Top Banner
A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network to application Michael R Gettes Internet2 August 2007 An interpretation of the original MACE mission
23

A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Dec 18, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

A Middleware

Unified Field Theory

Identity Management / Directories

Privileges / Groups

Single Sign-On / Federation

Enterprise Integration

from network to application

Michael R GettesInternet2

August 2007

An interpretation of the original MACE mission

Page 2: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

VO?

Page 3: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Inter-EnterpriseWorkgroup

Collaborations

not sexy

Page 4: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

or

Collaborative

Organizations

CO

Page 5: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Identity

Groups

Privileges

Federated Access

Page 6: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

and …

Applications

Page 7: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Give

COntrol

To

COmmunity Members

Page 8: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Integrate with

Existing

COmmon

IT Infrastructuresin

Higher Education

Page 9: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Flexible

Scalable

Modular

Page 10: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

COmponents

S H I B B O L E T HS H I B B O L E T H

LDAP-PC

Signet Grouper

LDAPDirectory

IdentityMgr

Applications & Network

CO

Page 11: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

stop talkingstart walking

demo

COmanage.internet2.edu

Page 12: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

COmponents

S H I B B O L E T HS H I B B O L E T H

LDAP-PC

Signet Grouper

LDAPDirectory

IdentityMgr

Applications & Network

CO

Page 13: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Comanage …

is only a demonstration ofthe CO model

a CO fits within a service

delivery presentation

Page 14: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Stuff stored in Directories(everybody has one)

Priv/Group data more accessible

Allows for easy CO integration

Page 15: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Application Management

App Access to data ismanaged by LDAP (initially)

Identity data can be distributed by any desired mechanism in the future. SQL databases, feeds, message bus technologies.

Page 16: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Uses ShibbolethFederating technology

Promotes InCOmmon Federation

Might use other technologiesOpenID?

Page 17: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Truth be told…

LDAP-PC Large-Scale Performance and namespaces

SIGNETMinor UI and Deployment

GROUPER Some UI and Large-scale Performance

SIGNET only immediate concern

Page 18: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Many COson a single server

________

No local identity issued for external users to access

CO services big win!

Page 19: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Signet/Grouper COmplexity

A Service Opportunity?Middleware Service Provider (MSP)

May also be locally deployedby HE institutions

Page 20: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Future…

Protect CO by IdP can solve “IEEE problem”?

Begin addressing issuesof “attribute eCOnomy”

Page 21: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

Network Layer?Why not?

Integrate with Grids?Why not?

Addresses VO scenarios?Why not?

Page 22: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

VOVO?CO

Page 23: A Middleware Unified Field Theory Identity Management / Directories Privileges / Groups Single Sign-On / Federation Enterprise Integration from network.

done

Talk amongst yourselves