ELIXIR AAI
Mikael Linden, Michal Prochazka
AAI workshop 15-16 March 2016
www.elixir-europe.org
Schedule of day two ELIXIR parallel session
09:00 | Coffee and arrivals |
09:15 | Introduction to ELIXIR AAI |
10:45 | Coffee break |
11:00 | Integrating a SAML SP to the ELIXIR AAI |
12:30 | Lunch |
13:30 | Group management in ELIXIR |
15:00 | Coffee break |
15:15 | Integrating ELIXIR groups into the SAML SP |
16:15 | Wrap-up and post-workshop questionnaire |
16:30 | Close |
Motivation
Motivation
Yesterday you learned
Today
Introduction to ELIXIR AAI
AAI = Authentication and Authorisation Infrastructure
5
6
medicine
agriculture
bioindustries
environment
ELIXIR connects national bioinformatics centres and EMBL-EBI into a sustainable European infrastructure for biological research data
ELIXIR underpins life science research – across academia and industry
ELIXIR AAI history – where we are now
High level stuff:�ELIXIR AAI strategy (DRAFT)
Design of ELIXIR AAI
ELIXIR AAI design
10
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management (REMS)
Group/role mgmt (PERUN)
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
ELIXIR AAI design
11
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
ELIXIR Proxy IdP
In this training
12
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
ELIXIR Proxy IdP
Your Shibboleth SP
In this training (before lunch) you will integrate the Shibboleth SP you installed yesterday to the test environment of the ELIXIR Proxy IdP.
ELIXIR identity
13
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
EGA
wiki
Cloud
Intranet
…
Data archive
…
…
tommioffinland@google�(Google ID)
nyronen@csc.fi�(eduGAIN)
0000-0002-3634-3756 (ORCID)
tommi@elixir-europe.org�(ELIXIR ID)
ELIXIR AAI design
14
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Step-up Authentication
1. User authenticates weakly using external authentication
2. User authenticates with second factor
- e.g. SMS-OTP or a mobile app
ELIXIR AAI design
15
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Credential translation
ELIXIR AAI design
16
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Group management (PERUN)
In this training
17
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Bona fide management
Dataset authorisation management
Credential translation
EGA
eLearning
Cloud
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
ELIXIR Proxy IdP
Your Shibboleth SP
In this training (after lunch) you will configure your Shibboleth SP to consume group membership attributes set by PERUN for authorisation.
Group/role management
ELIXIR Directory
ELIXIR AAI design
18
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Bona Fide researchers
ELIXIR AAI design
19
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Dataset authorisation management (REMS)
�The REMS concept
Principal�investigator�Applicant
Research group�Members of the application
Metadata on dataset 1&2
Dataset 1
Dataset 2
DAC 1�Approver
DAC 2�Approver
REMS
Workflow
Reports
Entitlements
IdP
IdP
IdP
SP
1. Apply �for access
4. Approve
5. Access
3. Circulate to approver
2. Commit to licence terms
Integrating SAML SP into ELIXIR AAI�
ELIXIR IdP/SP Proxy
Steps
Register ELIXIR AAI Metadata
Each SAML SP must consume ELIXIR AAI Proxy IdP metadata
ELIXIR AAI Proxy IdP must consume metadata of your service
ELIXIR AAI Metadata configuration
Download metadata signing certificate
cd /etc/shibboleth/
sudo curl -k -o elixir-idp-certificate.pem https://engine.elixir-czech.org/authentication/idp/certificate
Edit /etc/shibboleth/shibboleth2.xml
<MetadataProvider type="XML" uri="https://engine.elixir-czech.org/authentication/idp/metadata"
backingFilePath="elixir-idp-metadata.xml" reloadInterval="1800">
<MetadataFilter type="Signature" certificate="elixir-idp-certificate.pem"/>
</MetadataProvider>
If you have more metadata sources, use covering element
<MetadataProvider type="Chaining">
...Metadata providers
</MetadataProvier>
SP Metadata requirements
<md:Organization>
<md:OrganizationName xml:lang="en">Masaryk University</md:OrganizationName>
<md:OrganizationDisplayName xml:lang="en">Masaryk University</md:OrganizationDisplayName>
<md:OrganizationURL xml:lang="en">http://www.muni.cz/</md:OrganizationURL>
</md:Organization>
<md:ContactPerson contactType="technical">
<md:GivenName>Michal</md:GivenName>
<md:SurName>Prochazka</md:SurName>
<md:EmailAddress>michalp@ics.muni.cz</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
ELIXIR AAI Discovery Service
Edit /etc/shibboleth/shibboleth2.xml
If your service will be connected just to ELIXIR AAI
<SSO entityID="https://engine.elixir-czech.org/authentication/idp/metadata">
SAML2</SSO>
Otherwise add
<SessionInitiator id="elixir" location="/elixir" type="SAML2" relayState="ss:mem" template="bindingTemplate.html" ascIndex="1" entityID="https://engine.elixir-czech.org/authentication/idp/metadata">
</SessionInitiator>
Available SAML2 Attributes
Available SAML2 attributes
Attribute mapping
Write a request to ELIXIR AAI
Write an email to aai-contact@elixir-europe.org
Test the authentication
https://sp#.example.org/Shibboleth.sso/Login
Work in progress: �design of an ELIXIR Log-in button
A PNG file you could place to your ELIXIR SP as a login button for the end user to click.
Clicking the button would trigger ELIXIR AAI authentication.
Graphical guidelines being developed in the ELIXIR hub.
Use cases:�ELIXIR Intranet and mailing lists�
Intranet and mailing lists
For the management of ELIXIR, the ELIXIR hub has rolled out
To join a group, a person needs
Intranet and mailing lists
35
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Bona fide management
Dataset authorisation management
Credential translation
EGA
eLearning
Cloud
wiki
…
…
Attribute self-management
Step-up AuthN
ELIXIR Proxy IdP
Intranet (Drupal)
Current operational integration to ELIXIR AAI.
Group management (Perun)
ELIXIR Directory
Mailing lists (Mailman)
Authentication
Group memberships�(batch job)
ELIXIR group hierarchy has three branches
root
Community
Nodes
Custom
For people involved in building ELIXIR, e.g. EXCELERATE.
�Governance: ELIXIR hub
For group management in the node services
�Governance: each node
For other services (exact policy TBD)
ELIXIR groups under ”Community” branch
Compute platform
Executive committee
EXCELERATE WP4
Integration
AAI
Data platform
Executive committee
EXCELERATE WP3
Tools platform
Executive committee
EXCELERATE WP1
EXCELERATE WP2
User communities
Human data
Marine
Plant
Rare desease
Governance
Board
Heads of Nodes
Technical Coordinators
Training Coordinators
Etc…
The full list of groups: https://www.elixir-europe.org/groups�The group management plan: �https://www.elixir-europe.org/documents/elixir-aai-group-management-plan
ELIXIR AAI Dimensions of �authentication and authorisation
The dimensions of authentication and authorisation
The planned assurance levels for authentication
Basic�(in place now)
Raised
Strong
Self-registrated accounts, password authN
Organisation-registed accounts, password authN
Face-to-face proof of identity, two factor authN
The three authorisation layers
41
Any ELIXIR user
Bona fide ELIXIR user
Public
Registered
Controlled
e.g. training, …
Availability catalogue
Sensitive human data
Endorsed ELIXIR user
Service type
Example service
User qualification
The three authorisation layers
42
Any ELIXIR user
Bona fide ELIXIR user
e.g. training, …
Availability catalogue
Sensitive human data
Endorsed ELIXIR user
Example service
User qualification
Any user:
Public
Registered
Controlled
Service type
The three authorisation layers
43
Any ELIXIR user
Bona fide ELIXIR user
e.g. training, …
Availability catalogue
Sensitive human data
Endorsed ELIXIR user
Example service
User qualification
”Bona Fide” researcher
- Must commit to a Code of Conduct (to be defined)
Public
Registered
Controlled
Service type
The three authorisation layers
44
Any ELIXIR user
Bona fide ELIXIR user
e.g. training, …
Availability catalogue
Sensitive human data
Endorsed ELIXIR user
Example service
User qualification
Endorsed user
Public
Registered
Controlled
Service type
Use case: ELIXIR Beacon
Beacon idea – public access
Beacon network
Beacon
Beacon
Beacon
Do you have samples �with A in position 1234567 in chromosome 2?
Yes!
Yes!
Sorry, no
Beacon – restricted access
Bona fide researchers
Beacon network
Beacon
Beacon
Beacon
bona fide researcher
How many samples you have with A in position 1234567 in chromosome 2?
I have 123
I have 234
I have 345
ELIXIR AAI�proxy IdP
Log-in
attributes
Definition of a bona fide researcher �(Workshop 10.3.2016 in ELIXIR AHM)
An ELIXIR user receives Bona Fide researcher status if both:
Use cases:�Sensitive human data
50
Secure Compute Clouds
Supporting sample logistics
Services and Coordination
High speed encrypted data transfer
GridFTP/Globus/Aspera
Secure data access remote API
( GA4GH )
Sequencing centers
Data Users
EGA
at
Data Archiving
Bringing users
to data
Data Generation
Managing Access
Data Owner
Data Access Agreement
Data Access Committee
Data Request
Authorization Management Tools
( EGA and CSC REMS )
51
On-demand secure replication of
to the EGA mirror sites (”Local EGA”)
Secure Compute Clouds
Supporting sample logistics
Services and Coordination
High speed encrypted data transfer
GridFTP/Globus/Aspera
Secure data access remote API
( GA4GH )
Sequencing centers
Data Users
EGA
at
Data Archiving
Bringing users
to data
Data Generation
Managing Access
Data Owner
Data Access Agreement
Data Access Committee
Data Request
Authorization Management Tools
( EGA and CSC REMS )
52
Secure storage of datasets in the mirror sites
Secure Compute Clouds
Supporting sample logistics
Services and Coordination
High speed encrypted data transfer
GridFTP/Globus/Aspera
Secure data access remote API
( GA4GH )
Sequencing centers
Data Users
EGA
at
Data Archiving
Bringing users
to data
Data Generation
Managing Access
Data Owner
Data Access Agreement
Data Access Committee
Data Request
Authorization Management Tools
( EGA and CSC REMS )
53
Managing access to datasets
- Granted by the dataset’s Data Access Committee (DAC)
- Stored centrally at EGA
- Queried from EGA by the mirror sites on the fly
Secure Compute Clouds
Supporting sample logistics
Services and Coordination
High speed encrypted data transfer
GridFTP/Globus/Aspera
Secure data access remote API
( GA4GH )
Sequencing centers
Data Users
EGA
at
Data Archiving
Bringing users
to data
Data Generation
Managing Access
Data Owner
Data Access Agreement
Data Access Committee
Data Request
Authorization Management Tools
( EGA and CSC REMS )
54
Enforcing the access rights in the data center
- the user launches a VM
- the user has read access to the local replica iff the DAC has granted access to him
Secure Compute Clouds
Supporting sample logistics
Services and Coordination
High speed encrypted data transfer
GridFTP/Globus/Aspera
Secure data access remote API
( GA4GH )
Sequencing centers
Data Users
EGA
at
Data Archiving
Bringing users
to data
Data Generation
Managing Access
Data Owner
Data Access Agreement
Data Access Committee
Data Request
Authorization Management Tools
( EGA and CSC REMS )
Sensitive human data
55
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
Bona fide management
Attribute self-management
Group management (Perun)
ELIXIR Proxy IdP
Architecture being developed in EXCELERATE WP9.
ELIXIR Directory
EGA
Dataset authorisation management
Local EGA
Local EGA
Step-up AuthN
Credential translation
Cloud
VM
VM
VM
Cloud
VM
VM
VM
eduGAIN IdPs
File transfer
Dataset transfer
Dataset access
Dataset permissions
Setup ELIXIR AAI Authorization
ELIXIR AAI Authorization
Group to Service assignment
PUSH Mechanism
Service can receive data from Perun directly
Push mechanism schema
SAML authentication
ELIXIR IdP will do the authentication and release additional information about the user
Setting up the SP
<Attribute name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" id="entitlement"/>
Setup authorization based on group membership
Require shib-attr entitlement “elixir_test:AAI-Training-Manchester:Michal Prochazka”
Manage groups in Perun
Navigate to https://perun.elixir-czech.cz
Deployment status and roadmap
ELIXIR AAI design
70
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management (REMS)
Group/role mgmt (PERUN)
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
ELIXIR AAI design
71
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
ELIXIR Proxy IdP
Status/Plan:
ELIXIR identity
72
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
EGA
wiki
Cloud
Intranet
…
Data archive
…
…
tommioffinland@google�(Google ID)
nyronen@csc.fi�(eduGAIN)
0000-0002-3634-3756 (ORCID)
tommi@elixir-europe.org�(ELIXIR ID)
Status/Plan:�- ”Identity consolidator” roll-out together with eduGAIN integration
- eduGAIN roll-out pending: �Data protection Code of Conduct
Tested, roll-out?
In use
Tested- roll-out?
ELIXIR AAI design
73
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Step-up Authentication
1. User authenticates weakly using external authentication
2. User authenticates with second factor
- e.g. SMS-OTP or a mobile app
Status/Plan:�- planned to start 6/2016�- animation: https://www.surf.nl/en/knowledge-base/2015/animation-surfconext-strong-authentication.html�
ELIXIR AAI design
74
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Credential translation
Status/Plan:�- CILogon pilot with 2-3/2016
- Next steps based on the pilot
- SSH pubkey supported already��
ELIXIR AAI design
75
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Group management (PERUN)
Status/Plan:�- Up and running
- ELIXIR group hierarchy deployed ��
ELIXIR AAI design
76
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Bona Fide researchers
Status/Plan:�- on hold until we have agreed on a definition of ”bona fide researcher” ��
ELIXIR AAI design
77
ELIXIR AAI
External authentication�(e-infrastructures)
Relying services
eduGAIN IdPs
Common IdPs
ELIXIR Proxy IdP
ELIXIR Directory
Bona fide management
Dataset authorisation management
Group/role management
Credential translation
EGA
eLearning
Cloud
Intranet
wiki
Data archive
…
…
Attribute self-management
Step-up AuthN
Dataset authorisation management (REMS)
Status/Plan:�- Integration to ELIXIR AAI tested
- Working together with EBI/EGA for roll-out��
Groupwork
Questions to participants on their ELIXIR AAI needs
Name of the service and organisation providing it?
Description of the service?
Target users?
AAI needs of the service?
Timeframe?