Https://aarc-project.eu Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.

Slides:



Advertisements
Similar presentations
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
Advertisements

AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Networks ∙ Services ∙ People Mandeep Saini TF-MSP, Espoo, Finland Service Delivery and Adoption 10 th Sep 2015 Task Leader, GN4-1 SA7 T3.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
This document produced by Members of the Helix Nebula Partners and Consortium is licensed under a Creative Commons Attribution 3.0 Unported License. Permissions.
Authentication and Authorisation for Research and Collaboration Pilots on the Integrated R&E AAI Paul van Dijk, Activity Lead Pilots.
Géant-TrustBroker project overview Slides assembled by the Géant-TrustBroker team at Leibniz Supercomputing Centre, Germany for a short presentation by.
Test your IdP
Federation as a Service Marina Vermezović, AMRES Federated Identity Technology Workshop Sofia, Bulgaria, 20. Jun 2014.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Authentication and Authorisation for Research and Collaboration Niels van Dijk AARC General Meeting Authentication and Authorisation.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Report and plans Attribute.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos GRNET Proposed Pilots for Libraries and eGov.
Authentication and Authorisation for Research and Collaboration Mikael Linden AARC all hands Milan Authentication and Authorisation.
Géant-TrustBroker Project Overview Daniela Pöhn 7 th FIM4R meeting Frascati, Italy April 24 th, 2014.
Authentication and Authorisation for Research and Collaboration Milan, Italy Training and Outreach Authentication and Authorisation.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Authentication and Authorisation for Research and Collaboration David Groep AARC All Hands meeting Milano Policy and Best Practice.
John Dyer Business & Technology Strategist TERENA ASPIRE Project Manager TF-MSP February 2013 ASPIRE Foresight Study
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
Networks ∙ Services ∙ People Daniela Pöhn REFEDS EWTI, Vienna IdPs and Federations Service Aspects of Assurance SA5T1.
A uthentication & A uthorization for R esearch & C ollaboration Pilots in SA1 Paul van Dijk, SURFnet AARC.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Connect communicate collaborate Trust & Identity EC meets GÉANT 19 June 2014 Brussels Valter Nordh, NORDUnet Federation as a Service Task Leader Trust.
Javier Orellana JRA4 Coordinator Face to Face Partners Meeting University College London 11 December 2003 EGEE is proposed as a project funded by the European.
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
3rd Helix Nebula Workshop on Interoperability among e-Infrastructures and Commercial Clouds Carmela ASERO, EGI.eu 17 September 2013, Madrid
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Networks ∙ Services ∙ People Ann Harding GÉANT Symposium, Vienna Users Session A3 Trust and Identity March GÉANT Activity Leader Trust.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting AARC and AARC2 Vienna, 1 st December.
Networks ∙ Services ∙ People Mandeep Saini TNC15, Porto, Portugal Virtual organisation Authorisation Management Practices in Research and.
WP9– Evaluation, roadmap & development plan Rupert Lueck EMBL – 26 June
Authentication and Authorisation for Research and Collaboration Bari, Italy Training and Outreach Authentication and Authorisation.
Networks ∙ Services ∙ People Andrea Biancini #TNC15, Porto, Portugal Implementing Grouper to federate user authorization Federated Authorization.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Heiko Hütter, Martin Haase, Peter Gietz, David Groep AARC 3 rd.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Utrecht.
Javier Orellana EGEE-JRA4 Coordinator CERN March 2004 EGEE is proposed as a project funded by the European Union under contract IST Network.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
How eduGAIN can help education: a real life story Sabita Behari Product Manager TNC14.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Networks ∙ Services ∙ People Ann Harding Networkshop 44, Manchester Thinking globally, acting locally Trust and Identity in the GÉANT project.
Making the future happen Some remarks from the perspective of the Reykjavik-Group Chair full report:
WP6 – Inter-operability with e-Infrastructures Sergio Andreozzi - WP6 Task Leader Strategy and Policy Manager, EGI.eu Helix Nebula - 1st Year Review 1.
Authentication and Authorisation for Research and Collaboration Brussels Training and Outreach Authentication and Authorisation.
Helix Nebula Workshop on Interoperability among e-Infrastructures and Commercial Cloudsa Wrap-up This document produced by Members of the Helix Nebula.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Networks ∙ Services ∙ People Mandeep Saini AARC/CORBEL Workshop Collaborative Organisation Platform as a Service June 1, 2016, Paris Product.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Authentication and Authorisation for Research and Collaboration On behalf of the MJRA1.2 scribes J Jensen.
Networks ∙ Services ∙ People Di4R Network. Services. People. GÉANT 28 th September, Krakow.
WLCG Update Hannah Short, CERN Computer Security.
User Community Driven Development in Trust and Identity
Cyber-crisis exercises
eduTEAMS platform for collaboration Niels Van Dijk
Identity Federations - Overview
An AAI solution for collaborations at scale
Sustainability and Operational models
Common Authentication and Authorisation Service for Life Science Research Mikael Linden, ELIXIR Finland.
AAI Architectures – current and future
Presentation transcript:

Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan scoping and approach Integration with Commercial Services 2-4 November 2015 AARC SA1.3 Poznan Supercomputing and Networking Center

To pilot SSO access for commercial (cloud) services for research community and consider both technical/architectural solutions (in collaboration with JRA1) and legal and policy aspects (in collaboration with NA3). This work will build on the results of the service activity “Support to cloud" that is part of the GN3plus. The commercial services will be selected together with the user community and we will work together with eduGAIN/GEANT4 to ensure a sustainable service delivery model. 2 Aim of the task According to the Technical Annex

User community How to select the community? Who we shall contact?

Problem statement DJRA1.1 section on GN4­1 Cloud Activity - making CSP service’s available through eduGAIN Awareness and understanding of eduGAIN Need for development environment and guidelines CSP often even have SAML endpoints, but don’t know how to perform IdP service discovery Lack of infrastructure services CSP are used to simple, manual integration with single IdP, but not to automatically handle a large number of IdPs Need for a Discovery Service Confusing registration procedure Registering to a national federation instead of eduGAIN (esp. For pan-European providers) Different policies in federations Need to reach out and to negotiate with individual IdPs regardless joining eduGAIN The set of available attributes from the eduGAIN IdPs is too limited for delivering personalized service, at least globally unique id for each user is required.

Scope of commercial services pilots We shall cooperate with NA2 to involve the commercials, they need explanations and support Define pilot solution with service discovery The aim is not connecting a CSP to eduGAIN, it is a kind of operational work of eduGAIN/Geant, not AARC. Our focus will be to improve the technical enrolment of commercial service providers The solution must be generic The pilot must be usable for the community Questions: What types of commercial services? Web-SSO only? Focus on Authentication only, or authoritative attributes as well? How many SP?

Selection of suitable providers Source: Helix Nebula project and HN Marketplace Canopy, CLOUDEO, CloudSigma, Cloudwatt, DataCentered, DEAC, DBCE, Exoscale, Prologue, SixSq, T-Systems, Ultimum Technologieshttp:// GEANT Cloud Catalogue CloudSigma, Advania, Axess Systems, Ultimum Technologies, Zettabox Selection criteria: already involved in public-commercial cooperations medium-size (big enough to have required potential, small enough to be ready to talk with us) Cooperate with the community Questions: Are the above criteria ok. (e.g. some people have experience with bigger players)? Anyone have experience or contacts with listed SPs? Someone in the audience have other leads? Shall we limit to those based/operating in Europe?

Discovery Service Delivery modes By SP By VO By national node (NREN) By European instance (eduGAIN) Question: Which mode we shall suggest to CSP (and use in the pilot)?

Discovery Service Possible solutions SURFconext offers a test environment with test IdPs where SPs can test their setup before the whole contractual phase is started Similar solutions may be available also in NRENs. DiscoJuice -flexible User Interface JS library for implementing an IdP Discovery Service. Shibboleth Discovery Service -standard Java web application rvice rvice MAGIC Deliverable D3.2: Assessment of Group Management Standards, NREN tools and value services –to be checked

Workplan for the next 6 months Involve user community Define possible scope of the pilot (with comunity representatives) Contact candidate providers Setup pilots involving at least 2 CSPs

© GÉANT on behalf of the AARC project. The work leading to these results has received funding from the European Union’s Horizon 2020 research and innovation programme under Grant Agreement No (AARC). Thank you Any Questions?