Policy and Best Practice … in practice

Slides:



Advertisements
Similar presentations
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
Advertisements

AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Updates Licia Florio, TERENA REFEDS Meeting 5 Sept 2012.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Mikael Linden AARC all hands Milan Authentication and Authorisation.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos
Authentication and Authorisation for Research and Collaboration David Groep AARC All Hands meeting Milano Policy and Best Practice.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Authentication and Authorisation for Research and Collaboration Taipei Taiwan Authentication and Authorisation for Research and.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Authentication and Authorisation for Research and Collaboration Heiko Hütter, Martin Haase, Peter Gietz, David Groep AARC 3 rd.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos David Groep 9 th FIM4R Meeting The AARC Project.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
Introduction to AAI Services
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
Authentication and Authorisation for Research and Collaboration
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
LoA Policy Harmonisation and Best Practices
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
JRA3 Introduction Åke Edlund EGEE Security Head
Policy and Best Practices … the Story So Far
eduTEAMS platform for collaboration Niels Van Dijk
Policy and Best Practice Harmonisation
AARC Strategy and Approach
Policy and Best Practices … the Story So Far
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
GÉANT 4-2 JRA3 T1 Something with Federations and Campus VC
Boosting AAI for research and collaboration
Updates on Training Andrea Biancini (AARC2.AHM)2 NA2 WP leader
Bringing Harmonized Policy and Best Practice
Towards hamonized policies and best practices
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
Dissemination and outreach plans
The AARC Project Licia Florio AARC Coordinator GÉANT
LoA Policy Harmonisation and Best Practices
Minimal Level of Assurance (LoA)
Frameworks for harmonized policies and practices
Policy in harmony: our best practice
Sustainability and Operational models
Thursday pilot session: 7-minutes
Towards hamonized policies and best practices
WP3: Policy and Best Practice Harmonisation
NA2 Overview Andrea Biancini (AARC2.AHM)2 NA2 WP leader Reti SpA
AARC Athens AHM meeting – NA3 session
Meeting summary Licia Florio
AARC Overview Licia Florio
Updated (VO) Community Security Policies
Update - Security Policies
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
OIDC Federation for Infrastructures
AARC2 JRA1 Update Nicolas Liampotis
RCauth.eu CILogon-like service in EGI and the EOSC
WP3: Policy and Best Practice Harmonisation
David Groep for the entire AARC Policy Team I2TechEX18 meeting
David Groep for the entire AARC Policy Team AARC2 AHM4 meeting
Baseline Expectations for Trust in Federation
Federated Incident Response
Presentation transcript:

Policy and Best Practice … in practice David Groep P&BP activity lead AARC All Hands meeting Milano 2015-11-03

Policy and best practice development What does assurance mean? And to whom? How much differentiation of LoA can people handle? How can we address incidents that propagate through the federated space? Can we get policy coordination to scale? What is the place of third-party commercial and eGov providers? How does that help guest identity? What’s a sustainable distribution of responsibilities amongst AAI participants? How can we share necessary accounting?

Agenda for this morning Some words on policy coordination in AARC (~15min) Introduction to and discussion of each of the current key areas ~ 15 min of introduction presentation, opening on to ~20min of discussion each Assurance baseline Incident response Sustainability models coffee break Scalable negotiation mechanisms Accounting and logging data privacy Open policy questions needing attention in 2017+ (~20min)

Objectives Develop recommendations for best practice in the areas of identity and attribute assurance, and identify the minimal set of policies and best practices that permits grouping of identity and attribute providers. Objectives provide a level of assurance (LoA) framework that meets the requirements of resource providers and can at the same time be supported by institutions (identity providers); identify a distributed approach to handling security incidents in a federated environment; specify scalable policy negotiation mechanisms between identity providers, attribute providers and service providers to facilitate resource providers; investigate terms of usage for delivering commercial services. To reach the objectives, also policy development will need to be tested & piloted ;-)

Assurance – Mikael Linden MNA3.1: “Recommendation on minimal assurance level relevant for low-risk research use cases” Based on an interview approach, reaching both communities and RIs Baseline is expected to be ‘feasible’ for IdPs Due by M7 (end of this month) Evolution of the assurance work in AARC Differentiated LoA recommendation is planned for the next stage Also includes evolution of the current requirements

Security Incident Response for Federations (SIRTFI) – Hannah Short First version of the SirTFi document is now ready and going through REFEDS consultation A phased approach permits gradual engagement by federations and IdPs Final deliverable is at the end of the project, but intermediate progress is very promising although much will depend on take-up in the federations, for which dissemination is essential

Sustainabilty models and guest IdPs – Peter Gietz (& Martin Haase) Sustainability models need to be developed for many stakeholders Interviews with federation operators to evaluate federation models – there are many, and recommendations esp. for new federations are needed Especially interesting for (semi?) federations around RIs – the issues might be quite similar Models (for federations and also Guest IdPs) are technology agnostic Needs much input: here and based on interview (you as a federation will be asked ;-) Sustainability also involves the development of business models and (possibly?) a market User-centric identity in an identity market place (will users pay for their attributes and authenticator to be managed? Why? How much?) Split of authenticator and attribute stores, turning our ‘current IdPs’ into attribute providers as well

Scalable policy negotiation – Dave Kelsey What is the current take-up of mechanisms? Entity Categories seen as a key element in expressing policies in federation Initial survey (by RENATER) showed increasing but still limited take-up – how can this be promoted? Policies in common design patterns? There are new opportunities and issues with scaling policy compliance or expression in ‘proxying’ SP communities – which are appearing as a key design principle Should all hidden services behind an SP proxy be R&S to make the proxy R&S? What happens to (commercial) services used by communities inside their infrastructure (and behind their SP proxy)? Can we define a template policy that communities can sign up to, making it a ‘policy proxy’?

Accounting and logging data protection – Uros Stevanovic & Marcus Hardt We need to know what to protect now, in order to scope the policy recommendations The inventory is a M7 (end of this month) milestone Based on a wide survey of both infrastructure as well as community requirements Includes needs for incident response, accounting, and metering A (set of) accounting data protection policies is due by the end of AARC

Policy challenges that are likely to remain open? Community attribute authority operations best practice (“AA operations guidelines”)? Recommendations on resource value and sensitivity with respect to appropriate assurance? Incident response within distributed user communities, engagement of the “VOs”? Policy composition and precedence – expressed in access control system implementations? Significant amounts of outreach, preaching, and training on the adoption of best practices … and you will have more ideas: let’s feed them into AARC2 We come back to this at the end of the morning!

davidg@nikhef.nl

OQSD: Open Questions for Stimulating Discussion how to pilot the LoA floor in SA1, and if we can use production federations for that ... ? how step-up authentication - for the later phase if communities need that - would fit in the blueprint architecture? how can policy be effectively disseminated by training to the IdPs? How can we engage federations in that? How can we pilot new entity categories via SA1? Can we do that in production (I think we must!)? Does the (blueprint) architecture generate state in AAI systems with personal data that then needs to be protected? Can training help in promoting EC adoption for scalable policy? Should we try this for attribute authorities as well in SA1? The guest IdPs developed in JRA1 and SA1 (there are several), how do they map on the foreseen sustainability model? Is there a commercial market for IdPs? Are folks willing to pay? An amalgamated IdP with LoA? In there collective experience in the AARC consortium to provide input to any sustainability model? Which existing federations and relying party consortia provide role models for sustainability? What is the spread?