JRA3-T4 eduroam development - plan Stefan Winter Task Leader JRA3-T4

Slides:



Advertisements
Similar presentations
eduroam Delegate Authentication System with Shibboleth SSO
Advertisements

RadSec – A better RADIUS protocol
DIRECT TRANSPORT FOR QH 10/18-19 F2F NOTES (SPN).
Private and Confidential ThinkControl & ProLiant Essentials Rapid Deployment Pack.
Eduroam – Roam In a Day Louis Twomey, HEAnet Limited HEAnet Conference th November, 2006.
Using InCommon Client Certs for eduroam Jeff Hagley and Ryan Martin October 3 rd, 2011 Internet2 Fall Member Meeting.
Winter Consolidated Server Deployment Guide for Hosted Messaging and Collaboration version 3.5 Philippe Maurent Principal Consultant Microsoft.
MIT Libraries’ FileMaker Use Policy as an example local DLC policy.
Cloud Control Senior Project Summer Overview Cloud Control is a platform to control data transmission to/from internet connected devices from the.
AARNet Copyright 2010 Network Operations The eduroam project group
Eduroam Louis Twomey HEAnet Library Services Day 20 th November 2014.
Education roaming Secure Wireless Service for Research and Education.
 Introduction to Operating System Introduction to Operating System  Types Of An Operating System Types Of An Operating System  Single User Single User.
Registration Processing for the Wireless Internet Ian Gordon Director, Market Development Entrust Technologies.
Michal Procházka, Jan Oppolzer CESNET.
1 Thomas Lippert Senior Product Manager - Mobile What’s new in SMC 5.0.
What’s New in Fireware v11.9.5
Blueprint Meeting Notes Feb 20, Feb 17, 2009 Authentication Infrastrusture Federation = {Institutes} U {CA} where both entities can be empty TODO1:
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Case Study.  Client needed to build data collection agents for various mobile platform  This needs to be integrated with the existing J2ee server 
Windows 8 A touch screen computer on a desktop. Windows Metro.
Presentation at ISMS WG Meeting1 ISMS – March 2005 IETF David T. Perkins.
IPS Infrastructure Technological Overview of Work Done.
Using InCommon Client Certs for eduroam Jeff Hagley and Ryan Martin October 3 rd, 2011 Internet2 Fall Member Meeting.
Networks ∙ Services ∙ People Tomasz Wolniewicz TNC15, Porto Supporting user privacy, security and ease of use in eduroam June 2015 PSNC &
Easy 802.1X Onboarding with EAPConfig files and Supplicant Configuration Automatic Discovery (SCAD) Gareth Ayres (Speaker) Stefan.
©2010 Check Point Software Technologies Ltd. | [Unrestricted] For everyone Endpoint Security VPN R75 (SecureClient Next Generation)
A leap ahead... Darren Kearney Don Miller Ilya Pinchuk.
OSG PKI Transition Impact on CMS. Impact on End User After March , DOEGrids CA will stop issuing or renewing certificates. If a user is entitled.
INFSO-RI Enabling Grids for E-sciencE GOCDB2 Matt Thorpe / Philippa Strange RAL, UK.
Computer Security: Principles and Practice First Edition by William Stallings and Lawrie Brown Lecture slides by Lawrie Brown Chapter 17 – IT Security.
IPitomy SIP Trunks 101 Programing and activating SIP Trunks with IPitomy’s assisted turn-up.
| Presenters: Chris Phillips – CANARIE, Canada Stefan Winter – RESTENA, Luxembourg Looking into the Future:
1 RESTENA Foundation TF-MNM 16 feb 2011 eduroam “next gen” Stefan Winter -
Wireless Security - Encryption Joel Jaeggli For AIT Wireless and Security Workshop.
Selecting the Management Platform Cloud-based Management Standalone Windows Intune No existing Configuration Manager deployment Simplified policy.
RADIUS infrastructure monitoring
eduroam-as-a-service
The Parent Portal Version 3.0 Last Updated on 14/10/2016.
MaaS360 MDM for iOS, Android & Windows Phone 7
SDN challenges Deployment challenges
Dispatcher Phoenix Is…
Hybrid Cloud Web Filtering Platform
eduroam Managed IdP - Roadmap
Apache web server Quick overview.
EGEE is a project funded by the European Union
Live Customer Support Solution
Shared Services with Spotfire
Configuring and Troubleshooting Routing and Remote Access
Two-factor authentication
4th Forum How to easily offer your application as a self-service template by using OpenShift and GitLab-CI 4th Forum Alberto.
Tweaking the Certificate Lifecycle for the UK eScience CA
Neil Witheridge’s slides
RESTENA Foundation TF-MNM 16 feb 2011
Introduction To Networking
RIM Blackberry at SAP Key Benefits / Survey Results April 2004 SAP IT Enterprise Telecommunication Services.
802.1X and key interactions Tim Moore November 2001
Outlook Technical Support It’s a web based service which is being used by Millions of users and owned by Microsoft. Microsoft.
How it works: Step 1 99% of CAD systems can do this without modification is sent to a unique address for your agency Example:
What’s New in Fireware v12.1.1
Printer Admin Print Job Manager
An Introduction to Online Timetabling
Software Defined Networking (SDN)
What is Concurrent Programming?
Björn Erik Abt :: Paul Scherrer Institut
Executives & Management
IP Control Gateway (IPCG)
Rollout Guide Day 1 to 10 Day 11 to 20 Day 21 to 30 Day 31 to 40
SETUP ALEXA APP Setup Alexa on your favorite device and control your smart device with the help of Alexa.
Setting up eduroam for an IdP means …
Presentation transcript:

JRA3-T4 eduroam development - plan Stefan Winter Task Leader JRA3-T4 R&D Engineer, RESTENA Foundation JRA3 Kick-Off Meeting, Zürich 12 July 2016

Work Areas eduroam-as-a-service, comprising Self-Service Support IdP-as-a-service (“Silver Bullet IdP”) SP-as-a-service (“No fancy name”) Self-Service Support for end users (“Why am I not online?”) For admins (“I need to talk to IdP/SP X because…”) CAT “business as usual” development new devices like Kindle beefing-up of current installers (more Passpoint support...) Let’s RadSec

IdP-as-a-service “Silver Bullet” IdP Requires Exploits EAP-TLS based “IdP” admin gets simple web interface to manage own users Requires CA which issues/revokes user certificates in real-time RADIUS server(s) which terminate EAP-TLS and do actual authentication More than one? Decentralisation difficult due to EAP server verification! Management UI for the admins Exploits Availability of installer generation engine in eduroam CAT (“just yet another EAP type”) Existing admin UI in CAT for the config parts unrelated to Silver Bullet Additional SSIDs Institution Logo Helpdesk contact details … you name it

SP-as-a-service Just an ordinary proxy-only RADIUS server Best-of-class: implement all optional/recommended features we like to but seldomly do see in real life Easy to distribute: central, NRO level, at the spot With Let’s RadSec: uplink with eduroam SP certificate

Self-Service For users: For admins: integrate monitoring subsystems and real-time diagnostics into a cohesive and simple user experience give simple explanations / instructions / steps forward automate wherever possible e.g. instead of generic “contact your IdP”: show web form which will be sent to relevant contact at IdP – users do not need to know contact details themselves fallbacks in place (no IdP email known? Display phone, or send to NRO instead) Needs improvements in eduroam monitoring -> operations For admins: automate workflows for common issues where flow was previously “contact your NRO and wait for guidance” typical use cases: abuse complaints, reject due to missing MAC address in request, informing SP of lack of IP addresses in DHCP pool, malformed Operator-Name web forms all around

eduroam CAT eduroam CAT Devices Features Not many “actually new” devices on the radar. Contrary, Windows Phone is dead! Kindle (FireOS) is mostly Android, but different enough to potentially be(come) difficult Features Passpoint now configurable on all our supported platforms (currently implemented only on iOS / OS X  room for improvement) Shift from install-once to a permanent assistance application on all platforms Initial installation Ongoing account management (check expiry and consequences, renew cert) Running diagnosis where needed Maps of coverage I would call it the “Companion” if that name weren’t already taken ;-)

Let’s RadSec RADIUS/TLS for server infrastructure is all nice But getting certificates too cumbersome in practice Need a more automated solution Prototype can provision RADIUS/TLS server certificates to EAP servers fully automated EAP server == eduroam IdP security profile still under discussion Unfortunately, eduroam IdPs unlikely first adopters Rather expect trickle-down from NRO level So, need a provisioning method for the other slice of servers NRO RADIUS proxies in top priority (then eduroam IdPs, mostly solved) eduroam SPs CSR copy&paste to web form the likely best candidate for SPs and NRO