edugain: services and identity
|
|
|
- Deborah Osborne
- 9 years ago
- Views:
Transcription
1 edugain: services and identity Brook Schofield edugain Task Leader, GN3 Project & Project Development Officer, TERENA Innovation through participation
2
3
4 edugain status (in numbers)! 14 participant federations! 3 candidate federations! 2 existed in original pilot! 6 European federations not participating! 6 other federations not participating! 10 GN3 Partners without a federation Innovation through participation
5 Adoption Width vs Depth edugain-enabled Federation Federation Federation Federation Federation Federation Federation! Good federation adoption (Width)! Entity Adoptions (Depth) has yet to grow connect Innovation communicate through participation collaborate 9
6 Width and Depth in Numbers edugain participants Federation Federation Federation Federation Federation Federation Federation! 55% of European of national federations are edugain participants Or 40% of total 30 national federations worldwide Source is Refeds Wiki: About 2% entities opted-in so far! Out of about 2500 s and s that edugain members operate! Half of entities are s! Note: It is not reasonable for every and to interfederate! Federation connect Innovation communicate through participation collaborate 10
7 What makes up edugain?! edugain entities are a subset of a national federation (via opt in)! Profiles and policies to harmonize environment 7 connect Innovation communicate through participation collaborate 7
8 Upstream Federation Metadata Upstream Federation Metadata A 1 MDS Your Federation Goal Generate SAML 2 metadata document and sign it Metadata must contain only local federation entities that opted-in Format and elements must meet edugain Metadata Profile Publish metadata document online Send URL of document together with signing cert to OT connect Innovation communicate through participation collaborate 11
9 Upstream Federation Metadata MDS Your Federation 2 Downstream edugain Metadata Goal Download edugain metadata from MDS Verify signature using the edugain signing certificate Process metadata (adding/removing/modifying entity data) Sign metadata using a certificate known in your federation Publish new metadata document to opt-in subset of your federation 3 connect Innovation communicate through participation collaborate 15
10 Phonebook publishing tools Question SWITCH RR Fed Reg AAF JANUS-S In-House Which Federation? SWITCHaai, Haka, NIIF, Edugate AAF, Tuakiri (NZ), CAFe WAYF, SURFconext Customisation Lots None Lots Belnet, ACOnet-aai, RENATER, SURFfederatie Language Java, PHP Groovy PHP XSLT, Perl, PHP Missing Features Dependent on generation of software. *Process available but requires documentation. edugain optin, MDUI, MD Aggregation *edugain optin, MD Aggregation Self-Service, edugain optin, MDUI, MD Aggregate NB:- Signing of metadata outside the scope of these tools solutions exist. Innovation through participation
11 TODO and Current Activities! Federation Infrastructure training! simplesamlphp & Shibboleth! JANUS-S for Metadata Management! Istanbul mid 2011 and Amsterdam late 2011! How to write a federation policy training! SWAMID Policy (technology independent) + explain it! REFEDS research on Federation Policies! Template Policy as the basis for new federations (eduroam + IdFed)! Federation-as-a-Service! Code of Conduct for Personally Identifiable Data Transmission! Stop people being scared of data protection rules! Develop around a smaller set of MD Aggregators + MD Registries! Aggregators are the 1 st step Shibboleth MA1 Innovation through participation
EUMEDCONNECT2 AAI information day
EUMEDCONNECT2 AAI information day Rome, 9 November 2010 Stefano Zanmarchi Università di Padova [email protected] Agenda I Federations 11.00 11.30 Coffe Break II Digital Identity Management 13.00
Federated Identity Management. Willem Elbers (MPI-TLA) EUDAT training
Federated Identity Management Willem Elbers (MPI-TLA) EUDAT training Date: 26 June 2012 Outline FIM and introduction to components Federation and metadata National Identity federations and inter federations
Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department [email protected]
Masdar Institute Single Sign-On: Standards-based Identity Federation John Mikhael ICT Department [email protected] Agenda The case for Single Sign-On (SSO) Types of SSO Standards-based Identity Federation
Licia Florio Project Development Officer [email protected] www.terena.org Identity Federations in Europe
APAN Conference Honolulu, Hawaii 24 January 2008 Licia Florio Project Development Officer [email protected] www.terena.org Identity Federations in Europe Outline Networking Organisations in Europe Requirements
Shibboleth User Verification Customer Implementation Guide 2015-03-13 Version 3.5
Shibboleth User Verification Customer Implementation Guide 2015-03-13 Version 3.5 TABLE OF CONTENTS Introduction... 1 Purpose and Target Audience... 1 Commonly Used Terms... 1 Overview of Shibboleth User
Collaboration in the Cloud. Niels van Dijk, SURFnet, [email protected] CAMP, Nov 15 2013, San Francisco
Collaboration in the Cloud Niels van Dijk, SURFnet, [email protected] CAMP, Nov 15 2013, San Francisco R&E SURF in and The SURFnet Netherlands: SURF and SURFnet National Research & Education Network
SURFfederatie - edugain. Opt-in Metadata Management for a Hub & Spoke Federation
SURFfederatie - edugain Opt-in Metadata Management for a Hub & Spoke Federation Content - History of SURFfederatie - Federation models - Functional view - Consequences of hub & spoke - edugain - Future
Federated Identity Management
Federated Identity Management SWITCHaai Team [email protected] Agenda 2 What is Federated Identity Management? What is a Federation? The SWITCHaai Federation Interfederation Evolution of Identity Management
Разработка программного обеспечения промежуточного слоя. TERENA BASNET Workshop, 16-17 November 2009 Joost van Dijk - SURFnet
Разработка программного обеспечения промежуточного слоя TERENA BASNET Workshop, 16-17 November 2009 Joost van Dijk - SURFnet Contents - SURFnet Middleware Services department: - eduroam, SURFfederatie,
Federated Identity Management
Federated Identity Management SWITCHaai Introduction Course Bern, 1. March 2013 Thomas Lenggenhager [email protected] Overview What is Federated Identity Management? What is a Federation? The SWITCHaai Federation
VOPaaS Virtual Organisation Platform as a Service
VOPaaS Virtual Organisation Platform as a Service Marina Adomeit Task Leader, AMRES, Serbia Niels Van Dijk Technical Lead, SURFnet, The Netherlands FIM4R meeting Nov 30, 2015, Austria About VOPaaS in GÉANT
Federations 101. An Introduction to Federated Identity Management. Peter Gietz, Martin Haase
Authentication and Authorisation for Research and Collaboration Federations 101 An Introduction to Federated Identity Management Peter Gietz, Martin Haase AARC NA2 Task 2 - Outreach and Dissemination DAASI
A Shibboleth View of Federated Identity. Steven Carmody Brown Univ./Internet2 March 6, 2007 Giornata AA - GARR
A Shibboleth View of Federated Identity Steven Carmody Brown Univ./Internet2 March 6, 2007 Giornata AA - GARR Short Section Title Agenda Assumptions and Trends Identity Management and Shibboleth Shibboleth
Federated Identity Management for Research Communities (FIM4R)
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL, UK) [email protected] Federations Virtual Day 19 Jun 2013 Who am I? Head of Particle Physics Computing at RAL
Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x
Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x Sverview Trust between SharePoint 2010 and ADFS 2.0 Use article Federated Collaboration with Shibboleth 2.0 and SharePoint 2010 Technologies
An Infocard-based proposal for unified SSO to eduroam
An Infocard-based proposal for unified SSO to eduroam Enrique de la Hoz, Antonio García, Diego López, Samuel Muñoz University of Alcala (Spain), RedIRIS (Spain) TNC2009, Málaga (Spain), June 9 th 2009
Logout Support on SP and Application
Logout Support on SP and application Logout Support on SP and Application Possibilities and and Limitations SWITCHaai Team [email protected] Single Logout: Is it possible? Single Logout will work only in some
OSOR.eu eid/pki/esignature Community Workshop in Brussels, 13. November 2008 IT Architect Søren Peter Nielsen - [email protected]
The OIOSAML Toolkits Accelerating a common egov infrastructure using open source reference implementations OSOR.eu eid/pki/esignature Community Workshop in Brussels, 13. November 2008 IT Infrastructure
Index. Registry Report
2013.1-12 Registry Report 01 02 03 06 19 21 22 23 24 25 26 27 28 29 31 34 35 Index Registry Report 02 Registry Report Registry Report 03 04 Registry Report Registry Report 05 06 Registry Report Registry
Middleware integration in the Sympa mailing list software. Olivier Salaün - CRU
Middleware integration in the Sympa mailing list software Olivier Salaün - CRU 1. Sympa, its middleware connectors 2. Sympa web authentication 3. CAS authentication 4. Shibboleth authentication 5. Sympa
Additional information >>> HERE <<< Download, For Free, 2012 silverpop email marketing metrics benchmark study ebook
Additional information >>> HERE
Title: A Client Middleware for Token-Based Unified Single Sign On to edugain
Title: A Client Middleware for Token-Based Unified Single Sign On to edugain Sascha Neinert Computing Centre University of Stuttgart, Allmandring 30a, 70550 Stuttgart, Germany e-mail: [email protected]
Lets get a federated identity. Intro to Federated Identity. Feide OpenIdP. Enter your email address. Do you have access to your email?
Lets get a feated identity Intro to Feated Identity EuroCAMP Training for APAN32 This work is licensed un a Creative Commons Attribution ShareAlike 3.0 Unported License. Do you have access to your email?
SAML Authentication within Secret Server
SAML Authentication within Secret Server Secret Server allows the use of SAML Identity Provider (IdP) authentication instead of the normal authentication process for single sign-on (SSO). To do this, Secret
Federated Identity for Cloud Computing and Cross-organization Collaboration
Federated Identity for Cloud Computing and Cross-organization Collaboration Steve Moitozo Strategy and Architecture SIL International 20110616.2 (ICCM) Follow me @SteveMoitozo2 2 Huge Claims You want federated
Open Access Repositories Technical Considerations. Introduction. Approaches to Setting up Repositories
Open Access Repositories Technical Considerations Peter Millington SHERPA Technical Development Officer Introduction Approaches to Setting up Repositories Totally in-house Externally assisted - Externally
How Single-Sign-On Improves The Usability Of Protected Services For Geospatial Data
2014 Fifth International Conference on Computing for Geospatial Research and Application How Single-Sign-On Improves The Usability Of Protected Services For Geospatial Data Andreas Matheus University of
AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle [email protected]
AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes Lukas Hämmerle [email protected] Berne, 13. August 2014 Introduction App by University of St. Gallen Universities
Federated Identity Management Interest Group
1 Federated Identity Management Interest Group The FIM interest group (FIMig) is an international crossdomain interest group to work on all issues related to the use FIM for the implementation of AAIs
Structured Data Capture (SDC) The Use of Structured Data Capture for Clinical Research
Structured Data Capture (SDC) The Use of Structured Data Capture for Clinical Research July 2015 S&I Initiative Coordinator: Ed Hammond HHS/ONC Sponsor: Farrah Darbouze SDC Overview Launched in 2013 in
A Federated Authorization and Authentication Infrastructure for Unified Single Sign On
A Federated Authorization and Authentication Infrastructure for Unified Single Sign On Sascha Neinert Computing Centre University of Stuttgart Allmandring 30a 70550 Stuttgart [email protected]
Dynamic Identity Federation using Security Assertion Markup Language (SAML) IDMAN 2013 9 April, 2013
Dynamic Identity Federation using Security Assertion Markup Language (SAML) Md. Sadek Ferdous & Ron Poet IDMAN 2013 9 April, 2013 Introduction Dynamic Federation: Definition Trust issues involved formulating
Connecting Web and Kerberos Single Sign On
Connecting Web and Kerberos Single Sign On Rok Papež ARNES [email protected] Terena networking conference Malaga, Spain, 10.6.2009 Kerberos Authentication protocol (No) authorization Single Sign On
Funded by the European Union s H2020 Programme. D4.1 Virtual Collaboration Platform
Funded by the European Union s H2020 Programme D4.1 Virtual Collaboration Platform 1 PROJECT DOCUMENTATION SHEET Project Acronym Project Full Title : TANDEM : TransAfrican Network Development Grant Agreement
Federation Operator Practice (FOP): Metadata Registration Practice Statement
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 Preface to the Template Document Federation
Moodle and Office 365 Step-by-Step Guide: Federation using Active Directory Federation Services
Moodle and Office 365 Step-by-Step Guide: Federation using Active Directory Federation Services This document is provided as-is. Information and views expressed in this document, including URL and other
GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services. Utrecht October 14 2015
GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services Utrecht October 14 2015 Why and what TODAY More information about IaaS delivery through GÉANT Tender Provider GÉANT interaction Opportunity
Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Drupal
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
How To Protect Your Data From Being Hacked On Security Cloud
F-SECURE SECURITY CLOUD Purpose, function and benefits October 2015 CONTENTS F-Secure Security Cloud in brief 2 Security Cloud benefits 3 How does Security Cloud work? 4 Security Cloud metrics 4 Security
DAMe Deploying Authorization Mechanisms for Federated Services in the eduroam Architecture
DAMe Deploying Authorization Mechanisms for Federated Services in the eduroam Architecture Sascha Neinert Marseille, 06.02.2008, Sascha Neinert, 06.02.2008 Seite 1 Overview Project Goals Partners Network
Identity and Access Management for Federated Resource Sharing: Shibboleth Stories
Identity and Access Management for Federated Resource Sharing: Shibboleth Stories http://arch.doit.wisc.edu/keith/apan/ apanshib-060122-01.ppt Keith Hazelton ([email protected]) Sr. IT Architect,
Canadian Access Federation: Trust Assertion Document (TAD)
Participant Name: University of Lethbridge 1. Purpose A fundamental requirement of Participants in the Canadian Access Federation is that they assert authoritative and accurate identity attributes to resources
Federating with Web Applications
Federating with Web Applications Janusz Ulawski HEAnet Ltd November 11, 2010 Agenda 1 Providing access to your WebApp 2 Federated Access Software with SAML 2.0 support 3 Federating your WebApp Shibboleth
AAI Info-Day 2005. The SWITCHaai Team, <[email protected]> 2005 SWITCH
AAI Info-Day 2005 The SWITCHaai Team, 2005 SWITCH Agenda 8:45 9:30 Basic Introduction for participants new to Ueli Kienholz, SWITCH SWITCHaai and Shibboleth Valéry Tschopp, SWITCH Patrik
Single Logout. TF-EMC2 2010 Vienna 17 th February 2010. Kristóf Bajnok NIIF Institute
TF-EMC2 2010 Vienna 17 th February 2010 Kristóf Bajnok NIIF Institute TF-EMC2 2010 Vienna 17 th February 2010 Kristóf Bajnok NIIF Institute Everybody wants to logout... Single sign-on is a powerful toy
Introduction to perfsonar
Introduction to perfsonar Loukik Kudarimoti, DANTE 27 th September, 2006 SEEREN2 Summer School, Heraklion Overview of this talk Answers to some basic questions The need for Multi-domain monitoring What
EWTI 2014 SESSION NOTES TABLE OF CONTENTS
EWTI 2014 SESSION NOTES TABLE OF CONTENTS 1 IdP of Last Resort (home for the homeless, UnitedID.org)... 2 2 Auth Bridge between STORK and edugain... 4 3 Government ID for Research & Education a.k.a. Separating
TERENA Trusted Cloud Drive
SUCRE Workshop Open Source Clouds in the public sector 16-17 April, 2013 Poznan, Poland Peter Szegedi Project Development Officer [email protected] www.terena.org TERENA Trusted Cloud Drive Unleashing
Shibboleth Identity Provider (IdP) Sebastian Rieger [email protected]
Shibboleth Identity Provider (IdP) Sebastian Rieger [email protected] Gesellschaft für wissenschaftliche Datenverarbeitung mbh Göttingen, Germany CLARIN AAI Hands On Workshop, 25.02.2009, Oxford
Smart Card Authentication. Administrator's Guide
Smart Card Authentication Administrator's Guide October 2012 www.lexmark.com Contents 2 Contents Overview...4 Configuring the applications...5 Configuring printer settings for use with the applications...5
Agenda. How to configure
[email protected] Agenda Strongly Recommend: Knowledge of ArcGIS Server and Portal for ArcGIS Security in the context of ArcGIS Server/Portal for ArcGIS Access Authentication Authorization: securing web services
AA enabling a closed source legacy application
AA enabling a closed source legacy application Jan Du Caju ICT security officer K.U.Leuven Belgium AA enabling a closed source legacy application Introduction: context association K.U.Leuven Case: AA enabling
F-Secure Internet Security 2014 Data Transfer Declaration
F-Secure Internet Security 2014 Data Transfer Declaration The product s impact on privacy and bandwidth usage F-Secure Corporation April 15 th 2014 Table of Contents Version history... 3 Abstract... 3
Integration of Shibboleth and (Web) Applications
workshop Integration of Shibboleth and (Web) Applications MPG-AAI Workshop Clarin Centers Prague 2009 2009-11-06 (Web) Application Protection Models Classical Application behind Shibboleth Standard Session
External Authentication with WebCT. What We ll Discuss
External Authentication with WebCT WebCT, Inc http://www.webct.com/ What We ll Discuss Introductions Terminology Authentication in WebCT External Authentication Custom Authentication Authorization in WebCT
Research Data Store User Guide
Research Data Store User Guide Contents Accessing Research Data Store... 2 Home Screen and Navigation... 3 Getting Started... 3 What are Activities and Collections?... 3 Starred activities... 4 Activities...
CLOUD POWER. NREN collaboration in GÉANT @ STF
CLOUD POWER NREN collaboration in GÉANT to enable and facilitate the Research and Education community to use online services on a large scale, with the right conditions @ STF MARCH 24 Andres Steijaert
MULTI COMPANY 4 YOU for VTIGER CRM 6.x
MULTI COMPANY 4 YOU for VTIGER CRM 6.x Introduction The Multi Company 4 You module allow in easier way to manage your companies within one vtiger CRM installation. It means you can define additional companies
The RAI Application and Content Management System for itv A brief overview
The RAI Application and Content Management System for itv A brief overview Alberto Messina Multimedia meets Radio and TV EBU Seminar Geneva 23 & 24 March 2006 Contents RAI s current experience and roadmap
365 Services. 1.1 Configuring Access Manager. 1.1.1 Prerequisite. 1.1.2 Adding the Office 365 Metadata. docsys (en) 2 August 2012
1 1Configuring Single Sign-On For Office 365 Services NetIQ Access Manager is compatible with Office 365 and provides single sign on access to Office 365 services. Single sign on access is supported for
Federated Identity Management and Shibboleth. Noreen Hogan Asst. Director Enterprise Admin. Applications
Federated Identity Management and Shibboleth Noreen Hogan Asst. Director Enterprise Admin. Applications Federated Identity Management Management of digital identity/credentials (username/password) Access
AAI for mandatory authentication and proxy usage to allow internet access on public workstations of ETH-Bibliothek
AAI for mandatory authentication and proxy usage to allow internet access on public workstations of ETH-Bibliothek Wolfgang Lierz, ETH-Bibliothek, IT Services Cristian Tuduce, ETH Zürich, ID-Basisdienste
