Federated Identity Management at BNL
FIM4R@FNAL
September 12, 2019
Overview
Brookhaven Lab-Level SSO and Federation
Info: Dave Cortijo BNL ITD
Scientific Data and Computing Center (SDCC)
SDCC Federation Mechanisms (1)
SDCC Federation Mechanisms (2)
Glance at Keycloak Central IDP Hub
IDP selections are configurable per App/Service bases.
Observations, Progress
Issues, Challenges
Likely Future Directions, Options
Questions
Current Prod + Pre-prod
Pilot projects directly federating with CILogon/COManage. Plugins doing AuthZ.
Shared cloud-based COManage instances.
KeyCloak bridging to InCommon, using BNL IDP, ready to use rest of InCommon.
One Possible Future...
KeyCloak as main glue, primary service auth server. Bridging to CILogon, OneID. Service-by-service auth choice.
COManage could be provided, or run locally, with attribute syncing via API.
OIDC as standard protocol, but supporting SAML where needed.
Questions? Discussion...