CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

Federation management A mess? Nordunet Conference Mikael Linden CSC, the Finnish IT Center for Science.
Resource Entitlement Management System Manne Miettinen Mikael Linden Janne Lauros CSC – IT Center for Science.
JISC Metaleth Project Athens, Shibboleth and the University of Bristol 29 th January 2007.
5/25/2015 AEB/Yleisesittely Roaming network access using Shibboleth in University of Helsinki Fall 2004 Internet2 Member Meeting 29th of September, 2004.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Kalmar Union Mikael Linden CSC, the Finnish IT Center for Science.
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
UCLA’s Shibboleth Plan Shibboleth is an integral part of UCLA’s Enterprise Directory & Identity Management Infrastructure (EDIMI) Project Integrate with.
CSC – Tieteen tietotekniikan keskus Oy CSC – IT Center for Science Ltd. The Language Bank of Finland User Authentication and Authorization Service
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Copyright JNT Association 20051OptionalCopyright JNT Association 2007 Overview of the UK Access Management Federation Josh Howlett.
CSC Grid Activities Arto Teräs HIP Research Seminar February 18th 2005.
Refeds federation survey update Theme of the day: Campus Identity Management TF-EMC2 Umeå 9th Jul 2008 CSC, the Finnish IT Center.
SWITCHaai Team Federated Identity Management.
AAI with simpleSAMLphp
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
Feide is a identity management system on a national level for the educational sector in Norway. Federated Electronic Identity for Norwegian Education Tromsø,
AAF Middleware update February Presented by Terry Smith Technical Manager and Heath Marks Manager.
Innovation through participation Interfederation through eduGAIN - steps and challenges eduGAIN interfederation service Federated Identity Systems.
Exploring InCommon Getting Started with InCommon: Creating Your Roadmap.
TNC2004 Rhodes 1 Authentication and access control in Sympa mailing list manager Serge Aumont & Olivier Salaün May 2004.
I2Q & WMnet Pilot Presented by Jason Rousell – i2Q Jay Neale - i2Q.
Australian Access Federation and other Middleware Initiatives Presented at TF-EMC2, Prague 4 Sep 2007 Patty McMillan, The University of Queensland.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
Helsinki Institute of Physics (HIP) Liberty Alliance Overview of the Liberty Alliance Architecture Helsinki Institute of Physics (HIP), May 9 th.
Update Finland TF-EMC Mikael Linden CSC, the Finnish IT Center for Science.
HAKA project HAKA User administration inside Finnish Higher Education Institutes results from the KATO project Barbro Sjöblom EDS 2003 Uppsala.
Shibboleth in Finnish Higher Education Organisations E-ICOLC 2005 Poznan, Poland.
Kalmar Union, a Conferedation of Nordic Identity Federations TNC2009 Mikael Linden, CSC Andreas Solberg, UNINETT.
10/25/2015 AEB/Yleisesittely Organising Federated Identity in Finnish Higher Education TNC2005 Mikael Linden June 8th, 2005.
Campus Identity Management Requirements (=IAP) REFEDs meeting Mikael Linden,
Schac attributes and common vocabularies TF-EMC Mikael Linden CSC, the Finnish IT Center for Science.
Kalmar Union lessons: Findings in federation harmonisation REFEDS Mikael Linden, CSC.
Federations round table Haka federation of Finland EuroCAMP Mikael Linden CSC, the Finnish IT Center for Science.
Copyright JNT Association 20051Optional Copyright JNT Association The UK federation Mark Tysom, JANET(UK) 9 October 2007.
SAML a mature six year old? Glenn Wearen, Paul Caskey & Josh Howlett.
Innovation through participation eduGAIN interfederation service for research and education Cern FedID workshop in RAL, UK 2-3 Nov 2011 Mikael Linden,
Services Information University Project Sentinel Middleware & Identity Management for the Health Sciences Chad La Joie Georgetown University.
Innovation through participation eduGAIN policy: A worm report TF-EMC2 Vienna Mikael Linden, CSC The worm farmer.
Center for Scientific Computing Ltd. Development of Funding Models for FUNET Markus Sadeniemi CSC - Center for Scientific Computing Ltd
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Federations, the Data Protection Directive and WP29 TF-EMC2 Mikael Linden, CSC, the Finnish IT Center for Science.
CARSI: Federated Identity and Resource Sharing over CERNET Dr. PING CHEN Peking University( 北京大学 ) Jan, 24 th, 2008.
Copyright JNT Association 20051Optional Copyright JNT Association The UK federation TNC - 22 nd May 2007 Mark Tysom, UKERNA.
Haka federation status  24 institutions and IdPs end users 96% coverage in universities, 41% in polytechnics  41 services Elearning Libraries.
/ 8 FEIDHE Electronic Identification in Finnish Higher Education Janne Kanner FEIDHE Electronic Identification in Finnish Higher Education.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Licensing in a European Perspective - case Finnish National Consortium ELAG 2001, Prague Kristiina Hormia-Poutanen.
Stanford University & National Student Clearinghouse Shibboleth Pilot CAMP Phoenix, AZ February 5, 2009.
June 9, 2009 SURFfederatie: implementing a multi- protocol federation Hans Zandbelt & Joost van Dijk, SURFnet.
Programme ›TERENA ›Overview of the middleware initiatives in the European Higher Education ›What is eduroam: the technology and how to set up eduroam ›eduroam-in-a-box:
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Andrea Biancini #TNC15, Porto, Portugal Implementing Grouper to federate user authorization Federated Authorization.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
How eduGAIN can help education: a real life story Sabita Behari Product Manager TNC14.
Innovation through participation Data Protection Code of Conduct (DP CoC) TNC2013 conference, 4 June 2013 Mikael Linden, CSC – IT Center for Science
WACREN EduID Fostering Identity Federations in West and Central Africa 3rd Sci-GaIA Workshop Dar es Salaam, Tanzania – 5 th September Omo Oaiya.
David Millman—Columbia January 2005
Géant-TrustBroker Dynamic inter-federation identity management
John O’Keefe Director of Academic Technology & Network Services
ESA Single Sign On (SSO) and Federated Identity Management
The French federation Eurocamp 2007 Helsinki
Some data about the CBIC Federation
Presentation transcript:

CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science

Outline  Finnish higher education overview  Status  Technology  Organisation  Privacy  Service categories  Institutional Identity Management

Finnish higher education overview  20 universities, 29 polytechnics (universities of applied sciences) Small units spread all over the country  degree students, employees CSC, the Finnish IT Center for Science  Non-profit company owned by the ministry of education  To provide centralised IT services to higher education and research Scentific computing, supercomputing Funet – the Finnish national research network (NREN) Haka identity federation

Status of Haka federation  Pilot federation operational 12/2003  Production federation operational 8/2005  Current members: 8/20 universities, 5/29 polytechnic Big universities; coverage 72% of eduPersons in universities Goal: 12/ /20 universities, 15/29 polytechs  Agreement for federation partners available, no partners yet  IdPs and SPs 8 IdPs 8 SPs ~ logins to services in February 2006

Technology in Haka  Shibboleth 1.2/1.3 Implemented IdP-side logout as an add-on feature  Schema: funetEduPerson 1.0 eduPerson + 10 national attributes (national identity code, date of birth, homeOrganization, student number, target degree/educational program/major of a univ/polytech student) Going to release a new version soon (Schac adopted)  PKI/Server certificates: Sonera CA (a pop-up free Finnish CA) CSC has a framework agreement with Sonera CA  Federation metadata management: SWITCH’s Resource Registry We (the operator) use it internally only  WAYF: going to migrate to the PHP WAYF of SWITCH To be placed in a commercial High Availability machineroom with 24x7 monitoring

Haka is a service provided to the institutions by CSC (”the operator”) Federation partners Operator Federation members CSC – scientific computing ltd Central AAI services IdPPalvelu IdPPalvelu IdPSP Advisory comm.Operations comm.

Haka federation and privacy  In Finland, Personal data act implements the data protection directive  Only relevant attributes are released to a SP When a new SP is registered to the federation, the SP provides a list of necessary attributes to the operator The operator constructs the site-ARP and distributes it to IdPs as part of the federation metadata  IdP asks user’s consent for attribute release beforehand After Shib IdP authenticates the user, before s/he is redirected back to the SP  To make the consent informed, the Privacy Policy of the SP is provided to the user The operator has a centralised service that gathers links to the Privacy Policies of the SPs in the federation IdP may use a redirection service with a simple interface

Resource categories so far 1.Library services  The library management system (Voyager), the library portal (Metalib), the digital content repository (Encompass, work in progress)  The content providers (work in progress) 2.eLearning services  Learning management systems (Moodle, A&O, Optima)  Electronic application form for becoming a visiting student in another Finnish university ( 3.Nationally provided services  CSC’s extranet services to researchers  Research funding application form (work in progress) 4.ASP services in the administration of the institution  Circulation of travel expence reports & incoming invoices (work in progress)  HR software/Employee self-service (work-in-progress)

Haka federation and the quality of institutional identity management  High-quality institutional identity management is a necessity for an IdP joining Haka The typical problem: accounts not closed as students/employees leave the organisation Best practice: link the IdP’s user database to student&HR registry  When a new IdP is being registered to the federation, the institution makes an IdM self-audit The operator checks that the minimum requirement is fulfilled

Supporting institutions to improve IdM: ”School in user administration”  CSC’s workshop of 3 days for staff in IT departments in HEIs  1 st day 1/2005 -Theory, best practices, commercial/open source products… -First homework: evaluate your current institutional IdM 2 nd day 5/2005 -homeworks gone through -The concept of an identity federation introduced -Second homework: set target for your institutional IdM 3 rd day 11/2005 -Again, homeworks gone through -More best practices and products…

Future Challenges  Shibboleth/SAML 2.0  Focus from new IdPs to new SPs  Monitoring, reporting and configuration management  Trying to catalyse commercial companies to provide IdP hosting for small institutions  More ASP services  Cross-national confederation

More Information   TNC’05 conference paper “Organising Federated Identity in Finnish Higher Education”, available: resentations/show.php?pres_id=77