Https://aarc-project.eu Authentication and Authorisation for Research and Collaboration Niels van Dijk AARC General Meeting Authentication and Authorisation.

Slides:



Advertisements
Similar presentations
Cancún - Mexico, Andrea Biancini Towards a Federation as a Service From IdP in the Cloud project to FaaS.
Advertisements

Client Installation StratusLab Tutorial (Orsay, France) 28 November 2012.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
StratusLab is co-funded by the European Community’s Seventh Framework Programme (Capacities) Grant Agreement INFSO-RI Virtual Machine Isolation.
EMI INFSO-RI AAI in EEF Projects John White (Helsinki University) EMI Security Area Leader.
Advanced Topics StratusLab Tutorial (Orsay, France) 28 November 2012.
Technical Break-out group What are the biggest issues form past projects – need for education about standards and technologies to get everyone on the same.
Authentication and Authorisation for Research and Collaboration Pilots on the Integrated R&E AAI Paul van Dijk, Activity Lead Pilots.
Test your IdP
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Authentication and Authorisation for Research and Collaboration Mikael Linden AARC all hands Milan Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
Authentication and Authorisation for Research and Collaboration AARC general meeting in Milan, November 3 Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Milan, Italy Training and Outreach Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos
Networks ∙ Services ∙ People Daniela Pöhn REFEDS EWTI, Vienna IdPs and Federations Service Aspects of Assurance SA5T1.
June 9, 2009 SURFfederatie: implementing a multi- protocol federation Hans Zandbelt & Joost van Dijk, SURFnet.
Networks ∙ Services ∙ People Bert van Pinxteren General Assembly, Porto, Portugal Transition to one GÉANT Annual Review June,
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Networks ∙ Services ∙ People Ann Harding eduGAIN Town Hall eduGAIN in the GÉANT Project Activity Leader GÉANT Trust and Identity.
Networks ∙ Services ∙ People Ann Harding GÉANT Symposium, Vienna Users Session A3 Trust and Identity March GÉANT Activity Leader Trust.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
Networks ∙ Services ∙ People Mandeep Saini TNC15, Porto, Portugal Virtual organisation Authorisation Management Practices in Research and.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Authentication and Authorisation for Research and Collaboration Bari, Italy Training and Outreach Authentication and Authorisation.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Networks ∙ Services ∙ People Andrea Biancini #TNC15, Porto, Portugal Implementing Grouper to federate user authorization Federated Authorization.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE PY5 new activities Peter Solagna – EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
Authentication and Authorisation for Research and Collaboration Heiko Hütter, Martin Haase, Peter Gietz, David Groep AARC 3 rd.
StratusLab is co-funded by the European Community’s Seventh Framework Programme (Capacities) Grant Agreement INFSO-RI StratusLab: Enhancing Grid.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
Status and plans of AARC SA1 Libraries pilots Pete Birkinshaw, Martin Haase, Peter Gietz / DAASI Lalla Mantovani, Barbara Monticini,
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Operating Systems & Information Services CERN IT Department CH-1211 Geneva 23 Switzerland.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Utrecht.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC f-2-f Meeting One Year of AARC Utrecht, 24 May.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Networks ∙ Services ∙ People TNC 2016, Prague Alice Through the Looking Glass Science DMZ goes above the network 13 June
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Authentication and Authorisation for Research and Collaboration TeSS Service Provider Training, Manchester Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Networks ∙ Services ∙ People Ann Harding Networkshop 44, Manchester Thinking globally, acting locally Trust and Identity in the GÉANT project.
Authentication and Authorisation for Research and Collaboration Brussels Training and Outreach Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Networks ∙ Services ∙ People Mandeep Saini AARC/CORBEL Workshop Collaborative Organisation Platform as a Service June 1, 2016, Paris Product.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Authentication and Authorisation for Research and Collaboration On behalf of the MJRA1.2 scribes J Jensen.
Networks ∙ Services ∙ People Di4R Network. Services. People. GÉANT 28 th September, Krakow.
Status Umbrella ID Mirjam van Daalen.
Web application hosting with Openshift, and Docker images
Web application hosting with Openshift, and Docker images
Implementing bomgar remote support tool in the school of medicine
eduTEAMS platform for collaboration Niels Van Dijk
Identity Federations - Overview
Revamping IdP in the Cloud pilot activities
ESA Single Sign On (SSO) and Federated Identity Management
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
Multi-Domain User Applications Research (JRA3)
Community AAI with Check-In
WP6 – EOSC integration J-F. Perrin (ILL) 15th Jan 2019
Presentation transcript:

Authentication and Authorisation for Research and Collaboration Niels van Dijk AARC General Meeting Authentication and Authorisation for Research and Collaboration AARC pilots Platform 03 November 2015 Paul’s sidekick Technical Project Manager, SURFnet

For all outward facing pilots we should run on a platform with ‘enough’ attention to security, branding and availability Production VM platform VPN access and key based AuthN Real certificates Real AARC DNS Use appropriate logo’s Provide some basic services for testing As AARC will not run services in the long run, we should aim for reproducibility so VOs or others can pick up our results Document the setup in the AAR wiki Discuss setup proposal with peers Install using tools like e.g. JENKINS, PUPPET or ANSIBLE for deployment Development work may be done wherever you like 2 AARC pilot platform Goals

~okeanos IaaS platform, kindly provided by GRnet Resources available VMs: 30 Hard Disk Storage GB CPUs: 50 RAM: 60.0 GB Private networks: 10 Public IPs: 30 AARC OS Images will become available preconfigured with VPN & SSH access, FW and NTP and uptime monitoring enabled CentOS 7 Debian 8.x Ubuntu LTS 3 AARC pilot platform Resources

Access: VPN based on ZeroTier (clients: SSH & sudo based on pubkey only (Service for providing pubkeys will be available shortly) All ports available within VPN subnet (no firewalling) HTTPS publicly available by default Other public ports upon request DNS - *.pilots.aarc-project.eu Please put the DNS name(s) you need in the pilot description HTTPS Certificates: *.pilots.aarc-project.eu Use a star certificate for all aarc pilots Do NOT use this for SAML signing! (selfsigned Certs is good) Support Office Hours, Best effort Use AARC Pilot Gitlab for request and issues 4 AARC pilot platform Access, DNS and certificates

Test IdP(s) AARC Shibboleth IdP – with test users AARC SimpleSAMLphp IdP – with test users AARC Mujina IdP – on the fly IdP provisioning ( UnitedID ( Test SP SimpleSAMLphp; just showing received attributes Metadata registration Metadata for SPs and IdPs must be registered in REEP ( Test IdPs will accept any AARC SP in REEP Central Discovery Service uses REEP Do we need eduGAIN integration for Pilots? 5 AARC pilot platform Testing Services

Think trough your setup Write down your pilot plan in the template and discuss planning with your Pilot activity lead and Paul Request resources via AARC gitlab 6 AARC pilot platform How do I get this?

© GÉANT on behalf of the AARC project. The work leading to these results has received funding from the European Union’s Horizon 2020 research and innovation programme under Grant Agreement No (AARC). Thank you Any Questions?