Presentation is loading. Please wait.

Presentation is loading. Please wait.

EduGAIN Code of Conduct Workshop, 2012-02-09, Brussels GEANT eduGAIN Data Protection "Code of Conduct" Workshop Dieter Van Uytvanck

Similar presentations


Presentation on theme: "EduGAIN Code of Conduct Workshop, 2012-02-09, Brussels GEANT eduGAIN Data Protection "Code of Conduct" Workshop Dieter Van Uytvanck"— Presentation transcript:

1 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels GEANT eduGAIN Data Protection "Code of Conduct" Workshop Dieter Van Uytvanck dieter.vanuytvanck@mpi.nl Brussels 1

2 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels We, the Service Providers CLARIN SPs – www.clarin.eu/spfwww.clarin.eu/spf DARAH SPs More general: DASISH community EUDAT community 2

3 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels German IDF Dutch IDF Finish IDF … User Depositor EU IDF (GEANT/eduGain) CLARIN ERIC CLARIN Service Provider Organization CLARIN SPs

4 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels The ideal world… 4

5 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels Identity Provider Service Provider Discovery Service 3. User selects IdP 5. User enters credentials

6 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels Back to reality Main problems: Not enough (worst case: no) attributes are released Opt-in at the side of the Identity Providers No support for “exotic” SAML profiles like ECP at the side of the providers 6

7 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels Identity Provider Service Provider Discovery Service 3. User selects IdP 5. User enters credentials

8 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels Identity Provider Service Provider Error "Universiteit van Tilburg" is not in the list of organisations that have requested access for the service "CATALOG (CLARIN)". If you require access you need to contact your organization's ICT department regarding this service; when they agree, they can contact SURFfederatie to include your organization in the list. Error "Universiteit van Tilburg" is not in the list of organisations that have requested access for the service "CATALOG (CLARIN)". If you require access you need to contact your organization's ICT department regarding this service; when they agree, they can contact SURFfederatie to include your organization in the list.

9 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels University ICT dept. Faculty ICT dept. Research Group ICT dept. But which ICT department?

10 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels And what to ask for? From: christianh@someuniversity.euchristianh@someuniversity.eu To: support@someuniversity.eusupport@someuniversity.eu Re: Component Registry Dear support team, I would like to access the CLARIN component registry but get an error message: "Universiteit van Tilburg" is not in the list of organisations that have requested access for the service "CATALOG (CLARIN)" What should I do now? Best regards, Christian

11 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels … to summarize Logging in to an SP for the first time: Takes a while (asking for permission!) Depends on a non-standardized workflow Depending on the reaction of the researcher Depending on the reaction of the IT helpdesk Adds to the bureaucratic burden that AAI was supposed to address Takes more effort for the user than creating a new ad-hoc account Scalability problem: many SPs and IdPs (CLARIN e.g. – S * I times permission requests)

12 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels Exotic SAML profiles CLARIN and DARIAH want to use web service trust delegation This has been tested by DARIAH and works … … but depends on the IdP, who has to configure the ECP SAML profile correctly

13 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels Summarizing our needs Less problematic attribute release policy (eduGAIN code of conduct = good initiative!) Get rid of opt-in for IdPs Try to configure the ECP profile by default at the side of IdP

14 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels Temporary workaround For CLARIN: the CLARIN IdP In practice: running our own federation Not what we want to do! Gold standard for attributes: eduPersonPrincipleName (EPTID) Common name Organisation (schacHomeOrganisation) Mail eduPersonScopedAffiliation

15 eduGAIN Code of Conduct Workshop, 2012-02-09, Brussels Practical questions about CoC What about trust delegation? Web service A calls web service B on behalf of user X How long can a Service Provider store attributes?


Download ppt "EduGAIN Code of Conduct Workshop, 2012-02-09, Brussels GEANT eduGAIN Data Protection "Code of Conduct" Workshop Dieter Van Uytvanck"

Similar presentations


Ads by Google