Got Directory? January 28, 2004 TIP2004. 2015-06-01 2 metadirectory enterprise directory database departmental directories OS directories (MS, Novell,

Slides:



Advertisements
Similar presentations
NIH-EDUCAUSE PKI Interoperability Project Electronic Grant Application With Multiple Digital Signatures Peter Alterman, Ph.D. Director of Operations Office.
Advertisements

PKI Solutions: Buy vs. Build David Wasley, U. California (ret.) Jim Jokl, U. Virginia Nick Davis, U. Wisconsin.
May 06, 2002 Getting Started with Digital Certificates: Is PKI-Lite Real PKI? Internet2 Spring Meeting 2002 Wash, DC.
Internet2 Middleware BASE CAMP slides Michael R. Gettes Principal Technologist Georgetown University
Copyright Judith Spencer This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
1 HEPKI-TAG Update EDUCAUSE/Dartmouth PKI Summit July 26, 2005 Jim Jokl University of Virginia.
Schema: eduPerson views Michael R Gettes Duke University EuroCAMP, November 2005.
NIH – EDUCAUSE PKI Interoperability Pilot Update Peter Alterman, Ph.D. Director of Operations, Office of Extramural Research, NIH and Senior Advisor to.
Update on federations, PKI, and federated PKI for US feds and higher eds Tom Barton University of Chicago.
PKI in US Higher Education TAGPMA Meeting, March 2006 Rio De Janeiro, Brazil.
PKI Activities at Virginia January 2004 CSG Meeting Jim Jokl.
David L. Wasley Information Resources & Communications Office of the President University of California Directories and PKI Basic Components of Middleware.
US Higher Ed PKI Activities Internet2/EDUCAUSE ++ TF-EMC2 November, 2004 Amsterdam Michael R Gettes, Duke University TF-EMC2 November, 2004 Amsterdam Michael.
PKI: Glue of Middleware Michael R Gettes, Duke University EuroCAMP March, 2005 Michael R Gettes, Duke University EuroCAMP March, 2005.
The 4BF The Four Bridges Forum Higher Education Bridge Certificate Authority.
PKI Update. Topics Background: Why/Why Not, The Four Planes of PKI, Activities in Other Communities Technical activities update S/MIME Pilot prospects.
Higher Education Bridge Certificate Authority (HEBCA) Project Progress Fed/Ed December 2004.
Higher Education Bridge Certificate Authority (HEBCA) Project Progress July 2004 Dartmouth PKI Summit.
1 USHER Update Fed/ED December 2007 Jim Jokl University of Virginia.
1 11 th Fed/Ed PKI Meeting Some quick updates from recent HEPKI-TAG and SURA work Jim Jokl
9/20/2000www.cren.net1 Root Key Cutting and Ceremony at MIT 11/17/99.
InCommon Policy Conference April Uses  In order to encourage and facilitate legal music programs, a number of universities have contracted with.
Inside the PKI Framework: * Activating the Puzzle Pieces PKI Summit Snowmass August
1 Digital Credential for Higher Education John Gardiner August 11, 2004.
1 Grids and PKI Bridges (Globus Toolkit) EDUCAUSE/Dartmouth PKI Summit July 26, 2005 Shelley Henderson - USC Jim Jokl - Virginia.
Virginia Tech Overview of Tech Secure Enterprise Technology Initiatives e-Provisioning Group Frank Galligan Fed/Ed.
EDUCAUSE PKI Working Group Where Are We and Where are We Going.
Administering the Mesh/s of Trust: Old Whine in New Battles.
PKI: Glue of Middleware Michael R Gettes, Duke University CAMP Enterprise Authentication Michael R Gettes, Duke University CAMP Enterprise Authentication.
3 September 2015 Federated R US. Agenda  Background on Internet2 Middleware and NSF Middleware Initiative  The body of work  Directories  Shibboleth.
1 PKI Update September 2002 CSG Meeting Jim Jokl
Transforming Education Through Information Technologies Common Solutions Group, January, 2002 (Sanibel Island) HEBCA: Higher Education.
HEBCA Overview Internet2 Meeting, Fall 2002 Michael R Gettes Georgetown University
Australian Access Federation and other Middleware Initiatives Presented at TF-EMC2, Prague 4 Sep 2007 Patty McMillan, The University of Queensland.
HEPKI-TAG UPDATE Jim Jokl University of Virginia
1 PKI & USHER/HEBCA Fall 2005 Internet2 Member Meeting Jim Jokl September 21, 2005.
X.509/PKI There is progress.... Topics Why PKI? Why not PKI? The Four Stages of X.509/PKI Other sectors Federal Activities - fBCA, NIH Pilot, ACES, other.
CAMP PKI UPDATE August 2002 Jim Jokl
The NIH PKI Pilots Peter Alterman, Ph.D. … again.
HEPKI-PAG Policy Activities Group David L. Wasley University of California.
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Schema: eduPerson views Michael R Gettes Duke University EuroCAMP, March 2005.
Internet2 Middleware PKI: Oy-vey! Michael R. Gettes Principal Technologist Georgetown University
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 NMI R3 Enterprise Directory Components.
HEBCA Overview CSG, uWash, 2002 Michael R Gettes Georgetown University
A community-based CA: The (slow) rise of the house of Usher (The CA former known as CREN)
Leveraging Campus Authentication for Grid Scalability Jim Jokl Marty Humphrey University of Virginia Internet2 Meeting April 2004.
February 1, 2002 Internet2 Middleware Initiative and MACE RL "Bob" Morgan, University of Washington.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
The Feds and Shibboleth Peter Alterman, Ph.D. Asst. CIO, E-Authentication National Institutes of Health.
PKI Session Overview 1:30 pm edt - Welcome, etiquette, session outline 1:40 pm edt - HEPKI-TAG Update (Jim Jokl, Virginia) 2:00 pm edt - HEPKI-PAG Update.
Higher Ed Bridge CA Extending Trust Across Higher Education - And Beyond David L. Wasley University of California.
Shibboleth Trust Model Shibboleth/SAML Communities (aka Federated Administrations) Club Shib Club Shib Application process Policy decision points at the.
Day 3 Roadmap and PKI Update. When do we get to go home? Report from the BoFs CAMP assessment, next steps PKI technical update Break Research Issues in.
Welcome to Base CAMP: Enterprise Directory Deployment Ken Klingenstein, Director, Internet2 Middleware Initiative Copyright Ken Klingenstein This.
1 Internet2 Middleware update Main source Based on I2 Member meeting, Oct 2000 (trip report.
October 2, 2001 Middleware: Pieces and Processes RL "Bob" Morgan, University of Washington.
Internet2 Spring Meeting, Washington DC April NMI R2 Directory Services Components Overview Art Vandenberg Director, Advanced Campus Services Information.
Trusted Electronic Communications for Federal Student Aid Mark Luker Vice President EDUCAUSE Copyright Mark Luker, This work is the intellectual.
Higher Education Bridge Certification Authority Scaleable Linking of PKI trust domains Scaleable Linking of PKI trust domains David L. Wasley Fall 2006.
1 US Higher Education Root CA (USHER) Update Fed/Ed Meeting December 14, 2005 Jim Jokl University of Virginia.
Current Activities in Middleware
USHER U.S. Higher Education Root Certificate Authority
Internet2 Member Meeting
Inter-institutional Trust Fabric Overview and Synergies
Fed/ED December 2007 Jim Jokl University of Virginia
Administering the Mesh/s of Trust: Old Whine in New Battles
September 2002 CSG Meeting Jim Jokl
Higher Education Bridge Certificate Authority (HEBCA) Project Progress Sixth Annual PKI Summit at Snowmass, Colorado August 2004.
Presentation transcript:

Got Directory? January 28, 2004 TIP2004

metadirectory enterprise directory database departmental directories OS directories (MS, Novell, etc) border directory registries source systems Enterprise applications dir A Campus Directory Architecture

eduPerson  Schema for US Higher Education  Low hanging fruit, interoperable data Easy stuff that we can all agree is true  LocalEduPerson -- local stuff local prob  International efforts under way  US Person? Will the Feds listen to us?  eduOrg continues to be developed 

LDAP-Recipe  A hitchhiker’s guide to LDAP in H.E. A user’s perspective (a discussion, not a manual) of how to deploy directories. Covering: Directory Tree, Access Control, Attribute Firewalls, Group Management, How all the name attributes work, Authentication, Schema Management and Design, RDN issues that most don’t know about, Considerations for directory enabled routing, Software reference, Replication eduPerson discussion (read recipe as well as eduPerson specification)

Video Middleware (VID-MID)  Post 9/11/2001 Video on the Internet is how people will communicate due to US Airline Industry impact  Video and middleware folks get together Video is largely a human managed process How to integrate video into enterprise? Directory enabling versus directory slurping  CommObject is born and H.350 results

 Traditional X.500 naming: dn: cn=Michael R Gettes, ou=Server Group, ou=OIT, o=Duke University, c=US  domainComponent (DC) naming: dn: uid=gettes,ou=People,dc=duke,dc=edu Problems with Cisco and others in the past, fixed (mostly) HEPKI has issued guidance and advice on DC= naming domainComponent (DC=) Naming

Group Toolset Architecture

RADIUS server NAS (terminal server) Dialup Users User calls CalledId from NAS is mapped to guRadProf Directory Server Netid = gettes guRadProf = guRadProf = guRadProf = OracleFin LDAP Filter is: guRadProf = NetID = gettes RADIUS + LDAP

LDAP Analyzer  Todd Piket, Michigan Tech  Web based tool to empirically analyze a directory  eduPerson compliance  Indexing and naming  LDAP-Recipe guidance (good practice)  H.350 compliance  eduOrg compliance

What’s up in Directory Land?  Directory Architecture +  eduPerson +  eduOrg  Local Schema (localEduPerson)  Non-eduPerson Persons (international efforts)  usPerson? Working the Feds  LDAP-Recipe +  Group Management +  Video Middleware + H.350 for Video Infrastructure

Directory Land (continued)  DC naming +  RADIUS Integration +  LDAP Analyzer +  Medical Middleware  MACE-CourseID  Authorization work (the holy grail)

LDAP: Buyer Beware!!!  LDAP is LDAP is LDAP – yeah, right!  “Sure! We support LDAP!” What does that mean?  Contract for functionality and performance  Include your Directory/Security Champion!!!  Verify with other schools – so easy, rarely done.  Beware of products that specify Dir Servers  Get vendor to document product requirements and behavior. You paid for it!

Higher Education Bridge Certification Authority and USHER Status Update Michael R Gettes Duke University January 2004, TIP2004

Technical Policy PKI is 1/3 Technical and 2/3 Policy?

A community-based CA: The (slow) rise of the house of Usher (The CA former known as CREN)

The CA formerly known as CREN  Lots of discussion for a looong time – HEPKI-TAG, HEBCA-BID, PKI Labs  Plan is finally emerging A few related certificate services –USHER - Level 1 - soon –USHER – Level 2 - start detailed planning for implementation USHER CP –Others if warranted, eventually –All operate on high levels of assurance in I/A of the institution, and in their internal operation at both Internet2 and subcontractors –Place varying degrees of pain, and power, to the institutions Helping on a packaging of open-source low-cost CA servers Work with EDUCAUSE on their related initiatives

Usher-Level 1  Modeled after Federal Citizen and Commerce CP/CPS (  Issues only institutional certs  Those certs can be used for any purposes  CP will place few constraints on campus operations User identification and key management Campus CA/RA activities  Will be operated itself at high levels of confidence  Will recommend a profile for campus use  Good for building local expertise, insuring some consistency in approaches among campuses, and may be suitable for many campus needs and some inter-campus uses  Will not work for signing federal grants, etc…  Operational soon

Usher - Level 2  Modeled after FBCA Basic level CP  Issues only institutional certs  Those certs can be used for most purposes  CP will place more constraints on campus operations User identification and key management Campus CA/RA activities  Will be operated itself at high levels of confidence  Will recommend a profile for campus use  Good for many campus needs, many inter-campus uses, and many workings with the federal government  Will peer at the HEBCA  Detailed planning now starting; stand up sometime mid-next year

Interesting and Open Issues…  Policy Authority for USHER? Conservation of policy groups HEBCA PA? InCommon-Exec?  Final pricing and packaging Working numbers <$2K first year, <$1K renewal Includes strong institutional I/A, strong USHER operations Leverages InCommon operations  Applications and use

Interesting and Open Issues 2  Cost for Usher to peer at bridges  Ability to put Usher into various browsers  Relation to InCommon Distinguishing one from the other –To applications –To users Leveraging one with the other

/- of Usher  Pluses Pricing and lack of usage constraints on campus roots Strong institutional I/A – external and for subdomains Community-consistent ???  Negatives Not easily in browsers Uncharted peering with feds, commercials, etc Places more emphasis on running your own campus CA. ??

What ’ s a Bridge anyway? Traditional PKI With Root CA Pre-Existing?

Board of Instantiation and Development (BID)  Clair Goldsmith, Chair, UT System –Augustson (PSU), Klingenstein (Internet2), Levine (Dartmouth), Wasley (UCOP), Hazelton (Wisconsin-Madison), Brentrup (Dartmouth), Gettes (Duke), Jokl (Virginia) –EDUCAUSE: Luker, Worona Staff: Faut  Purpose is to instantiate a HE Bridge, organization and policy structures by November, 2003 (or sometime around that point -- okay, so we are running a tad behind schedule, sosu-us)  Foster Deployment and Development of Bridged PKI  Supported by EDUCAUSE

HEPKI Council  Jack McCredie, Chair –Michael Baer, Sr VP ACE –Rich Guida, Johnson & Johnson –Mark Luker, EDUCAUSE –Mark Olson, EVP of NACUBO –Dave Smallen, Hamilton College –Nancy Tribbensee, ASU  Not operational, policy and oversight  Will approve the creation of the HEBCA Policy Authority  Charged with Higher Education direction and strategy for PKI initiatives, not just Bridge  Supported by EDUCAUSE

HEPKI National PKI

Current Status: January, 2004  Charter  HEBCA Certificate Policy (brother Wasley) –Will develop CPS from this policy  Dartmouth College –Contracted to implement HEBCA in 12/03 –EDUCAUSE funded –Received AEG from Sun Microsystems ($50K) Equipment ordered and received Signing Hardware -- not yet. Working software agreement with RSA as first CA in bridge –Maybe even further deal with Higher Ed for CA services & s/w  Begin process of cross-certification with US Gov  Recommending to PKI Council to create the HEBCA Policy Authority

EDUCAUSE/NIH Interoperability Project  December 2003, NIH demonstrated the latest ability to submit doubly digitally signed documents to a web site that is validated using Bridge PKI. UCOP, Wisconsin, Dartmouth, UT Health Science Center (Barry Ribbeck)  Directory Infrastructure at Duke :-)  General doc submission facility -- freely available -- cool stuff.

National PKI  Levels of Assurance / HE CP –Get mapped all the way down, the key to interop  Business/Marketing: Separate Prob  Policy Authorities likely to merge  HEPKI umbrella should be org structure for all PKI activities in HE

Global? Trust Diagram (TWD)

Sample InterFederation

Shib/PKI Inter-Federations This model demonstrates the similarities of the PKI communities and Shib Federations. This does not mean that Shib == PKI, just that we can leverage the trust infra of a global PKI to maybe solve some larger inter-federation issues of other techno / policy spaces in a common fashion.