FeduShare Update. AuthNZ the SAML way for VOs

Similar documents
Moonshot. Workshop on Federated Identity and (OpenStack) Cloud Services - SWITCH

Guidelines on non-browser access

Goal. TeraGrid. Challenges. Federated Login to TeraGrid

EGI-InSPIRE. GridCertLib Shibboleth authentication for X.509 certificates and Grid proxies. Sergio Maffioletti

INDIGO AAI An overview and status update!

SAML-Based SSO Solution

EUDAT. Towards a pan-european Collaborative Data Infrastructure

Federated Access Management Futures

SAML-Based SSO Solution

Leveraging the InCommon Federation to access the NSF TeraGrid

Attribute Aggregation in Federated Identity Management. David Chadwick, George Inman, Stijn Lievens University of Kent

Introduction of Identity & Access Management Federation. Motonori Nakamura, NII Japan

LionShare: A Hybrid Secure Network for Academic Collaboration. Michael J. Halm, Marek Hatala, Derek Morr and Alex Valentine

Project Moonshot. IETF 77, Anaheim. Sam Hartman, Painless Security LLC Josh Howlett, JANET(UK) Image Viatour Luc (

Liberty Alliance Project

The SciTokens Authorization Model: JSON Web Tokens & OAuth

Attributes for Apps How mobile Apps can use SAML Authentication and Attributes

Now SAML takes it all:

Federated XDMoD Requirements

globus online Globus Nexus Steve Tuecke Computation Institute University of Chicago and Argonne National Laboratory

Network Device Provisioning

Trusting External Identity Providers for Global

Diamond Moonshot Pilot Participation

The EGI AAI CheckIn Service

Georgia State University Cyberinfrastructure Plan

Trust and Identity Services an introduction

DARIAH Update. 9th FIM4R Workshop. Vienna, Novemer 30, Peter Gietz, DAASI International GmbH.

The AAF - Supporting Greener Collaboration

Globus Research Data Management: Campus Deployment and Configuration. Steve Tuecke Vas Vasiliadis

GÉANT Community Programme

Assurance Enhancements for the Shibboleth Identity Provider 19 April 2013

David Simonsen, Jacob-Steen Madsen, Mads Freek Petersen, Jacob Christiansen WAYF login 1

Supporting a Widely Deployed Campus Shibboleth Implementation

Identity management. Tuomas Aura T Information security technology. Aalto University, autumn 2011

Identity Services Overview from 3 rd Party UK federation commercial identity Providers

The Trusted Attribute Aggregation Service (TAAS)

Identity management. Tuomas Aura CSE-C3400 Information security. Aalto University, autumn 2014

Canadian Access Federation: Trust Assertion Document (TAD)

This talk aims to introduce the Shibboleth web authentication/authorization framework and its intended deployment in the UK academic community and

Using Your Own Authentication System with ArcGIS Online. Cameron Kroeker and Gary Lee

Do I Really Need Another Account? External Identities for Campus Applications

CILogon. Federating Non-Web Applications: An Update. Terry Fleury

Higher Education external Attribute Authority. Mihály Héder István Tétényi (MTA SZTAKI) 19-May-2015

Eastern Regional Network (ERN) Barr von Oehsen Internet2 Tech Exchange 10/16/2018

The safe share project John Chapman, Deputy head, information security, Jisc

Configuration Guide - Single-Sign On for OneDesk

Management der Virtuellen Organisation DARIAH im Rahmen von Shibboleth- basierten Föderationen. 58. DFN- Betriebstagung, Berlin, 12.3.

Leveraging Globus Identity for the Grid. Suchandra Thapa GlobusWorld, April 22, 2016 Chicago

Morningstar ByAllAccounts SAML Connectivity Guide

Authentication & Authorization systems developed for CTA

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

Canadian Access Federation: Trust Assertion Document (TAD)

Identity management and distributed computing: What LIGO wants from Condor

All about SAML End-to-end Tableau and OKTA integration

Canadian Access Federation: Trust Assertion Document (TAD)

Major SAML 2.0 Changes. Nate Klingenstein Internet2 EuroCAMP 2007 Helsinki April 17, 2007

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

GÉANT-TrustBroker project overview

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for PingFederate

A Guanxi Shibboleth based Security Infrastructure for e-social Science

CAS s IDP system and resources in Education Cloud

Authentication in the Cloud. Stefan Seelmann

ArcGIS Server and Portal for ArcGIS An Introduction to Security

The Long, Long Road to True Single Sign On at Fermilab. Al Lilianstrom and Dr. Olga Terlyga NLIT 2018 May 22 nd, 2018

Case Study Identity Management at Texas A&M University

The Challenges of User Consent

INDIGO-Datacloud Identity and Access Management Service

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES BEST PRACTICES FOR IDENTITY FEDERATION IN AWS E-BOOK

New trends in Identity Management

Integrating VMware Workspace ONE with Okta. VMware Workspace ONE

Géant-TrustBroker Project Overview

Introduction to SciTokens

Qualys SAML 2.0 Single Sign-On (SSO) Technical Brief

Thebes, WS SAML, and Federation

Middleware, Ten Years In: Vapority into Reality into Virtuality

ACCI Recommendations on Long Term Cyberinfrastructure Issues: Building Future Development

IBM Exam C IBM Tivoli Federated Identity Manager V6.2.2 Implementation Version: 6.0 [ Total Questions: 134 ]

From UseCases to Specifications

InCommon Federation: Participant Operational Practices

SAP Security in a Hybrid World. Kiran Kola

Extending Services with Federated Identity Management

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

AAI in EGI Current status

Grouper Working Group

DARIAH-AAI. DASISH AAI Meeting. Nijmegen, March 9th,

Federated Services for Scientists Thursday, December 9, p.m. EST

ArcGIS Enterprise Security: An Introduction. Gregory Ponto & Jeff Smith

SLCS and VASH Service Interoperability of Shibboleth and glite

Allowing the user to define the attribute release 21 May 2014

ShibVomGSite: A Framework for Providing Username and Password Support to GridSite with Attribute based Authorization using Shibboleth and VOMS

Building the Modern Research Data Portal. Developer Tutorial

CILogon Project

TRUST IDENTITY. Trusted Relationships for Access Management: AND. The InCommon Model

Single Logout with the SWITCH edu-id IdP

Shibboleth authentication for Sync & Share - Lessons learned

FEDERATED IDENTITY AT ARGONNE NATIONAL LABORATORY

RSA SecurID Access SAML Configuration for StatusPage

CAS, Shibboleth, And an evolving SSO approach

Jisc Assent Service Technical Specification

2010 Kerberos Conference

Transcription:

FeduShare Update AuthNZ the SAML way for VOs

FeduShare Goals: Provide transparent sharing of campus resources in support of (multiinstitutional) collaboration Support both HTTP and non-web access using federated authentication and Shib ECP Leverage the knowledge and talents of campus IAM staff Eliminate GUEST/AFFILIATE identities Commence/increase communication between IAM experts at NCSA, GeNI, XSEDE, OSG and campus

Assumptions Campus supports Shibboleth Campus may support OAuth Shib ECP + R&S Resource owner sets policy and controls access to shared resource There is a federated Virtual Organization management service Resource owner authorization processes should make use of the federated VO service

FeduShare use case 1: Shared use of campus HPC Federated SSH (non-web) Demonstrated Utah login to Clemson Palmetto cluster in October 2015, using Shib-ECP and modified OpenSSH (gss-mechsaml-ecp) Partnership with JISC Moonshot Project Uses gss-mechsaml-eap Partnership with GeNI project office Have implemented a Shibboleth Attribute Authority that can assert a subset of information such as GeNi Project membership or role as a SAML assertion

Today s Demo: We will demonstrate integration with MoonShot ssh client GUI Authorization will use attribute(s) from an Attribute Authority separate from campus CILogon 2.0 GENI RBAC infrastructure We have fixed prior need to store password in a local file We will review security concerns

Attribute based access control Access denied by clearing local-login-user attribute Shibboleth SP and IdP provide configurable rules for denying attributes Examples: #1 SP queries AA with EPPN AA releases list of identifiers of VOs user is a member of SP denies access if list does not include resource owner s VO #2 SP queries AA with EPPN and VO identifier

Demo SAML Metadata (Federation) SAML IdP (home organization) 2. SAML Authn Request 3. User Authentication 4. SAML Authn Assertion SAML AA (VO membership) 6. SAML Attribute Query 7. SAML Attribute Assertion SAML AA (local account mapping) 8. SAML Attribute Query SSH client (SAML ECP enabled) 1. SAML Authn Request 5. SAML Authn Assertion SSH server (ECP enabled SAML SP) 9. SAML Attribute Assertion

SSH ECP Security: Distributed Trust Federation signs metadata containing IdP/SP/AA identities and public keys IdP verifies signature on authentication request from SP IdP informs the client of the SP's verified identity SP verifies signatures on assertions from IdP/AAs GSS channel binding connects SAML flows with SSH session User trusts client to send password securely to home IdP SP trusts IdP to authenticate the user

How does this relate to TIER Shibboleth for federated authentication Co-Manage is a proven VO management service (LIGO) Co-Manage already supports OAuth Look at Co-Manage as a vehicle for replacing GUEST/AFFILIATE identities Conversation about stand-alone Attribute Authorities needed in InCommon

Moonshot updates and use cases macos support is coming! Mac development house engaged, contracts are being exchanged Initial support expected in early 2017 SSH forwarding (ProxyCommand etc) Proven to work with Moonshot Chained multiple levels and it happily works Used by emedlab project in the UK New projects + federations looking at Moonshot emedlab (EMBL-EBI, Sanger + FARR Institutes, QMUL, etc)

FeduShare Futures Observation: a shared campus resource might exist in one or more clouds Co-Manage is being integrated with CILogon for access to XSEDE and OSG resources; how can this service be used by campuses? If campuses set up local Co-Manage instances, can we establish common practices so that there is consistency across campuses and with CILogon? Will we need a WIYVO (Where is your VO?) service akin to WAYF? Sustainability: Will JISC adopt gss-mechsaml-ecp? Would there be any US funding to do this? Will campuses discuss shared resource policies in campus silos, or will there be community discussion?