High-quality Internet for higher education and research AAI from the NREN perspective Schiphol, October 17, 2005

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Terena Mobility Taskforce update Klaas Wierenga SURFnet.
Licia Florio EUNIS05, Manchester 1 Eduroam EUNIS Conference, June Licia Florio.
Copyright JNT Association 2006 The JANET Roaming Service.
TAC - Poznan, 6 June 2005 Building trust with a European style Diego R. Lopez RedIRIS.
EduRoam ESA workshop 17 December 2004 Utrecht.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
EuroCAMP Ljubljana, 3-5 March 2006 TERENA Server Certificate Service Towards the large-scale use of affordable popup-free server certificates for the European.
Network Access and 802.1X Klaas Wierenga SURFnet
High-quality Internet for higher education and research Federated network access with Klaas Wierenga SURFnet Ljubljana, April.
TF-EMC2 February 2006, Zagreb Deploying Authorization Mechanisms for Federated Services in the EDUROAM Architecture (DAME) -Technical Project Proposal-
High-quality Internet for higher education and research eduroam EuroCAMP, Porto, November 9, 2005
Federated Identity Management for the context of storage Bart Kerver - TERENA Storage-meeting, Amsterdam,
EDINA 20 th March 2008 EDINA Geo/Grid - Security Prof. Richard O. Sinnott Technical Director, National e-Science Centre University of Glasgow, Scotland.
EduRoam: movilidad por Europa... y España Toledo, 29 de octubre de 2004
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
Deliverable H: the interoperability testbed design Klaas Wierenga SURFnet.
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
The TERENA Academic CA Repository. eIRG Meeting. Dublin, 16/04/2004 Diego R. Lopez – TF-AACE  Task Force on Authentication and.
Wireless ambitions Frans Panken I2 Spring meeting 24 april 2012.
EduRoam Australia Project Experience in location independent wireless networking with international collaboration with TERENA EduRoam Project 19 th APAN.
(From Radius Hierarchy to AAI) Miroslav Milinović University Computing Centre - Srce EuroCAMP Ljubljana, March 2006.
EuroPKI 2008 Manuel Sánchez Óscar Cánovas Gabriel López Antonio F. Gómez Skarmeta University of Murcia Levels of Assurance and Reauthentication in Federated.
Developments and challenges in authentication and authorisation Klaas Wierenga Berlin, 23 May 2006.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Connect. Communicate. Collaborate First steps in federation peering: eduGAIN and eduroam Diego R. Lopez - RedIRIS.
TNC2004 Rhodes 1 Authentication and access control in Sympa mailing list manager Serge Aumont & Olivier Salaün May 2004.
High-quality Internet for higher education and research Paul Dekkers April 4th, Turkey.
Michal Procházka, Jan Oppolzer CESNET.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
High-quality Internet for higher education and research do you like to puzzle, build an AAI ! xxx AA systems 2nd EuroCAMP - Porto November 8, 2005
EMI INFSO-RI AAI in EEF Projects John White (Helsinki University) EMI Security Area Leader.
Connect. Communicate. Collaborate Federation Interoperability Made Possible By Design: eduGAIN Diego R. Lopez (RedIRIS)
Comité Réseau des Universités News from CRU activities: Identity federation, eduroam, PKI, SCS, Sympa, security policies cru.fr 7th.
802.1X in SURFnet 22 May 2003.
OGF22 25 th February 2008 OGF22 Demo Slides Prof. Richard O. Sinnott Technical Director, National e-Science Centre University of Glasgow, Scotland
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
Connect. Communicate. Collaborate The authN and authR infrastructure of perfSONAR MDM Ann Arbor, MI, September 2008.
Connect. Communicate. Collaborate AAI scenario: How AutoBAHN system will use the eduGAIN federation for Authentication and Authorization Simon Muyal,
Connect. Communicate. Collaborate Federated peering the NREN way: eduGAIN and eduroam Diego R. Lopez (RedIRIS) Klaas Wierenga (SURFnet)
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Connect. Communicate. Collaborate TERENA Networking Conference, 7 june 2005 Eduroam: past, present, and future.
Diego R. Lopez, RedIRIS JRES2005, Marseille On eduGAIN and the Coming GÉANT Middleware Infrastructure.
NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Authentication and Authorisation in eduroam Klaas Wierenga, AA Workshop TNC Lyngby, 20th May 2007.
Deploying Authorization Mechanisms for Federated Services in eduroam Klaas Wierenga, EuroCAMP Helsinki, 17&18th April 2007.
Community PKIs Initiatives Updates TF-EMC2 Meeting Loughborough, UK 6-7 May, 2009 Licia Florio, TERENA
PAPI-PERMIS Integration Project Proposal David Chadwick
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
Programme ›TERENA ›Overview of the middleware initiatives in the European Higher Education ›What is eduroam: the technology and how to set up eduroam ›eduroam-in-a-box:
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Connect. Communicate. Collaborate educonf Coordinated support of European videoconferencing under the GN2 SA6 framework Dimitris Daskopoulos, GRNET, AUTH.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Workshop on Security for Web Services. Amsterdam, April 2010 Applying SAML to Identity Data Exchange.
AAI Interconnection with an European style Diego R. Lopez RedIRIS.
Connect. Communicate. Collaborate Applying eduGAIN to network operations The perfSONAR case Diego R. Lopez (RedIRIS) Maurizio Molina (DANTE)
Project Moonshot Daniel Kouřil EGI Technical Forum
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
10 Years of eduroam (from an idea to a product)
Applying eduGAIN to network operations The perfSONAR case
First steps in federation peering: eduGAIN and eduroam
TF-Mobility update TF-EMC2, Barcelona 9 September 2005.
The DAMe’s First Steps: eduroam and NAS-SAML
Some data about the CBIC Federation
Multi-Domain User Applications Research (JRA3)
Presentation transcript:

High-quality Internet for higher education and research AAI from the NREN perspective Schiphol, October 17, 2005

High-quality Internet for higher education and research Contents NRENs and AAI Federations for Network Access –eduroam Federations for Application (Web) Access –AuthN –AuthZ –eduGAIN Supporting Services –SCHAC –PKI’s –SCS –TACAR Questions

High-quality Internet for higher education and research The AAI domain Authentication Systems Administrative Systems Autorisation Systems Applications login

High-quality Internet for higher education and research NREN’s and AAI In the beginning there were: –Network access solutions –Web single sign-on solutions –Identity management systems –Authorisation engines –PKI’s –Directories Then: need for collaboration beyond institutional borders: Federations Now: need for collaboration beyond national borders: Confederations

High-quality Internet for higher education and research Federated network access: eduroam Security –IEEE 802.1X Roaming –RADIUS Trust –Policies

High-quality Internet for higher education and research eduroam architecture RADIUS server University B RADIUS server University A SURFnet Central RADIUS Proxy server Authenticator (AP or switch) User DB Supplicant Gast Student VLAN Commercial VLAN Employee VLAN data signalerling Trust based on RADIUS plus policy documents 802.1X (VLAN assigment)

High-quality Internet for higher education and research Tunneled authentication (PEAP/TTLS) Uses TLS/SSL tunnel to protect data –The TLS tunnel is set up using the server certificate, thus authenticating the server and preventing man-in-the- middle attacks –The user sends his credentials through the secure tunnel to the server, thus authenticating the user Can use dynamic session keys for ‘in the air’ encryption © Alfa&Ariss

High-quality Internet for higher education and research Status of eduroam Over 400 institutions in Europe and Australia USA, Taiwan will follow shortly

High-quality Internet for higher education and research Federated application (Web) access A number of web single sign-on solutions exist –Shibboleth (Australia, Finland, Switzerland, UK etc.) –PAPI (Spain, UK) –A-Select (Netherlands, Australia) –FEIDE/Moria (Norway) Authorisation Systems –PERMIS –SPOCP Single technology federations are or have been built Now through the Geant2 JRA5 project these will be integrated.

High-quality Internet for higher education and research Web AuthN: A-Select “Black box” that: Accepts many authentication methods Interfaces with many applications Allows an institution to take authN out of the application

High-quality Internet for higher education and research Web AuthZ: Shibboleth Allows institutions that belong to the same federation to share resources Lingua Franca: SAML © SWITCH

High-quality Internet for higher education and research eduGAIN Goal: to federate federations Web-services and SAML based As much as possible Shibboleth compatible 4 basic interactions: –AuthnReq/Resp –HLSReq/Resp –AttrReq/Resp –AuthZReq/Resp Defining parameters, protocols and profiles

High-quality Internet for higher education and research Supporting services: SCHAC SChema HArmonisation Committee Find agreement on a set of minimal attributes to facilitate inter-institutional and international data- exchange An initial list of attributes has been agreed Let the schema evolve as time goes by and needs arise Work is ongoing to define a formal LDAP schema SCHAC would help the Bologna process

High-quality Internet for higher education and research Supporting services: PKI’s PKI’s are complex “Pop-up problem” Path validation problems Cross certification tedious NREN’s never managed to distribute client certificates on a large scale Server certificates cost money But the GRID community seem to have pulled this thing off!

High-quality Internet for higher education and research Supporting services: Server Certificate Service (SCS) Flat-fee Pop-up free Server certificates only! Rooted in commercial CA provider National RA’s Pilot funded by ACONET, CARNet, CESNET, CRU(RENATER), RedIRIS, SURFnet, SWITCH and UNI-C Currently in procurement procedure

High-quality Internet for higher education and research Supporting services: TACAR Trusted repository of verified root-CA certificates for NRENs and not for profit research projects rooted in academic community. Currently containing: –AustrianGridCA, CERN CA, CESNET CA, DFN PCA, DOEGrids, DutchGrid, EGCA, EuroPKI, Grid Canada CA, Grid-Ireleand CA, GridKa CA, GRNET, HellasGrid CA, IGC CRU, INFN CA, LIP CA, NIIF CA, RedIRIS, SURFnet, SWITCH, SwUPKI, UK e-Science CA, University of Thessaloniki Root of trust for International Grid Trust Federation (IGTF) Notice all the GRID certificates, it seems that we have found each other here already!

High-quality Internet for higher education and research Questions Is there life beyond certificates in the GRID? How do you do authorisation? How do you overcome the Grid infrastructure scalability problems? –Certificates deployment and life cycle management –Sources of authority “VO” (many VOs and users belonging to many of them) –Plug-and-play, Plug-and-be-played How may we help you? How can you help us?

High-quality Internet for higher education and research More information eduroam – TERENA TF-Mobility – TERENA TF-EMC2 – – TACAR – Géant2 Joint Research Activity 5 (authorisation and roaming) –