1 of 79

ELIXIR AAI

Mikael Linden, Michal Prochazka

AAI workshop 15-16 March 2016

www.elixir-europe.org

2 of 79

Schedule of day two ELIXIR parallel session

09:00

Coffee and arrivals

09:15

Introduction to ELIXIR AAI

10:45

Coffee break

11:00

Integrating a SAML SP to the ELIXIR AAI

12:30

Lunch

13:30

Group management in ELIXIR

15:00

Coffee break

15:15

Integrating ELIXIR groups into the SAML SP

16:15

Wrap-up and post-workshop questionnaire

16:30

Close

3 of 79

Motivation

4 of 79

Motivation

Yesterday you learned

  • to install a Shibboleth SP
  • that the Shibboleth SP needs to be registered to a federation

Today

  • You will learn to integrate the Shibboleth SP to �a federation called ELIXIR AAI
  • You will learn what supplementary services ELIXIR AAI offers on top of just the SAML-based authentication

5 of 79

Introduction to ELIXIR AAI

AAI = Authentication and Authorisation Infrastructure

5

6 of 79

6

medicine

agriculture

bioindustries

environment

ELIXIR connects national bioinformatics centres and EMBL-EBI into a sustainable European infrastructure for biological research data

ELIXIR underpins life science research – across academia and industry

7 of 79

ELIXIR AAI history – where we are now

  • Use case gathering -- Autumn 2014
  • Requirements and design – Spring 2015
  • Deployment starts – Autumn 2015 – EXCELERATE WP4.3.1
    • Part of ELIXIR Compute platform
  • First release -- August 2016
    • Until that ELIXIR AAI in pilot status
    • Key components up and running already

8 of 79

High level stuff:�ELIXIR AAI strategy (DRAFT)

  • Covers
    • ELIXIR AAI under the responsibility of the hub
    • Relations to e-infrastructures (collaborate, make use of)
    • Relations to other BMS research infrastructure (common AAI)
    • ELIXIR AAI policies for end users, relying parties and AAI operators
  • https://www.elixir-europe.org/documents/draft-elixir-aai-strategy
  • Under community consultation until 15 Apr
  • To be presented to ELIXIR Heads of Nodes in June

9 of 79

Design of ELIXIR AAI

10 of 79

ELIXIR AAI design

10

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management (REMS)

Group/role mgmt (PERUN)

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

11 of 79

ELIXIR AAI design

11

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

ELIXIR Proxy IdP

  • User has one ELIXIR identity
  • User can authenticate using external identities
  • Proxy IdP consolidates the Ids
  • Acts as SAML IdP for Relying services (later also OAuth2)

12 of 79

In this training

12

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

wiki

Data archive

Attribute self-management

Step-up AuthN

ELIXIR Proxy IdP

Your Shibboleth SP

Google

In this training (before lunch) you will integrate the Shibboleth SP you installed yesterday to the test environment of the ELIXIR Proxy IdP.

13 of 79

ELIXIR identity

13

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

EGA

wiki

Cloud

Intranet

Data archive

tommioffinland@google�(Google ID)

nyronen@csc.fi�(eduGAIN)

0000-0002-3634-3756 (ORCID)

tommi@elixir-europe.org�(ELIXIR ID)

14 of 79

ELIXIR AAI design

14

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Step-up Authentication

1. User authenticates weakly using external authentication

2. User authenticates with second factor

- e.g. SMS-OTP or a mobile app

15 of 79

ELIXIR AAI design

15

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Credential translation

  • ELIXIR Proxy IdP is web
  • Some services are non-web
    • Access to cloud middleware
    • SSH access to a cloud VM
    • Triggering file transfer
  • X.509 (CILogon)
  • SSH public key
  • Kerberos

16 of 79

ELIXIR AAI design

16

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Group management (PERUN)

  • Users can create and manage groups
    • Add/Invite new members
    • Remove members
    • Etc
  • Access to services can rely on group memberships

17 of 79

In this training

17

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Bona fide management

Dataset authorisation management

Credential translation

EGA

eLearning

Cloud

wiki

Data archive

Attribute self-management

Step-up AuthN

ELIXIR Proxy IdP

Your Shibboleth SP

Google

In this training (after lunch) you will configure your Shibboleth SP to consume group membership attributes set by PERUN for authorisation.

Group/role management

ELIXIR Directory

18 of 79

ELIXIR AAI design

18

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Bona Fide researchers

  • Anyone can have ELIXIR ID
  • Bona Fide researcher: a member of bioinformatics community with certain basic privileges
  • For instance: access to availability database

19 of 79

ELIXIR AAI design

19

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Dataset authorisation management (REMS)

  • Sensitive human data
  • Data access application needed

20 of 79

�The REMS concept

Principal�investigator�Applicant

Research group�Members of the application

Metadata on dataset 1&2

Dataset 1

Dataset 2

DAC 1�Approver

DAC 2�Approver

REMS

Workflow

Reports

Entitlements

IdP

IdP

IdP

SP

1. Apply �for access

4. Approve

5. Access

3. Circulate to approver

2. Commit to licence terms

21 of 79

Integrating SAML SP into ELIXIR AAI�

22 of 79

ELIXIR IdP/SP Proxy

23 of 79

Steps

  1. Install Shibboleth SP - DONE
  2. Configure Shibboleth SP - DONE
  3. Register ELIXIR Proxy IdP Metadata in Shibboleth SP
  4. Get Metadata of the Shibboleth SP
  5. Send a request to the ELIXIR AAI
  6. Point to the ELIXIR AAI Discovery Service
  7. Test the authentication

24 of 79

Register ELIXIR AAI Metadata

Each SAML SP must consume ELIXIR AAI Proxy IdP metadata

  • They are already in metadata feed you configured yesterday

ELIXIR AAI Proxy IdP must consume metadata of your service

  • Detailed description on https://goo.gl/6LNFb2

25 of 79

ELIXIR AAI Metadata configuration

Download metadata signing certificate

cd /etc/shibboleth/

sudo curl -k -o elixir-idp-certificate.pem https://engine.elixir-czech.org/authentication/idp/certificate

Edit /etc/shibboleth/shibboleth2.xml

<MetadataProvider type="XML" uri="https://engine.elixir-czech.org/authentication/idp/metadata"

backingFilePath="elixir-idp-metadata.xml" reloadInterval="1800">

<MetadataFilter type="Signature" certificate="elixir-idp-certificate.pem"/>

</MetadataProvider>

If you have more metadata sources, use covering element

<MetadataProvider type="Chaining">

...Metadata providers

</MetadataProvier>

26 of 79

SP Metadata requirements

  • Download your metadata from
  • curl -k -O https://sp#.example.org/Shibboleth.sso/Metadata
  • Compliance with SAML2Int profile
  • Add contact information including technical contact to metadata file (just before last element /md:EntityDescriptor)

<md:Organization>

<md:OrganizationName xml:lang="en">Masaryk University</md:OrganizationName>

<md:OrganizationDisplayName xml:lang="en">Masaryk University</md:OrganizationDisplayName>

<md:OrganizationURL xml:lang="en">http://www.muni.cz/</md:OrganizationURL>

</md:Organization>

<md:ContactPerson contactType="technical">

<md:GivenName>Michal</md:GivenName>

<md:SurName>Prochazka</md:SurName>

<md:EmailAddress>michalp@ics.muni.cz</md:EmailAddress>

</md:ContactPerson>

</md:EntityDescriptor>

27 of 79

ELIXIR AAI Discovery Service

Edit /etc/shibboleth/shibboleth2.xml

If your service will be connected just to ELIXIR AAI

<SSO entityID="https://engine.elixir-czech.org/authentication/idp/metadata">

SAML2</SSO>

Otherwise add

<SessionInitiator id="elixir" location="/elixir" type="SAML2" relayState="ss:mem" template="bindingTemplate.html" ascIndex="1" entityID="https://engine.elixir-czech.org/authentication/idp/metadata">

</SessionInitiator>

28 of 79

Available SAML2 Attributes

Available SAML2 attributes

  • eduPersonPrincipalName
    • Life Science ID (ELIXIR ID) for CoCo SPs
    • Hashed eduPersonPrincipalName for others
  • eduPersonUniqueID = Life Science ID (ELIXIR ID)/Hashed eduPersonPrincipalName
  • eduPersonEntitlement
    • list of group memberships/REMS
  • displayName
  • mail = preferred mail contact selected by the user

29 of 79

Attribute mapping

  • Check the /etc/shibboleth/attribute-map.xml and uncomment next attributes
  • mail
    • urn:oid:0.9.2342.19200300.100.1.3
  • displayName
    • urn:oid:2.16.840.1.113730.3.1.241
  • Comment “urn:mace:dir” type of attributes
    • Avoid getting multiple values
    • Especially eduPersonPrincipalName and eduPersonEntitlement

30 of 79

Write a request to ELIXIR AAI

Write an email to aai-contact@elixir-europe.org

  • Name of the service
  • Purpose of the service
  • List of required attributes with reasoning why you need these attributes
    • Available options: eduPersonPrincipalName, eduPersonUniqueId, displayName, mail, eduPersonEntitlement
  • Attach SAML2 metadata of the service
    • For training: Just write the hostname of your machine sp#.example.org
  • If your service complies with Code of Conduct (CoCo)

31 of 79

Test the authentication

  • In order to test the authN you have to have a valid ELIXIR account, register here https://www.elixir-europe.org/register

  • For test purposes you will have your own group whose members can access your service, see https://perun.elixir-czech.cz/

  • When the request is approved, you can try the authentication

https://sp#.example.org/Shibboleth.sso/Login

32 of 79

Work in progress: �design of an ELIXIR Log-in button

A PNG file you could place to your ELIXIR SP as a login button for the end user to click.

Clicking the button would trigger ELIXIR AAI authentication.

Graphical guidelines being developed in the ELIXIR hub.

33 of 79

Use cases:�ELIXIR Intranet and mailing lists�

34 of 79

Intranet and mailing lists

For the management of ELIXIR, the ELIXIR hub has rolled out

  • Intranet (based on Drupal sw)
    • For sharing information within and between platforms, user communities and other groups
  • Mailing lists (based on Mailman software)
    • For managing ELIXIR mailing lists

To join a group, a person needs

  1. Register to ELIXIR AAI (http://www.elixir-europe.org/intranet)
  2. Elixir hub assigns them to the proper groups

35 of 79

Intranet and mailing lists

35

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Bona fide management

Dataset authorisation management

Credential translation

EGA

eLearning

Cloud

wiki

Attribute self-management

Step-up AuthN

ELIXIR Proxy IdP

Intranet (Drupal)

Google

Current operational integration to ELIXIR AAI.

Group management (Perun)

ELIXIR Directory

Mailing lists (Mailman)

Authentication

Group memberships�(batch job)

36 of 79

ELIXIR group hierarchy has three branches

root

Community

Nodes

Custom

For people involved in building ELIXIR, e.g. EXCELERATE.

�Governance: ELIXIR hub

For group management in the node services

�Governance: each node

For other services (exact policy TBD)

37 of 79

ELIXIR groups under ”Community” branch

Compute platform

Executive committee

EXCELERATE WP4

Integration

AAI

Data platform

Executive committee

EXCELERATE WP3

Tools platform

Executive committee

EXCELERATE WP1

EXCELERATE WP2

User communities

Human data

Marine

Plant

Rare desease

Governance

Board

Heads of Nodes

Technical Coordinators

Training Coordinators

Etc…

38 of 79

ELIXIR AAI Dimensions of �authentication and authorisation

39 of 79

The dimensions of authentication and authorisation

40 of 79

The planned assurance levels for authentication

Basic�(in place now)

Raised

Strong

Self-registrated accounts, password authN

  • Google, LinkedIn, ORCID authentication

Organisation-registed accounts, password authN

  • Log in with Home Organisation IdPs (eduGAIN)
  • Requires Home Organisation complying to �a minimal assurance level

Face-to-face proof of identity, two factor authN

  • Step-up authentication
  • Possibly rely on external sources (e.g. eID)

41 of 79

The three authorisation layers

41

Any ELIXIR user

Bona fide ELIXIR user

Public

Registered

Controlled

e.g. training, …

Availability catalogue

Sensitive human data

Endorsed ELIXIR user

Service type

Example service

User qualification

42 of 79

The three authorisation layers

42

Any ELIXIR user

Bona fide ELIXIR user

e.g. training, …

Availability catalogue

Sensitive human data

Endorsed ELIXIR user

Example service

User qualification

Any user:

  • Who has committed to ELIXIR Acceptable Usage Policy�

Public

Registered

Controlled

Service type

43 of 79

The three authorisation layers

43

Any ELIXIR user

Bona fide ELIXIR user

e.g. training, …

Availability catalogue

Sensitive human data

Endorsed ELIXIR user

Example service

User qualification

”Bona Fide” researcher

- Must commit to a Code of Conduct (to be defined)

  • Possibly community approval
    • E.g. 5 bona fide researchers vouch for (”peer-to-peer”)
    • E.g. a designated person invites (”hierarchical”)

Public

Registered

Controlled

Service type

44 of 79

The three authorisation layers

44

Any ELIXIR user

Bona fide ELIXIR user

e.g. training, …

Availability catalogue

Sensitive human data

Endorsed ELIXIR user

Example service

User qualification

Endorsed user

  • The user needs to apply for access
    • attach a research plan
  • Each application is screened individually (e.g. by a data access committee, DAC)

Public

Registered

Controlled

Service type

45 of 79

Use case: ELIXIR Beacon

46 of 79

Beacon idea – public access

  • Simple REST API for the query
  • https://genomicsandhealth.org/work-products-demonstration-projects/beacons

Beacon network

Beacon

Beacon

Beacon

Do you have samples �with A in position 1234567 in chromosome 2?

 

Yes!

Yes!

Sorry, no

47 of 79

Beacon – restricted access

  • ELIXIR AAI would keep record on bona fide researchers
  • ELIXIR AAI would use OAuth2/OpenID Connect to deliver the bona fide attribute to the Beacon network & beacons
  • Each beacon would enforce access control

Bona fide researchers

Beacon network

Beacon

Beacon

Beacon

bona fide researcher

How many samples you have with A in position 1234567 in chromosome 2?

 

I have 123

 

I have 234

 

I have 345

 

ELIXIR AAI�proxy IdP

Log-in

attributes

48 of 79

Definition of a bona fide researcher �(Workshop 10.3.2016 in ELIXIR AHM)

An ELIXIR user receives Bona Fide researcher status if both:

  1. Passes the researcher check
    1. 1.1. They have publications in recognised magazines, OR
    2. 1.2. A person satisfying 1.1 vouches for them, OR
    3. 1.3. Their home institution confirms that they are researchers
  2. The person attests to a code
    • For instance ”I don’t try to re-identify the individuals”

49 of 79

Use cases:�Sensitive human data

50 of 79

50

Secure Compute Clouds

Supporting sample logistics

  • Federated Authentication
  • Authorization
  • Dataset registry
  • Data transfer hub
  • Policy and Legal Framework

Services and Coordination

High speed encrypted data transfer

GridFTP/Globus/Aspera

Secure data access remote API

( GA4GH )

Sequencing centers

Data Users

EGA

at

Data Archiving

Bringing users

to data

Data Generation

Managing Access

Data Owner

Data Access Agreement

Data Access Committee

Data Request

Authorization Management Tools

( EGA and CSC REMS )

51 of 79

51

On-demand secure replication of

  • Datasets
  • Dataset metadata

to the EGA mirror sites (”Local EGA”)

Secure Compute Clouds

Supporting sample logistics

  • Federated Authentication
  • Authorization
  • Dataset registry
  • Data transfer hub
  • Policy and Legal Framework

Services and Coordination

High speed encrypted data transfer

GridFTP/Globus/Aspera

Secure data access remote API

( GA4GH )

Sequencing centers

Data Users

EGA

at

Data Archiving

Bringing users

to data

Data Generation

Managing Access

Data Owner

Data Access Agreement

Data Access Committee

Data Request

Authorization Management Tools

( EGA and CSC REMS )

52 of 79

52

Secure storage of datasets in the mirror sites

  • Encrypted when stored
  • VMs see a shared copy
  • Decryption on the fly when accessed from a VM

Secure Compute Clouds

Supporting sample logistics

  • Federated Authentication
  • Authorization
  • Dataset registry
  • Data transfer hub
  • Policy and Legal Framework

Services and Coordination

High speed encrypted data transfer

GridFTP/Globus/Aspera

Secure data access remote API

( GA4GH )

Sequencing centers

Data Users

EGA

at

Data Archiving

Bringing users

to data

Data Generation

Managing Access

Data Owner

Data Access Agreement

Data Access Committee

Data Request

Authorization Management Tools

( EGA and CSC REMS )

53 of 79

53

Managing access to datasets

- Granted by the dataset’s Data Access Committee (DAC)

- Stored centrally at EGA

- Queried from EGA by the mirror sites on the fly

Secure Compute Clouds

Supporting sample logistics

  • Federated Authentication
  • Authorization
  • Dataset registry
  • Data transfer hub
  • Policy and Legal Framework

Services and Coordination

High speed encrypted data transfer

GridFTP/Globus/Aspera

Secure data access remote API

( GA4GH )

Sequencing centers

Data Users

EGA

at

Data Archiving

Bringing users

to data

Data Generation

Managing Access

Data Owner

Data Access Agreement

Data Access Committee

Data Request

Authorization Management Tools

( EGA and CSC REMS )

54 of 79

54

Enforcing the access rights in the data center

- the user launches a VM

- the user has read access to the local replica iff the DAC has granted access to him

Secure Compute Clouds

Supporting sample logistics

  • Federated Authentication
  • Authorization
  • Dataset registry
  • Data transfer hub
  • Policy and Legal Framework

Services and Coordination

High speed encrypted data transfer

GridFTP/Globus/Aspera

Secure data access remote API

( GA4GH )

Sequencing centers

Data Users

EGA

at

Data Archiving

Bringing users

to data

Data Generation

Managing Access

Data Owner

Data Access Agreement

Data Access Committee

Data Request

Authorization Management Tools

( EGA and CSC REMS )

55 of 79

Sensitive human data

55

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

Bona fide management

Attribute self-management

Group management (Perun)

ELIXIR Proxy IdP

Google

Architecture being developed in EXCELERATE WP9.

ELIXIR Directory

EGA

Dataset authorisation management

Local EGA

Local EGA

Step-up AuthN

Credential translation

Cloud

VM

VM

VM

Cloud

VM

VM

VM

eduGAIN IdPs

File transfer

Dataset transfer

Dataset access

Dataset permissions

56 of 79

Setup ELIXIR AAI Authorization

57 of 79

ELIXIR AAI Authorization

  • Authorization is based on group membership
  • Groups are managed by the ELIXIR Hub
  • Management of the group can be delegated
  • Principle: one group has several purposes

  • Service can receive data
    • via SAML2 attributes
    • via OIC (planned)
    • via PUSH mechanism
  • Service can receives only relevant groups
  • Selected services can receive all the groups

58 of 79

Group to Service assignment

  • ELIXIR Hub can assign groups to the services
    • Groups are then managed by to group managers
  • Service then receives if the user is member of assigned group

  • Do not reveal information about the users which are not relevant to the service

59 of 79

PUSH Mechanism

Service can receive data from Perun directly

  • Perun knows which data are required by the service to do the authorization decision
  • Perun prepares the data and propagates it to the service on every change (membership change, user details change, …)
  • Support for deprovisioing, the service is notified about user suspension or removal

60 of 79

Push mechanism schema

61 of 79

SAML authentication

ELIXIR IdP will do the authentication and release additional information about the user

  • including attribute eduPersonEntitlement containing group memberships

  • attribute value is in format
    • [vo_name]:[group_name][:subgroupName]...
    • example
      • elixir:Community:User communities:Marine

62 of 79

Setting up the SP

  • Check the attribute-map.xml if eduPersonEntitlement is mapped

<Attribute name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" id="entitlement"/>

  • Check the attribute-policy.xml if the eduPersonEntitlement is not filtered out

  • Check if you receive the entitlements from ELIXIR AAI
    • https://sp#.example.org/Shibboleth.sso/Session

63 of 79

64 of 79

Setup authorization based on group membership

  • On web server, e.g. Apache (/var/www/secure/.htaccess)

Require shib-attr entitlement “elixir_test:AAI-Training-Manchester:Michal Prochazka”

  • In your application, based on the eduPersonEntitlement value
    • Available via environment variable entitlement

65 of 79

Manage groups in Perun

Navigate to https://perun.elixir-czech.cz

  • Group manager role
    • You will see your group which is assigned to your service

  • Facility manager role
    • You will see assigned groups to your service

66 of 79

67 of 79

68 of 79

69 of 79

Deployment status and roadmap

70 of 79

ELIXIR AAI design

70

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management (REMS)

Group/role mgmt (PERUN)

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

71 of 79

ELIXIR AAI design

71

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

ELIXIR Proxy IdP

  • User has one ELIXIR identity
  • User can authenticate using external identities
  • Proxy IdP consolidates the Ids
  • Acts as SAML IdP for Relying services (later also OAuth2)

Status/Plan:

  • SAML2: Up and running
  • OAuth2/OIC: 1Q/2016

72 of 79

ELIXIR identity

72

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

EGA

wiki

Cloud

Intranet

Data archive

tommioffinland@google�(Google ID)

nyronen@csc.fi�(eduGAIN)

0000-0002-3634-3756 (ORCID)

tommi@elixir-europe.org�(ELIXIR ID)

Status/Plan:�- ”Identity consolidator” roll-out together with eduGAIN integration

- eduGAIN roll-out pending: �Data protection Code of Conduct

Tested, roll-out?

In use

Tested- roll-out?

73 of 79

ELIXIR AAI design

73

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Step-up Authentication

1. User authenticates weakly using external authentication

2. User authenticates with second factor

- e.g. SMS-OTP or a mobile app

Status/Plan:�- planned to start 6/2016�- animation: https://www.surf.nl/en/knowledge-base/2015/animation-surfconext-strong-authentication.html

74 of 79

ELIXIR AAI design

74

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Credential translation

  • ELIXIR Proxy IdP is web
  • Some services are non-web
    • Access to cloud middleware
    • SSH access to a cloud VM
    • Triggering file transfer
  • X.509 (CILogon)
  • SSH public key
  • Kerberos

Status/Plan:�- CILogon pilot with 2-3/2016

- Next steps based on the pilot

- SSH pubkey supported already�

75 of 79

ELIXIR AAI design

75

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Group management (PERUN)

  • Users can create and manage groups
    • Add/Invite new members
    • Remove members
    • Etc
  • Access to services can rely on group memberships

Status/Plan:�- Up and running

- ELIXIR group hierarchy deployed �

76 of 79

ELIXIR AAI design

76

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Bona Fide researchers

  • Anyone can have ELIXIR ID
  • Bona Fide researcher: a member of bioinformatics community with certain basic privileges
  • For instance: access to availability database

Status/Plan:�- on hold until we have agreed on a definition of ”bona fide researcher” �

77 of 79

ELIXIR AAI design

77

ELIXIR AAI

External authentication�(e-infrastructures)

Relying services

eduGAIN IdPs

Common IdPs

ELIXIR Proxy IdP

ELIXIR Directory

Bona fide management

Dataset authorisation management

Group/role management

Credential translation

EGA

eLearning

Cloud

Intranet

wiki

Data archive

Attribute self-management

Step-up AuthN

Dataset authorisation management (REMS)

  • Sensitive human data
  • Data access application needed

Status/Plan:�- Integration to ELIXIR AAI tested

- Working together with EBI/EGA for roll-out�

78 of 79

Groupwork

79 of 79

Questions to participants on their ELIXIR AAI needs

Name of the service and organisation providing it?

Description of the service?

Target users?

AAI needs of the service?

  • Attributes
  • Groups and other authorisations
  • strength of authentication
  • protocol to integrate to ELIXIR AAI (default: SAML)

Timeframe?