Data Services Integration Team WP1 – Federated Identity Paul Millar, Patrick Fuhrmann, Bernd Schuller, Arsen Hayrapetyan, Marcus Hardt, Shiraz Memon, Shahbaz Memon, Christian Bernardt, Tigran Mkrtchyan, Dennis Klein
The grid X.509 (user) certificates User Certificate VOMS t r e c r t t A The Grid Proxy Certificate 2 2014-12-11 Paul Millar – DFN meeting, DESY
The problem: typical user reaction to X.509 3 2014-12-11 Paul Millar – DFN meeting, DESY
Need a bridge between users and X.509 • The problem: • Infrastructure needs X.509 (isn't changing any time soon) • User experience is terrible (isn't changing any time soon) • Assume that: • users work with a web-browser • have a home institute that's part of DFN-AAI • We want that a web-portal somehow gets an X.509 credential for a user Portal interacts with resources on users behalf. 4 2014-12-11 Paul Millar – DFN meeting, DESY
Use-case: Globus Transfer Service Globus File Transfer Service CTS X.509 WAYF IdP X.509 User dCache GlobusFTP Data 5 2014-12-11 Paul Millar – DFN meeting, DESY
Use-case: 'Science Gateway' portal Provide a common place for interacting with “big” resources CTS Federation 9 0 5 . X Large-scale resources Science 9 0 (needs X.509 authn) 5 Gateway . X 6 2014-12-11 Paul Millar – DFN meeting, DESY
Use-case: life-cycle management 7 2014-12-11 Paul Millar – DFN meeting, DESY
Types of solution: in-band vs out-of-band SAML X.509 Delegation 6. 7. D SAML I 4. X.509 CTS IdP IdP CTS Portal Portal 5. SAML 3. 5. 2. 2. 4. SAML 3. D I 1. 1. in-band out-of-band 8 2014-12-11 Paul Millar – DFN meeting, DESY
This is not an original idea... • USA InCommon: CI-Login [in-band] • UK NGS: SHEBANGS [in-band], SARoNGS [in-band] • Switzerland SWITCH: WS-Trust, GridCertLib [out-of-band] • EGI: robot certificates [out-of-band] • ShibGrid [in-band?] • EMI: STS (software, WS-Trust) [out-of-band] • ... 9 2014-12-11 Paul Millar – DFN meeting, DESY
OAuth-based in-band X.509 emp- ID ID 9. T CSR 8. 2. 3. MyProxy- IdP Portal OAuth SAML 7. 4. 6. 5. ID emp- ID T SAML WebSSO MyProxy-OAuth 1. 10 2014-12-11 Paul Millar – DFN meeting, DESY
OAuth ( MyProxy-OAuth, CI-Login-OAuth, ... ) User's Portal CTS laptop SAML WebSSO 11 2014-12-11 Paul Millar – DFN meeting, DESY
SHEBANGS (portal first) solution (detail) Diagram stolen from http://pos.sissa.it/archive/conferences/162/150/EGICF12-EMITC2_150.pdf 12 2014-12-11 Paul Millar – DFN meeting, DESY
SARoNGS solution (detail) Diagram stolen from http://pos.sissa.it/archive/conferences/162/150/EGICF12-EMITC2_150.pdf 13 2014-12-11 Paul Millar – DFN meeting, DESY
14 2014-12-11 Paul Millar – DFN meeting, DESY
EGI Federated Cloud and Science Gateways “The EGI Federated Cloud is a seamless grid of academic private clouds and virtualised resources, built around open standards and focusing on the requirements of the scientific community.” → i.e., lots of IaaS services. The EGI Science gateways are “a popular and rapidly developing tool used by researchers to access the European Grid Infrastructure.” → i.e., lots of portals that want to use Federated Cloud resources. • EGI also needs to solve these problems, too – potential for collaboration. 15 2014-12-11 Paul Millar – DFN meeting, DESY
Thanks for watching Questions? 16 2014-12-11 Paul Millar – DFN meeting, DESY
VOMS groups and roles model 17 2014-12-11 Paul Millar – DFN meeting, DESY
Recommend
More recommend