RCauth.eu CILogon-like service in EGI and the EOSC


Similar presentations
CLARIN AAI, Web Services Security Requirements

AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration David Groep AARC All Hands meeting Milano Policy and Best Practice.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No B2ACCESS LSDMA.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Authentication and Authorisation for Research and Collaboration David Groep AARC 3 rd AHM meeting Mapping component distribution.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
Building Trust for Research and Collaboration
Introduction to AAI Services
WLCG Update Hannah Short, CERN Computer Security.
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
The RCauth.eu CILogon-like service in the EGI AAI
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
User Community Driven Development in Trust and Identity
Policy and Best Practices … the Story So Far
eduTEAMS platform for collaboration Niels Van Dijk
Policy and Best Practice Harmonisation
Christos Kanellopoulos
Policy and Best Practices … the Story So Far
CheckIn: the AAI platform for EGI
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Check-in Nicolas Liampotis
Boosting AAI for research and collaboration
Bringing Harmonized Policy and Best Practice
Towards hamonized policies and best practices
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
The RCauth.eu CILogin-like TTS Pilot in EGI
Sustainability for the AARC CILogin-like TTS Pilot
Policy in harmony: our best practice
Assessing Combined Assurance
Assessing Combined Assurance
Leveraging the IGTF authentication fabric for research
Leveraging the IGTF authentication fabric for research
“RaaS” – towards RCauth.eu as a Service
Policy and Best Practice … in practice
WP3: Policy and Best Practice Harmonisation
AARC Athens AHM meeting – NA3 session
OIDC Federation for Infrastructures
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
Updated (VO) Community Security Policies
AARC Blueprint Architecture and Pilots
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
OIDC Federation for Infrastructures
AAI Architectures – current and future
David Kelsey (STFC-RAL)
Community AAI with Check-In
AAI in EGI Status and Evolution
Federated Incident Response
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
Presentation transcript:

RCauth.eu CILogon-like service in EGI and the EOSC Deployment and Sustainability Models for the AARC CILogon-like TTS Pilot David Groep AARC NA3 coordinator, EGI AAI-TCB Nikhef PDP group EGI TCB-AAI May 2017 RCauth.eu is operated by Nikhef as part of the Dutch National e-Infrastructure for Research coordinated by SURF for the benefit of the collective European Research and e-Infrastructures

Aim: seamless access to existing services with eduGAIN for all Pan-European Access not country-opt-in based standards-based assurance No Changes to the Model for infrastructures and their service providers 1 : Dispersed User Base critical mass is beyond any single institution $ exec $oidc-> authenticate() echo "Hola $name" Command-line and VOMS with delegation and brokering Concentrate Sensitive Components no long-term token needs in the VO portal credential management by the Infrastructures Minimal Coding for the VO portals

CILogon-like TTS Pilot, the User’s work flow user login flow: VO portal → Community Infrastructure → RCauth service → federated AAI credential flow: authentication, SAML federation, Policy Filter, OpenID Connect, PKIX+OIDC, (VOMS), proxy-on-portal R&S science gateways delegation AARC Master Portal or Infrastructure Solution filtering WAYF server

Token Translator RCauth.eu service component Needs security and policy expertise (people) – and ability to maintain accreditation Needs operational and technical capabilities (hardware): hardware security modules, managed data centres, off-line and on-line secure areas, trained personnel, designate infrastructure to security operations Connects to – a handful of – Master Portals (MPs) with explicit agreements to take care of user credential protection and compliance Connects (many, we hope scalably) federations, IdPs and (few) SP-IdP-Proxies Serves many communities, some of which we don’t yet know, and beyond just the European e-Infrastructures Considerations: Trust and compliance, with IGTF accreditation Single logical instance, with HA built in for production Managed by a consortium: in Europe agreed by at least EGI, EUDAT, GÉANT, ELIXIR, and SURF

Where are we today? In ‘pre-production’ since May 2016, now several connections deployed to EGI, ELIXIR, DNI/SURF, … ‘production demonstrator’ instance of Rcauth.eu set up in the ‘right way’ at Nikhef (only for now): Dedicated secure environment, FIPS 140 level 3 approved HSM, anchored in a stable way Policy and practices accredited under ‘unique-identifier’ profile at the IGTF – good enough for some infrastuctures, and within EGI in combination with vetted & managed communities Scalable negotiation model based on Sirtfi and REFEDS R&S section 6 Requirements on attached credential stores defined (for key protection) Trust anchors in production (RCauth.eu is part of the ‘EGI-CAM’ package) But it’s a production demonstrator, not true production, without an SLA, and with limited capacity (~2k users) … and it’s a bit a ‘Heath Robinson’ service, using mostly pre-available hardware … intended availability is high, but no on-site 24x365, nor redundancy

Planned RCauth.eu management model shared governance through a Policy Management Authority non-discriminatory policy and practices joint PMA authoritative for policy and operations Stakeholders EGI, EUDAT, SURF, GÉANT, ELIXIR, … in-kind or explicit contributions of services, kit, and operators trust by any and all global relying parties Infrastructure-specific Master Portals and Credential Repository user contact service by specific stakeholder

Service distribution and support plans Beyond just the ‘Nikhef Best Effort’ service what is ‘the service’ in this context: Delegation Service & WAYF can be anywhere between a few kEur to well over 100+kEur cost per year … Recuperation model Master Portals (Credential Management) from other (non-RCauth) funding Delegation Service/RCauth.eu: free at point of use funded via in-kind contributions by the major e-Infrastructures distributed H/A setup, leveraging existing capabilities and some additional person effort EOSC Hub Consortium picked middle ground contribute effort and some hardware resources to the joint pan-European pool help steer the development through joint, independent, management body (PMA) partners with existing security operations expertise: GRNET, STFC, FZJ + SURF/Nikhef

References https://wiki.geant.org/display/AARC/Models+for+the+CILogon-like+TTS+Pilot https://www.rcauth.eu/ DIY demo – for users from Sirtfi’ed R&S Institutions, or through the IGTF eduGAIN bridge: https://rcdemo.nikhef.nl/

and to Jim Basney of NCSA, CTSC and CILogon davidg@nikhef.nl Parts of this work have also been performed as part of the work programme of EGI-ENGAGE EGI-Engage is co-funded by the Horizon 2020 Framework Programme of the European Union under grant number 654142 Thanks to all collaborators on this joint enterprise: EGI, EUDAT, GEANT, SURF; Nikhef, GRNET, Christos Kanellopoulos and to Jim Basney of NCSA, CTSC and CILogon davidg@nikhef.nl