Intro to Identity for Developers Tom Barton, U Chicago Scott Cantor, Ohio State Patrick Michaud, U Washington.

Slides:



Advertisements
Similar presentations
The Basics of Federated Identity. Overview of Federated Identity and Grids Workshop Session 1 - for all Basics and GridShib Session 2 – more for developers.
Advertisements

Open Grid Forum 19 January 31, 2007 Chapel Hill, NC Stephen Langella Ohio State University Grid Authentication and Authorization with.
The Art of Federations. Topics Federations of what… Federated identity versus federations Federations in other sectors – business, gov, ad hoc R&E Federations.
The Internet2 NET+ Services Program Jerry Grochow Interim Vice President CSG January, 2012.
Managing Roles & Privileges with Grouper and Signet Middleware Nate Klingenstein (some words stolen from Tom Barton & Lynn Mcrae) Helsinki EuroCAMP, April.
Drive-By Dialogues. Presenter’s Name Topics The Long Strange Trip of I2 – NLR Merger A Brief Comment on Optical Networking Middleware Developments Security.
A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Internet Scale Identity, Collaboration and Higher Education.
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
InCommon and Federated Identity Management 1
Widely Distributed Access Management Tom Barton University of Chicago.
Presenter’s Name InCommon Approximately 80 members and growing steadily More than two million “users” Most of the major research institutions (MIT joining.
InCommon Policy Conference April Uses  In order to encourage and facilitate legal music programs, a number of universities have contracted with.
New CyberInfrastructure for Collaboration between Higher Ed and NIH.
A Model for Enterprise Group and Affiliation Management RL “Bob” Morgan University of Washington CAMP, June 2005.
Signet and Grouper for Distributed Attribute Administration
Introduction to Grouper Part 1: Access Management & Grouper Tom Barton University of Chicago and Internet2 Manager – Grouper Project.
Stuff Ken Klingenstein. Stuff sack InCommon Stuff Infocard, Open Id, etc… Federation soup Cormack slides on EU (and US) privacy International.
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
The InCommon Federation The U.S. Access and Identity Management Federation
BfB: Supporting Collaboration with Infrastructure.
I2/NMI Update: Signet, Grouper, & GridShib Tom Barton University of Chicago.
Maturation & Convergence in Authentication & Authorization Services in US Higher Education: Keith Hazelton, Sr. IT Architect, University.
External Identity and Authorization in GENI. Topics Federated identity and virtual organizations ABAC Creating and transporting attributes.
Federated Identity and the International Research Community Dr Ken Klingenstein Director, Internet2 Middleware and Security.
Campus middleware in the service of Science Keith Hazelton Internet2 Middleware Architecture Committee for Education NSF Internet2 Day October 19, 2006.
VO and Internet2 Middleware. Presenter’s Name Topics Motivations for Internet2 Middleware work Federated identity and InCommon Other IdM Groups, privileges,
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
What is Cyberinfrastructure? Russ Hobby, Internet2 Clemson University CI Days 20 May 2008.
Middleware Support for Virtual Organizations Internet 2 Fall 2006 Member Meeting Chicago, Illinois Stephen Langella Department of.
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Using Signet and Grouper for Access Management Using Signet and Grouper for Access Management Tom Barton, University of Chicago Lynn McRae, Stanford University.
Social Identity Working Group Steve Carmody. Agenda Intro to Using Social Accounts Status and Recent News –Current UT Pilot –Current InCommon Pilot with.
Collaborative Platforms. Collaborations and Virtual Organizations IdM is a critical dimension of collaboration, crossing many applications.
COmanage and InCommon: Present and Future Activities and Interactions Heather Flanagan, COmanage Project Coordinator, Internet2.
Federations 101 John Krienke Internet2 Fall 2006 Internet2 Member Meeting.
Integrated Institutional Identity Infrastructure: Implications and Impacts RL “Bob” Morgan University of Washington Internet2 Member Meeting, May 2005.
A Role for Libraries in Helping Users Manage Collaboration.
Access Information Management Tom Barton University of Chicago.
Virtual organizations: Team Science, Team Shakespeare.
Taking Care of Our Core Business: Managing Collaborations Dr. Ken Klingenstein, Senior Director, Internet2 Middleware and Security.
Scared Straight… if you want to go outside… Authenticate Locally, Act Globally.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Cyberinfrastructure Overview Russ Hobby, Internet2 ECSU CI Days 4 January 2008.
More Allergic Reactions Some Potential Next Steps Tom Barton University of Chicago.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
~60 staff 1.Collaborators around the world 2.Supports communities of collaborators external to Internet2 3.Community uses wiki, mailing lists, instant.
Current Middleware Picture Tom Barton University of Chicago Tom Barton University of Chicago.
Federated Identity in the Global Landscape. Presenter’s Name Topics Federated identity basics International deployments and issues National, local and.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
1 Identities and Federation: The Next IT Wave (The Canadian Access Federation) Rick Bunt President The Canadian University Council of CIOs (CUCCIO)
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Leveraging Campus Authentication to Access the TeraGrid Scott Lathrop, Argonne National Lab Tom Barton, U Chicago.
Collaboration and Federated Identity Two powerful forces being leveraged – the rise of federated identity – the bloom in collaboration tools, most particularly.
LIGO Identity and Access Management
I2/NMI Update: Signet, Grouper, & GridShib
John O’Keefe Director of Academic Technology & Network Services
ESA Single Sign On (SSO) and Federated Identity Management
The Future of Indoor Plumbing
New CyberInfrastructure for Collaboration between Higher Ed and NIH
Context, Gaps and Challenges
NSF Middleware Initiative: GridShib
Signet Privilege Management
Guests and Collaborators
A History of the Next Five Years: (the rise of indoor plumbing)
Virtual organizations: Team Science, Team Shakespeare
Signet & Privilege Management
Signet Privilege Management
Presentation transcript:

Intro to Identity for Developers Tom Barton, U Chicago Scott Cantor, Ohio State Patrick Michaud, U Washington

Plan for the afternoon [All] Why are we here? [Tom] Internet2 Middleware big picture [Scott] Identity-enabling web applications Break [Patrick] Catalyst case study [Tom] Collaboration management [All] IAM current issues 2

Earlier Identity & Access Management plumbing Federations are rising Later Identity Services Collaboration management 3 Internet2 Middleware Initiative (I2MI) big picture themes

Many Sources of Authority Policy making bodies Resource managers Program/activity heads Self Identification vs. authorization Distributed management Within an organization Among organizations Common & articulating infrastructure Departments/programs/activities should not have to build their own Articulate between organizations Access Management Realities 4

To ease the management of inter-org collaborative activities, campus IAM practices must be good enough Identification & identifiers Authentication Attributes Common practices & standards Early I2MI revelation 5

Pre-indoor plumbing

Basic enterprise-wide services that are used by many applications Now being extended through federations to include inter-institutional and virtual organization needs Authentication, single sign on, directories, identifiers, authorization and privilege management Perhaps workflow, digital rights management, enterprise service bus and a few others As much policy, governance, and practice as technology I2MI's notion of middleware

Application integration Administrative Academic and collaborative Institutional and business process integration Working with authoritative sources Becoming an authoritative source People and process time - not software and hardware expense Making it reliable, flexible and invisible – true indoor plumbing Keys to success in middleware

9

Identity & Access Management reflected in a campus LDAP entry uid: tbarton chicagoID: N eduPersonAffiliation: staff isMemberOf: uc:drdepts:nsit:integration uc:adhoc:fact uc:directors uc:nsit:srdirs uc:nsit:integration:iteco_wr app:gems:44:251:staff uid: tbarton chicagoID: N eduPersonAffiliation: staff isMemberOf: uc:drdepts:nsit:integration uc:adhoc:fact uc:directors uc:nsit:srdirs uc:nsit:integration:iteco_wr app:gems:44:251:staff

New tools Management Capabilities Infrastructure & Application Integration Distributed Management Namespace Management Delegation Roles Privileges Externalize Access Management

Relative Roles of Signet & Grouper Users are placed into groups Privileges are assigned to groups Groups can be arranged hierarchically to give privileges indirectly Grouper manages groups Signet manages privileges Aligns with diverse Sources of Authority Grouper Signet

13 Privilege Elements by Example By authority of the Dean grantor principal investigators grantee (group/role) who have completed training prerequisite can approve purchases function in the School of Medicine scope for research projects resource up to $100,000 limit until January 1, 2009 as long as a faculty member at … conditions Privilege Lifecycle

Single domain University (usually!) Single service domain, two user domains Campus services & users, plus "guests" Single service domain, many user domains Higher Ed service providers such as … Library services, administrative ASPs, direct-to-student services Many service domains, many user domains State & regional consortia Some Virtual Orgs or Collaborative Orgs Some grid infrastructures Sources of Authority & access management infrastructure are distributed across domains Multi-domain access scenarios 14

15 Federated Identity "IdP" "SP" ala Shibboleth

16 The rise of federations Federations are now occurring broadly, and internationally, to support inter-institutional and external partner collaborations Almost all in the corporate world are bi- lateral; almost all in the R&E world are multilateral They provide a powerful leverage of enterprise (campus, site) credentials Federations are learning to peer Internal federations are also proving useful

17 InCommon Federation: Essential Data US R&E Federation, a 501(c)3 Addresses legal, LoA, shared attributes, business proposition Members are universities, service providers, government agencies, national labs Over 80 organizations and growing steadily 1.7 million user base now Uses range over popular and academic content, wiki and list controls, ASPs, NIH, MS DreamSpark, …

Trust fabric: Metadata so that IdP's & SP's can mutually authenticate & interoperate Multilateral agreement among federation participants Agree to actually operate as they claim to A “Where Are You From Service” available InCommon Federation: Essential Services 18

19 Campus Science Gateway provision accounts run monitor attributes run monitor InCommon Federation TeraGrid Resources ~10 Sites run monitor ~20 Sites ~125 Sites Example: TeraGrid and multiple domains

In the cloud 20 ServiceSelf IdentityAttributes Org IdentityAttributes Many technologies

Decouple application design from implementation of identity services Identity Services 21 Application Attributes PrivsGroups Identity Intro- duction Authen- tication

Two powerful forces being leveraged the rise of federated identity the bloom in collaboration tools, most particularly in the Web 2.0 space but including file shares, list procs, etc Collaboration management platforms provide identity services to “well-behaved collaboration applications” Results in user and collaboration centric identity, not tool-based identity Collaboration and Federated Identity

Management of collaboration a real impediment to collaboration, particularly with the growing variety of tools Goal is to develop a “platform” for handling the identity management aspects of many different collaboration tools Platform includes a framework and model, specific running code that implements the model, and applications that take advantage of the model This space presents possibilities of improving the overall unified UI as well as UI for specific applications and components. Collaboration Management Platforms

A collaboration management platform, supported in part by a NSF OCI grant, being developed by the Internet2 community, with Stanford as a lead institution Open source, open protocol Uses Shibboleth, Grouper, and Signet Parallels activities in the UK and Australia COmanage

Already done Sympa, Federated wikis, Asterisk (open-source IP audioconferencing), Dim-Dim (open-source web meeting), Bedeworks (federated open-source calendar) Immediate targets Rich access controlled wikis Web-based file shares, IM, Google Apps for Education Domain science resources Instruments Grids Comanageable applications

Some general COmanage comments A limited number of consoles present the basic identity services; can move directly between services as a standard workflow Early in the development; the GUI is particularly primitive Underlying store is an LDAP directory; alternatives include MySQL db, RTF store, etc. COmanage can be deployed by a campus, a department, a VO, a VO service center; COmanage instances communicate with each other by the “attribute ecosystem” voodoo

Federated Wiki Domain Science Grid Domain Science Instrument University AUniversity B Laboratory X Collaboration Management Platform Collaboration Tools/ Resources Application Attributes Home Org & Id Providers/ Sources of Authority Attribute Ecosystem Flows Attribute/Resource Info Data Store Collaboration Management Platform (CMP) and the Attribute Ecosystem Sources of Authority C o Authorization – Group Info Authorization – Privilege Info Authentication People Picker Other Functions manage File Sharing Calendar Phone/ Video Conference List Manager

Level of Assurance Campus Roles Shibboleth & Active Directory OpenID and (campus) attributes Privacy & consent Guest management Current issues in IAM 28