3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run...

20
3 New Services Streamlining Access to eResearch Capabilities John Scullen ([email protected]) Manager, Strategic Initiatives & Managed Services

Transcript of 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run...

Page 1: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

3 New Services Streamlining Access to eResearchCapabilitiesJohn Scullen ([email protected])Manager, Strategic Initiatives & Managed Services

Page 2: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

(EDUcation Global Authentication INfrastructure)

Page 3: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC
Page 4: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC
Page 5: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC
Page 6: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

Growing International Community

55 federations

Identity Providers: 2883Service Providers: 2195• 195 Research & Scholarship

services already available• Other services added by request

See technical.edugain.org/entities

Page 7: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

eduGAIN Benefits

Service Providers• One integration• Thousands of potential

users• Extend the reach of

research infrastructure• Reduce cost and

complexity

Identity Providers• Easier access to

international services• Simplifies international

collaboration

Page 8: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

Connecting to eduGAIN

Use latest software

Technical config

• metadata• attribute

request / release

• discovery

Research & Scholarship Security

• SIRTFI

Page 9: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

Find Out More

aaf.edu.au/edugain

Page 10: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC
Page 11: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

Benefits

• Release your IdM staff for more important work• Feature updates and security patches• eduGAIN-ready• High availability• Reduce infrastructure• Security designed in from the beginning• Faster deployment of new IdPs• Lowers entry barriers for smaller organisations

Page 12: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

On-Premise Cost Factors

• Staffing• Servers• Storage• Backup• Load balancer costs• Data centre costs• Monitoring costs

• Governance• Security• Compliance• Disaster recovery• Testing• Change management /

stakeholder comms

Page 13: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

Find Out More

aaf.edu.au/rapid

Rapid Identity Provider

Rapid Identity Provider

powered by AAF

Page 14: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

AAF CENTRAL

Page 15: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

AAF Central

• A major step toward a multi-protocol federation• Support for applications using Open ID Connect (OIDC)• Design can accommodate other authentication protocols

Page 16: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

Why OIDC?

• Developing with OIDC / OAuth2 is simpler than SAML• Add your preferred OIDC library to your development environment• No need to deploy servers or run Shibboleth service provider software

• Easier to find experienced developers• OIDC / OAuth2 is widely used to integrate with Google, Facebook and cloud

services

• Not just web-based authentication• API access• Mobile applications

Page 17: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

How does it work?

OpenID ConnectProvider

rec

res

req

rec

Identity Broker

req

rec

rec

res

AAF Central

Application(OIDC RP)

SAML Federation Resolver

rec

res

req

rec

SAML Federation

Page 18: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

Current State• Available now as a pre-production service

• Passes OIDC conformance tests• Peer-reviewed and load tested• Manual connection for now• No eduGAIN support – use SAML if you want to expose your service to international

partners• Reasonable coverage of OIDC specification• 3 services in production

• ecocloud.org.au• Store.Monash• TERN

• 13 services in test

Page 19: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

OpenID ConnectProvider

rec

res

req

rec

Identity Broker

req

rec

rec

res

AAF Central

Application(OIDC RP)

SAML Federation Resolver

rec

res

req

rec

SAML Federation

Rapid ConnectProvider

rec

res

req

rec

Application (Rapid Connect)

eduGAINResolver

rec

res

req

rec

eduGAINFederation

Social IdentityResolver

rec

res

req

rec

Google / Facebook

etc

Utopia

Page 20: 3 New Services Streamlining Access to eResearch Capabilities · •No need to deploy servers or run Shibboleth service provider software •Easier to find experienced developers •OIDC

Find Out More

Bradley Beddoes ([email protected])

AAF Central