SURFfederatie - edugain. Opt-in Metadata Management for a Hub & Spoke Federation



Similar documents
Разработка программного обеспечения промежуточного слоя. TERENA BASNET Workshop, November 2009 Joost van Dijk - SURFnet

Step-up-authetication as a service

Licia Florio Project Development Officer Identity Federations in Europe

Collaboration in the Cloud. Niels van Dijk, SURFnet, CAMP, Nov , San Francisco

About Me. Software Architect with ShapeBlue Specialise in. 3 rd party integrations and features in CloudStack

Load Balancing Lync Jaap Wesselius

IP-NBM. Copyright Capgemini All Rights Reserved

HOL9449 Access Management: Secure web, mobile and cloud access

Federation At Fermilab. Al Lilianstrom National Laboratories Information Technology Summit May 2015

IGI Portal architecture and interaction with a CA- online

VOPaaS Virtual Organisation Platform as a Service

IC Rating NPSP Composieten BV. 9 juni 2010 Variopool

Windows Azure Push Notifications

Cloud federation. Prelude to Hybrid Clouds. CHEP 2015 Okinawa, Japan. Marek Denis CERN Geneva, Switzerland

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

Shibboleth N-Tier Support. Chad La Joie

The information in this report is confidential. So keep this report in a safe place!

Federated Identity Management. Willem Elbers (MPI-TLA) EUDAT training

Getting Started with Single Sign-On

Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure

This chapter describes how to use the Junos Pulse Secure Access Service in a SAML single sign-on deployment. It includes the following sections:

Single Sign-on. Overview. Using SSO with the Cisco WebEx and Cisco WebEx Meeting. Overview, page 1

Authentication Integration

Risk-Based Monitoring

Logout Support on SP and Application

THE EMOTIONAL VALUE OF PAID FOR MAGAZINES. Intomart GfK 2013 Emotionele Waarde Betaald vs. Gratis Tijdschrift April

Federated Identity for Cloud Computing and Cross-organization Collaboration

GFIPM & NIEF Single Sign-on Supporting all Levels of Government

Single Sign On. SSO & ID Management for Web and Mobile Applications

How Single-Sign-On Improves The Usability Of Protected Services For Geospatial Data

Configuring EPM System for SAML2-based Federation Services SSO

Identity and Access Management for Federated Resource Sharing: Shibboleth Stories

OVERVIEW. DIGIPASS Authentication for Office 365

Configuring ADFS 3.0 to Communicate with WhosOnLocation SAML

JOSSO 2.4. Ws-Federation Integration Tutorial

Automated Testing of SAML 2.0 Service Providers. Andreas Åkre Solberg UNINETT

Relationele Databases 2002/2003

Connecting Web and Kerberos Single Sign On

Federated Identity Management

IMPLEMENTING SINGLE SIGN- ON USING SAML 2.0 ON JUNIPER NETWORKS MAG SERIES JUNOS PULSE GATEWAYS

ADFS Integration Guidelines

Hoe kies je de juiste Microsoft Hosted Exchange Service Provider?

Improving Security and Productivity through Federation and Single Sign-on

SAML Profile for Privacy-enhanced Federated Identity Management

~ We are all goddesses, the only problem is that we forget that when we grow up ~

Moodle and Office 365 Step-by-Step Guide: Federation using Active Directory Federation Services

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

The end-to-end principle in the Internet. 15 maart 2005

Extending DigiD to the Private Sector (DigiD-2)

SAML SSO Configuration

GMP-Z Annex 15: Kwalificatie en validatie

TIB 2.0 Administration Functions Overview

Federated Identity Management

employager 1.0 design challenge

Agenda. How to configure

Title: A Client Middleware for Token-Based Unified Single Sign On to edugain

Virtualisatie. voor desktop en beginners. Gert Schepens Slides & Notities op gertschepens.be

How to create a SP and a IDP which are visible across tenant space via Config files in IS

Federated Identity Management Solutions

OGH: : 11g in de praktijk

SURFnet Dashboard. Concept, Impressions and ideas. High quality internet for higher Education and Research

Web Services Security and Federated Identity Management

Getting Started with AD/LDAP SSO

Managed Security Services Als je het doet moet je het goed doen.

HP Software as a Service

AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle

Authentication Methods

password, just as if you were accessing the SharePoint environment with a browser. This prompting is also handled via Windows.

Test Plan for Liberty Alliance SAML Test Event Test Criteria SAML 2.0

The saga of WebFTS and Federated Identity


total dutch speak Dutch instantly no books no writing absolute confi dence

Microsoft Office 365 Using SAML Integration Guide

SAML 2.0 Configurations at SAP NetWeaver AS ABAP and Microsoft ADFS

Non-web federated authentication

Transcription:

SURFfederatie - edugain Opt-in Metadata Management for a Hub & Spoke Federation

Content - History of SURFfederatie - Federation models - Functional view - Consequences of hub & spoke - edugain - Future changes 1

Once upon a time 1996 2001 2004 2006 2007 2008 2

Federation models (communication/ login, not metadata) - 1-1 - Business VS: SAML 1.x IDP SP - de-facto - NxN - Shared trust, pt2pt IDP IDP SP SP - Education VS/Europa IDP SP - 2xN - Central gateway (CFC) IDP SP - protocol translation - SURFfederatie IDP IDP CFC SP SP = CFC, IDP, SP 3

Functional view (Since August 2008) Identity Providers SURFfederatie CORE Service Providers A-Select Cross Credentials A-Select Cross Central Federation Components Shibboleth Applications SAML 2.0 SAML 2.0 WS-Fed / ADFS WS-Fed / ADFS 4

Metadata & proxying IDP1 SP1 A-1 B-1 IDP2 A-2 A-3 B-2 B-3 SP2 IDP3 SP3 SP1=A-1 {IDP1, IDP2} SP2=A-2 SP3=A-3 {all} IDP1=B-1 IDP2=B-2 IDP3=B-3 5

/-less operation IDP1 SP1 IDP2 IDP3 SP2 SP3 6

hub & spoke pros/cons Pros Cons - 1 connection for IDP/SP - Minimal overhead for IDPs - Centralized (technical) management - Specialist knowledge @ SN - Less needed for IDP/SP - Scales well at national level - Extra features easier to do - Web services - Group support - Procedures - release consent per SP - Key/cert/metadata changes - Lack of knowledge @ IDP - Double-edged sword - Scalability European level - Can only support common denominator 7

Importing edugain SPs SPz edugain IDP1 SP1 SPx=ddd IDP2 A-1 A-2 A-3 A-z B-1 B-2 B-3 SP2 SPy=eee SPz=fff IDP3 SP3 SP1=A-1 {IDP1, IDP2} IDP1=B-1 SP2=A-2 IDP2=B-2 SP3=A-3 {all} IDP3=B-3 SPz=A-z 8

Exporting IDPs edugain IDP1 SP1 SPx=ddd IDP2 A-1 A-2 A-3 A-z B-1 B-2 B-3 SP2 SPy=eee SPz=fff IDP3=B-3 IDP3 SP3 SP1=A-1 {IDP1, IDP2} IDP1=B-1 SP2=A-2 IDP2=B-2 SP3=A-3 {all} IDP3=B-3 SPz=A-z 9

Exporting SPs to edugain edugain IDP1 SP1 SPx=ddd IDP2 A-1 A-2 A-3 A-z B-1 B-2 B-3 SP2 SPy=eee SPz=fff SP3=SP3 IDP3 SP3 SP1=A-1 {IDP1, IDP2} IDP1=B-1 SP2=A-2 IDP2=B-2 SP3=A-3 {all} IDP3=B-3 IDPz SPz=A-z 10

SP auth list (optional) edugain IDP1 SP1 IDP2 IDP3 A-1 A-2 A-3 A-z B-1 B-2 B-3 SP2 SP3 SPx=ddd SPy=eee SPz=fff SP3=SP3 IDPx IDPy IDPz SP1=A-1 {IDP1, IDP2} SP2=A-2 SP3=A-3 {all} IDP1=B-1 IDP2=B-2 IDP3=B-3 Per SP auth list SP3: - IDP1 - IDP2 - IDPz IDPz SPz=A-z 11

SP auth list (optional) edugain IDP1 SP1 IDP2 IDP3 A-1 A-2 A-3 A-z B-1 B-2 B-3 SP2 SP3 SPx=ddd SPy=eee SPz=fff SP3=SP3 IDPx IDPy IDPz SP1=A-1 {IDP1, IDP2} SP2=A-2 SP3=A-3 {all} IDP1=B-1 IDP2=B-2 IDP3=B-3 Per SP auth list SP3: - IDP1 - IDP2 - IDPz IDPz SPz=A-z 12

Future plans - Integrate with SURFconext - Procedural/organisational - Technical (level of integration TBD) - Change of consent model - Opt-in à Opt-out - Addition of User Consent - Web Service support - Needed for (scientific) workflows - Rich client/beyond web SSO/mobile support - Rethink procedures/management 13

Remco Poortinga van Wijnen remco.poortinga@surfnet.nl federatie-beheer@surfnet.nl www.surfnet.nl Presentation released under Creative Commons http://creativecommons.org/licenses/by/3.0/ 14

15

Backup slides 16

URLs SP die wil meedoen moet SAML doen (want daarvoor zijn we geen proxy zoals normaal) https://wayf.surfnet.nl/federate/surfnet/edugain 2 IDPS: SN & TERENA 1 SP: TERENA (MDS laat ook zien: TERENA IDP via gateway met URL encoded ipv SAML scoped (zoals ) -> niet iedereen implementeert dat, dus vanwege interop. Doen we het zo. Ook mogelijk om SP specifiek metadata te genereren (per SP uit onze fed) die niet zelf auth lijst willen bijhouden. Bevat SF IDPs + approved edugain IDPs 17 (C) 2011 SURFnet B.V.

Metadata https://aai-viewer.switch.ch/interfederation-test/test/ Wij nu niet saml2int compliant. (behandelen attribs als format unspecified, moet uri zijn volgens spec) 18 (C) 2011 SURFnet B.V.