Bringing ASEAN and TEIN- Beneficiary Countries towards Federation: Issues and Challenges Suhaimi Napis, (Universiti Putra Malaysia) and Muhammad Farhan Sjaugi (Perdana University of Malaysia) suhaimi@upm.my; farhan@perdanauniversity.edu.my
Outline Introduction TEIN Identity Management and Federation Application Workshops Issues and Challenges Lesson Learned and Possible Strategies
Introduction The development of trust framework generally starts with each country building its National Identity and Access Management or National Federation. And before national federation organizations need to have Single Sign On (SSO) And before SSO, organizations need to have LDAP
Our Aspirations And thats what we want all organizations wishing to develop IAM to know by constantll engaging them through workshops and awareness seminar Gakunin helped Malaysia for Secure Identity Federation on Unified Lightweight Access management (SIFULAN.my) We are desirous to bring in ASEAN countries to ASEAN Regional Federation
TEIN IMF Application Workshops Held two Identity Management and Federation Workshop sponsored by TEIN Application Workshop Fund; Bandung and Kuala Lumpur Objectives:: To create awareness on the trust framework surrounding identity federation and access management To introduce the steps towards national federation To teach basic knowledge on the technical deployment of national federation
TEIN IMF Application Workshops ASEAN Countries: Malaysia, Singapore, Indonesia, Thailand, Vietnam, Myanmar,Philipines, Laos, Cambodia Beneficiary Countries: Pakistan, Bangladesh, Sri Lanka, Afghanistan, Kyrzystan Each country has specific and diverse issues and no one-size-fits-all solution. We underestimated the big task prior to the workshops and met up with participants So the future approach is to do IMF workshop for each country!
Workshop contents IMF1: Identity Federation IMF2: Identity Federation + Eduroam Eduroam-Shibboleth Virtual Appliance (EduShib VA) Malaysia has Secure Identity Federation on Unified Lightweight Access Management (SIFULAN.my) Collaborated with GAKUNIN (Gakunin map Group Management) and CESNET (Atlases Pathological Images) Eduroam is now at USM, UTM, UPM and UMT with another two Universities (UM and USIM)
Communities Research and education: 20 Public universities; (~500K students); 10 public Research Institutes; Government Identity Federation starting for govt services Will be receipients for the mentioned cloud services like Office 365, Net+, library subscription,
Issues and Challenges Technical expertise issue; Need two types of staff (1) IT staff for System and (2) Administration Staff for documentation Biggest challenge is the engagement and awareness on the importance of IAM=Human Factor (always worried about exposure of ID/PW) Cost; Need to invest in servers for developing entire ecosystem of LDAP, SSO Integration of campus applications
Other Countries Philipines is seeking assistance for their Federation Sri Lanka has indicated interest We will do our best and committed to spread the adoption of IAM to all ASEAN and Beneficiary countries
EduShib Virtual Appliance Edushib VA (eduroam and shibboleth virtual appliance) image to assist organization that want to get onboard immediately with less hassle. Most of the configuration of edushib va is preconfigured for eduroam.my and SIFULAN federation, but it can be customized for other federation as well.
EduShib VA Advantages Virtual appliance/machine based is better (in case of Malaysia) as most of universities/institutes already have virtualization/cloud infrastructure hence the implementation cost would be significantly lower and faster instead of using physical server. Upgrade the infrastructure to physical server for better performance when necessary Universities/institutes management has give great attention to the initiative and become regular user.
Summary SIFULAN.my is the baby of GAKUNIN Gakunin and SIFULAN desire to replicate what we did in Malaysia to other countries. We have the expertise and experience to assist based on lesson-learned from the IMF Workshops. Will use REFEDS, EduGAIN as the model