Identity and Access Management for LIGO: International Challenges



Similar documents
LIGO Authentication and Authorization 2.0

LIGO Mailing List Group Configuration

Three Case Studies in Access Management

SSO Questions. Request for 10 minute overview/demo on Grouper software package set-up (IT-oriented)

Federation At Fermilab. Al Lilianstrom National Laboratories Information Technology Summit May 2015

Shibboleth User Verification Customer Implementation Guide Version 3.5

Federated Identity Management and Shibboleth. Noreen Hogan Asst. Director Enterprise Admin. Applications

Development and deployment of integrated attribute based access control for collaboration

Federations 101. An Introduction to Federated Identity Management. Peter Gietz, Martin Haase

A Shibboleth View of Federated Identity. Steven Carmody Brown Univ./Internet2 March 6, 2007 Giornata AA - GARR

Business and Process Requirements Business Requirements mapped to downstream Process Requirements. IAM UC Davis

Getting Started with Single Sign-On

Curriculum Vitae et Studiorum. Giovanni Losurdo

Authentication Integration

Cloud Computing. Lecture 5 Grid Case Studies

Identity Management Systems for Collaborations and Virtual Organizations

Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department

SAML-Based SSO Solution

IGI Portal architecture and interaction with a CA- online

Three Campus Case Studies: Managing Access with Grouper

Getting Started with Single Sign-On

Federated Identity: Leveraging Shibboleth to Access On and Off Campus Resources

External and Federated Identities on the Web

Single Sign On. SSO & ID Management for Web and Mobile Applications

Provisioning and Deprovisioning 1 Provisioning/De-provisiong replacement 1

Federated Identity Management

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

Shibboleth and Library Resources

Concepts and Architecture of the Grid. Summary of Grid 2, Chapter 4

Top 8 Identity and Access Management Challenges with Your SaaS Applications. Okta White paper

Centralized Oracle Database Authentication and Authorization in a Directory

SAML 2.0 SSO Deployment with Okta

Windows Services. Support Windows and mixed-platform workgroups with high-performance, affordable network services. Features

Single Sign-on (SSO) technologies for the Domino Web Server

Oracle Identity Manager, Oracle Internet Directory

Authentication Methods

Approaches to Enterprise Identity Management: Best of Breed vs. Suites

Cloud federation. Prelude to Hybrid Clouds. CHEP 2015 Okinawa, Japan. Marek Denis CERN Geneva, Switzerland

LIGO Cybersecurity Status

Moodle and Office 365 Step-by-Step Guide: Federation using Active Directory Federation Services

Federated Identity Management. Willem Elbers (MPI-TLA) EUDAT training

Using Shibboleth for Single Sign- On

How To Use Netscaler As An Afs Proxy

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

IVOA Single-Sign-On Profile: Authentication Mechanisms Version 2.0

Flexible Identity Federation

Novell Access Manager

The New Grouper: Its New User Interface and More

Title: A Client Middleware for Token-Based Unified Single Sign On to edugain

UW System Identity & Access Management (IAM) Recommended Strategic Roadmap

White Paper. FFIEC Authentication Compliance Using SecureAuth IdP

Shibboleth Authentication. Information Systems & Computing Identity and Access Management May 23, 2014

APPLICATION ACCESS MANAGEMENT (AAM) Augment, Offload and Consolidate Access Control

Federated Authentication and Credential Translation in the EUDAT Collaborative Data Infrastructure

SAML-Based SSO Solution

Canadian Access Federation: Trust Assertion Document (TAD)

Provisioning and deprovisioning in an identity federation

Collaboration in the Cloud. Niels van Dijk, SURFnet, CAMP, Nov , San Francisco

HOL9449 Access Management: Secure web, mobile and cloud access

MIT Tech Talk, May 2013 Justin Richer, The MITRE Corporation

Using Grouper: Newcastle University case studies. Richard James Caleb Racey

Computer Services Documentation

DEPLOYMENT GUIDE. SAML 2.0 Single Sign-on (SSO) Deployment Guide with Ping Identity

The Top 5 Federated Single Sign-On Scenarios

Request for Proposals. Statewide Two Factor Authentication Solution. Addendum #2 October 5, Questions and Responses

Transcription:

Identity and Access Management for LIGO: International Challenges Scott Koranda for LIGO and CTSC University of Wisconsin-Milwaukee November 14, 2012 LIGO-XXXXXXXX-v1 1 / 26

LIGO Science Mission LIGO, the Laser Interferometer Gravitational-wave Observatory, seeks to detect gravitational waves ripples in the fabric of spacetime. First predicted by Einstein in his theory of general relativity, gravitational waves are produced by exotic events involving black holes, neutron stars and objects perhaps not yet discovered. 2 / 26

LIGO Hanford, WA 3 / 26

LIGO Livingston, LA 4 / 26

LIGO Laboratory LIGO Laboratory = LIGO Caltech + LIGO MIT + LIGO Hanford Observatory + LIGO Livingston Observatory 5 / 26

LIGO India! Anticipated to be operational 2020 6 / 26

LIGO Scientific Collaboration The LIGO Scientific Collaboration (LSC) is a self-governing collaboration seeking to detect gravitational waves, use them to explore the fundamental physics of gravity, and develop gravitational wave observations as a tool of astronomical discovery. The LIGO Scientific Collaboration was founded in 1997 and currently has just over 1000 members from 70 institutions worldwide. 7 / 26

8 / 26

LIGO Identity and Access Management (IAM) Project Knit together existing technologies and tools Goals: Single identity for each LIGO person Single source of membership info Single credential for each LIGO person SSO across web, grid, command-line 9 / 26

LIGO electronic identity Kerberos principal for each LIGO member scott.koranda@ligo.org users call it their at LIGO.ORG login also known as their albert.einstein login roster drives creation of principal for each member roster pushes principal and details into LDAP 10 / 26

Single authoritative source of group membership Decided to leverage Grouper from I2 Flexible enough to reflect community structure Ready-to-use admin web front-end SOAP and RESTful WS APIs Privilege, Role, Attribute support Provision into LDAP 11 / 26

12 / 26

Single sign-on for LIGO web space Deploy I2 Shibboleth System Single sign-on across LIGO web tools/pages LIGO Identity Provider (IdP) Authenticate via REMOTE USER and mod auth kerb Attributes pulled from LDAP master server Focus mainly on IsMemberOf (via Grouper) Consume federated identities LIGO joined InCommon for many U.S. institutions Support access for external collaborators 13 / 26

LIGO and InCommon: External Collaborators 14 / 26

CILogon integrates LIGO Data Grid 15 / 26

CILogon integrates LIGO Data Grid 16 / 26

Broader GW Community GW community is larger than LIGO... 17 / 26

Virgo interferometer, Cascina, Italy 18 / 26

KAGRA, Japan 19 / 26

Federated access for KAGRA Date: Fri, 19 Oct 2012 05:15:41-0500 From: Nelson Christensen <nchriste@carleton.edu> Subject: access to remote participation wiki Hi Scott, Warren, Stuart, I am not sure if you are the right guys for this, but I will start with you. Is there any way that we can give access to the remote participation wiki to our KAGRA colleague Yoichi Aso who is the new KAGRA member on our remote participation committee. Thanks, Nelson 20 / 26

Federated access for KAGRA Need to share technical drawings and like with about 50 KAGRA scientists 21 / 26

Peer-to-peer federation necessary InCommon membership enables only US federation Ongoing negotiation with UK Access Federation Early work with edugain in Europe Other? LIGO also expects relying parties in Candada, Australia, India, Korea, China,... No option now but peer-to-peer negotiation or joining each national identity federation. IDEM in Italy will be next federation for LIGO 22 / 26

LIGO CTSC international federation engagement (6 mo) Goals 1. Document technical and policy changes for a peer-to-peer 2. LIGO membership in IDEM 3. Prototype interoperability with UK via InCommon 4. Research likelihood and timeline for edugain via InCommon 5. Assist LIGO-India with developing use cases 23 / 26

Peer-to-peer federation with KAGRA IdP managed by University of Tokyo Metadata exchange was easy Negotiation on attributes was easy eppn, givenname, sn, email Anticipate difficuly with edugain Access control is largest issue No LIGO/KAGRA working group ACL based on eppn Only admins know eppn Grouper can consume federated identity, but no sophisticated onboarding/offboarding or enrollment, notification 24 / 26

Managing Collaboration with COmanage 25 / 26

Final thoughts... There is no distinction between web and grid Scientists just want to use tools Don t care if web or grid Typical use case: Submit large workflow to grid Jobs run for week analyzing data Workflow generates 1000 s of summary images Need to POST summary into analysis wiki Seamless cred management across grid, web, cloud Delegation is important Need Higher Ed and Grid communities to build together 26 / 26