Campus Middleware Issues

Slides:



Advertisements
Similar presentations
© 2012 Open Grid Forum Simplifying Inter-Clouds October 10, 2012 Hyatt Regency Hotel Chicago, Illinois, USA.
Advertisements

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Agenda 2 factor authentication Smart cards Virtual smart cards FIM CM
From Authentication to Privilege Management to the Attribute Economy: Marketing runs amok…
Autenticazione e Gestione delle Identità Giacomo Aimasso – CISM – CISA.
JISC Metaleth Project Athens, Shibboleth and the University of Bristol 29 th January 2007.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.
Federated Identity, Levels of Assurance, and the InCommon Silver Certification Jim Green Identity Management Academic Technology Services © Michigan State.
Identity & Access Management DCS 861 Team2 Kirk M. Anne Carolyn Sher-Decaustis Kevin Kidder Joe Massi John Stewart.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Copyright JNT Association 20051OptionalCopyright JNT Association 2007 Overview of the UK Access Management Federation Josh Howlett.
Peter Deutsch Director, I&IT Systems July 12, 2005
Microsoft Identity and Access Solutions Market Trends and Futures
Credential Provider Operational Practices Statement CAMP Shibboleth June 29, 2004 David Wasley.
Sierra Systems itSMF Development Days Presentation March 4 th, 2014 Colin James Assyst Implementation Specialist.
Overview of Access and Information Protection
InCommon Michigan State Common Solutions Group, January 2011 Matt Kolb
EuroPKI 2008 Manuel Sánchez Óscar Cánovas Gabriel López Antonio F. Gómez Skarmeta University of Murcia Levels of Assurance and Reauthentication in Federated.
Developments and challenges in authentication and authorisation Klaas Wierenga Berlin, 23 May 2006.
Single Sign-On Multiple Benefits via Alaska K20 Identity Federation 20 May 2011 BTOP Partner Meeting Anchorage, Alaska 20 May 2011 BTOP Partner Meeting.
1 © Material United States Department of the Interior Federal Information Security Management Act (FISMA) April 2008 Larry Ruffin & Joe Seger.
Campus Identity Management Requirements (=IAP) REFEDs meeting Mikael Linden,
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
CARSI: Federated Identity and Resource Sharing over CERNET Dr. PING CHEN Peking University( 北京大学 ) Jan, 24 th, 2008.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
2-Oct-0101 October 2001 Directories as Middleware Keith Hazelton, Senior IT Architect University of Wisconsin-Madison Keith Hazelton, Senior IT Architect.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Quarterly Customer Meeting Office 365 License Activation and Office 365 Cloud Services Assessment Status April 2014.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
European Life Sciences Infrastructure for Biological Information European Life Sciences Infrastructure for Biological Information.
Middleware: Directories Metadirectories Related Work Brendan Bellina, University of Notre Dame.
OpenRegistry MACE-Dir 5/18/09 1 OpenRegistry Initiative Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University May 2009.
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
ELIXIR AAI Michal Procházka, Mikael Linden, EGI VC 15 March 2016.
Cross-sector and user-centric AAI
EGI Updates Check-in Matthew Viljoen – EGI Foundation
Deployment Planning Services
Use case: Federated Identity for Education (Feide)
eduTEAMS platform for collaboration Niels Van Dijk
I2/NMI Update: Signet, Grouper, & GridShib
The State of Federations
University of Texas System
California State University CSUconnect Federation
Identity Management and Authorization
Timeline.
Federated Identity Management for Researchers (FIM4R)
Current Campus Issues – From My Horizon
THE STEPS TO MANAGE THE GRID
Minimal Level of Assurance (LoA)
ESA Single Sign On (SSO) and Federated Identity Management
Managing Digital Identity
Proposal to Create IAM Working Group
EduTEAMS at a Glance Mandeep Saini Linz, Austria 30 May 2017.
Topics The simple life The Simple Life GUI The full IdM life
PASSHE InCommon & Federated Identity Workshop
Guest Identities – Milan workshop goals
Identity & Access Management
AAI Architectures – current and future
"Cloud services" - what it is.
UK Access Management Federation
Identity Management at the University of Florida
Moving forward with assurance
Appropriate Access InCommon Identity Assurance Profiles
Agenda Purpose for Project Goals & Objectives Project Process & Status Common Themes Outcomes & Deliverables Next steps.
AAI in EGI Status and Evolution
Data, Policy, Stakeholders, and Governance
IT Management Services Infrastructure Services
Protecting Privacy with Federated AA
Presentation transcript:

Campus Middleware Issues Torbjörn Wiberg 091022, tf-emc2, Roma 1

Campus (non-Middleware) Issues What consequences are there of the fact that there are both campus and distance students on every course Economy, Efficiency, Roi in focus We must become much better in calculating and presenting economic consequences of the changes we propose Both before and after the changes (How) shall we act on the quick increase of cloud services Students are involved in many of our business processes

Economy of middeware How much does it cost to How much may it cost to… Issue an identity Use an identity (or use the AAI) Reset a password Loose a student due to .. slow distribution of account credentials To high requirements on LOA for initial identification How much may it cost to… How much is it worth to have authoritative information in our enterprise database

Middleware Issues Design and deploy of a campus middleware infrastructure Increased efficiency and flexibility in the IdM process Become a federation member, understand and exploit the possibilities with federations Moving focus from… authentication to authorisation directories to metadirectories

Campus middleware infrastructures = Dir+IdM+Metadirectory+AuthnS+AuthrS Deployment slow Metadirectory issues are complicated Boundaries between maintenance objects are up for discussion whenever there is a need to update or further develop a system component

IdM process issues Initial identification of distance education students We have to be quicker – waiting on an identity, as a student or personnel, is time and money lost

Technical Issues The number of systems integrated increases quickly raising the requirements on planning the system maintenance process Group and role management is an increasingly important support function as the number of users of enterprise systems increases provisioning and attribute services cms, lms, cscw, business systems

Federation Issues non-technical issues dominating what services are of interest how do we provide what authorisation information to service providers internal and external service providers

From Authn to Authr Again: The technology is not the botleneck Within an institution – each system owner wants system specific attributes for authr Between institutions – the community is waking up, and becoming aware of the fact that there are more attributes to discuss than eduPersonAffiliation

LOA There are two perspectives ... and two documents from the IdP – who wants to say that they issue eIDs at a certain LOA from the System – who wants to decide what LOA constitutes a risk they are prepared to take for each operation different eIDs ... and two documents The NIST Special Publication 800-63 Reference:M-04-04, Memorandum to the heads of all departments and agencies

Identities on different LOA How do you upgrade to an higher level LOA One LOA per IdP or not