oa sp-interfederation

31
Interfederation Working Nicole Harris UK Access Management Focus, JISC Advance @nicoleharris Slides: http://www.slideshare.net/nicolevharris Bookmarks: http://goo.gl/ ubxCR

Upload: nicole-harris

Post on 15-Jun-2015

573 views

Category:

Technology


0 download

DESCRIPTION

OASP11 presentation

TRANSCRIPT

Page 1: Oa sp-interfederation

Interfederation Working

Nicole Harris UK Access Management Focus, JISC Advance

@nicoleharrisSlides: http://www.slideshare.net/nicolevharris

Bookmarks: http://goo.gl/ubxCR

Page 2: Oa sp-interfederation

Me

• UK Access Management Focus;• Advisor to UK federation;• REFEDS Coordinator;• PEER Project Manager;• Shibboleth Consortium Manager;• Generally opinionated about access and identity.

Page 3: Oa sp-interfederation

What does the R&E Federation space look like?

Page 4: Oa sp-interfederation

R&E Federations Status (1)

Page 5: Oa sp-interfederation

R&E Federations Status (2)

• 27 Federations plus 2 confederations.• 4753 entities within those federations.• 1815 Identity Providers. • 2755 Service Providers. • Plus several ‘others’ (don’t worry about it).

Page 6: Oa sp-interfederation

Top resources?

• In 14 federations: – Czech Medical Atlas and Microsoft Dreamspark.

• In 12: – Web of Knowledge, Scopus, ScienceDirect.

• In 11: – IEEE, EBSCO.

• In 10: – Springer, OVID.

Page 7: Oa sp-interfederation

So it’s all working, right?

Page 8: Oa sp-interfederation

For SPs, Federation SucksI know because I wrote a paper on it!

Page 9: Oa sp-interfederation

Barriers

• Multiple registry of entity data. • Multiple legal documents. • One-off clauses.• Interpretation of data protection. • Sponsorship letters.• Fees.• Technical Barriers.

https://refeds.terena.org/index.php/Barriers_for_Service_Providers

Page 10: Oa sp-interfederation

Registering Entity Data

• Federations are just big metadata (xml) files.• Entity = your chunk of that data. • It goes a bit like this:

Page 11: Oa sp-interfederation

How does it work?

Federation A

Federation B

Federation C

You

Page 12: Oa sp-interfederation

What we need is a place where this can be centrally registered and then called on by federations…

Page 13: Oa sp-interfederation

PEER

http://beta.terena-peer.yaco.es/

Page 14: Oa sp-interfederation

Legal Contracts

Page 15: Oa sp-interfederation

Wouldn’t it be great if these were standardised and simplified?

Page 16: Oa sp-interfederation

REFEDs Policy Review

• Painstakingly taking apart every clause in every federation policy.

• Mapping these to generic content ‘blocks’ and ‘elements’ within each block.

• Making recommendations about structure and unnecessary language.

• NOT a legal review.

Page 17: Oa sp-interfederation

Isn’t there an easier way?

Page 18: Oa sp-interfederation

Full Interfederation

• The ability of federations to exchange metadata about their entities.

• Normally an additional legal agreement between the 2 federations.

• Full technical and policy integration. • UK piloting with eduGate – contact me if you

would like to be involved!

Page 19: Oa sp-interfederation

eduGain (1)

www.edugain.org

Page 20: Oa sp-interfederation

eduGain (2) – Drawbacks

• At least one of the federations you are a member of needs to have signed up for eduGain.

• Opt-in: you have to ask to be included in an aggregate.

• Not always clear which entities are interfederated – are your customers there?

Page 21: Oa sp-interfederation

eduGain (3) Benefits

• Only have to have a relationship with 1 federation.

• Technically, as an SP, you can chose with federation that is.

Page 22: Oa sp-interfederation

A quick note on Barriers to Users

Page 23: Oa sp-interfederation

Login Interfaces Suck I know this because I’ve tried to use them

Page 24: Oa sp-interfederation

How Bad?

Page 25: Oa sp-interfederation

New UK federation WAYF

Page 26: Oa sp-interfederation

You can use the data too!

Page 27: Oa sp-interfederation

MDUI Information (1)

Page 28: Oa sp-interfederation

MDUI Information (2)

Page 29: Oa sp-interfederation

MDUI, What do we need?

• A link to a logo on an https protected page, with a width between 64px and 350px and height between 64px and 170px.

• A Display Name.• A 100 character description of your service.• Send to: [email protected].

Page 30: Oa sp-interfederation

We can already make the horrible things Andy is going to talk about go away!

Shibboleth Embedded Discovery: https://wiki.shibboleth.net/confluence/display/EDS10/Embedded+Discovery+ServiceDiscoJuice: http://discojuice.org/

Page 31: Oa sp-interfederation

Thank you for listening