eosc-hub.eu
@EOSC_eu
EOSC-hub receives funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 777536.
On-line OIDC based PKIX credentials
RCauth.eu
2
Motivation and driving consideration about the service
Service architecture and interfaces: overview
- How the user can access the service
 E.g.: REST, GUI, CLIs, etc.
- Service options and attributes
Acceptable Usage Policy (AUP)
Access policy and business model
Use cases
Documentation/tutorial/information
11/27/2018
Content
3
provide access to PKI-secured services
leveraging client-certificate, and
deep delegation access, with
non-interactive use and AAI integration capabilities
…without exposing the complexity of PKI to the user
11/27/2018
Motivation
4
RCauth.eu is part of a credential management ecosystem
Can optionally be extended with a credential
management system: Master Portals (OIDC and SSH
access), WaTTS, and IAM
11/27/2018
Service architecture and interfaces
5
RCauth:
Three components:
- Web frontend (“delegation service”), based on US-CIlogon software:
OpenID Connect provider
- Back-end CA based on myproxy-server with an HSM
- Filtering WAYF towards eduGAIN
evolving towards a multi-tenant multi-national HA deployment
Operations: supported (not exclusively) by EOSC-HUB, SURF, GEANT, …
Further reading:
https://aarc-project.eu/digital-certificates-behind-the-scenes-the-aarc-
cilogon-pilot/
https://wiki.nikhef.nl/grid/AARC_Pilot
https://rcauth.eu/
17/04/2018
EOSC-hub AAI RCauth
6
Access is provided to qualified clients through:
an OIDC REST based protocol
to end-users through eduGAIN integrated WebSSO
11/27/2018
Service access
 CA:
 RCauth: an HSM-backed Online CA
 Login: via a filtering WAYF (R&S + Sirtfi) to
eduGAIN
 Several infra & community IdP/SPs are also
attached
 IGTF accredited under IOTA profile
(DOGWOOD)
 Provides 11-day certificates
 Clients to the CA:
 Clients are MasterPortals, WaTTS,
and also other non-EOSC TTS
services:
 Intermediary to the actual clients
which are the Science Gateways
 Needed for caching the credentials
 Handling the complexity
7
Research Infrastructures coordinated based on Scntfi
organized community management can bridge their own
users into RCauth.eu regardless of eduGAIN availability
https://www.igtf.net/snctfi/
https://aarc-project.eu/guidelines/aarc-g015/
Any user, anywhere in the world, can use the service provided
the assurance level is sufficient. The home organization and
the user must meet REFEDS R&S and Sirtfi incident response
expectations
Goes well together with AARC AAI proxy implementations
11/27/2018
Service options and attributes
8
The RCauth.eu service complies with the IGTF ‘dogwood’
assurance level, so users must meet its criteria as well
Detailed requirements:
https://rcauth.eu/policy/
You must agree to the privacy policy:
https://rcauth.eu/privacy
11/27/2018
Acceptable Usage Policy
9
This service is free at point of use, and is supported by funding
from a variety of national and European sources
SURF (NL), EOSC-HUB (EU), GEANT (EU), and Nikhef
Primary audience is the EMEA region
CIlogon.org is available in the US (and global).
There are no connection fees for RIs and e-Infrastructures –
material contributions may be required to participate as a
stakeholder in its governance model
For details, see the governance model terms
https://rcauth.eu/policy/RCauth-ICA-governance-DRAFT.pdf
11/27/2018
Access policies and funding models
10
Current use cases supported by RCauth.eu
ELIXIR AAI – as a back-end to access cloud resources
Project MinE – command-line access to HTC resources
using federated login for ALS researchers
WLCG federated access to transfer services (AuthZ)
... and many more …
Available in all major federated AAI proxy implementations
11/27/2018
Featured use cases
11
Do it Yourself example flow for RCauth-like scenarios
11
REFEDS R&S
Sirtfi Trust
see also https://rcdemo.nikhef.nl/
Built on CILogon and MyProxy
www.cilogon.org
Community Science Portal
Infrastructure Master
Portal Credential
Store
Policy Filtering WAYF / eduGAIN
User Home Org
or Infrastructure IdP
Accredited
PKIX Authority
12
For service documentation, see https://rcauth.eu/
For code transparency: https://github.com/rcauth-eu
Contact and service requests: ca@rcauth.eu
11/27/2018
Documentations
eosc-hub.eu @EOSC_eu
Thank you for
your attention!
ca@rcauth.eu
RCauth.eu is co-supported by
SURF, EOSC-HUB, GEANT, and Nikhef

More Related Content

PPTX
Startup InsurTech Award - Procede
PPTX
EOSC-hub_OPENCoastS
PDF
FIWARE Global Summit - Open Context Information Management at the Core of Sma...
PDF
20190523 archiver fim
PDF
FIWARE Global Summit - FIWARE: Open Standard for Agrifood Applications Integr...
PDF
Support.services.4.sg.developers
PPTX
SecureIoT Programming Support Service
PDF
ULOOP standardization
Startup InsurTech Award - Procede
EOSC-hub_OPENCoastS
FIWARE Global Summit - Open Context Information Management at the Core of Sma...
20190523 archiver fim
FIWARE Global Summit - FIWARE: Open Standard for Agrifood Applications Integr...
Support.services.4.sg.developers
SecureIoT Programming Support Service
ULOOP standardization

What's hot (9)

PPT
Delivering services over the N3 Network
PDF
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
PPTX
EGI Cloud Services in a Federated Multi-Supply Envirnment
PPTX
EOSC-hub rules of participation, Mark van de Sanden
PPTX
Medina general presentation
PDF
Archiver omc stansted_tendering_procedure_and_requirements_final
PDF
First Impressions on Experimenting with Automated Monitoring Requirements of ...
PDF
Day2.2 Paving the Road Towards Continuous Certification: OSCAL and the EUCS
PDF
Overview of the Danaos Platform by Dimitris Theodosiou
Delivering services over the N3 Network
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
EGI Cloud Services in a Federated Multi-Supply Envirnment
EOSC-hub rules of participation, Mark van de Sanden
Medina general presentation
Archiver omc stansted_tendering_procedure_and_requirements_final
First Impressions on Experimenting with Automated Monitoring Requirements of ...
Day2.2 Paving the Road Towards Continuous Certification: OSCAL and the EUCS
Overview of the Danaos Platform by Dimitris Theodosiou
Ad

Similar to EOSC-hub & RCauth.eu presentation (20)

PPTX
EOSC-hub AAI architecture (EOSC hub week, Malaga, 16 - 20 April 2018)
PPTX
WeNMR Suite for Structural Biology
PPTX
ENES Climate Analytics Service (ECAS)
PPTX
EOSC-hub: Dynamic On Demand Analysis Service
PDF
EUDAT B2DROP & EOSC-hub
PPTX
EOSC Ecosystem, EOSC-hub week, Prague
PDF
Overview of the Onboarding and validation process and the Rules of Participat...
PPTX
EOSC-hub RDA 11 Colocation Presentation
PPT
Shibboleth Access Management Federations as an Organisational Model for SDI
PDF
2019 04-08 hopu-aj
PPTX
EOSC-hub AAI: Initial building blocks (EOSC hub week, Malaga, 16 - 20 April 2...
PPT
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
PPT
OGC Web Service Shibboleth Interoperability Experiment
PPT
Shibboleth Federations and Secure SDI
PPTX
EOSC-hub - EGI Check-in service
PPTX
Introduction to the EOSC-hub project
PPTX
Service Management Framework and Principles of Engagement, Sy Holsinger
PPTX
EOSC-hub: A Collaborative Framework for the EOSC Implementation
PPT
Inspire2011 shibb am_fs_paper_v3
PPTX
Becoming a service provider within EOSC - towards some principles of engagement
EOSC-hub AAI architecture (EOSC hub week, Malaga, 16 - 20 April 2018)
WeNMR Suite for Structural Biology
ENES Climate Analytics Service (ECAS)
EOSC-hub: Dynamic On Demand Analysis Service
EUDAT B2DROP & EOSC-hub
EOSC Ecosystem, EOSC-hub week, Prague
Overview of the Onboarding and validation process and the Rules of Participat...
EOSC-hub RDA 11 Colocation Presentation
Shibboleth Access Management Federations as an Organisational Model for SDI
2019 04-08 hopu-aj
EOSC-hub AAI: Initial building blocks (EOSC hub week, Malaga, 16 - 20 April 2...
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
OGC Web Service Shibboleth Interoperability Experiment
Shibboleth Federations and Secure SDI
EOSC-hub - EGI Check-in service
Introduction to the EOSC-hub project
Service Management Framework and Principles of Engagement, Sy Holsinger
EOSC-hub: A Collaborative Framework for the EOSC Implementation
Inspire2011 shibb am_fs_paper_v3
Becoming a service provider within EOSC - towards some principles of engagement
Ad

More from EOSC-hub project (20)

PPTX
EOSC-hub Early Adopter Programme
PPTX
2019 05-21 egi and eosc - final
PPTX
Introduction to service management and FitSM
PPTX
Service management board (SMB), Service providers’ forum (SPF)
PPTX
Joining the EOSC-hub as a Service Provider
PDF
PID services - understandability and findability of data
PDF
Software for data management and exploitation
PDF
Repositories for long-term preservation - certification
PDF
EOSC working group on FAIR
PDF
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...
PDF
Services to support FAIR data - Introduction
PDF
EOSC-synergy
PDF
PDF
EOSC-Pillar
PDF
NI4OS-Europe
PDF
Excellerat CoE
PDF
Pathways for EOSC-hub and MaX collaboration
PDF
Overview on the HPC CoEs panorama
PDF
ELIXIR Competence Centre in EOSC-hub
PDF
Data sharing in EOSC-hub: perspectives on “sensitive” data
EOSC-hub Early Adopter Programme
2019 05-21 egi and eosc - final
Introduction to service management and FitSM
Service management board (SMB), Service providers’ forum (SPF)
Joining the EOSC-hub as a Service Provider
PID services - understandability and findability of data
Software for data management and exploitation
Repositories for long-term preservation - certification
EOSC working group on FAIR
Updates on the FAIR Data Maturity Model RDA Working Group & the DG RTD FAIR i...
Services to support FAIR data - Introduction
EOSC-synergy
EOSC-Pillar
NI4OS-Europe
Excellerat CoE
Pathways for EOSC-hub and MaX collaboration
Overview on the HPC CoEs panorama
ELIXIR Competence Centre in EOSC-hub
Data sharing in EOSC-hub: perspectives on “sensitive” data

Recently uploaded (20)

PDF
Communicating Health Policies to Diverse Populations (www.kiu.ac.ug)
PPT
Mutation in dna of bacteria and repairss
PPT
1. INTRODUCTION TO EPIDEMIOLOGY.pptx for community medicine
PPT
Cell Structure Description and Functions
PDF
5.Physics 8-WBS_Light.pdfFHDGJDJHFGHJHFTY
PPT
LEC Synthetic Biology and its application.ppt
PPTX
gene cloning powerpoint for general biology 2
PPTX
GREEN FIELDS SCHOOL PPT ON HOLIDAY HOMEWORK
PDF
Packaging materials of fruits and vegetables
PDF
CuO Nps photocatalysts 15156456551564161
PPTX
perinatal infections 2-171220190027.pptx
PPTX
A powerpoint on colorectal cancer with brief background
PPTX
HAEMATOLOGICAL DISEASES lack of red blood cells, which carry oxygen throughou...
PPTX
Presentation1 INTRODUCTION TO ENZYMES.pptx
PPTX
Substance Disorders- part different drugs change body
PDF
Science Form five needed shit SCIENEce so
PPTX
Preformulation.pptx Preformulation studies-Including all parameter
PPTX
PMR- PPT.pptx for students and doctors tt
PDF
Worlds Next Door: A Candidate Giant Planet Imaged in the Habitable Zone of ↵ ...
PDF
GROUP 2 ORIGINAL PPT. pdf Hhfiwhwifhww0ojuwoadwsfjofjwsofjw
Communicating Health Policies to Diverse Populations (www.kiu.ac.ug)
Mutation in dna of bacteria and repairss
1. INTRODUCTION TO EPIDEMIOLOGY.pptx for community medicine
Cell Structure Description and Functions
5.Physics 8-WBS_Light.pdfFHDGJDJHFGHJHFTY
LEC Synthetic Biology and its application.ppt
gene cloning powerpoint for general biology 2
GREEN FIELDS SCHOOL PPT ON HOLIDAY HOMEWORK
Packaging materials of fruits and vegetables
CuO Nps photocatalysts 15156456551564161
perinatal infections 2-171220190027.pptx
A powerpoint on colorectal cancer with brief background
HAEMATOLOGICAL DISEASES lack of red blood cells, which carry oxygen throughou...
Presentation1 INTRODUCTION TO ENZYMES.pptx
Substance Disorders- part different drugs change body
Science Form five needed shit SCIENEce so
Preformulation.pptx Preformulation studies-Including all parameter
PMR- PPT.pptx for students and doctors tt
Worlds Next Door: A Candidate Giant Planet Imaged in the Habitable Zone of ↵ ...
GROUP 2 ORIGINAL PPT. pdf Hhfiwhwifhww0ojuwoadwsfjofjwsofjw

EOSC-hub & RCauth.eu presentation

  • 1. eosc-hub.eu @EOSC_eu EOSC-hub receives funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 777536. On-line OIDC based PKIX credentials RCauth.eu
  • 2. 2 Motivation and driving consideration about the service Service architecture and interfaces: overview - How the user can access the service  E.g.: REST, GUI, CLIs, etc. - Service options and attributes Acceptable Usage Policy (AUP) Access policy and business model Use cases Documentation/tutorial/information 11/27/2018 Content
  • 3. 3 provide access to PKI-secured services leveraging client-certificate, and deep delegation access, with non-interactive use and AAI integration capabilities …without exposing the complexity of PKI to the user 11/27/2018 Motivation
  • 4. 4 RCauth.eu is part of a credential management ecosystem Can optionally be extended with a credential management system: Master Portals (OIDC and SSH access), WaTTS, and IAM 11/27/2018 Service architecture and interfaces
  • 5. 5 RCauth: Three components: - Web frontend (“delegation service”), based on US-CIlogon software: OpenID Connect provider - Back-end CA based on myproxy-server with an HSM - Filtering WAYF towards eduGAIN evolving towards a multi-tenant multi-national HA deployment Operations: supported (not exclusively) by EOSC-HUB, SURF, GEANT, … Further reading: https://aarc-project.eu/digital-certificates-behind-the-scenes-the-aarc- cilogon-pilot/ https://wiki.nikhef.nl/grid/AARC_Pilot https://rcauth.eu/ 17/04/2018 EOSC-hub AAI RCauth
  • 6. 6 Access is provided to qualified clients through: an OIDC REST based protocol to end-users through eduGAIN integrated WebSSO 11/27/2018 Service access  CA:  RCauth: an HSM-backed Online CA  Login: via a filtering WAYF (R&S + Sirtfi) to eduGAIN  Several infra & community IdP/SPs are also attached  IGTF accredited under IOTA profile (DOGWOOD)  Provides 11-day certificates  Clients to the CA:  Clients are MasterPortals, WaTTS, and also other non-EOSC TTS services:  Intermediary to the actual clients which are the Science Gateways  Needed for caching the credentials  Handling the complexity
  • 7. 7 Research Infrastructures coordinated based on Scntfi organized community management can bridge their own users into RCauth.eu regardless of eduGAIN availability https://www.igtf.net/snctfi/ https://aarc-project.eu/guidelines/aarc-g015/ Any user, anywhere in the world, can use the service provided the assurance level is sufficient. The home organization and the user must meet REFEDS R&S and Sirtfi incident response expectations Goes well together with AARC AAI proxy implementations 11/27/2018 Service options and attributes
  • 8. 8 The RCauth.eu service complies with the IGTF ‘dogwood’ assurance level, so users must meet its criteria as well Detailed requirements: https://rcauth.eu/policy/ You must agree to the privacy policy: https://rcauth.eu/privacy 11/27/2018 Acceptable Usage Policy
  • 9. 9 This service is free at point of use, and is supported by funding from a variety of national and European sources SURF (NL), EOSC-HUB (EU), GEANT (EU), and Nikhef Primary audience is the EMEA region CIlogon.org is available in the US (and global). There are no connection fees for RIs and e-Infrastructures – material contributions may be required to participate as a stakeholder in its governance model For details, see the governance model terms https://rcauth.eu/policy/RCauth-ICA-governance-DRAFT.pdf 11/27/2018 Access policies and funding models
  • 10. 10 Current use cases supported by RCauth.eu ELIXIR AAI – as a back-end to access cloud resources Project MinE – command-line access to HTC resources using federated login for ALS researchers WLCG federated access to transfer services (AuthZ) ... and many more … Available in all major federated AAI proxy implementations 11/27/2018 Featured use cases
  • 11. 11 Do it Yourself example flow for RCauth-like scenarios 11 REFEDS R&S Sirtfi Trust see also https://rcdemo.nikhef.nl/ Built on CILogon and MyProxy www.cilogon.org Community Science Portal Infrastructure Master Portal Credential Store Policy Filtering WAYF / eduGAIN User Home Org or Infrastructure IdP Accredited PKIX Authority
  • 12. 12 For service documentation, see https://rcauth.eu/ For code transparency: https://github.com/rcauth-eu Contact and service requests: ca@rcauth.eu 11/27/2018 Documentations
  • 13. eosc-hub.eu @EOSC_eu Thank you for your attention! ca@rcauth.eu RCauth.eu is co-supported by SURF, EOSC-HUB, GEANT, and Nikhef

Editor's Notes

  • #12: VO portal can be anything even a simple shell Certs stored only for 11 days Master portal can add attributes via VOMS (or others in the future)