Information sharing Keeping in touch http://wiki.eugridpma.org/Main/OIDCFed oidcfed@igtf.net (https://igtf.net/mailman/oidcfed) but don’t forget everyone else! oidcre@lists.refeds.org (REFEDS) TIIME, TNC, TechEx, …

Building a global trust fabric Questions? Building a global trust fabric Interoperable Global Trust Federation 2005 - 2018