UPKI Activities - July 2008 - NII & UPKI Initiative Hideaki Sone, Tohoku University.

Slides:



Advertisements
Similar presentations
UPKI Inter-University Authentication and Authorization Platform for Japanese Cyber-Science Infrastructure Yasuo OKABE Academic Center for Computing and.
Advertisements

eduroam Delegate Authentication System with Shibboleth SSO
Research Structure for the Future Network in Asia Jun Murai, Akira Kato and Hiroshi Esaki WIDE Project.
Resource WG Summary Mason Katz, Yoshio Tanaka. Next generation resources on PRAGMA Status – Next generation resource (VM-based) in PRAGMA by UCSD (proof.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Licia Florio EUNIS05, Manchester 1 Eduroam EUNIS Conference, June Licia Florio.
TERENA: European Collaboration in Research and Education Networking Belarus-Poland NREN Cross Border Link Inauguration Event Minsk, Belarus,
UK Campus Grid Special Interest Group Dr. David Wallom University of Oxford.
Internet2 Middleware BASE CAMP slides Michael R. Gettes Principal Technologist Georgetown University
Toward Production Level Operation of Authentication System for High Performance Computing Infrastructure in Japan Eisaku Sakane and Kento Aida National.
Update of Japanese Academic Access Management Federation GakuNin in 2011 Nakamura, M, Yamaji, K.
Copyright JNT Association 2006 The JANET Roaming Service.
Eduroam – Roam In a Day Louis Twomey, HEAnet Limited HEAnet Conference th November, 2006.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Federation of Campus PKI and Grid PKI for Academic GOC Management Conformable to APGrid PMA National Institute of Informatics, JAPAN Toshiyuki Kataoka,
TF-EMC2 February 2006, Zagreb Deploying Authorization Mechanisms for Federated Services in the EDUROAM Architecture (DAME) -Technical Project Proposal-
2015/6/21 UPKI project update Yasuo Okabe Academic Center for Computing and Media Studies Kyoto University.
US Higher Ed PKI Activities Internet2/EDUCAUSE ++ TF-EMC2 November, 2004 Amsterdam Michael R Gettes, Duke University TF-EMC2 November, 2004 Amsterdam Michael.
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
Development and Implementation of Multifactor Authentication Motonori Nakamura at National Institute of Informatics and Takuya Matsuhira at Kanazawa University,
1 USHER Update Fed/ED December 2007 Jim Jokl University of Virginia.
Inside the PKI Framework: * Activating the Puzzle Pieces PKI Summit Snowmass August
PKI: Glue of Middleware Michael R Gettes, Duke University CAMP Enterprise Authentication Michael R Gettes, Duke University CAMP Enterprise Authentication.
Grid security in NAREGI project NAREGI the Japanese national science grid project is doing research and development of grid middleware to create e- Science.
GakuNin Registration System Motonori Nakamura, NII Japan APAN33 rd Meeting (16 Feb. 2012)
EuroPKI 2008 Manuel Sánchez Óscar Cánovas Gabriel López Antonio F. Gómez Skarmeta University of Murcia Levels of Assurance and Reauthentication in Federated.
Maturation & Convergence in Authentication & Authorization Services in US Higher Education: Keith Hazelton, Sr. IT Architect, University.
Grid security in NAREGI project July 19, 2006 National Institute of Informatics, Japan Shinichi Mineo APAN Grid-Middleware Workshop 2006.
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
Michal Procházka, Jan Oppolzer CESNET.
Australian Access Federation and other Middleware Initiatives Presented at TF-EMC2, Prague 4 Sep 2007 Patty McMillan, The University of Queensland.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
Helsinki Institute of Physics (HIP) Liberty Alliance Overview of the Liberty Alliance Architecture Helsinki Institute of Physics (HIP), May 9 th.
Eduroam JP and development of UPKI roaming Yoshikazu Watanabe*, Satoru Yamano* Hideaki Goto**, Hideaki Sone** * NEC Corporation, Japan ** Tohoku University,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
2006 © SWITCH Grid Activities at SWITCH Christoph Witzig EGEE - 06 Geneva Sep 28, 2006.
High-quality Internet for higher education and research AAI from the NREN perspective Schiphol, October 17, 2005
Introduction of NAREGI-CA National Institute of Informatics JAPAN Toshiyuki Kataoka, July 19, 2006 APAN Grid-Middleware Workshop, Singapore.
Connect. Communicate. Collaborate Federation Interoperability Made Possible By Design: eduGAIN Diego R. Lopez (RedIRIS)
Kerberos and Identity Federations Daniel Kouřil, Luděk Matyska, Michal Procházka, Tomáš Kubina AFS & Kerberos Best Practices Worshop 2008.
Comité Réseau des Universités News from CRU activities: Identity federation, eduroam, PKI, SCS, Sympa, security policies cru.fr 7th.
Claudio Allocchio TERENA Technical Programme - Update General Assembly, 21 October 2005, Budapest 1 TERENA Technical Programme Update Claudio Allocchio.
1 Protection and Security: Shibboleth. 2 Outline What is the problem Shibboleth is trying to solve? What are the key concepts? How does the Shibboleth.
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
1 UPKI-Federation based on Shibboleth National Institute of Informatics Motonori Nakamura Toshiyuki Kataoka, Kyoto University Yasuo Okabe.
Eduroam.us Operational Experiment Kevin Miller Duke University Andy Rosenzweig Merit Network ESCC/Internet2 Joint.
Building Federations in APAN: What’s Worked? Nate Klingenstein Internet2 / Shibboleth Consortium / InCommon February 2012, APAN 33, Chiang.
Connect. Communicate. Collaborate Universität Stuttgart A Client Middleware for Token- Based Unified Single Sign On to eduGAIN Sascha Neinert, University.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
1 Internet2 Middleware update Main source Based on I2 Member meeting, Oct 2000 (trip report.
Grid Security and Identity Management Mine Altunay Security Officer, Open Science Grid, Fermilab.
Community PKIs Initiatives Updates TF-EMC2 Meeting Loughborough, UK 6-7 May, 2009 Licia Florio, TERENA
19-Sep-05 Alex Reid: Australian Middleware 1 Middleware Picture in Australia Alex Reid Director, eResearch/Middleware, AARNet.
Programme ›TERENA ›Overview of the middleware initiatives in the European Higher Education ›What is eduroam: the technology and how to set up eduroam ›eduroam-in-a-box:
126/02/2016 META ACCESS MANAGEMENT SYSTEM A Ship on the Grid – Interoperability between Shibboleth and the Grid – Dr. Erik Vullings Programme Manager Macquarie.
IETF 78 Maastricht 27 July 2010 Josh Howlett, JANET(UK)
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
The Roadmap of NAREGI Security Services Masataka Kanamori NAREGI WP
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
Project Moonshot Daniel Kouřil EGI Technical Forum
APGridPMA Update Eric Yen 35 th Amsterdam, NL September 7, 2015.
LIGO Identity and Access Management
GakuNin: Federated Identity Management Activities in Japan
USHER U.S. Higher Education Root Certificate Authority
The DAMe’s First Steps: eduroam and NAS-SAML
Updates on Recent Activities in eduroam-JP
EUGridPMA 41 and IGTF All-Hands Meeting
Presentation transcript:

UPKI Activities - July NII & UPKI Initiative Hideaki Sone, Tohoku University

UPKI Plan in FY2008 (April-March) UPKI WG in NII –in collaboration with universities and “ac.jp” institutes Public PKI Layer –Server Certificate Project –Client Certificate (Study) Campus PKI Layer –Federation between Campus PKIs –Promotion of Campus PKI –R&D of Applications for Campus PKI Grid PKI –Cooperation with GOC (Grid Op Ctr)

Univ DB Univ NII CiN ii E-Journals Univ DB NII IdP Hosting IdP Univ IdP Server Certificate Time Certificate WTCA Public PKI Layer Campus PKI Layer Grid PKI Layer Client Certificate (study) Univ DB Grid CA IdP federationIdP Federation Cert DB Federation with Univs Certificate Content certification AuthN by Univ DB Grid Certificate Use in applications Federation in LAN Access Foregn Universities Int’l Fed’n Domestic Grid sites Foreign e-Jounals Federation Foreign Grid Sites Grid Operation Job entry Collaborating Campus PKI in FY2008

Promotion of Campus PKI (AAI) Working groups (Chair: NII Open-House, events, Seminars, caravan, lectures Collaboration with academic/research meetings –TERENA (REFEDS, TNC, etc.) –SWITCH (Shibboleth Fests) –APAN Middleware WG (-2008)

Federation between Campus PKIs “UPKI-Fedration” Trial of Federating SSO over Shibboleth –Mixture of PKI + ID/PW auth. –IdP’s + SP’s in universities (+NII) –Automatic redirection –Mgmt policies for Japanese Univs –Start UPKI-Fed in 2009

Activities for “UPKI-Fedration” 2006 –Study of Shibboleth1.3, SAML –UPKI members visited SWITCH to learn SWITCH AAI. –NII invited Mr. Nate Klingenstein from Internet2 to support UPKI-Fed plan. –Development of Shib-PKI (DS Plug-in). –Development of Testbed including Shib-PKI Plug-in. –Overall Plan and Initial Policy Draft for UPKI-Fed

Server Certificate Project Trial (-- FY2009) –Practical study on various cases Fault certificate (cancel & re-issue) Procedure for renewal (after expiration) Virtual hosts, Mass (bulk) application (450) –Audit –Policies (CP, CPS, etc.) and models 62 institutes, 492 certificates –Feedback, Survey

Number of Server Certificates

R&D of Applications for Campus PKI Network Access Roaming –eduroam (Operation, Promotion, R&D) –Roaming with Commercial ISPs –Next Generation 1300 High-Edu’s in Japan, Access Ctrl, VPN, etc. UPKI Specifications (Std of Recmdn) –Sample CP/CPS guidelines Time Cert., SSO, roaming VPN over SINET3 S/MIME repository servers

UPKI Website –(Japanese literacy required)