120 likes | 200 Views
Platforms for Collaboration – Plus brief update from Australia –. 9-11-2006 My condolences. Dr. Erik Vullings MAMS Project Macquarie University’s E-Learning Centre of Excellence (MELCOE) Erik.Vullings@mq.edu.au Skype name: Erik_Vullings. Contents. Brief update on AU-Federation status
E N D
Platforms for Collaboration– Plus brief update from Australia – 9-11-2006 My condolences Dr. Erik Vullings MAMS Project Macquarie University’s E-Learning Centre of Excellence (MELCOE) Erik.Vullings@mq.edu.au Skype name: Erik_Vullings META ACCESS MANAGEMENT SYSTEM
Contents • Brief update on AU-Federation status • Mini-grant projects • User privacy mgmt via Autograph • Shibbolized IM: ShibJIM • Platform for Collaboration: • A Virtual Organization (similar to myVocs) • Based on Shibbolized GridSphere & MyProxy • With cross-federation IdP manager, SP manager and workspace support… META ACCESS MANAGEMENT SYSTEM
Round 1 (Feb 2006): AARNet: IdP, ENUM SP Griffith: IdP, Wiki SP, Gnomic DB QUT: ATN IdP, eGrad School SP QU IdP, Fez (Fedora GUI) SP USYD IdP, Sensor data SP Round 2 (Jul 2006): Deakin: IdP, e-Lectures JCU: IdP, SRB & Plone Melbourne: IdP, IAM suite (LIGO) Monash IdP, IAM suite SP Murdoch & MQ: IdP, Online Librarian WAGUL: 5 IdP, reciprocal borrowing MAMS $40k-Grant Program(Federation status: 600,000 Shibboleth Identities, 20%HE) META ACCESS MANAGEMENT SYSTEM
Who am I? Privacy Management with AutographControl what’s on your SAML assertion… SP uses SAML handle to retrieve user attributes Service Provider Identity Provider META ACCESS MANAGEMENT SYSTEM
Different cards open different doors – Services & Service Level – META ACCESS MANAGEMENT SYSTEM
Different cards open different doors – Services & Service Level – META ACCESS MANAGEMENT SYSTEM
Adding Personal Attributes Other examples: Accessibility info (colorblind, blind), Skype user name, IM account name, etc. META ACCESS MANAGEMENT SYSTEM
IAM Suite– [I AM Suite] Prototyping a PfC – “All research projects are different, but most project infrastructures are more equal than not” All projects require: • Collaboration between project members • Collaboration with external people • Dissemination of research results • AuthN & AuthZ (what’s public, what’s not) META ACCESS MANAGEMENT SYSTEM
IAM Suite– [I AM Suite] Prototyping a PfC – Scope: • A toolkit for eResearch Projects and Dept., wishing to leverage Federated ID for accessing data, resources and generic collaboration tools over the grid, but excl. research-specific tools. Installation: • Similar to ISP that hosts your CMS, forum etc.: Tick the box and you are ready to run… META ACCESS MANAGEMENT SYSTEM
Gateway (CTS) Possible MiddlewareHE Infrastructure for Collaboration Federation Services WAYF <<SP>>MyProxy server <<SP>>CA? Federation Level … IdP1@UQ IdP2@UTS IdPn@MQ … Institutions Level <<SP>> IR <<SP>> VO Portal <<SP>> CMS MyProxy Client GTK: Grid SP: Forum Virtual Org. Level(intra-institution, eResearch project) VO IdP GTK: HPC SP: Wiki GTK: Store SP: CMS META ACCESS MANAGEMENT SYSTEM
Federation IAM Suite Login via IdP Receive assertions Search AFS adaptor Federation SP VO-WAYF Contains VO group attributes for RBAC. Fedora (internal or external, e.g. IR) GridSphere VO-IdP GroupModule ShARPE AuthN IM Autograph FedoraWeb Send SAML assertions MyProxy Sendproxy cert. Presence GTK GTK VO-SP VO-SP PeoplePicker Storage Cluster Forum Wiki Calendar AuthZ Mgnr GTK GTK VO-SP VO-SP Specific tools Equipm. LMS Etc. META ACCESS MANAGEMENT SYSTEM
FLASH DEMO IAM SUITE • Shib login to GS via VO-WAYF • admin adds Wiki service and tests it • Create a group • Add a resource and service to a group • TBD authN source (none, IdP, VO-IdP, cert) • Workspace (virtual room): • Create workspace & roles, add VO members, services, and resources… META ACCESS MANAGEMENT SYSTEM