100 likes | 223 Views
Middleware in Australia - Update TF-ECM2 Malaga 16-Oct-06. Alex Reid Director, eResearch/Middleware AARNet. Areas of Middleware Activity in Australia. MAMS (Meta Access Management System): Shibboleth Federation: grant programme to accelerate take-up
E N D
Middleware in Australia - Update TF-ECM2 Malaga 16-Oct-06 Alex Reid Director, eResearch/Middleware AARNet
Areas of Middleware Activity in Australia • MAMS (Meta Access Management System): • Shibboleth Federation: grant programme to accelerate take-up • Shibboleth extensions (eg ShARPE, Autograph, People Picker) • Shibbolised DSpace, Fedora, Zope/Plone, MediaWiki, … • Shibbolised GridSphere portal, MyProxy • CAUDIT PKI Investigations • Grid & Research Community: • PKI • Nimrod-G • Ontologies • Middleware Action Plan & Strategy Project (MAPS) • NCRIS Platforms for Collaboration – Decisions • eduroam taken over by AARNet • Funding: • SII – multiple rounds • NCRIS • “private”
AHERTF • Preference for lightweight as much as possible • More work on governance needed (eg can we avoid liability issues?) • CAUDIT to convene discussion; no view yet on final owner • High-level overarching policy, 2+ implementations (Shib + PKI) • Parallel, connected OAs • Non-compliance processes - avoid liability if possible - best efforts • User education • Systemic investments: • AHERTF governance & policy development • initial get it up and running • investment to achieve economical & reliable sustainability - this is critical • contribution to operation of OAs • local costs borne locally
Shibboleth • Continue testbed, move to formal when AHERTF ready • Develop policy within AHERTF • Develop agreed attribute sets & naming (eg eduPerson, Aust extensions, how to extend it locally if necessary - note that many institutions are currently planning to re-do their IdP, so a good time to do this) • Align Shib & PKI - formal launch together • OA to manage Shib tasks, eg WAYF & further development & rollout (AARNet?) • Systemic investments: • ongoing tasks of OA • accounting/finance/audit features development • SP implementation assistance • IdP hosting & policy • non-http Shib (for Grid end-users) - WS-* version of Shib
PKI • One body to coordinate all certs across Aust in HE/research sector • Undertake a WebTrust audit • CA/RA policies must be accepted by institutions • Align PKI & Shib • Explore other government standards (eg as used by AGIMO, DST) • OA manage PKI tasks (AusCERT?) • Systemic investments: • ongoing tasks of OA • help existing CAs moving to CA in special cases (eg APAC) • initial audit framework & 1st iteration assessment (set up for least-cost ongoing audit) • IdP hosting (will we need only one for both Shib & PKI?)
Grid Middleware • Will be part of national federation • Develop AAA deeper into the Grid (more for Shib than PKI) • Systemic investments: deeper integration • VOs: • attribute management, not Id management, where possible • attribute definitions beyond VO context (is eduPerson enough or need extending?) • how manage extra attributes, eg after VO closed down? • this area is important to NCRIS • are there multiple ways of doing this? • delegation of attribute management • client tools to use VO membership information • some may need IdP hosting
Authorisation • Encourage shift to policy-based AuthR, vs Id-based • Client tools • Language to express policy (eg see B+, XACML) • Go for small set of widely-used policies • Systemic investments: • demonstrators • human • policy
NCRIS PfC Middleware Agreed 15-Sep • Define functionality of AHERTF • Need more on business case for it; in particular, do we need to cover off on alternative technologies and why we've rejected them? • Can NCRIS accelerate this? • AusCERT to further develop policy/structure for AHERTF • MAMS to develop use cases • Look at how PKI/security structure/standards being proposed relates to AGIMO, etc • Establish a Shibbolised Wiki for the project • Another meeting for late November; then final meeting Feb??
Uncertainties • Funding and location of Operating Agencies • Need use cases, business cases • Need "killer app" for PKI • Need "killer app" for Shib • Funding for non-research-sector components • Capitalising on MAMS momentum
Thank You alex.reid@aarnet.edu.au www.middleware.edu.au http://www.federation.org.au/FedManager/jsp/index.jsp https://mams.melcoe.mq.edu.au/zope/mams http://www.aarnet.edu.au/engineering/middleware/ http://www.eduroam.edu.au/