120 likes | 273 Views
Introduction to the LIN Trial & its transition to a JANET Roaming Service. Mark Tysom Authentication & Authorisation Project Manager. Covering… . Background to the Trial Technology Overview Current Status of the Trial Future JANET Service Parallel International Effort RADIUS Developments.
E N D
Introduction to the LIN Trial & its transition to a JANET Roaming Service Mark Tysom Authentication & Authorisation Project Manager
Covering… • Background to the Trial • Technology Overview • Current Status of the Trial • Future JANET Service • Parallel International Effort • RADIUS Developments
Terminology • Location Independent Networking (LIN) • eduroam • JANET Roaming Service (JRS) • Three names, one infrastructure!
Background • JANET Wireless Advisory Group (WAG) established May 2003 • Develop a Location Independent Networking infrastructure to enable wired & wireless networks to support guest users in a transparent & secure manner (“visiting scholar problem”) • PoC tests carried out based on RADIUS (Remote Authentication Dial-In User Server) hierarchy
How it works • Hierarchy of RADIUS proxy servers: • Organisational RADIUS Proxy Server (ORPS) • National RADIUS Proxy Server (NRPS) • International RADIUS Proxy Server (IRPS)
For example, using 802.1x to authenticate… Client University of Bristol RADIUS server Institution A (ORPS) UKERNA RADIUS server (ORPS) Authenticator (AP or switch) User DB User DB Guest Username markt@ukerna.ac.uk JANET National RADIUS Proxy server (NRPS)
LIN Trial • Commenced January 2005 • Currently 36 JANET connected organisations • Accepting additional sites on a case by case basis • Ending in January 2006 • Then…?
Sales pitch… • Free service • Launching in Spring 2006 • Resilient NRPS infrastructure • Dedicated support teams • Documentation: deployment, support and user guides
LIN/JRS is part of the eduroam federation • 24 participating European countries plus Australia & Taiwan • IRPS hosted in Denmark and the Netherlands on behalf of TERENA enable international roaming • http://www.eduroam.org/
FWNA (Federated Wireless NetAuth) • Internet2 working group • Trial in early stages • Close collaboration between TERENA and I2 • http://security.internet2.edu/fwna/
RADIUS Developments • Utilising the RADIUS hierarchy infrastructure currently used for authentication • Incorporating authorisation mechanisms, i.e. access to applications • eg. the LICHEN Project