SlideShare una empresa de Scribd logo
1 de 24
Descargar para leer sin conexión
REFEDS Update on Canadian Access
Federation

Chris Phillips | Nov11,2013 | Internet2 idweek2013 | San Francisco

www.canarie.ca
About CANARIE
Operates Canada’s ultrahigh-bandwidth research
network

•  Connects one million users at
1,100 institutions, “big science”
facilities like TRIUMF, NEPTUNE,
CLS, SNOLAB, and to Compute
Canada HPC consortia
•  19,000km of fibre with a 40 Gbps
backbone
•  Funds programs that enable
greater access to research data,
tools and peers and to stimulate
the ICT sector

Operator of the Canadian
Access Federation
•  SAML federation based on
Shibboleth
•  Canadian Eduroam 802.1x
wireless roaming operator
•  eduGAIN participant

Primary investment
from Government of
Canada - $480 M since 1993

Map date: 29 May 2012

www.canarie.ca

2
About CANARIE
Operates Canada’s ultrahigh-bandwidth research
network

•  Connects one million users at
1,100 institutions, “big science”
facilities like TRIUMF, NEPTUNE,
CLS, SNOLAB, and to Compute
Canada HPC consortia
•  19,000km of fibre with a 40 Gbps
backbone
•  Funds programs that enable
greater access to research data,
tools and peers and to stimulate
the ICT sector

Additional Programs

Operator of the Canadian
DAIR - Digital Accelerator for Innovation and Research
Access Federation
An on-demand, advanced R&D cloud environment that supports Canada’s
•  SAML federation based on
Shibboleth
tech innovators. Openstack based, with 2 regions (Alberta, Quebec).
•  Canadian Eduroam 802.1x
wireless roaming operator
RPI - Research Platform Infrastructure
•  eduGAIN participant
An investment in middleware by CANARIE that leverages existing platforms &
Primary investment
is the evolution of the NEP program. Reduces duplication, increases re-use
from Government of
and collaboration between programs. http://science.canarie.ca/
Canada - $480 M since 1993
NEP - Network Enabled Platforms
Similar in nature to GEANT opencall. Research initiatives showing innovative
uses of the network. Has evolved to be even more collaborative and
generates new interfaces/ RPI services to be reused between projects.
Map date: 29 May 2012

www.canarie.ca

3
This is what it feels like trying to collaborate….
Image: Phil Roeder - Flickr

www.canarie.ca

4
This is how we want it to feel.
www.canarie.ca

5
How?

Facilitate collaboration at the largest scale possible.

www.canarie.ca
How?

t
st bu
Easie !
d
ruste
t
v
Facilitate collaboration at the largest scale possible.
!
lessly
Seam

v

www.canarie.ca
Roaming wireless

• 
• 
• 
• 

International wireless roaming
Ability to automatically sign on
using your home credential
Reduces barriers to mobile
users
Worldwide and expanding
coverage:
•  Canada: 64 sites
•  65 countries worldwide

Successful Logins
2,000,000
1,500,000
1,000,000
500,000
-

• 
• 
• 
• 

International
Canada

~3M logins Sept 2013
2.5x traffic growth in 1yr
48 sites ~50% universities in
Canada
40% growth in sites in 1yr

Federated identity

•  Federated Single Sign On for
services
•  Web and non web sign on
•  Authentication
•  Authorization
•  Attribute release
•  Across different security domains

Interfederation
•  International wireless roaming
•  • eduGAIN to automatically sign on
Ability as primary, exploring
other direct relationships
using your home credential
•  • Bridge to internationalto mobile
Reduces barriers community
•  Enables CAF participants to:
users
•  Accept identities inbound
•  Worldwide and expanding
from outside Canada to
coverage:
• Canadian services
Canada: 48 sites
•  • Use Canadian identities in
60 countries worldwide
services outside Canada

Total CAF enabled users –
SAML & eduroam
1,040,000
1,020,000
1,000,000
980,000
960,000
940,000
920,000
900,000
880,000

1,011,793

1,020,387

986,765
937,000

•  24 Service Providers – 160%
increase in 1yr
•  21 Identity Providers
www.canarie.ca

•  Int’l NREN CEO Forum placed
eduGAIN as a key effort
•  CAF was early adopter - joined
last year when there were 8, and
eduGAIN now has 20 countries
A Glimpse at eduroam traffic
eduroam Successful Logins - up to Oct 30,2013
4,000,000

25.00%

3,500,000
20.00%

2,500,000

15.00%

2,000,000
10.00%

1,500,000

1,000,000
5.00%
500,000

-

0.00%

www.canarie.ca

% No Reply from Server

Successful Log ins

3,000,000

International
Canada
Closing the gap
•  Eduroam evidence of success àWhy not same for FSSO?
•  Talked to new & old participants, other federations
•  Analyzed over a years worth of data

http://www.flickr.com/photos/asparagus_hunter/483841638/ asparagus hunter

www.canarie.ca
Regular Approach

Identity Appliance

Choose RADIUS server
Install & Configure
Test & Connect

Supported Server installed
Pre-configured
Tested & Connected

Choose platform
Install & Configure
Test & Connect

Supported platform installed

Pre-Configured
Tested & Connected

Why?
• 
• 
• 
• 

Evolved approach to better match campus IT reality
Reduced cost/effort to be CAF participant
Simplifies CAF installation experience
Easier day to day operations

http://www.flickr.com/photos/madison_guy/3386919046/sizes/o/in/photostream/ Madison Guy

www.canarie.ca
Regular Approach

Identity Appliance

Choose RADIUS server
Install & Configure
Test & Connect

Supported Server installed
Pre-configured
Tested & Connected

Choose platform
Install & Configure
Test & Connect

Supported platform installed

Pre-Configured
Tested & Connected

Why? Deeper
A Bit
• 
• 
• 
• 
• 
• 
• 

Reviewed many styles, better match doing both eduroam
Evolved approach tobut no one really campus IT reality AND
Federated cost/effort to
Reduced SSO w/SAML be CAF participant
Inspired by many DevOps style approaches, adopted installer
Simplifies CAF installation experience
based model (SWAMID approach, others influencial too)
Easier dayalpha now, FedSSO going through test cycles
eduroam in to day operations

•  Sites will be connected to both eduroam & eduGAIN
http://www.flickr.com/photos/madison_guy/3386919046/sizes/o/in/photostream/ Madison Guy

www.canarie.ca
Inter-federation
•  In use and business as usual
•  Eduroam Configuration Assistant Tool(CAT) driving current IdPs
•  Appliance approach will see sites joining eduGAIN when they join
CAF.

www.canarie.ca
Eduroam CAT service (accessed via eduGAIN)
•  Builds & hosts
profile installers for
all platforms and
devices(MSFT,App
le, Linux)
•  Profile = specific
configuration on
your device to
connect to the
network

www.canarie.ca
Signing on to Manage Your eduroam Site
•  Access is only for site
admins
•  Requires Federated
Single Sign On +
invitation one time link
•  Can create multiple
admins
•  Can create multiple
‘profiles’ for testing prior
to release.
•  Production Profiles can
be downloaded via CAT
www.canarie.ca
Once Signed in

Snapshot of eduroam CAT
• 
• 
• 
• 

# of federations with at least 1 production Idp: 30
Total idps registered: 391
IdPs which enabled public download interface: 264
End User Downloads of installersso far : 162,289
www.canarie.ca
Sub-national Topic
•  Different groups across Canada expressed interest in ‘CAF+ . . .’
•  Needs were diverse yet common: additional schema, workflow for
special sets of entities only, allow entities to be members of multiple
sets, notify about joining set.
•  View is that it can be done centrally through CAF, but tools &
processes need improvements
www.canarie.ca
Unified Collaboration & Interconnection
CAF
SP
SP
SP

Idp
Idp
Idp

Special Interest Trust Groups
SP

SP

Idp

Higher Assurance

Local Fed
Idp

SP

SP

Local Fed
Idp

SP

SP

•  Efficient, least effort for SP/IdP
•  Local fed incubates federation
aware apps
•  SITG can leverage common
infrastructure, and overlay
special attribute sets & specific
policies

Idp

www.canarie.ca
Improving Tools
•  Federation Operations needed to rise to the challenge
•  Federation Registry tools space has very rich offerings (AAF: Fed’n
Mgr, HEANET: Resource Registry, REEP to name a few)
•  Tough to choose because of the great work out there
•  Gravitated to HEANET RR
http://www.flickr.com/photos/chazferret/2075442918/

www.canarie.ca
Skating to where the puck will be
•  Our usual ‘customers’ are changing, we need to as well.
•  Centralized services with delegation functionality avoid
duplication of effort in the community and saves time and
effort for sites
http://www.flickr.com/photos/mag3737/1997114236/ mag3737

www.canarie.ca
Seed Topics for the ACAMP
•  Effective Attribute release from IdPs
•  Centralized authorization and user preferences being sought – should we
run an instance of grouper or CoManage?
•  Non web SAML for restful webservices, looking for some interesting
approaches
•  Interested in any mobile plays for Fed. SSO on smartphones.
http://www.flickr.com/photos/the_yes_man/4648999621/sizes/l/in/photostream/

www.canarie.ca
www.canarie.ca
Additional Material

www.canarie.ca
Digital Accelerator
for Innovation and Research (DAIR)
An on-demand, advanced R&D environment that
supports Canada’s tech innovators and
entrepreneurs in designing, prototyping, validating
and demonstrating their new technology apps,
products and services.
www.canarie.ca/en/dair

INTERNET

Cloud Computing and Storage

+
Optical Regional Advanced Networks
(ORANs)
Réseaux optiques régionaux évolués
(ROREs)

www.canarie.ca

Infonuagique et stockage

Más contenido relacionado

Similar a CANARIE Canadian Access Federation Update @ Internet2 Identity Week 2013

Webinar: Is the Cloud Right for You 2016-10-18
Webinar: Is the Cloud Right for You 2016-10-18Webinar: Is the Cloud Right for You 2016-10-18
Webinar: Is the Cloud Right for You 2016-10-18TechSoup
 
CAF Workshop BCNet2014
CAF Workshop BCNet2014CAF Workshop BCNet2014
CAF Workshop BCNet2014Chris Phillips
 
Eduroam: A current view of the worldwide service
Eduroam: A current view of the worldwide serviceEduroam: A current view of the worldwide service
Eduroam: A current view of the worldwide serviceChris Phillips
 
Gab Genai Cloudera - Going Beyond Traditional Analytic
Gab Genai Cloudera - Going Beyond Traditional Analytic Gab Genai Cloudera - Going Beyond Traditional Analytic
Gab Genai Cloudera - Going Beyond Traditional Analytic IntelAPAC
 
Superfast Business - Moving to the Cloud
Superfast Business - Moving to the CloudSuperfast Business - Moving to the Cloud
Superfast Business - Moving to the CloudSuperfast Business
 
Ready, Set, SD-WAN: Best Practices for Assuring Branch Readiness
Ready, Set, SD-WAN: Best Practices for Assuring Branch ReadinessReady, Set, SD-WAN: Best Practices for Assuring Branch Readiness
Ready, Set, SD-WAN: Best Practices for Assuring Branch ReadinessThousandEyes
 
SD-WAN & Hybrid-WAN Solutions for CSPs
SD-WAN & Hybrid-WAN Solutions for CSPsSD-WAN & Hybrid-WAN Solutions for CSPs
SD-WAN & Hybrid-WAN Solutions for CSPsRicky Pierson
 
Building Successful API Programs in Higher Education
Building Successful API Programs in Higher EducationBuilding Successful API Programs in Higher Education
Building Successful API Programs in Higher Education3scale
 
Jisc trust and identity update
Jisc trust and identity updateJisc trust and identity update
Jisc trust and identity updateJisc
 
Qtility software ltd
Qtility software ltdQtility software ltd
Qtility software ltdclarkems
 
20190523 archiver fim
20190523 archiver fim20190523 archiver fim
20190523 archiver fimArchiver
 
From Monoliths to Services: Paying Your Technical Debt
From Monoliths to Services: Paying Your Technical DebtFrom Monoliths to Services: Paying Your Technical Debt
From Monoliths to Services: Paying Your Technical DebtTechWell
 
The New Frontier: Optimizing Big Data Exploration
The New Frontier: Optimizing Big Data ExplorationThe New Frontier: Optimizing Big Data Exploration
The New Frontier: Optimizing Big Data ExplorationInside Analysis
 
Solution Centric Architectural Presentation - A Journey from Data Paralysis t...
Solution Centric Architectural Presentation - A Journey from Data Paralysis t...Solution Centric Architectural Presentation - A Journey from Data Paralysis t...
Solution Centric Architectural Presentation - A Journey from Data Paralysis t...Denodo
 
How to Leverage SAFe 5.0 for Your Enterprise Cloud Strategy
How to Leverage SAFe 5.0 for Your Enterprise Cloud StrategyHow to Leverage SAFe 5.0 for Your Enterprise Cloud Strategy
How to Leverage SAFe 5.0 for Your Enterprise Cloud StrategyCprime
 
A non-technical introduction to Cloud Computing
A non-technical introduction to Cloud ComputingA non-technical introduction to Cloud Computing
A non-technical introduction to Cloud ComputingWilliam Pourmajidi
 

Similar a CANARIE Canadian Access Federation Update @ Internet2 Identity Week 2013 (20)

Webinar: Is the Cloud Right for You 2016-10-18
Webinar: Is the Cloud Right for You 2016-10-18Webinar: Is the Cloud Right for You 2016-10-18
Webinar: Is the Cloud Right for You 2016-10-18
 
CAF Workshop BCNet2014
CAF Workshop BCNet2014CAF Workshop BCNet2014
CAF Workshop BCNet2014
 
DAIR programme and relevance for FIRE
DAIR programme and relevance for FIREDAIR programme and relevance for FIRE
DAIR programme and relevance for FIRE
 
Eduroam: A current view of the worldwide service
Eduroam: A current view of the worldwide serviceEduroam: A current view of the worldwide service
Eduroam: A current view of the worldwide service
 
Gab Genai Cloudera - Going Beyond Traditional Analytic
Gab Genai Cloudera - Going Beyond Traditional Analytic Gab Genai Cloudera - Going Beyond Traditional Analytic
Gab Genai Cloudera - Going Beyond Traditional Analytic
 
All Things eduroam
All Things eduroamAll Things eduroam
All Things eduroam
 
ION Costa Rica Opening Slides
ION Costa Rica Opening SlidesION Costa Rica Opening Slides
ION Costa Rica Opening Slides
 
Superfast Business - Moving to the Cloud
Superfast Business - Moving to the CloudSuperfast Business - Moving to the Cloud
Superfast Business - Moving to the Cloud
 
Ready, Set, SD-WAN: Best Practices for Assuring Branch Readiness
Ready, Set, SD-WAN: Best Practices for Assuring Branch ReadinessReady, Set, SD-WAN: Best Practices for Assuring Branch Readiness
Ready, Set, SD-WAN: Best Practices for Assuring Branch Readiness
 
SD-WAN & Hybrid-WAN Solutions for CSPs
SD-WAN & Hybrid-WAN Solutions for CSPsSD-WAN & Hybrid-WAN Solutions for CSPs
SD-WAN & Hybrid-WAN Solutions for CSPs
 
Building Successful API Programs in Higher Education
Building Successful API Programs in Higher EducationBuilding Successful API Programs in Higher Education
Building Successful API Programs in Higher Education
 
Jisc trust and identity update
Jisc trust and identity updateJisc trust and identity update
Jisc trust and identity update
 
Rdfa semtech2011
Rdfa semtech2011Rdfa semtech2011
Rdfa semtech2011
 
Qtility software ltd
Qtility software ltdQtility software ltd
Qtility software ltd
 
20190523 archiver fim
20190523 archiver fim20190523 archiver fim
20190523 archiver fim
 
From Monoliths to Services: Paying Your Technical Debt
From Monoliths to Services: Paying Your Technical DebtFrom Monoliths to Services: Paying Your Technical Debt
From Monoliths to Services: Paying Your Technical Debt
 
The New Frontier: Optimizing Big Data Exploration
The New Frontier: Optimizing Big Data ExplorationThe New Frontier: Optimizing Big Data Exploration
The New Frontier: Optimizing Big Data Exploration
 
Solution Centric Architectural Presentation - A Journey from Data Paralysis t...
Solution Centric Architectural Presentation - A Journey from Data Paralysis t...Solution Centric Architectural Presentation - A Journey from Data Paralysis t...
Solution Centric Architectural Presentation - A Journey from Data Paralysis t...
 
How to Leverage SAFe 5.0 for Your Enterprise Cloud Strategy
How to Leverage SAFe 5.0 for Your Enterprise Cloud StrategyHow to Leverage SAFe 5.0 for Your Enterprise Cloud Strategy
How to Leverage SAFe 5.0 for Your Enterprise Cloud Strategy
 
A non-technical introduction to Cloud Computing
A non-technical introduction to Cloud ComputingA non-technical introduction to Cloud Computing
A non-technical introduction to Cloud Computing
 

Más de Chris Phillips

TNC2014 Think Globally act locally: Simplifying Federated technologies
TNC2014 Think Globally act locally: Simplifying Federated technologiesTNC2014 Think Globally act locally: Simplifying Federated technologies
TNC2014 Think Globally act locally: Simplifying Federated technologiesChris Phillips
 
National Federation Perspectives & Insights
National Federation Perspectives & InsightsNational Federation Perspectives & Insights
National Federation Perspectives & InsightsChris Phillips
 
Scim2012 q1update chrisphillips
Scim2012 q1update chrisphillipsScim2012 q1update chrisphillips
Scim2012 q1update chrisphillipsChris Phillips
 
Chris Phillips SCIM Mace-Dir Internet2 Fall Member Meeting Refresh
Chris Phillips SCIM Mace-Dir Internet2 Fall Member Meeting RefreshChris Phillips SCIM Mace-Dir Internet2 Fall Member Meeting Refresh
Chris Phillips SCIM Mace-Dir Internet2 Fall Member Meeting RefreshChris Phillips
 
Canarie Federated Non Web Signon
Canarie Federated Non Web SignonCanarie Federated Non Web Signon
Canarie Federated Non Web SignonChris Phillips
 
Canarie CAF-eduroam Technical Workshop
Canarie CAF-eduroam Technical WorkshopCanarie CAF-eduroam Technical Workshop
Canarie CAF-eduroam Technical WorkshopChris Phillips
 
Canarie CAF- Shibboleth Workshop Topics
Canarie CAF- Shibboleth Workshop TopicsCanarie CAF- Shibboleth Workshop Topics
Canarie CAF- Shibboleth Workshop TopicsChris Phillips
 
Moonshot Brainstorming Strawman
Moonshot Brainstorming StrawmanMoonshot Brainstorming Strawman
Moonshot Brainstorming StrawmanChris Phillips
 
Moonshot Brainstorming Strawman
Moonshot Brainstorming StrawmanMoonshot Brainstorming Strawman
Moonshot Brainstorming StrawmanChris Phillips
 
CANARIE - What Do I Need to Connect with eduroam and Shibboleth
CANARIE - What Do I Need to Connect with eduroam and ShibbolethCANARIE - What Do I Need to Connect with eduroam and Shibboleth
CANARIE - What Do I Need to Connect with eduroam and ShibbolethChris Phillips
 
CANARIE Eduroam and Shibboleth Lessons & Areas of interest
CANARIE Eduroam and Shibboleth Lessons & Areas of interestCANARIE Eduroam and Shibboleth Lessons & Areas of interest
CANARIE Eduroam and Shibboleth Lessons & Areas of interestChris Phillips
 

Más de Chris Phillips (11)

TNC2014 Think Globally act locally: Simplifying Federated technologies
TNC2014 Think Globally act locally: Simplifying Federated technologiesTNC2014 Think Globally act locally: Simplifying Federated technologies
TNC2014 Think Globally act locally: Simplifying Federated technologies
 
National Federation Perspectives & Insights
National Federation Perspectives & InsightsNational Federation Perspectives & Insights
National Federation Perspectives & Insights
 
Scim2012 q1update chrisphillips
Scim2012 q1update chrisphillipsScim2012 q1update chrisphillips
Scim2012 q1update chrisphillips
 
Chris Phillips SCIM Mace-Dir Internet2 Fall Member Meeting Refresh
Chris Phillips SCIM Mace-Dir Internet2 Fall Member Meeting RefreshChris Phillips SCIM Mace-Dir Internet2 Fall Member Meeting Refresh
Chris Phillips SCIM Mace-Dir Internet2 Fall Member Meeting Refresh
 
Canarie Federated Non Web Signon
Canarie Federated Non Web SignonCanarie Federated Non Web Signon
Canarie Federated Non Web Signon
 
Canarie CAF-eduroam Technical Workshop
Canarie CAF-eduroam Technical WorkshopCanarie CAF-eduroam Technical Workshop
Canarie CAF-eduroam Technical Workshop
 
Canarie CAF- Shibboleth Workshop Topics
Canarie CAF- Shibboleth Workshop TopicsCanarie CAF- Shibboleth Workshop Topics
Canarie CAF- Shibboleth Workshop Topics
 
Moonshot Brainstorming Strawman
Moonshot Brainstorming StrawmanMoonshot Brainstorming Strawman
Moonshot Brainstorming Strawman
 
Moonshot Brainstorming Strawman
Moonshot Brainstorming StrawmanMoonshot Brainstorming Strawman
Moonshot Brainstorming Strawman
 
CANARIE - What Do I Need to Connect with eduroam and Shibboleth
CANARIE - What Do I Need to Connect with eduroam and ShibbolethCANARIE - What Do I Need to Connect with eduroam and Shibboleth
CANARIE - What Do I Need to Connect with eduroam and Shibboleth
 
CANARIE Eduroam and Shibboleth Lessons & Areas of interest
CANARIE Eduroam and Shibboleth Lessons & Areas of interestCANARIE Eduroam and Shibboleth Lessons & Areas of interest
CANARIE Eduroam and Shibboleth Lessons & Areas of interest
 

Último

MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
VIP Call Girls Gandi Maisamma ( Hyderabad ) Phone 8250192130 | ₹5k To 25k Wit...
VIP Call Girls Gandi Maisamma ( Hyderabad ) Phone 8250192130 | ₹5k To 25k Wit...VIP Call Girls Gandi Maisamma ( Hyderabad ) Phone 8250192130 | ₹5k To 25k Wit...
VIP Call Girls Gandi Maisamma ( Hyderabad ) Phone 8250192130 | ₹5k To 25k Wit...Suhani Kapoor
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
A305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdfA305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdftbatkhuu1
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsMichael W. Hawkins
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876dlhescort
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyEthan lee
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 DelhiCall Girls in Delhi
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaShree Krishna Exports
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfOnline Income Engine
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxpriyanshujha201
 

Último (20)

MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
VIP Call Girls Gandi Maisamma ( Hyderabad ) Phone 8250192130 | ₹5k To 25k Wit...
VIP Call Girls Gandi Maisamma ( Hyderabad ) Phone 8250192130 | ₹5k To 25k Wit...VIP Call Girls Gandi Maisamma ( Hyderabad ) Phone 8250192130 | ₹5k To 25k Wit...
VIP Call Girls Gandi Maisamma ( Hyderabad ) Phone 8250192130 | ₹5k To 25k Wit...
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
A305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdfA305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdf
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael Hawkins
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in India
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdf
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 

CANARIE Canadian Access Federation Update @ Internet2 Identity Week 2013

  • 1. REFEDS Update on Canadian Access Federation Chris Phillips | Nov11,2013 | Internet2 idweek2013 | San Francisco www.canarie.ca
  • 2. About CANARIE Operates Canada’s ultrahigh-bandwidth research network •  Connects one million users at 1,100 institutions, “big science” facilities like TRIUMF, NEPTUNE, CLS, SNOLAB, and to Compute Canada HPC consortia •  19,000km of fibre with a 40 Gbps backbone •  Funds programs that enable greater access to research data, tools and peers and to stimulate the ICT sector Operator of the Canadian Access Federation •  SAML federation based on Shibboleth •  Canadian Eduroam 802.1x wireless roaming operator •  eduGAIN participant Primary investment from Government of Canada - $480 M since 1993 Map date: 29 May 2012 www.canarie.ca 2
  • 3. About CANARIE Operates Canada’s ultrahigh-bandwidth research network •  Connects one million users at 1,100 institutions, “big science” facilities like TRIUMF, NEPTUNE, CLS, SNOLAB, and to Compute Canada HPC consortia •  19,000km of fibre with a 40 Gbps backbone •  Funds programs that enable greater access to research data, tools and peers and to stimulate the ICT sector Additional Programs Operator of the Canadian DAIR - Digital Accelerator for Innovation and Research Access Federation An on-demand, advanced R&D cloud environment that supports Canada’s •  SAML federation based on Shibboleth tech innovators. Openstack based, with 2 regions (Alberta, Quebec). •  Canadian Eduroam 802.1x wireless roaming operator RPI - Research Platform Infrastructure •  eduGAIN participant An investment in middleware by CANARIE that leverages existing platforms & Primary investment is the evolution of the NEP program. Reduces duplication, increases re-use from Government of and collaboration between programs. http://science.canarie.ca/ Canada - $480 M since 1993 NEP - Network Enabled Platforms Similar in nature to GEANT opencall. Research initiatives showing innovative uses of the network. Has evolved to be even more collaborative and generates new interfaces/ RPI services to be reused between projects. Map date: 29 May 2012 www.canarie.ca 3
  • 4. This is what it feels like trying to collaborate…. Image: Phil Roeder - Flickr www.canarie.ca 4
  • 5. This is how we want it to feel. www.canarie.ca 5
  • 6. How? Facilitate collaboration at the largest scale possible. www.canarie.ca
  • 7. How? t st bu Easie ! d ruste t v Facilitate collaboration at the largest scale possible. ! lessly Seam v www.canarie.ca
  • 8. Roaming wireless •  •  •  •  International wireless roaming Ability to automatically sign on using your home credential Reduces barriers to mobile users Worldwide and expanding coverage: •  Canada: 64 sites •  65 countries worldwide Successful Logins 2,000,000 1,500,000 1,000,000 500,000 - •  •  •  •  International Canada ~3M logins Sept 2013 2.5x traffic growth in 1yr 48 sites ~50% universities in Canada 40% growth in sites in 1yr Federated identity •  Federated Single Sign On for services •  Web and non web sign on •  Authentication •  Authorization •  Attribute release •  Across different security domains Interfederation •  International wireless roaming •  • eduGAIN to automatically sign on Ability as primary, exploring other direct relationships using your home credential •  • Bridge to internationalto mobile Reduces barriers community •  Enables CAF participants to: users •  Accept identities inbound •  Worldwide and expanding from outside Canada to coverage: • Canadian services Canada: 48 sites •  • Use Canadian identities in 60 countries worldwide services outside Canada Total CAF enabled users – SAML & eduroam 1,040,000 1,020,000 1,000,000 980,000 960,000 940,000 920,000 900,000 880,000 1,011,793 1,020,387 986,765 937,000 •  24 Service Providers – 160% increase in 1yr •  21 Identity Providers www.canarie.ca •  Int’l NREN CEO Forum placed eduGAIN as a key effort •  CAF was early adopter - joined last year when there were 8, and eduGAIN now has 20 countries
  • 9. A Glimpse at eduroam traffic eduroam Successful Logins - up to Oct 30,2013 4,000,000 25.00% 3,500,000 20.00% 2,500,000 15.00% 2,000,000 10.00% 1,500,000 1,000,000 5.00% 500,000 - 0.00% www.canarie.ca % No Reply from Server Successful Log ins 3,000,000 International Canada
  • 10. Closing the gap •  Eduroam evidence of success àWhy not same for FSSO? •  Talked to new & old participants, other federations •  Analyzed over a years worth of data http://www.flickr.com/photos/asparagus_hunter/483841638/ asparagus hunter www.canarie.ca
  • 11. Regular Approach Identity Appliance Choose RADIUS server Install & Configure Test & Connect Supported Server installed Pre-configured Tested & Connected Choose platform Install & Configure Test & Connect Supported platform installed Pre-Configured Tested & Connected Why? •  •  •  •  Evolved approach to better match campus IT reality Reduced cost/effort to be CAF participant Simplifies CAF installation experience Easier day to day operations http://www.flickr.com/photos/madison_guy/3386919046/sizes/o/in/photostream/ Madison Guy www.canarie.ca
  • 12. Regular Approach Identity Appliance Choose RADIUS server Install & Configure Test & Connect Supported Server installed Pre-configured Tested & Connected Choose platform Install & Configure Test & Connect Supported platform installed Pre-Configured Tested & Connected Why? Deeper A Bit •  •  •  •  •  •  •  Reviewed many styles, better match doing both eduroam Evolved approach tobut no one really campus IT reality AND Federated cost/effort to Reduced SSO w/SAML be CAF participant Inspired by many DevOps style approaches, adopted installer Simplifies CAF installation experience based model (SWAMID approach, others influencial too) Easier dayalpha now, FedSSO going through test cycles eduroam in to day operations •  Sites will be connected to both eduroam & eduGAIN http://www.flickr.com/photos/madison_guy/3386919046/sizes/o/in/photostream/ Madison Guy www.canarie.ca
  • 13. Inter-federation •  In use and business as usual •  Eduroam Configuration Assistant Tool(CAT) driving current IdPs •  Appliance approach will see sites joining eduGAIN when they join CAF. www.canarie.ca
  • 14. Eduroam CAT service (accessed via eduGAIN) •  Builds & hosts profile installers for all platforms and devices(MSFT,App le, Linux) •  Profile = specific configuration on your device to connect to the network www.canarie.ca
  • 15. Signing on to Manage Your eduroam Site •  Access is only for site admins •  Requires Federated Single Sign On + invitation one time link •  Can create multiple admins •  Can create multiple ‘profiles’ for testing prior to release. •  Production Profiles can be downloaded via CAT www.canarie.ca
  • 16. Once Signed in Snapshot of eduroam CAT •  •  •  •  # of federations with at least 1 production Idp: 30 Total idps registered: 391 IdPs which enabled public download interface: 264 End User Downloads of installersso far : 162,289 www.canarie.ca
  • 17. Sub-national Topic •  Different groups across Canada expressed interest in ‘CAF+ . . .’ •  Needs were diverse yet common: additional schema, workflow for special sets of entities only, allow entities to be members of multiple sets, notify about joining set. •  View is that it can be done centrally through CAF, but tools & processes need improvements www.canarie.ca
  • 18. Unified Collaboration & Interconnection CAF SP SP SP Idp Idp Idp Special Interest Trust Groups SP SP Idp Higher Assurance Local Fed Idp SP SP Local Fed Idp SP SP •  Efficient, least effort for SP/IdP •  Local fed incubates federation aware apps •  SITG can leverage common infrastructure, and overlay special attribute sets & specific policies Idp www.canarie.ca
  • 19. Improving Tools •  Federation Operations needed to rise to the challenge •  Federation Registry tools space has very rich offerings (AAF: Fed’n Mgr, HEANET: Resource Registry, REEP to name a few) •  Tough to choose because of the great work out there •  Gravitated to HEANET RR http://www.flickr.com/photos/chazferret/2075442918/ www.canarie.ca
  • 20. Skating to where the puck will be •  Our usual ‘customers’ are changing, we need to as well. •  Centralized services with delegation functionality avoid duplication of effort in the community and saves time and effort for sites http://www.flickr.com/photos/mag3737/1997114236/ mag3737 www.canarie.ca
  • 21. Seed Topics for the ACAMP •  Effective Attribute release from IdPs •  Centralized authorization and user preferences being sought – should we run an instance of grouper or CoManage? •  Non web SAML for restful webservices, looking for some interesting approaches •  Interested in any mobile plays for Fed. SSO on smartphones. http://www.flickr.com/photos/the_yes_man/4648999621/sizes/l/in/photostream/ www.canarie.ca
  • 24. Digital Accelerator for Innovation and Research (DAIR) An on-demand, advanced R&D environment that supports Canada’s tech innovators and entrepreneurs in designing, prototyping, validating and demonstrating their new technology apps, products and services. www.canarie.ca/en/dair INTERNET Cloud Computing and Storage + Optical Regional Advanced Networks (ORANs) Réseaux optiques régionaux évolués (ROREs) www.canarie.ca Infonuagique et stockage