Federations round table Haka federation of Finland EuroCAMP 17.4.2007 Mikael Linden CSC, the Finnish IT Center for Science.

Slides:



Advertisements
Similar presentations
Federation management A mess? Nordunet Conference Mikael Linden CSC, the Finnish IT Center for Science.
Advertisements

Eduserv Athens Federations David Orrell Eduserv Athens Technical Architect.
Innovation through participation GÉANT Data Protection Code of Conduct (DP CoC) FIM for research collaboration workshop Mikael Linden,
Resource Entitlement Management System Manne Miettinen Mikael Linden Janne Lauros CSC – IT Center for Science.
5/25/2015 AEB/Yleisesittely Roaming network access using Shibboleth in University of Helsinki Fall 2004 Internet2 Member Meeting 29th of September, 2004.
Kalmar Union Mikael Linden CSC, the Finnish IT Center for Science.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
Innovation through participation eduGAIN federation operator training eduGAIN policy eduGAIN training in Vienna Oct 2011
UC Irvine’s Pre-Shib Attribute Setup PH / QI Directory Provides Authoritative Attribute Store –Had both Faculty / Staff and Student Information UCI’s Campus.
UCLA’s Shibboleth Plan Shibboleth is an integral part of UCLA’s Enterprise Directory & Identity Management Infrastructure (EDIMI) Project Integrate with.
CSC – Tieteen tietotekniikan keskus Oy CSC – IT Center for Science Ltd. The Language Bank of Finland User Authentication and Authorization Service
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
CSC Grid Activities Arto Teräs HIP Research Seminar February 18th 2005.
Credential Provider Operational Practices Statement CAMP Shibboleth June 29, 2004 David Wasley.
Educause 2006, Dallas TX What does a University need from Access Management? John Paschoud InfoSystems Engineer, LSE Library London School of Economics.
Refeds federation survey update Theme of the day: Campus Identity Management TF-EMC2 Umeå 9th Jul 2008 CSC, the Finnish IT Center.
SWITCHaai Team Federated Identity Management.
AAI with simpleSAMLphp
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science
Exploring InCommon Getting Started with InCommon: Creating Your Roadmap.
The ReFEDS/GÉANT Code of Conduct (CoC) An Approach to Compliance with the EU Data Protection Directive Steve Carmody April 23, 2012.
Copyright JNT Association 2005Copyright JNT Association An Introduction to Access Management and the UK Federation Simon Cooper.
I2Q & WMnet Pilot Presented by Jason Rousell – i2Q Jay Neale - i2Q.
Australian Access Federation and other Middleware Initiatives Presented at TF-EMC2, Prague 4 Sep 2007 Patty McMillan, The University of Queensland.
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
Update Finland TF-EMC Mikael Linden CSC, the Finnish IT Center for Science.
HAKA project HAKA User administration inside Finnish Higher Education Institutes results from the KATO project Barbro Sjöblom EDS 2003 Uppsala.
Shibboleth in Finnish Higher Education Organisations E-ICOLC 2005 Poznan, Poland.
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
Serving society Stimulating innovation Supporting legislation Danny Vandenbroucke & Ann Crabbé KU Leuven (SADL) AAA-architecture for.
Kalmar Union, a Conferedation of Nordic Identity Federations TNC2009 Mikael Linden, CSC Andreas Solberg, UNINETT.
Introduction Moonshot workshop
10/25/2015 AEB/Yleisesittely Organising Federated Identity in Finnish Higher Education TNC2005 Mikael Linden June 8th, 2005.
Campus Identity Management Requirements (=IAP) REFEDs meeting Mikael Linden,
Current list of common attributes of the EDIT federation Single Sign-On for the EDIT platform Lutz Suhrbier¹, Andreas Kohlbecker², Andreas Müller² 1 Freie.
Schac attributes and common vocabularies TF-EMC Mikael Linden CSC, the Finnish IT Center for Science.
Kalmar Union lessons: Findings in federation harmonisation REFEDS Mikael Linden, CSC.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
VETUMA, the web portal for strong authentication Tietotekniikkaosasto Ismo Aulaskari
SAML a mature six year old? Glenn Wearen, Paul Caskey & Josh Howlett.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Services Information University Project Sentinel Middleware & Identity Management for the Health Sciences Chad La Joie Georgetown University.
Innovation through participation eduGAIN policy: A worm report TF-EMC2 Vienna Mikael Linden, CSC The worm farmer.
Federations, the Data Protection Directive and WP29 TF-EMC2 Mikael Linden, CSC, the Finnish IT Center for Science.
CARSI: Federated Identity and Resource Sharing over CERNET Dr. PING CHEN Peking University( 北京大学 ) Jan, 24 th, 2008.
Authentication and Authorisation for Research and Collaboration Mikael Linden AARC all hands Milan Authentication and Authorisation.
Haka federation status  24 institutions and IdPs end users 96% coverage in universities, 41% in polytechnics  41 services Elearning Libraries.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Clain update TF-EMC Mikael Linden, CSC.
Attribute Delivery - Level of Assurance Jack Suess, VP of IT
Innovation through participation EduGAIN policy (working draft) Status update REFEDs 30th May 2010
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Leveraging Campus Authentication to Access the TeraGrid Scott Lathrop, Argonne National Lab Tom Barton, U Chicago.
6/12/2016 AEB/Yleisesittely WLAN roaming experiences using Shibboleth TNC 2004, Rhodes 7th of June, 2004 Mikael Linden, Viljo Viitanen,
User Registration in the SeaDataNet V1 system by Dick M.A. Schaap – technical coordinator Oostende, June 08.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Innovation through participation Data Protection Code of Conduct (DP CoC) TNC2013 conference, 4 June 2013 Mikael Linden, CSC – IT Center for Science
Using Your Own Authentication System with ArcGIS Online
John O’Keefe Director of Academic Technology & Network Services
Minimal Level of Assurance (LoA)
ESA Single Sign On (SSO) and Federated Identity Management
Klaas Wierenga, EuroCAMP Helsinki, 17&18th April 2007
The French federation Eurocamp 2007 Helsinki
eduPersonAffiliation semantics – a spin-off of eduGAIN policy
Vendor Portal Registration Procedures
GEANT Data protection Code of Conduct 2.0 REFEDS meeting 16 June 2019
Presentation transcript:

Federations round table Haka federation of Finland EuroCAMP Mikael Linden CSC, the Finnish IT Center for Science

Status of Haka Federation  Operational 8/2005  23 (of 48) Federation Members with end users (68% of eduPersons; in universities 90%)  3 Federation partners Library content providers, ASP service providers  13 IdPs operational with end users (51% of eduPersons)  20 SPs  logins in March 2007  federating sw: Shibboleth ver IdPs still running Shibboleth 1.2

SPs in the federation Library services  Nelli portal (Ex libris Metalib)  Library management system (Endeavor Voyager) eLearning  Moodle, A&O, Optima learning management systems CSC’s services  Funet extranet  Scientist’s Interface Student administration  Application form for becoming a visiting student HR administration  Competence management system/ASP (Personec hr) Other administration  Process database for universities WLAN roaming (Jyväskylä polytech)

Campus IdM policies in Haka federation Home organisations must make sure that  only fresh attributes are released to SPs when an end user departs, the accounts must be closed (or the roles updated) no later than in seven days  initial authentication face-to-face (or similar) using photo ID issued by the police  on-line authentication at least with passwords no less than 8 characters + other quality checks

Campus IdM policy enforcement in Haka  Home organisation publishes its IdM practices in the web using a template provided by federation operator;  Self-Audit for joining IdPs When an IdP is registered to the federation, the federation operator checks the published document to assess if minimum requirements are met If OK, the IdP is added to the federation metadata  If it turns out that the policy is not followed by a home organisation there is a procedure for dropping a home organisation from the federation

Privacy and the Data Protection Directive (DPD) in Haka 1.Only SPs related to research and education can be registered to the federation DPD: dependability on the purpose of processing personal data 2.Only attributes relevant for the service are released to an SP when a new SP is registered, the SP admin declares the relevant attributes based on the declaration, federation operator constructs and distributes Shibboleth Site-ARPs to the IdPs 3.End user’s informed consent is a requirement for attribute release to make the consent informed, the end user is provided with a link to the service’s privacy policy document

Schemas, roles and groups in Haka  funetEduPerson 2.0 schema incorporates schac  roles/groups in funetEduPerson eduPersonAffiliation – a Finnish interpretation of the vocabulary is presented in funetEduPerson funetEduPersonStudentCategory – 10 categories for students (BSc,MSc,doctor,other,open-university,exchange-student…) students’ target degree – e.g. MSc in Engineering students’ educational degree probram – e.g. Political history students’ specialisation option – e.g. software engineering student status – present/absent student union membership schacHomeOrganizationType – university/polytechnic

Level of assurance for authentication in Haka  currently one LoA: the miminum requirement is a password stronger methods ”can be used” University of Helsinki has had a pilot on PKI/Smartcards in Shibboleth 1.x IdP  Waiting for Shibboleth/SAML2.0 authentication context concept Services asking for certain level of authentication  candidates for stronger authentication PKI/smartcards OTPs provided by the Finnish banks