DK-AAI - a federation in the making

16
DK-AAI - a federation in the making EuroCAMP, Helsinki 17th of April 2007 [email protected]

description

DK-AAI - a federation in the making. EuroCAMP, Helsinki 17th of April 2007 [email protected]. The founders were. Libraries Universities Research network. 2005. Todays' Dish. A SAML based ID-federation for higher education and research - by 2008. Ingredients. Choose a technology - PowerPoint PPT Presentation

Transcript of DK-AAI - a federation in the making

Page 1: DK-AAI - a federation in the making

DK-AAI- a federation in the making

EuroCAMP, Helsinki17th of April 2007

[email protected]

Page 2: DK-AAI - a federation in the making

The founders were...

•Libraries

•Universities

•Research network

2005

Page 3: DK-AAI - a federation in the making

Todays' Dish•A SAML based ID-federation for

higher education and research - by 2008

Ingredients•Choose a technology

•Write a policy

•Establish the federations' semantics

•Set up the organisation

Page 4: DK-AAI - a federation in the making

Financing•Year II - IV (2007 - 2009): €

360.000/year

Funding bodies

•Ministry of education (further education)

•Ministry of Science (universities)

•Ministry of Culture (Libraries)

Page 5: DK-AAI - a federation in the making

Organisation

Page 6: DK-AAI - a federation in the making

The landscape•12 universities (fusions underway: soon only 6)

•Further education, many medium size institutions

•Few 'sector research institutions'

•Few/no killer apps (unlike Swizerland, Norway, UK)

•Many (commercial) service providers interested(main driver?)

•Growing understanding of shared services

Page 7: DK-AAI - a federation in the making

Status•Test federation (Shib) since mid-

2006

•7 IdP's (one German)

•Ver. 1.0 of DKeduPerson

•Policy underway, first draft ready

•Solid interest from service providers

•Stagnating interest from IdP's

•Corporation on the Kalmar Union

Page 8: DK-AAI - a federation in the making

IdM practices/policies

•Define minimal IdM-reqs.

•Institutions sign the policy, including min IdM reqs.

•Informed user consent, important

Page 9: DK-AAI - a federation in the making

Policy enforcement

•Initial interview on IdM, before signing

•Institutions must document IdM-practices - when asked to do so

•Inspections might occur

•DS484 (national security standard) reqs. enough (?)

•Existing revision enough (?)

Page 10: DK-AAI - a federation in the making

Auth levels

•Minimal reqs. TBD...

•netID - initial authentication via web bank ?(+ self service for password reset (driver))-> pilot project coming

Page 11: DK-AAI - a federation in the making

Schema(s)

•dkEduPerson v.1:

• eduPerson

• norEduPerson

• SCHAC schema

Page 12: DK-AAI - a federation in the making

Certificates

?

Page 13: DK-AAI - a federation in the making

Shibboleth concept

The technology

Page 14: DK-AAI - a federation in the making

Shibboleth for real

Federation ?

Federation ?

Federation ?

Federation ?

ElseVier

Page 15: DK-AAI - a federation in the making

Norwegian-federation model

Page 16: DK-AAI - a federation in the making

Combination?