dk update david simonsen, wayf (the federation formerly known as dk-aai) it's a wayfit's...

15
DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYF It's about consent It's a project

Upload: marquise-andry

Post on 01-Apr-2015

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

DK updateDavid Simonsen, WAYF

(the federation formerly known as DK-AAI)

It's a WAYFIt's about consentIt's a project

Page 2: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

SAML2 LDAPHost’ed

simpleSAMLphp

Shibboleth 1.3 + CAS

WAYF architecture

Page 3: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

Supported interfaces

•SP: SAML2

•SP: Shibboleth 1.3

•IdP: SAML2

•IdP: LDAP (hosted login page)

•IdP: CAS + LDAP

Page 4: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

IdM requirements

•Describe your IdP routines (will not be publicly available)

•24 hours after status is changed, status is changed...

•LoA - not supported

•Strenth of initial authentication not flagged

Page 5: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

AttributesMUST

---- Personal information-----

SurName

GivenName

CommonName

eduPersonPricipleName

Mail

eduPersonPrimaryAffiliation

----- Information about the organisation-----

schacHomeOrganization

MAY

---- Personal information ----

norEduPersonNIN

eduPersonScopedAffiliation

PreferredLanguage

eduPersonEntitelment

----- Information about the organisation------

Attributtes provided / generated by WAYF

eduPersonTargedID (hash (SP-ID + hash (IdP-ID + salt + unique-personID) + salt)

OrganizationName

Page 6: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

Attribute profilesNormal profile

eduPersonPrimaryAffiliation

schacHomeOrganization

Extended profile with persistent ID

eduPersonPrimaryAffiliation

schacHomeOrganization

eduPersonTargedID

Extended profil with persistent ID and name

eduPersonPrimaryAffiliation

schacHomeOrganization

eduPersonTargedID

SurName

GivenName

CommonName

Extended profil with persistent ID, name and email

eduPersonPrimaryAffiliation

schacHomeOrganization

eduPersonTargedID

SurName

GivenName

CommonName

mail

Page 7: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

WAYF is live•as of 28th of March 2008

•All central services running

•WAYF, consent, consent-admin

•Central federating component (CFC): simpleSAMLphp

•Contract draft (turned down yesterday)

•websites open (Danish only so far)

•Production evironment + QA

•Press release to come (with ministers)

Page 8: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

•Only a few services still

•Cross federated to FEIDE (OpenWiki, Foodle)

WAYF is live

Page 9: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

Connected institutions

•The Royal Library

•Roskilde University

•Syddansk University

•The State Library

• WAYF Orphanage

•Århus University

•Technical University of DK

Page 10: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

Planned services•Connect, Forskningsnettets

videotjeneste

•DSB

•NetID

•BBC Motion Gallery

•Danske reklamefilm

•eduMedia, Forskningsnettet

•Studenterportaler

Page 11: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

•NIAS, Nordisk Inst. for Asien Studier (Kalmar)

•Microsoft's 'Dream Sparks'

•ElseVier (forlag)

•OVID (forlag)

•EBSCO (forlag)

•WAYF-baseret ID-oprettelse

Planned services

Page 12: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

Users' consent

Page 13: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

The users' informed consent

Obligation to inform

Consent

Volontarily

InformedSpecific

No personal info is kept

Page 14: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

Ingen personlige oplysninger gemmes

2km4756k4l3n43j34j38ds989g+sdfhkjrwk30!

Page 15: DK update David Simonsen, WAYF (the federation formerly known as DK-AAI) It's a WAYFIt's about consentIt's a project

DEMONSTRATION

•www.wayf.dk

•www.dk-aai.dk

•wiki.dk-aai.dk

•https://wayf.wayf.dk/consent/consentAdmin.php