EGEE-II INFSO-RI-031688 Enabling Grids for E-sciencE www.eu-egee.org EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability AAI and Grids Christoph.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MyProxy and EGEE Ludek Matyska and Daniel.
Federated Identity for Grid Architects Tom Scavo NCSA
Open Grid Forum 19 January 31, 2007 Chapel Hill, NC Stephen Langella Ohio State University Grid Authentication and Authorization with.
Combining the strengths of UMIST and The Victoria University of Manchester Adapting to Federated Identity SHEBANGS Shibboleth Enabled Bridge to Access.
Shibbolising UK Census and ESDS services Lucy Bell Associate Director, Head of Information Systems and Preservation, UKDA 26 May 2005.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
TNC 2008 / Short Lived Credential Service Implementation Based on National AAI Short Lived Credential Service Implementation Based on National AAI Emir.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
2006 © SWITCH SWITCH Plans for Shibboleth and Grid GGF16 Feb 14, 2006 Christoph Witzig (Thomas Lenggenhager, Valery Tschopp, Placi Flury) SWITCH.
WebFTS as a first WLCG/HEP FIM pilot
SWITCHaai Team Federated Identity Management.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Simply monitor a grid site with Nagios J.
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
INFSO-RI Enabling Grids for E-sciencE Logging and Bookkeeping and Job Provenance Services Ludek Matyska (CESNET) on behalf of the.
AAI-enabled VO Platform “VO without Tears” Christoph Witzig EGI TF, Amsterdam, Sept 15, 2010.
May 8, 20071/15 VO Services Project – Status Report Gabriele Garzoglio VO Services Project – Status Report Overview and Plans May 8, 2007 Computing Division,
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
Apr 30, 20081/11 VO Services Project – Stakeholders’ Meeting Gabriele Garzoglio VO Services Project Stakeholders’ Meeting Apr 30, 2008 Gabriele Garzoglio.
2006 © SWITCH Grid Activities at SWITCH Christoph Witzig EGEE - 06 Geneva Sep 28, 2006.
EMI AAI Strategy & Plans John White / Helsinki Institute of Physics Federated Identity Systems for Scientific Collaborations Workshop , CERN,
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
Neil Witheridge APAN29 Sydney February 2010 ARCS Authorisation Services Neil Witheridge Manager, ARCS Authorisation Services APAN29, Sydney, February 2010.
EMI INFSO-RI AAI in EEF Projects John White (Helsinki University) EMI Security Area Leader.
Supporting Are we ready? REFEDS, Oct 2013 Ann Harding
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security and Job Management.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA3 status, news, actions EGEE’07 Gergely.
Portal-based Access to Advanced Security Infrastructures John Watt UK e-Science All Hands Meeting September 11 th 2008.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security Token Service Valéry Tschopp - SWITCH.
INFSO-RI Enabling Grids for E-sciencE SA1 and gLite: Test, Certification and Pre-production Nick Thackray SA1, CERN.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Introduction to GILDA and gaining access.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Next steps with EGEE EGEE training community.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Multi-level monitoring - an overview James.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks VOMS SAML Vincenzo Ciaschini MWSG Zurich,
Connect. Communicate. Collaborate The authN and authR infrastructure of perfSONAR MDM Ann Arbor, MI, September 2008.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks VOMS Vincenzo Ciaschini EGEE/OSG Workshop.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Shibboleth & Grid Integration STFC and University of Oxford (and University of Manchester)
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks New Authorization Service Christoph Witzig,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Update Authorization Service Christoph Witzig,
INFSO-RI Enabling Grids for E-sciencE - II SLCS, VASH, and LCAS/LCMAPS Plugins All-Hands Meeting Helsinki Placi Flury, SWITCH 19.
INFSO-RI Enabling Grids for E-sciencE - II VOMS Attributes from Shibboleth (VASH) JRA1 All-Hands meeting Catania 8 March 2007.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
EMI is partially funded by the European Commission under Grant Agreement RI Federated Grid Access Using EMI STS Henri Mikkonen Helsinki Institute.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks gLite configuration (plans) Robert Harakaly.
Gridshib-intro-dec051 GridShib An Introduction Tom Scavo NCSA.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks OpenSAML extension library and API to support.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Study on Authorization Christoph Witzig,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Study on Authorization Christoph Witzig,
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Enabling Grids for E-sciencE gLite security pratical tutorial Dario Russo INFN Catania Catania,
Kipper – a Grid bridge to Identity Federation Andrey Kiryanov.
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
2007© SWITCH SWITCHslcs the new AAI-based short-lived credential service for Grid users C.Witzig Swiss Grid Day, Berne, May 7, 2007.
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Operating Systems & Information Services CERN IT Department CH-1211 Geneva 23 Switzerland.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Authorization Service Christoph Witzig, SWITCH.
INFSO-RI Enabling Grids for E-sciencE JRA3 Åke Edlund On behalf of JRA3 EGEE 8th All-activity meeting January 18-19,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Argus gLite Authorization Service Workplan.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Argus: command line usage and banning Christoph.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
AAI in EGI Status and Evolution
Presentation transcript:

EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph Witzig, SWITCH OGF19 Jan 30, 2007

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Outline Introduction –Basic approach to the problem Phase 1: Short-lived credential service (SLCS) Phase 2: Attribute exchange to VOMS Next Steps

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, AAI and Grid in Switzerland SWITCH built and operates now SWITCHaai - a national Shibboleth-based AAI Current Status: –Approx. 160’000 (75%) members of the Swiss higher education sector have AAI-enabled accounts –Approx. 10% use SWITCHaai to access about 100 resources on a regular basis No “national” grid infrastructure –Various grid efforts (e.g. LCG Tier 2 center, Swiss Bio Grid, …) Effort underway to launch a national Grid initiative

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Prerequisites Our work is part of EGEE (gLite) Aim to be open for other grid middleware (if possible) AAI federation –Shibboleth is main target –But there are also other federations (A-Select, PAPI)  eduGAIN –By far not everyone within EGEE has an AAI federation Must take deployment into account –existing infrastructure

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Work Plan EGEE-II: –April Mar 2008 –Year 1: Phase 1 and 2  Add interoperability by starting “small” with minimal changes to gLite –Year 2: Extend SAML to grid resources EGEE-III: –Continuation in EGEE-III

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Basic Idea

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, SP1 (“CA SP”) and SP2 (“VOMS SP”) should be independent of each other –Separate Service Providers –Deployed independently SP1 should be independent of the Grid middleware SP2 should only be dependent on VOMS

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Alternative Scenarios (1) Instead of SP1 issuing a short-lived X.509 certificate –Keep using X.509 certificate from a (“classical”) CA  IdP not used for authN  May make sense if one wants to use only IdP attributes –Generate proxy X.509 if authN at IdP successful  authN from CA and IdP –Issue (long-lived) X.509 credential based on auth at IdP  TAGPMA MICS profile  User has to maintain long-lived certificate –Use a “low quality” CA (i.e. not accredited)  Much less work  Compatibility with existing infrastructure (EGEE, LCG)

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Alternative Scenarios (2) Instead of SP2 being independent of SP1 –Merge them into one utility, which  Issues a X.509 certificate containing the IdP attributes as an extension X.509 certificate is no longer a “bare” X.509 User cannot choose to not expose his/her attributes Code must handle attributes from two sources: IdP attributes and the VOMS VO attributes Revocation whenever attribute changes  IdP issues an AC to be inserted into proxy X.509 (just like VOMS) IdP must be known to every grid resource Requires code change at the IdP –Attribute aggregation in SAML: Longer term project (dependencies on Shib 2 and future VOMS work) –Question: should data privacy be observed when releasing IdP attributes?

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Outline Introduction –Basic approach to the problem Phase 1: Short-lived credential service (SLCS) Phase 2: Attribute exchange to VOMS Next Steps

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, SLCS Profile SLCS = short lived credential service Minimum requirements: SLCSX.509 Certificate Certificate is generated based on Identity Management system “traditional” Registration Authority (e.g. passport) Lifetime < 1mio secLifetime < 1 year + 1 month Revocation handling optional Revocation handling

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, SWITCHslcs: CA Setup

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, SWITCHslcs: Operation For the user: from the command line: invisible part of gLite UI (3.1) (can be installed independently) For the RA from web-based admin tool: Can enable or disable individual users (only for his institution) Can obtain log information SWITCH: Operates the service Strict access control Operate also a second test CA (everything being installed on the MSCS CA will be tested there first)

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, SWITCHslcs Design goals: –Private key is never transferred –Use commercial CA and only standard protocols –Modular design such that other people can use components

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Status SLCS Software development is finished MJRA1.4 document: Operation of SLCS TEST CA in test-bed – CP/CPS: –Submitted to EuGridPMA for review Production CA setup: –In progress (delivery of production HSM, CA server configuration, hardening and testing)

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Outline Introduction –Basic approach to the problem Phase 1: Short-lived credential service (SLCS) Phase 2: Attribute exchange to VOMS Next Steps

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Design VASH: –VOMS Attributes from Shibboleth Shibboleth SP –Browser-based –Specific for  Federation  VO “lightweight” SP –No administrator duties –No management of attributes –Simply transfers attributes upon user request

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Design (2) X.509 and proxy X.509 with VOMS AC unchanged No change in VOMS –Needs version or higher VO registration not changed Administrative domain between Shibboleth federation and VOMS fully decoupled User manages mapping between DN in VOMS and Shibboleth user id –For “classic” X.509 –For SLCS X.509 Becomes a service which knows the mapping Shibboleth userid - DN

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30,

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Status Software implementation done MJRA1.5 document: Need to develop plug-ins to evaluate the Shibboleth attributes at the grid resource

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Next Steps Near future (3 months): –Evaluation modules for Shibboleth attributes at grid resource –Test-bed: Access to Shibboleth resources for grid users Medium future (1 year): –Deployment of phase 1 and phase 2 –Phase 3: currently in design Long-term future: –To what extent shall authN, authZ be based on certificates? –What is feasible within a regional / national / international grid?

Enabling Grids for E-sciencE EGEE-II INFSO-RI gLite Shib OGF19 Jan 30, Q & A