Download presentation
Presentation is loading. Please wait.
1
Introduction Moonshot workshop 6.2.2014 Mikael.Linden@csc.fi
2
2 Connect | Communicate | Collaborate Federated identity in Finnish HE Haka – WebSSO (47 organisations) eduroam – network access (30 organisations) Project Moonshot – non-web SSO Combination of the two above Standardisation (IETF) implementation (Mac, Linux, FreeBSD, Windows, Openssh, OpenLDAP, Samba, Apache, NFS…) Piloting (GN3plus)
3
3 Connect | Communicate | Collaborate Moonshot technical architecture 3 SSH clientSSH serverRADIUS server (2) SSH negotiation(4) RADIUS (3) Authentication (1) Username/password issued to the user (5) Attributes (6) SSH session OpenSSH used as example of application; many others also apply Slide by Janet(UK)
4
4 Connect | Communicate | Collaborate Benefits Information security –Password never exposed to the SP (and a rootkit) –Audit trail to serve forensics analysis –Accounts closed when the user departs Usability –Less usernames and passwords for the user Service provisioning –Removes obstacles for streamlining service provisioning to the users
5
5 Connect | Communicate | Collaborate Downsides Understanding it requires wide competence –RADIUS, SAML, GSS-API… Requires client-side software installation –Moonshot libraries and Identity selector Still early work…
6
6 Connect | Communicate | Collaborate Example use scenarios Services Centralised servies E.g. CSC’s computing or data services Grid services Cloud services (IaaS) Technologies SSH secure shell (OpenSSH) iRODS Grid/MyProxy IMAP
7
7 Connect | Communicate | Collaborate About Moonshot technilogy Development led by Janet(UK) Pilot in GN3plus project 4/2013-3/2015 UK, France, Hungary, Switzerland, Croatia, Czech, Finland and Spain Janet, RENATER, NIIFI, SWITCH, CARNet, CESNET, NORDUnet (Funet), RedIRIS Trust fabrics can be based on Eduroam techonology Trust router technology
8
The Finnish Moonshot pilot
9
9 Connect | Communicate | Collaborate Goals Learn the technology, its maturity and applicability Study alternatives to organise Moonshot as a service Extension of Haka, extension of eduroam, something else? Trust router or eduroam…? International co-operation via GN3plus project Foreign Moonshot services?
10
10 Connect | Communicate | Collaborate What? Real end users to real services E.g. selected research groups from their home universities Still a pilot No promise of production quality service Moonshot IdP RADIUS Computing server IDA service HU TUT CSC (Moonshot SP)
11
11 Connect | Communicate | Collaborate Timeline HU and TUT set up the Moonshot IdP 2-3/2014 Works against CSC’s production SPs Kick-off with pilot users 4/2014 Involving the pilot users Pilot with the pilot uses 5-6/2014
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.