Programme ›TERENA ›Overview of the middleware initiatives in the European Higher Education ›What is eduroam: the technology and how to set up eduroam ›eduroam-in-a-box:

Slides:



Advertisements
Similar presentations
1 European Research Networking Development Activities Karel Vietsch TERENA
Advertisements

Lousy Introduction into SWITCHaai
Usage of PGP in TACAR 19th OGF Meeting Chapel Hill, USA February 1, 2007 Licia Florio Project Development Officer
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
TERENA: European Collaboration in Research and Education Networking Belarus-Poland NREN Cross Border Link Inauguration Event Minsk, Belarus,
Federated Digital Rights Management Mairéad Martin The University of Tennessee TERENA General Assembly Meeting Prague, CZ October 24, 2002.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public University of the Future 1 TF-Mobility future Klaas Wierenga
Media Management and Distribution Workshop Next Step… Media Management and Distribution Workshop Zurich, Switzerland January, 2009 Peter Szegedi.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI - Identity Management Steven Newhouse Director, EGI.eu Federated Identity.
TechSec WG: Related activities overview Information and discussion TechSec WG, RIPE-45 May 14, 2003 Yuri Demchenko.
TAC - Poznan, 6 June 2005 Building trust with a European style Diego R. Lopez RedIRIS.
The EARNEST Foresight Study Results from the EARNEST Technical Study Licia Florio, TERENA EARNEST Workshop, Amsterdam, 8.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
EuroCAMP Ljubljana, 3-5 March 2006 TERENA Server Certificate Service Towards the large-scale use of affordable popup-free server certificates for the European.
Federated Identity Management for the context of storage Bart Kerver - TERENA Storage-meeting, Amsterdam,
The TERENA Academic CA Repository. eIRG Meeting. Dublin, 16/04/2004 Diego R. Lopez – TF-AACE  Task Force on Authentication and.
Credential Provider Operational Practices Statement CAMP Shibboleth June 29, 2004 David Wasley.
EduRoam Australia Project Experience in location independent wireless networking with international collaboration with TERENA EduRoam Project 19 th APAN.
SWITCHaai Team Federated Identity Management.
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
To identity federation and beyond! Josh Howlett JANET(UK) HEAnet 2008.
John Dyer Business & Technology Strategist TERENA Business & Technology Strategist December 2013 European NRENs Evolution.
CASE: Haka federation EuroCAMP, 3-5 April, 2006 CSC, the Finnish IT Center for Science
Directory Services at UMass  Directory Services Overview  Some common definitions  What can a directory do or not do?  User Needs Assessment  What.
New Developments in Authentication and Access Management Alan Robiette JISC Development Group JISC-NSF-DLI2 Meeting, 2002.
Bert van Pinxteren Jornadas Técnicas RedIRIS, 26 October Developments in RedIRIS as seen in the Context of Developments in other NRENs
Single Sign-On Multiple Benefits via Alaska K20 Identity Federation 20 May 2011 BTOP Partner Meeting Anchorage, Alaska 20 May 2011 BTOP Partner Meeting.
John Dyer Business & Technology Strategist TERENA 10 February 2014 TF-MSP Meeting ACOnet, Vienna Aggregation of Demand Collaborative.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
John Dyer Business & Technology Strategist TERENA Business & Technology Strategist 4 October 2013 European NRENs Evolution.
Helsinki Institute of Physics (HIP) Liberty Alliance Overview of the Liberty Alliance Architecture Helsinki Institute of Physics (HIP), May 9 th.
TERENA Updates TF-EMC2 Meeting Bologna 7-8 Nov 2011 Licia Florio
High-quality Internet for higher education and research do you like to puzzle, build an AAI ! xxx AA systems 2nd EuroCAMP - Porto November 8, 2005
High-quality Internet for higher education and research AAI from the NREN perspective Schiphol, October 17, 2005
TERENA TF-EMC2 Workshop David Groep,
Kerberos and Identity Federations Daniel Kouřil, Luděk Matyska, Michal Procházka, Tomáš Kubina AFS & Kerberos Best Practices Worshop 2008.
Shibboleth at Columbia Update David Millman R&D July ’05
Comité Réseau des Universités News from CRU activities: Identity federation, eduroam, PKI, SCS, Sympa, security policies cru.fr 7th.
John DYER African Research & Education Networking 26 September 2005, Geneva. 1 Setting up an NREN European Experiences John DYER Chief Technical Officer.
Claudio Allocchio TERENA Technical Programme - Update General Assembly, 21 October 2005, Budapest 1 TERENA Technical Programme Update Claudio Allocchio.
TERENA Activities Internet2 Members Meeting, International Task Force 8 October 2007.
Connect. Communicate. Collaborate The authN and authR infrastructure of perfSONAR MDM Ann Arbor, MI, September 2008.
TERENA update Karel Vietsch TERENA CEO Internet2 Fall Meeting, Atlanta 30 October 2000.
TNC 2006, Catania TERENA Technical Programme 2006 update Claudio Allocchio VP Technical Programme.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
New Developments in Access Management: Setting the Scene Alan Robiette JISC Development Group JISC-CNI Conference, June 2002.
Federations, the Data Protection Directive and WP29 TF-EMC2 Mikael Linden, CSC, the Finnish IT Center for Science.
Connect. Communicate. Collaborate Universität Stuttgart A Client Middleware for Token- Based Unified Single Sign On to eduGAIN Sascha Neinert, University.
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Authentication and Authorisation in eduroam Klaas Wierenga, AA Workshop TNC Lyngby, 20th May 2007.
Deploying Authorization Mechanisms for Federated Services in eduroam Klaas Wierenga, EuroCAMP Helsinki, 17&18th April 2007.
Community PKIs Initiatives Updates TF-EMC2 Meeting Loughborough, UK 6-7 May, 2009 Licia Florio, TERENA
G É ANT2 Development Support Activity and the Republic of Moldova 1st RENAM User Conference Chisinau, Republic of Moldova 14-May-2007 Valentino Cavalli.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
1 Identities and Federation: The Next IT Wave (The Canadian Access Federation) Rick Bunt President The Canadian University Council of CIOs (CUCCIO)
European collaboration on research networking development update on TERENA activities Karel Vietsch TERENA CEO Spring 2002 Internet2 Member Meeting Arlington.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
AAI Interconnection with an European style Diego R. Lopez RedIRIS.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Internet Governance: A View From the RIPE NCC Paul Rendek Director External Relations, RIPE NCC Ukrainian Internet Governance Forum 2-3 September 2011.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
TERENA Organisation A not-for-profit association of European National Research and Education Networks Based in Amsterdam, The Netherlands Membership: 36.
Presentation transcript:

Programme ›TERENA ›Overview of the middleware initiatives in the European Higher Education ›What is eduroam: the technology and how to set up eduroam ›eduroam-in-a-box: a tool to ease eduroam deployment ›eduroam federation

Overview of Middleware Developments in Europe Eduroam MiniCAMP April 5, 2007 Licia Florio, Paul Dekkers, Rok Papež TERENA, SURFnet, ARNES

Outline ›What is TERENA ›European landscape in higher education ›TERENA’s role ›Why Federated Identity ›Federation concepts ›A quick look at the future

TERENA Organisation ›A not-for-profit association of European National Research & Education Networks (since 1986) ›NRENs ›Secretariat located in Amsterdam (The Netherlands) ›33 National Members ›2 International Members: ›CERN, ESA ›10 Associate Members ›including DANTE, NORDUnet, equipment vendors and telecoms operators

TERENA Mission ›Collaborate ›Innovate ›Share knowledge ›TERENA does not run a network!

TERENA Mission ›Represent common interests and opinions of membership ›Make political and industrial contacts ›Lobby European Union and national governments ›Liaise with other continents (e.g. APAN, Internet2, CLARA) ›Knowledge Transfer ›Conferences TNC: Copenhagen 21 to 24 May 2007 ›Vendor demonstrations, new technologies, NREN showcase ›Workshops & Seminars ›eduroam Minicamp and others ›Developing informational, best-practice and training material. ›TERENA activities are open to everyone ›TERENA community is wider than the TERENA membership ›Activities span over different field ›See htttp://

TERENA Support to Middleware Deployment ›TERENA provides support for the middleware activities: ›Via Task Forces (open to anybody) ›TF-Mobility ›TF-EMC2 ›Via services like ›Server Certificate Service (SCS) ›Schema HArmonisation Committee (SCHAC) ›TERENA Academic CA Repository (TACAR) ›Workshops ›EuroCAMP (Apirl 16-17, Helsinki) ›NREN-Grids (June, date and location tbc)

Services: SCS ›What is it about? ›SCS= Server Certificate Service ›To issue server certificates - popup free - unlimited number - Very low price (price is not per certificate) -Already 1400 certificates issued ›For whom? ›For the National Research and Education Network community in Europe ›How did we get there? ›Example of Terena interaction with industry for benefit of research networks

What is TACAR ›TACAR: TERENA ACAdemic Repository ›Offers a way for building a PKI-based web of trust within the European academic community ›And beyond ›>25 root CA certificates (root of trust for IGTF) ›Conceived as a collection of trust-anchors ›Based on the principle: ›Keep it simple ›TACAR is open to: ›All NRENs; › National Academic PKI ’ s in the TERENA member countries; › Non-profit research projects (Grid CA ’ s)

EuroCAMP ›Workshops to promote the use of middleware technologies in the Campuses ›Three EuroCAMP workshops took place already ›Topics covered: IdM systems and Federations mainly ›Very successful ›Since June 06 MiniCAMPs ›Organised as part of GEANT2/NA4 project ›Focused on eduroam ›So far three events have been organised

Services: ›TF-EMC2 ›Harmonise schemas in the field of high education ›Complements eduPerson schema from Internet2 ›Mainly concerned for inter-institutional data exchange ›Needed for interoperability ›Which data ›What format of data

What is Identity Management ›From a global perspective: ›Identity Management ›Giving each user an electronic identity ›Set of technologies and policies to control users access to resources ›Can be anything ›SQL database ›passwd file ›LDAP/AD ›More needs, more complexities ›Kerberos ›Web based SSO

The Needs For Federated Identity ›Increasing dynamics in the education system ›Students can access courses outside their organisation ›On-line courses are more common ›Users want to access the same services no matter where they are ›Grid: example of access to distributed resources ›Centralized login ›More institutions dealing with the same users means: ›Multiple registration of users ›Overhead to manage guest users › Increased possibility of error in managing the users ’ records ›Sharing of user identity ›Institutional borders ›International borders ›User logs in with the same credentials on the same page for every resource

Federations ›Enable the sharing of educational resources ›Network ›Wireless and/or not ›Applications ›Online learning systems ›Require agreement on: ›Legal Framework and Policies ›Trust ›Technology ›Security ›Common Language ›Interoperability

Example of Not Federated Access User from Inst X InstX Y Institution Y X Institution X Learning Material Network

Example of Federated Access User Inst X Learning Material Network Institution Y Federated Access Others Resources… Institution X

The Building Blocks of Federations Identity ProviderService Provider publisher webmail

Federated Access to (Web) Applications ›Federations are being developed at national level by the NRENs ›Different (open source) solutions are used ›Shibboleth: UK, Finland, Switzerland ›PAPI: Spain ›A-Select: the Netherlands ›Sun Federation Manager based upon Liberty Alliance specification: Norway ›All these solutions are now inter-operable ›eduGain › They all recognize Security Assertion Markup Language (SAML) as “ the standard ” to transfer information (assertions) among each other

Federated Network Access ›Eduroam tests started in TF-Mobility ›Excellent example of a confederation

Conclusions ›Federations are the future ›Campuses/universities need to be involved ›Deploying IdMs is the first step to make life easier ›The campuses need to talk to their NRENs ›There will not be one unique multipurpose federation ›Different federations to fit different communities ›TERENA wants to promote cooperation and help the campuses to deploy middleware