Managing identities. TICAL 2012, Lima, Peru Roland Hedberg <roland.hedberg@adm.umu.se> tisdag 3 juli 12



Similar documents
Federations 101. An Introduction to Federated Identity Management. Peter Gietz, Martin Haase

Provisioning and Deprovisioning 1 Provisioning/De-provisiong replacement 1

Identity Management: Background, Principles, GENI

Licia Florio Project Development Officer Identity Federations in Europe

Enabling SAML for Dynamic Identity Federation Management

Enabling a federated environment to support biomedical research. Gianmauro Cuccuru CRS4

Issues in federated identity management

How Single-Sign-On Improves The Usability Of Protected Services For Geospatial Data

TRUST AND IDENTITY EXCHANGE TALK

RedIRIS Identity Service

Identity Management Systems for Collaborations and Virtual Organizations

Разработка программного обеспечения промежуточного слоя. TERENA BASNET Workshop, November 2009 Joost van Dijk - SURFnet

DAMe Deploying Authorization Mechanisms for Federated Services in the eduroam Architecture

Federated Identity- and Access Management for the Max-Planck Society

Enterprise & Vertical Reporting. Challenges and Solutions

Cloud federation. Prelude to Hybrid Clouds. CHEP 2015 Okinawa, Japan. Marek Denis CERN Geneva, Switzerland

Collaboration in the Cloud. Niels van Dijk, SURFnet, CAMP, Nov , San Francisco

Identity Management. Manager, Identity Management. Academic Technology Services. Michigan State University Board of Trustees

Development and deployment of integrated attribute based access control for collaboration

IAMUCLA 2.0 SSO Updates

Deliverable D9.2 Market Analysis for Virtual Organisation Platform as a Service (VOPaaS)

A Shibboleth View of Federated Identity. Steven Carmody Brown Univ./Internet2 March 6, 2007 Giornata AA - GARR

Title: A Client Middleware for Token-Based Unified Single Sign On to edugain

SD Departmental Meeting November 28 th, Ale de Vries Product Manager ScienceDirect Elsevier

Federated Identity Management Checklist

GARR Cloud Services. GARR strategy towards the provisioning of Cloud Services. On behalf of the GARR Cloud Team

Authentication Integration

Secure Your Enterprise with Usher Mobile Identity

A Federated Authorization and Authentication Infrastructure for Unified Single Sign On

Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department

Ping Identity, Euro Cloud award entry

Shibboleth User Verification Customer Implementation Guide Version 3.5

Secure WiFi Access in Schools and Educational Institutions. WPA2 / 802.1X and Captive Portal based Access Security

Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure

Overcoming Barriers to Federation and Making IdPs Easier

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

Federated Identity: Leveraging Shibboleth to Access On and Off Campus Resources

VOPaaS Virtual Organisation Platform as a Service

Identity and Access Management for LIGO: International Challenges

Identity Federation For Authenticating and Authorizing Researchers

Federated Wikis Andreas Åkre Solberg

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

Introduction to Identity and Access Management for the engineers. Radovan Semančík April 2014

HOL9449 Access Management: Secure web, mobile and cloud access

Experiences in Supporting Service Providers and User Communities. Lukas Hämmerle, GÉANT/SWITCH Conference 26 November 2014

INF3510 Information Security University of Oslo Spring Lecture 8 Identity and Access Management. Audun Jøsang

Modern Approach for User and Service Management. Michal Procházka CESNET Czech Republic

The Top 5 Federated Single Sign-On Scenarios

Adding Federated Identity Management to Openstack

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

Identity and Access Management for Federated Resource Sharing: Shibboleth Stories

IDENTITY MANAGEMENT AND WEB SECURITY. A Customer s Pragmatic Approach

EXECUTIVE VIEW. EmpowerID KuppingerCole Report. By Peter Cummings October By Peter Cummings

UNI. UNIfied identity management. Krzysztof Benedyczak ICM, Warsaw University

Standards for Identity & Authentication. Catherine J. Tilton 17 September 2014

Canadian Access Federation: Trust Assertion Document (TAD)

From centralized to single sign on

Single Sign On. SSO & ID Management for Web and Mobile Applications

Identity Governance Evolution

Joint Research Activity 5 Task Force Mobility

An introduction of several development activities related to Shibboleth and Web browser-based simple PKI

eduroam(radius based Federation)

perfsonar AAI for network-oriented services Cándido Rodríguez

External and Federated Identities on the Web

Active Directory Integration WHITEPAPER

Adding Federated Identity Management to OpenStack

Identity Management in the Asia Pacific Region: Facilitating Secure and Easy Access to Online Services

Integrating Multi-Factor Authentication into Your Campus Identity Management System

InCommon Basics and Participating in InCommon

My Private Cloud. Project Objectives

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

GÉANT IaaS suppliers meeting Towards Pan-European Cloud Services. Utrecht October

An Infocard-based proposal for unified SSO to eduroam

Federated Identity for Cloud Computing and Cross-organization Collaboration

Standardisation of eduroam Testing, Monitoring, Metrics and Support Tools

managing SSO with shared credentials

Increase the Security of Your Box Account With Single Sign-On

HP Software as a Service. Federated SSO Guide

OpenID Connect for SURFconext

Toward campus portal with shibboleth middleware

Identity Management for the Cloud

NCSU SSO. Case Study

Federated Identity Management

The Future of Cloud Identity Security. Michael Schwartz Founder / CEO Gluu

MY1LOGIN SOLUTION BRIEF: PROVISIONING. Automated Provisioning of Users Access to Apps

Active Directory Integration twitter.com/onelogin ONELOGIN WHITEPAPER

Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management

InCommon Affiliates Webinar Three Case Studies with Unicon September 18, 2013

Single-Sign-On between On-Premises and the Cloud: Leveraging Windows Azure Active Directory to authenticate custom solutions and Apps

EUDAT Federated AAI TF (Authentication Authorization Infrastructure Task Force)

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

Copyright: WhosOnLocation Limited

NORDUnet. AGREEMENT ADDENDUM No. 05 between. NORDUnet Af S Kastruplundgade 22 DK-2770 Kastrup DENMARK. UNINETf Abels gate 5 NO-7030 Trondheim NORWAY

Federated access to Grid resources

BOF4803 Open source identity and access management. 1 October :30p San Francisco CA

Introduction to CERNET+ IPv6 Cloud Services Platform Initiative

Brian Spector CEO, CertiVox. CloudAuthZ

Federation At Fermilab. Al Lilianstrom National Laboratories Information Technology Summit May 2015

Topics. Context. Scalable Privacy. Frontiers. R&E federations globally InCommon

Transcription:

Managing identities TICAL 2012, Lima, Peru Roland Hedberg <roland.hedberg@adm.umu.se>

Who am I? Got into networking in 1987 Managed computer networks and network applications Worked with standardisation of directory technologies Software developer/senior researcher

Umeå, Sweden Latitude: 63 50' North Longitude: 20 15' East

Topics Why How Future

What s an identity?

What s an identity? The collective aspect of the set of characteristics by which a thing is definitively recognizable or known.

What s an identity? The collective aspect of the set of characteristics by which a thing is definitively recognizable or known.

What s an identity? The collective aspect of the set of characteristics by which a thing is definitively recognizable or known. A set of attributes and values

Why?

Historic progression late 80 A set of completely autonomous systems

1st transition LDAP mid 90 Some know how to use LDAP LDAP is populated manually

2nd transition 2007 Single-Sign-On ubiquitous in-house Extra info from LDAP SSO Metadirectory

3rd transition today Identity federations SAML Eduroam

IdPs over the world as seen from Norway

Driving forces 1st & 2nd transition Centralized cheaper than decentralized 3rd transition User convinience and economy of scale

Eduroam

Eduroam status 43 member NROs > 5300 service locations + 400 (Au, Nz) 250 M successful authn (~6% international) may 2011- april 2012 eduroam is ranked as 27th most widely used SSID (5th most frequent operator SSID)

Why! Enables trustworthy exchange of information between federations Reduces the costs of developing and operating services Improves the security and end-user experience of services Enables service providers to greatly expand their user base Enables identity providers to increase the number of services available to their users

How

SWAMID offers quality assured and secure identification of employees, students, alumni and other associated in higher education in Sweden, in the Nordic countries, in the rest of Europe and also in North America and Asia. The edugain service is intended to enable the trustworthy exchange of information related to identity, authentication and authorisation between the GÉANT (GN3) Partners' federations. InCommon provides a secure and privacy-preserving trust fabric for research and higher education institutions, and their partners, in the United States.

SWAMID offers quality assured and secure identification of employees, students, alumni and other associated in quality higher education assured in Sweden, in the Nordic countries, in the rest of Europe and also in North America and Asia. The edugain service is intended to enable the trustworthy trustworthy exchange of information exchange related to identity, authentication and authorisation between the GÉANT (GN3) Partners' federations. InCommon provides a secure and privacy-preserving trust fabric trust fabric for research and higher education institutions, and their partners, in the United States.

TRUST

Federation policies SWAMID Federation Policy v2.0 SWAMID Basic Identity Assurance Profile v1.0 SWAMID eduroam Technology Profile v1.0 SWAMID SAML WebSSO Technology Profile v1.0

Explicit trust Kantara Identity Assurance Framework (IAF) http://kantarainitiative.org/confluence/display/idassurance/home Common Organizational Service Assessment Criteria Operational Service Assessment Criteria

Trust in Security environment IdM checklist

Some outstanding issues

Problem of scale A few services has many users Many services has few users

Which identity provider to use? OpenID NASCAR problem Where Are You From (WAYF)

Attribute releases Specific for every Identity - Service provider pair Solution Service categories

Service examples

SWAMID coverage All universities with more than 1000 FTE students are part of SWAMID ~ 97 % of all students and employees

Studera.nu

NyA-webben Student administration Student admission system Base user urn:mace:swami.se:gmai:nya-dw:base:o=yy Department user urn:mace:swami.se:gmai:nya-dw: department:o=yy:noreduorgunituniquenumber=zzzz

Adobe Connect

BOX.COM Business agreement between SUNET and BOX.COM

Hospital contact

Foodl https://foodl.org/

Future

Non-web http://www.project-moonshot.org/ Project Moonshot is a JANET(UK)-led initiative, in partnership with the GEANT project and others, to develop a single unifying technology for extending the benefits of federated identity to a broad range of non-web services, including Cloud infrastructures, High Performance Computing & Grid infrastructures and other commonly deployed services including mail, file store, remote access and instant messaging.

The great divide Higher Education and public services SAML2 Social services OpenId/OAuth2/OpenId Connect

Conclusion Get your identity management in order Document and secure your IdM process Join the Identity federations