Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA...

11
Shibboleth Development and Support Services SDSS Development Federation — Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November 2005

Transcript of Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA...

Page 1: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

SDSS Development

Federation

— Next PhaseSandy Shaw, EDINA

JISC CM Programme Meeting, Windermere, 14–15 November

2005

Page 2: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 2

Original project goals

• Implement a development federation …

… to support other CM projects

… to participate in Internet2 development

… to convert EDINA services

• Gain experience relevant to the

creation of a UK production federation

Page 3: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 3

New goals

• Work with UKERNA to ensure lessons

learned in SDSS can be applied to the

UK federation

• Work with UKERNA to ensure SDSS

members have a painless transition to

the UK federation

Page 4: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 4

Compare and contrast

• SDSS federation vs UK federation

SDSS

federation

UK federation

Status Project Service

Duratio

n

3 years Ongoing

Scale Programme National

Home EDINA National

Data Centre

UKERNA

Page 5: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 5

Metadata issues (multi-federation membership)

• Goal is identical metadata in both (all) federations:

• 1) Scopes

– e.g. @ed.ac.uk or @edinburgh.ac.uk but not both

• 2) Certificates

– commercial CAs accepted by SDSS should be fine

– status of SDSS certificates still open

• 3) Entity names

– originally, appeared to be federation-relative urn:mace:ac.uk:sdss.ac.uk:provider:identity:uni.ac.uk

– preference now to use federation-independent URIs https://idp.uni.ac.uk/shibboleth

Page 6: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 6

Differences

• Assuming metadata is preserved, other

immediate changes are trivial for members:

– differences in enrolment method for new members

– new mechanism for requesting amendments

– new location for federation metadata

– different signature on federation metadata

• Policy development will bring change

Page 7: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 7

Impact of the transition

• Modest for SDSS members

• Policy for eligibility may affect new members

– projects? Other ad hoc groups?

– experience is that these can coexist with higher assurance members, but may be other issues

Page 8: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 8

Timetable

• Early days

– initial discussions very recent

• UKERNA's initial role until April 2008 …

– … but 2006 will be busy!

• Transition largely transparent …

– same configuration file can be used for both federations

• more significant change will come with

Shibboleth 2.0

Page 9: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 9

Work items

• Work on policy to be completed (Core

Middleware Advisory Board)

– policy notes on SDSS document register

• Tasks:

– plan for federation service

– automation tools for enrolment and update requests

– testing the Athens gateways

– scoping outsourced IdP requirements

Page 10: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 10

Summary

• UK federation is on track

• SDSS is a safe route to it

• SDSS and UKERNA working to ensure smooth

transition between the two …

– … initially a copy & paste exercise, with later adaptation appropriate for a national service

• Staged (behind the scenes) rather than Big

Bang

Page 11: Shibboleth Development and Support Services SDSS Development Federation Next Phase Sandy Shaw, EDINA JISC CM Programme Meeting, Windermere, 14–15 November.

Shibboleth Development and Support Services

JISC CM Programme Meeting, Windermere 14–15 November 2005 11

Contacts

• SDSS project: http://sdss.ac.uk

• Contact: [email protected]