Presentation is loading. Please wait.

Presentation is loading. Please wait.

ShibGrid: Shibboleth access to the UK National Grid Service University of Oxford and STFC.

Similar presentations


Presentation on theme: "ShibGrid: Shibboleth access to the UK National Grid Service University of Oxford and STFC."— Presentation transcript:

1 ShibGrid: Shibboleth access to the UK National Grid Service University of Oxford and STFC

2 Motivation We want to encourage more users on the NGS –Need to cover all areas of research –From the single researcher to large projects –Security infrastructure must enable this PKI often a barrier Generalised not specific Straightforward to use Community is adopting Shibboleth

3 Requirements User/Project –Don’t want to know about certificates (or any other security mechanism!). –Transparent access to eScience facilities, consistent with other SSO-enabled components. –Access to components at home or away (even Internet Café). –Fit in with local authentication schemes. –Want to use own project portal. NGS –Must be compatible with GT2 and registration system. VOMS in the future.

4 Use cases Access to the Grid solely with Shibboleth Use standard Grid certificates when something extra is required – still many advantages Access to the Grid through a Portal –NGS portal/project portals Access to the Grid through other access methods –Globus, Java GSI-SSH Terminal, CoG, etc., Registration (for NGS) using Shibboleth

5 Shibboleth Overview Web-based federated access management system based on SAML Based on separation of authentication and authorisation –Authentication: Identity Provider (IdP) at user’s home institution –Authorisation: Service Provider (SP) based on attributes from the IdP –Discovery: Where Are You From (WAYF) service User can remain anonymous at the SP

6 Shibboleth Authentication and Authorisation (Thanks to Kang Tang)

7 Architectural Design Don’t change the user –Prevent extra logical steps: portal first –Easy to deploy in project portals –Support other access methods Don’t change other services –Work within Shibboleth and GSI frameworks

8 ShibGrid access to the NGS (via Portal) (Thanks to Kang Tang) Shibboleth Authentication and Authorisation

9 ShibGrid MyProxy Checks IdP (trusted) authentication/authorisation –Standard Shibboleth Portal (not trusted): –Standard MyProxy checks –+ check the attribute assertion was created for the portal Users: –Authentication: at IdP –Authorisation: Is user registered? username attribute = username used? –Attributes used to construct low-assurance certificate DNs

10 More than just portal access… Registration service –Data Protection Act/Acceptable Use Policy? –Supported IdP? –Correct configuration? –Link to NGS user registration Grid proxy download tool – For non portal Grid access methods Grid proxy upload tool

11 Logon via Shibboleth…

12 …Choose your home institution…

13 …background log-in in using Kerberos…

14 …welcome to the Portal…

15 …and we have a low- assurance Grid proxy

16 Certificate Download Tool Download a stored digital certificate from the MyProxy certificate store for use in other environments

17 Certificate Upload Tool Upload a standard UK e-Science certificate into the ShibGrid enabled MyProxy Server - enables download using Shib tools for those users who already have a digital certificate

18 Conclusion Succeeded in providing Shibboleth access to the Grid. Enabling NGS to grant access to users who do not have, and do not want, an e-Science certificate –lowering the barrier for beginners –widening the user base. Use of standard components and protocols ensures the product is easily deployable, maintainable, and interoperable. –Prototype was deployed in the NGS portal (both uPortal and StringBeans-based versions) –Software available through the OMII catalogue Led to some extra functionality being requested of the UK Shib federation

19 Thanks to the team! Jens Jensen David Meredith David Spence Kang Tang Matt Vilijoen

20 Questions


Download ppt "ShibGrid: Shibboleth access to the UK National Grid Service University of Oxford and STFC."

Similar presentations


Ads by Google