Federated Access to US CyberInfrastructure Jim Basney CILogon This material is based upon work supported by the National Science.

Slides:



Advertisements
Similar presentations
Federated Identity for Grid Architects Tom Scavo NCSA
Advertisements

Combining the strengths of UMIST and The Victoria University of Manchester Adapting to Federated Identity SHEBANGS Shibboleth Enabled Bridge to Access.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Contrail and Federated Identity Management
Case Studies in Identity Management for Scientific Collaboration 2014 Technology Exchange Jim Basney CILogon This material is.
July 18, 2012 XSEDE12 Panel: Security for Science Gateways and Campus Bridging Jim Basney, Randy Butler, Dan Fraser, Suresh Marru, and Craig Stewart go.illinois.edu/xsede12secpanel.
Update on federations, PKI, and federated PKI for US feds and higher eds Tom Barton University of Chicago.
National Center for Supercomputing Applications Integrating MyProxy with Site Authentication Jim Basney Senior Research Scientist National Center for Supercomputing.
National Center for Supercomputing Applications University of Illinois at Urbana-Champaign This material is based upon work supported by the National Science.
Federated Identity for Scientific Collaborations: Policy Issues Jim Basney 2 nd Workshop on Federated Identity Systems for Scientific.
Building Trusted Transactions Identity Authentication & Attribute Exchange In Public and Private Federations OASIS Conference September 2010 Joni Brennan,
Federated Access to US CyberInfrastructure Jim Basney CILogon This material is based upon work supported by the National Science Foundation.
National Center for Supercomputing Applications University of Illinois at Urbana-Champaign InCommon and TeraGrid Campus Champions Jim Basney
Single Sign-On for Java Web Start Applications Using MyProxy Terry Fleury, Jim Basney, and Von Welch November 3, 2006.
TeraGrid Science Gateway AAAA Model: Implementation and Lessons Learned Jim Basney NCSA University of Illinois Von Welch Independent.
TeraGrid ’06 National Center for Supercomputing Applications Managing Credentials on the TeraGrid with MyProxy Jim Basney.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
CILogon and InCommon: Technical Update Jim Basney This material is based upon work supported by the National Science Foundation under grant numbers
Distributed Web Security for Science Gateways Jim Basney In collaboration with: Rion Dooley Jeff Gaynor
The InCommon Federation The U.S. Access and Identity Management Federation
Distributed Web Security for Science Gateways Jim Basney In collaboration with: Rion Dooley Jeff Gaynor
11-July-2011, SURFnet Heather Flanagan, COmanage Project Coordinator Benn Oshrin, COmanage Developer Scott Koranda, U. Wisconsin – Milwaukee and LIGO.
National Center for Supercomputing Applications University of Illinois at Urbana-Champaign Secure Access to Research Infrastructure via the InCommon Federation.
Single Sign-On Multiple Benefits via Alaska K20 Identity Federation 20 May 2011 BTOP Partner Meeting Anchorage, Alaska 20 May 2011 BTOP Partner Meeting.
TeraGrid Science Gateways: Scaling TeraGrid Access Aaron Shelmire¹, Jim Basney², Jim Marsteller¹, Von Welch²,
InCommon as Infrastructure: How Recommended Practices and Federation Features Help Scale Federated Identity Management Michael R. Gettes, Carnegie Mellon.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Belnet Federation Belnet – Loriau Nicolas Brussels – 12 th of June 2014.
Helsinki Institute of Physics (HIP) Liberty Alliance Overview of the Liberty Alliance Architecture Helsinki Institute of Physics (HIP), May 9 th.
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
Neil Witheridge APAN29 Sydney February 2010 ARCS Authorisation Services Neil Witheridge Manager, ARCS Authorisation Services APAN29, Sydney, February 2010.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
Social Identity Working Group Steve Carmody. Agenda Intro to Using Social Accounts Status and Recent News –Current UT Pilot –Current InCommon Pilot with.
Federated Environments and Incident Response: The Worst of Both Worlds? A TeraGrid Perspective Jim Basney Senior Research Scientist National Center for.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
Tutorial: Building Science Gateways TeraGrid 08 Tom Scavo, Jim Basney, Terry Fleury, Von Welch National Center for Supercomputing.
Edugate Glenn Wearen HEAnet.. Summary 1 year Pilot Project / 2 years in production All IoT’s, Universities, Colleges, but only half of HEAnet’s members.
Federated Authentication at NIH: Trusting External Credentials at Known Levels of Assurance Debbie Bucci and Peter Alterman November, 2009.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Gridshib-tech-overview-dec051 GridShib A Technical Overview Tom Scavo NCSA.
Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney Senior Research Scientist National Center for Supercomputing Applications University.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Shibboleth & Grid Integration STFC and University of Oxford (and University of Manchester)
1 Earth System Grid Center for Enabling Technologies ESG-CET Security January 7, 2016 Frank Siebenlist Rachana Ananthakrishnan Neill Miller ESG-CET All-Hands.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Grid Security and Identity Management Mine Altunay Security Officer, Open Science Grid, Fermilab.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
EMI is partially funded by the European Commission under Grant Agreement RI Federated Grid Access Using EMI STS Henri Mikkonen Helsinki Institute.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay, James Basney,
Gridshib-intro-dec051 GridShib An Introduction Tom Scavo NCSA.
Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney, Terry Fleury, Von Welch TeraGrid Round Table Update May 21, 2009.
EMI is partially funded by the European Commission under Grant Agreement RI Security Token Service (STS) Simplified Credential Management Henri.
Leveraging Campus Authentication to Access the TeraGrid Scott Lathrop, Argonne National Lab Tom Barton, U Chicago.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
National Center for Supercomputing Applications University of Illinois at Urbana-Champaign This material is based upon work supported by the National Science.
WLCG Update Hannah Short, CERN Computer Security.
EGI Updates Check-in Matthew Viljoen – EGI Foundation
Community AAI with Check-In
Federated Environments and Incident Response: The Worst of Both Worlds
A Grid Authorization Model for Science Gateways
TeraGrid Identity Federation Testbed Update I2MM April 25, 2007
AAI in EGI Status and Evolution
Presentation transcript:

Federated Access to US CyberInfrastructure Jim Basney CILogon This material is based upon work supported by the National Science Foundation under grant number Any opinions, findings, and conclusions or recommendations expressed in this material are those of the author(s) and do not necessarily reflect the views of the National Science Foundation.

CILogonwww.cilogon.org CILogon Project Goal Enable campus logon to CyberInfrastructure (CI) –Use researchers’ existing security credentials at their home institution –Ease credential management for researchers and CI providers

CILogonwww.cilogon.org Why certificates? Command-line apps, non-web apps Multi-stage, unattended batch workflows Significant worldwide CI investment in PKI –Software, operations, standards, etc.

CILogonwww.cilogon.org InCommon is the federation for U.S. research and education, providing higher education and their commercial and non-profit partners with a common trust framework for access to online resources.

CILogonwww.cilogon.org Prior Work: go.teragrid.org Campus login to TeraGrid 35 campus IdPs Relied on TeraGrid identity vetting In production since September certificates issued to 65+ users IGTF accredited IDtrust 2010 paper: “Federated Login to TeraGrid” ( trust/2010/)

CILogonwww.cilogon.org (one-time only) Account Linking

CILogonwww.cilogon.org CILogon Service ( No TeraGrid account required Supports InCommon and OpenID authentication Delivers certificates to desktop, browser, and portals Available certificate lifetimes: from 1 hour to 13 months Supports close integration with CI projects Available now! FAQ:

CILogonwww.cilogon.org CILogon Portal Delegation Grid Portals and Science Gateways provide web interfaces to CI –Portals/Gateways need certificates to access CI on researchers’ behalf CILogon Delegation Service allows researchers to approve certificate issuance to portals (via OAuth) Web Browser CILogon Portal CI access request certificate authenticate & approve access

CILogonwww.cilogon.org Integration Example: OOI

CILogonwww.cilogon.org

CILogonwww.cilogon.org

CILogonwww.cilogon.org

CILogonwww.cilogon.org

CILogonwww.cilogon.org

CILogonwww.cilogon.org

CILogonwww.cilogon.org More Integration Examples

CILogonwww.cilogon.org Challenges Level of Assurance Non-Browser Apps IdP-SP On-Boarding User Catch-All IdPs

CILogonwww.cilogon.org Levels of Assurance LOA requirements differ across scientific collaborations –2-factor authentication –IGTF accreditation –Open access with usage statistics CILogon LOA options: –InCommon Silver: US Gov’t ICAM Level 2 –OpenID OIX: US Gov’t ICAM Level 1 –InCommon “Basic”

CILogonwww.cilogon.org CILogon and IGTF CILogon CA operations, key management, and certificate profiles meet IGTF standards Issue: subscriber ID vetting & authentication –Goal: rely on campuses for this –Need minimum standards for campus practices –Approach: rely on InCommon Identity Assurance Status: –CILogon Silver CA accredited October 2010 –Now waiting for InCommon Silver campuses… –CILogon Basic & OpenID CAs operating w/o IGTF accreditation

CILogonwww.cilogon.org Support for Non-Browser Apps Option #1: –Use browser-based authentication (SAML, OpenID) –Get URL for certificate download (wget/curl) Or use Java Web Start, etc. –Use certificate for non-browser authentication –Unfortunately still requires a browser Option #2 –Use SAML Enhanced Client or Proxy (ECP) authentication outside the browser to download certificate –ECP adoption by InCommon campuses beginning Successfully tested with U Washington, U Chicago, LIGO, LTER, and ProtectNetwork –For more info:

CILogonwww.cilogon.org ECP Example $ curl -sSO $ perl ecp.pl --get cert -c create -k userkey.pem -o usercert.pem -t 12 Select an Identity Provider (IdP): 1> LTER Network 2> ProtectNetwork 3> University of Chicago 4> University of Washington 5> Specify the URL of another IdP Choose [2]: 2 Enter a username for the Identity Provider: jbasney Enter a password for the Identity Provider: ************ $ grid-proxy-init -cert usercert.pem -key userkey.pem -hours 4 Your identity: /DC=org/DC=cilogon/C=US/O=ProtectNetwork/CN=Jim Basney A685 Creating proxy Done $ gsissh citest.example.edu ~]$

CILogonwww.cilogon.org SP On-Boarding Goal: Enable successful use of SPs by users from many IdPs –Particularly difficult for “no contract” SPs (“user-driven” SPs) Challenge: Attribute release –Technical solutions: user consent, attribute requirements in metadata, IdP filtering –Policy: privacy, FERPA, SP trust Policies differ for students versus faculty/staff Scaling: attribute bundles, default release policies

CILogonwww.cilogon.org SP On-Boarding

CILogonwww.cilogon.org

CILogonwww.cilogon.org User Catch-All Handling users w/o institutional logins –Home institution not (yet) in InCommon federation –Home institution not (yet) on-boarded w/ SP go.teragrid.org –TeraGrid username/password cilogon.org –“Request a New Organization” page –OpenID (Google, PayPal, VeriSign) –ProtectNetwork –Project logins (LTER, LIGO, …)

CILogonwww.cilogon.org CILogon: Lessons Learned InCommon today supports browser SSO –SAML->X.509 bridges are common for non-web apps (CILogon, TERENA Certificate Service, etc.) –SAML ECP adopted by ~5 InCommon IdPs so far ( Attribute release is a major challenge today for SPs that want to support many IdPs –New InCommon effort to address this challenge: esearch+and+Scholarship+Category Google OpenID is a popular “catch-all” IdP –US ICAM LOA 1 certified (

CILogonwww.cilogon.org References A Roadmap for Using NSF CyberInfrastructure with InCommon ( An Analysis of the Benefits and Risks to LIGO When Participating in Identity Federations ( ederationRiskAnalysis.pdf) Federated Security Incident Response (

CILogonwww.cilogon.org Thanks For more information: