CILogon and InCommon: Technical Update

J
CILogon and InCommon: Technical Update
Jim Basney <jbasney@ncsa.illinois.edu>
This material is based upon work supported by the National Science Foundation under grant numbers
0943633 and 1053575 and by the Department of Energy under award number DE-SC0008597. Any
opinions, findings, and conclusions or recommendations expressed in this material are those of the
authors and do not necessarily reflect the views of the United States Government or any agency thereof.
CILogon – https://cilogon.org/
•  Provides personal
digital certificates
for access to
cyberinfrastructure
•  Uses federated
authentication for
user identification
Federated Authentication
•  Log on to CILogon using your campus
(InCommon) or Google (OpenID) account
Integrated with Globus
Integrated with XSEDE
www.cilogon.org/xsede
Integrated with Campus
Bridging InCommon and IGTF
•  Translating mechanism and policy across
higher education and grid trust federations
!"#$%"&'()*+&
&
!"#$%%&'()*'(#$+*,-&).'/#0&-1#23#%-+4*&)'/#$4(#'%-4-1)%#&'5)-4/#
100+ InCommon Research and
Scholarship Identity Providers
Arizona State University
Boston University
Brookhaven National Laboratory
Brown University
California Institute of Technology
California State Polytechnic University, Pomona
California State University, Fresno
California State University, Fullerton
Carleton College
Carnegie Mellon University
Clemson University
Colorado School of Mines
Colorado State University
Columbia University
Cornell University
Florida International University
George Mason University
Georgia Institute of Technology
GPN (Great Plains Network)
Indiana University
Indiana University of Pennsylvania
Internet2
Iowa State University
Johns Hopkins
Kansas State University
Lawrence Berkeley National Laboratory
Lehigh University
LIGO Scientific Collaboration
Louisiana State University
LTERN (Long Term Ecological Research Network)
Massachusetts Institute of Technology
Montana State University - Bozeman
New York University
North Carolina State University
Northwestern University
Ohio State University
Ohio Technology Consortium (OH-TECH)
Oregon State University
Pomona College
Purdue University Main Campus
Reed College
Rice University
Rockefeller University
Rutgers, The State University of New Jersey
San Diego State University
Southern Illinois University
Southern Methodist University
Stevens Institute of Technology
Stony Brook University
Syracuse University
Texas A & M University
The University of Arizona
Towson University
Tufts University
University At Albany, State University of New York
University of Alabama at Birmingham
University of Alaska Statewide System
University of Arkansas
University of California, Davis
University of California, San Francisco
University of California, Santa Cruz
University of California-Irvine
University of California-Los Angeles
University of Central Florida
University of Chicago
University of Cincinnati Main Campus
University of Colorado at Boulder
University of Dayton
University of Florida
University of Hawaii
University of Houston Libraries
University of Illinois at Chicago
University of Illinois At Springfield
University of Illinois at Urbana-Champaign
University of Iowa
University of Kansas
University of Maryland Baltimore
University of Maryland Baltimore County
University of Maryland College Park
University of Massachusetts Amherst
University of Michigan
University of Minnesota
University of Missouri System
University of Nebraska-Lincoln
University of North Carolina at Chapel Hill
University of Oregon
University of Pennsylvania
University of Pittsburgh
University of South Florida
University of Southern California
University of Utah
University of Vermont
University of Virginia
University of Washington
University of Wisconsin-Madison
University of Wisconsin-Milwaukee
Utah State University
Utah Valley University
Vanderbilt University
Virginia Polytechnic Institute and State University
Weill Cornell Medical College
West Virginia University
Western Michigan University
Wheaton College (MA)
Yale University
id.incommon.org/category/research-and-scholarship
International Federation: eduGAIN
International R&S: REFEDS
Multiple Levels of Assurance
•  CILogon Silver CA
–  InCommon Silver IDs
–  IGTF accredited
February 2011
•  CILogon Basic CA
–  “Basic” InCommon IDs
–  IGTF accredited
June 2014
•  Google Authenticator
provides second
authentication factor
InCommon IGTF Server CA
Security Updates
SHA-1
SSL
OAuth 1.0
OpenID 2.0
SHA-2
TLS
OAuth 2.0
OpenID Connect
Fifteen years of securing cyberinfrastructure
2000 20102001 2002 2003 2004 2005 2006 2007 2008 2009
October 2001
Support for certificate-
based authentication
added by Daniel
Kouril and Miroslav
Ruda for the
European DataGrid
project.
December 2001
MyProxy version
0.4.1 was released,
adding support for
Globus Toolkit 2.0.
July 2002
NSF Middleware Initiative
MyProxy Project
collaborative project with
Marty Humphrey at the
University of Virginia began.
April 2003
The NSF Middleware Initiative
(NMI) issued its third software
release, the first NMI release
to include MyProxy.
April 2004
Condor-G 6.7.0
was released,
including
support for
managing
credentials with
MyProxy.
October 2005
MyProxy used in LTER
Grid demonstration.
TeraGrid '06
"Managing
Credentials on
the TeraGrid
with MyProxy"
February 2007
Inca 2.0 was
released with
support for
MyProxy.
February 2009
MyProxy passed
independent
vulnerability
assessment.
June 2009
CILogon project
started.
September 2009
New CILogon
Service provided
bridge between
InCommon and Grid
authentication.
MyProxy is part of the Globus Toolkit and is included in Fedora and Debian Linux operating system package repositories.
MyProxy is used by many grid projects including CILogon, OSG, and XSEDE.
February 2006
GridShib-CA was released,
demonstrating MyProxy use
with InCommon.
July 2003
MyProxy was used in
the NEESgrid MOST
experiment.
MyProxy was funded primarily by:
via
NLANR
NSF Middleware Initiative
NCSA Core Award
TeraGrid
STCI
Core MyProxy Team at NCSA
(current and past):
Jim Basney (lead)
Bill Baker
Randy Butler
Shiva Shankar Chetan
Patrick Duda
Mike Freemon
Terry Fleury
Zhenmin Li
Jason Novotny
Venkat Yekkirala
Von Welch
MyProxy Community Collaborators and
Contributors:
Jarek Gawor (ANL)
Monte Goode (LBNL)
Marty Humphrey (UVa)
Daniel Kouril (CESNET, CZ)
Alexandre Lossent (CERN)
Neill Miller (ANL)
Miroslav Ruda (CESNET/EGEE)
Steve Traylen (CERN/EGEE)
Benjamin Temko (IU)
Steven Tuecke (ANL)
Naotaka Yamamoto (AIST)
April 2000
MyProxy 0.1
was
released.
November 2000
A web-based grid
portal using MyProxy
for authentication
debuted at SC2000.
June 2008
NERSC deployed
authentication for
their Grid
resources using
MyProxy CA.
September 2006
NVO used MyProxy
with PubCookie for
web single sign-on.
September 2005
ESG used PURSE,
built on MyProxy, for
user authentication.
May 2005
FusionGrid
deployed
replicated
MyProxy for grid
portals and
credential
renewal.
August 2006
MyProxy 3.6 was
released, including
support for VOMS
authorization.
September 2005
MyProxy 3.0 was
released, with
contribution from
LBNL adding
certificate
authority
capability.
October 2014
MyProxy 6.1 was
released.
This was the 61st
release of MyProxy.
20152011 2012 2013 2014
February 2012
OAuth for MyProxy
v1.0 was released,
providing an OAuth-
compliant web
interface to MyProxy.
November 2011
Globus Online
supported OAuth
interface to XSEDE
MyProxy server.
June 2012
"An Online Credential Repository for
the Grid: MyProxy" was selected as
one of the best papers of the IEEE
HPDC conference's 20 years.
June 2013
OAuth for MyProxy
passed
independent
vulnerability
assessment.
September 2014
Globus Toolkit 6.0
included MyProxy 6.0.
January 2015
CILogon Service
passed XSEDE
acceptance tests.
Thanks!
jbasney@ncsa.illinois.edu
@JimBasney
1 of 15

Recommended

презентациякитай by
презентациякитайпрезентациякитай
презентациякитайnasten4ik_29
405 views16 slides
Module 2 by
Module 2Module 2
Module 2shakyra90
162 views4 slides
Getting Social With Social: Using social media education to build relationshi... by
Getting Social With Social: Using social media education to build relationshi...Getting Social With Social: Using social media education to build relationshi...
Getting Social With Social: Using social media education to build relationshi...Lindsay Nyquist
402 views40 slides
Prabhav services inc by
Prabhav services incPrabhav services inc
Prabhav services inchiren2012
326 views12 slides
Commissione pariopportunitalmaschile by
Commissione pariopportunitalmaschileCommissione pariopportunitalmaschile
Commissione pariopportunitalmaschileFrancesco Eterno
277 views26 slides
CILogon 2.0 at 2016 Internet2 Global Summit by
CILogon 2.0 at 2016 Internet2 Global SummitCILogon 2.0 at 2016 Internet2 Global Summit
CILogon 2.0 at 2016 Internet2 Global Summitjbasney
678 views28 slides

More Related Content

Viewers also liked

Se 29 by
Se 29Se 29
Se 29Kppkp Bangil
304 views4 slides
A sore throat or strep throat by
A sore throat or strep throatA sore throat or strep throat
A sore throat or strep throatMegan Perkins
386 views10 slides
Qui som by
Qui somQui som
Qui somIpomea Associació
904 views10 slides
Tt 200 2014 tt_btc full by
Tt 200 2014 tt_btc fullTt 200 2014 tt_btc full
Tt 200 2014 tt_btc fulllý Lác
342 views549 slides
SAML Security Contacts by
SAML Security ContactsSAML Security Contacts
SAML Security Contactsjbasney
791 views12 slides
Washtech presentation by
Washtech presentationWashtech presentation
Washtech presentationsorgho
362 views15 slides

Viewers also liked(16)

A sore throat or strep throat by Megan Perkins
A sore throat or strep throatA sore throat or strep throat
A sore throat or strep throat
Megan Perkins386 views
Tt 200 2014 tt_btc full by lý Lác
Tt 200 2014 tt_btc fullTt 200 2014 tt_btc full
Tt 200 2014 tt_btc full
lý Lác342 views
SAML Security Contacts by jbasney
SAML Security ContactsSAML Security Contacts
SAML Security Contacts
jbasney791 views
Washtech presentation by sorgho
Washtech presentationWashtech presentation
Washtech presentation
sorgho362 views
走出技术壁垒 by heavenhuang
走出技术壁垒走出技术壁垒
走出技术壁垒
heavenhuang321 views
A sore throat or strep throat by Megan Perkins
A sore throat or strep throatA sore throat or strep throat
A sore throat or strep throat
Megan Perkins283 views
Trusting External Identity Providers for Global Research Collaborations by jbasney
Trusting External Identity Providers for Global Research CollaborationsTrusting External Identity Providers for Global Research Collaborations
Trusting External Identity Providers for Global Research Collaborations
jbasney717 views
Ten ways to take your hashtags to the next level by Lindsay Nyquist
Ten ways to take your hashtags to the next levelTen ways to take your hashtags to the next level
Ten ways to take your hashtags to the next level
Lindsay Nyquist444 views
Cybersecurity for Conservation by jbasney
Cybersecurity for ConservationCybersecurity for Conservation
Cybersecurity for Conservation
jbasney653 views

Similar to CILogon and InCommon: Technical Update

CILogon 2.0 MAGIC SC16 by
CILogon 2.0 MAGIC SC16CILogon 2.0 MAGIC SC16
CILogon 2.0 MAGIC SC16jbasney
836 views18 slides
CILogon 2.0 Update at TechEx 2016 by
CILogon 2.0 Update at TechEx 2016CILogon 2.0 Update at TechEx 2016
CILogon 2.0 Update at TechEx 2016jbasney
513 views12 slides
CILogon 2.0 at Oct 2017 CICI PI meeting by
CILogon 2.0 at Oct 2017 CICI PI meetingCILogon 2.0 at Oct 2017 CICI PI meeting
CILogon 2.0 at Oct 2017 CICI PI meetingjbasney
621 views17 slides
CILogon PEARC17 by
CILogon PEARC17CILogon PEARC17
CILogon PEARC17jbasney
370 views13 slides
GENI Engineering Conference -- Ian Foster by
GENI Engineering Conference -- Ian FosterGENI Engineering Conference -- Ian Foster
GENI Engineering Conference -- Ian FosterIan Foster
1.4K views34 slides
CILogon: An Integrated Identity and Access Management Platform for Science by
CILogon: An Integrated Identity and Access Management Platform for ScienceCILogon: An Integrated Identity and Access Management Platform for Science
CILogon: An Integrated Identity and Access Management Platform for Sciencejbasney
547 views10 slides

Similar to CILogon and InCommon: Technical Update(20)

CILogon 2.0 MAGIC SC16 by jbasney
CILogon 2.0 MAGIC SC16CILogon 2.0 MAGIC SC16
CILogon 2.0 MAGIC SC16
jbasney836 views
CILogon 2.0 Update at TechEx 2016 by jbasney
CILogon 2.0 Update at TechEx 2016CILogon 2.0 Update at TechEx 2016
CILogon 2.0 Update at TechEx 2016
jbasney513 views
CILogon 2.0 at Oct 2017 CICI PI meeting by jbasney
CILogon 2.0 at Oct 2017 CICI PI meetingCILogon 2.0 at Oct 2017 CICI PI meeting
CILogon 2.0 at Oct 2017 CICI PI meeting
jbasney621 views
CILogon PEARC17 by jbasney
CILogon PEARC17CILogon PEARC17
CILogon PEARC17
jbasney370 views
GENI Engineering Conference -- Ian Foster by Ian Foster
GENI Engineering Conference -- Ian FosterGENI Engineering Conference -- Ian Foster
GENI Engineering Conference -- Ian Foster
Ian Foster1.4K views
CILogon: An Integrated Identity and Access Management Platform for Science by jbasney
CILogon: An Integrated Identity and Access Management Platform for ScienceCILogon: An Integrated Identity and Access Management Platform for Science
CILogon: An Integrated Identity and Access Management Platform for Science
jbasney547 views
UCCSC Sauter Award for Profiles by ericmeeks
UCCSC Sauter Award for ProfilesUCCSC Sauter Award for Profiles
UCCSC Sauter Award for Profiles
ericmeeks471 views
UCCSC 2013 Presentation on UCSF Profiles by lesliey
UCCSC 2013 Presentation on UCSF Profiles UCCSC 2013 Presentation on UCSF Profiles
UCCSC 2013 Presentation on UCSF Profiles
lesliey509 views
CILogon 2.0 at 2017 Internet2 Global Summit by jbasney
CILogon 2.0 at 2017 Internet2 Global SummitCILogon 2.0 at 2017 Internet2 Global Summit
CILogon 2.0 at 2017 Internet2 Global Summit
jbasney419 views
Pmd prospective students 2.22.2222 by KevinAlt1
Pmd prospective students 2.22.2222Pmd prospective students 2.22.2222
Pmd prospective students 2.22.2222
KevinAlt192 views
OntoSoft: A Distributed Semantic Registry for Scientific Software by dgarijo
OntoSoft: A Distributed Semantic Registry for Scientific SoftwareOntoSoft: A Distributed Semantic Registry for Scientific Software
OntoSoft: A Distributed Semantic Registry for Scientific Software
dgarijo919 views
Research Networking SEO state of the union 2015 by lesliey
Research Networking SEO state of the union 2015Research Networking SEO state of the union 2015
Research Networking SEO state of the union 2015
lesliey926 views
Federated id alignment 2011 by BCcampus
Federated id alignment 2011Federated id alignment 2011
Federated id alignment 2011
BCcampus338 views
20130821 Mozilla Badges OpenCall with Accreditrust by Eric Korb
20130821 Mozilla Badges OpenCall with Accreditrust20130821 Mozilla Badges OpenCall with Accreditrust
20130821 Mozilla Badges OpenCall with Accreditrust
Eric Korb1.3K views
Towards Knowledge Graphs of Reusable Research Software Metadata by dgarijo
Towards Knowledge Graphs of Reusable Research Software MetadataTowards Knowledge Graphs of Reusable Research Software Metadata
Towards Knowledge Graphs of Reusable Research Software Metadata
dgarijo624 views

More from jbasney

Guidance and Survey Results from the Trustworthy Data Working Group by
Guidance and Survey Results from the Trustworthy Data Working GroupGuidance and Survey Results from the Trustworthy Data Working Group
Guidance and Survey Results from the Trustworthy Data Working Groupjbasney
161 views52 slides
Federated Identity Needs for the Large Synoptic Survey Telescope (LSST) by
Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)
Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)jbasney
181 views21 slides
CILogon & SciTokens: OIDC/OAuth Federation by
CILogon & SciTokens: OIDC/OAuth FederationCILogon & SciTokens: OIDC/OAuth Federation
CILogon & SciTokens: OIDC/OAuth Federationjbasney
156 views12 slides
CILogon 2.0 - IAM Online Webinar Series by
CILogon 2.0 - IAM Online Webinar SeriesCILogon 2.0 - IAM Online Webinar Series
CILogon 2.0 - IAM Online Webinar Seriesjbasney
190 views22 slides
Lightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure by
Lightweight Cybersecurity Risk Assessment Tools for CyberinfrastructureLightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure
Lightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructurejbasney
474 views20 slides
11th FIM4R Workshop: US Projects Update by
11th FIM4R Workshop: US Projects Update11th FIM4R Workshop: US Projects Update
11th FIM4R Workshop: US Projects Updatejbasney
574 views11 slides

More from jbasney(9)

Guidance and Survey Results from the Trustworthy Data Working Group by jbasney
Guidance and Survey Results from the Trustworthy Data Working GroupGuidance and Survey Results from the Trustworthy Data Working Group
Guidance and Survey Results from the Trustworthy Data Working Group
jbasney161 views
Federated Identity Needs for the Large Synoptic Survey Telescope (LSST) by jbasney
Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)
Federated Identity Needs for the Large Synoptic Survey Telescope (LSST)
jbasney181 views
CILogon & SciTokens: OIDC/OAuth Federation by jbasney
CILogon & SciTokens: OIDC/OAuth FederationCILogon & SciTokens: OIDC/OAuth Federation
CILogon & SciTokens: OIDC/OAuth Federation
jbasney156 views
CILogon 2.0 - IAM Online Webinar Series by jbasney
CILogon 2.0 - IAM Online Webinar SeriesCILogon 2.0 - IAM Online Webinar Series
CILogon 2.0 - IAM Online Webinar Series
jbasney190 views
Lightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure by jbasney
Lightweight Cybersecurity Risk Assessment Tools for CyberinfrastructureLightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure
Lightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure
jbasney474 views
11th FIM4R Workshop: US Projects Update by jbasney
11th FIM4R Workshop: US Projects Update11th FIM4R Workshop: US Projects Update
11th FIM4R Workshop: US Projects Update
jbasney574 views
CTSC+SWAMP: cybersecurity resources for your campus by jbasney
CTSC+SWAMP: cybersecurity resources for your campusCTSC+SWAMP: cybersecurity resources for your campus
CTSC+SWAMP: cybersecurity resources for your campus
jbasney748 views
CTSC at TNC16 by jbasney
CTSC at TNC16CTSC at TNC16
CTSC at TNC16
jbasney463 views
CILogon 2.0 at REFEDS 30 by jbasney
CILogon 2.0 at REFEDS 30CILogon 2.0 at REFEDS 30
CILogon 2.0 at REFEDS 30
jbasney1.1K views

Recently uploaded

"Surviving highload with Node.js", Andrii Shumada by
"Surviving highload with Node.js", Andrii Shumada "Surviving highload with Node.js", Andrii Shumada
"Surviving highload with Node.js", Andrii Shumada Fwdays
56 views29 slides
"Node.js Development in 2024: trends and tools", Nikita Galkin by
"Node.js Development in 2024: trends and tools", Nikita Galkin "Node.js Development in 2024: trends and tools", Nikita Galkin
"Node.js Development in 2024: trends and tools", Nikita Galkin Fwdays
32 views38 slides
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit... by
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...ShapeBlue
159 views25 slides
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT by
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITUpdates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITShapeBlue
206 views8 slides
Future of Indian ConsumerTech by
Future of Indian ConsumerTechFuture of Indian ConsumerTech
Future of Indian ConsumerTechKapil Khandelwal (KK)
36 views68 slides
Transcript: Redefining the book supply chain: A glimpse into the future - Tec... by
Transcript: Redefining the book supply chain: A glimpse into the future - Tec...Transcript: Redefining the book supply chain: A glimpse into the future - Tec...
Transcript: Redefining the book supply chain: A glimpse into the future - Tec...BookNet Canada
41 views16 slides

Recently uploaded(20)

"Surviving highload with Node.js", Andrii Shumada by Fwdays
"Surviving highload with Node.js", Andrii Shumada "Surviving highload with Node.js", Andrii Shumada
"Surviving highload with Node.js", Andrii Shumada
Fwdays56 views
"Node.js Development in 2024: trends and tools", Nikita Galkin by Fwdays
"Node.js Development in 2024: trends and tools", Nikita Galkin "Node.js Development in 2024: trends and tools", Nikita Galkin
"Node.js Development in 2024: trends and tools", Nikita Galkin
Fwdays32 views
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit... by ShapeBlue
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...
ShapeBlue159 views
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT by ShapeBlue
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITUpdates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
ShapeBlue206 views
Transcript: Redefining the book supply chain: A glimpse into the future - Tec... by BookNet Canada
Transcript: Redefining the book supply chain: A glimpse into the future - Tec...Transcript: Redefining the book supply chain: A glimpse into the future - Tec...
Transcript: Redefining the book supply chain: A glimpse into the future - Tec...
BookNet Canada41 views
Redefining the book supply chain: A glimpse into the future - Tech Forum 2023 by BookNet Canada
Redefining the book supply chain: A glimpse into the future - Tech Forum 2023Redefining the book supply chain: A glimpse into the future - Tech Forum 2023
Redefining the book supply chain: A glimpse into the future - Tech Forum 2023
BookNet Canada44 views
KVM Security Groups Under the Hood - Wido den Hollander - Your.Online by ShapeBlue
KVM Security Groups Under the Hood - Wido den Hollander - Your.OnlineKVM Security Groups Under the Hood - Wido den Hollander - Your.Online
KVM Security Groups Under the Hood - Wido den Hollander - Your.Online
ShapeBlue221 views
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ... by ShapeBlue
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...
ShapeBlue126 views
The Power of Generative AI in Accelerating No Code Adoption.pdf by Saeed Al Dhaheri
The Power of Generative AI in Accelerating No Code Adoption.pdfThe Power of Generative AI in Accelerating No Code Adoption.pdf
The Power of Generative AI in Accelerating No Code Adoption.pdf
Saeed Al Dhaheri32 views
The Power of Heat Decarbonisation Plans in the Built Environment by IES VE
The Power of Heat Decarbonisation Plans in the Built EnvironmentThe Power of Heat Decarbonisation Plans in the Built Environment
The Power of Heat Decarbonisation Plans in the Built Environment
IES VE79 views
Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha... by ShapeBlue
Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha...Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha...
Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha...
ShapeBlue180 views
Business Analyst Series 2023 - Week 4 Session 7 by DianaGray10
Business Analyst Series 2023 -  Week 4 Session 7Business Analyst Series 2023 -  Week 4 Session 7
Business Analyst Series 2023 - Week 4 Session 7
DianaGray10139 views
VNF Integration and Support in CloudStack - Wei Zhou - ShapeBlue by ShapeBlue
VNF Integration and Support in CloudStack - Wei Zhou - ShapeBlueVNF Integration and Support in CloudStack - Wei Zhou - ShapeBlue
VNF Integration and Support in CloudStack - Wei Zhou - ShapeBlue
ShapeBlue203 views
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ... by Jasper Oosterveld
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
State of the Union - Rohit Yadav - Apache CloudStack by ShapeBlue
State of the Union - Rohit Yadav - Apache CloudStackState of the Union - Rohit Yadav - Apache CloudStack
State of the Union - Rohit Yadav - Apache CloudStack
ShapeBlue297 views
"Running students' code in isolation. The hard way", Yurii Holiuk by Fwdays
"Running students' code in isolation. The hard way", Yurii Holiuk "Running students' code in isolation. The hard way", Yurii Holiuk
"Running students' code in isolation. The hard way", Yurii Holiuk
Fwdays36 views
Digital Personal Data Protection (DPDP) Practical Approach For CISOs by Priyanka Aash
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Priyanka Aash158 views

CILogon and InCommon: Technical Update

  • 1. CILogon and InCommon: Technical Update Jim Basney <jbasney@ncsa.illinois.edu> This material is based upon work supported by the National Science Foundation under grant numbers 0943633 and 1053575 and by the Department of Energy under award number DE-SC0008597. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the authors and do not necessarily reflect the views of the United States Government or any agency thereof.
  • 2. CILogon – https://cilogon.org/ •  Provides personal digital certificates for access to cyberinfrastructure •  Uses federated authentication for user identification
  • 3. Federated Authentication •  Log on to CILogon using your campus (InCommon) or Google (OpenID) account
  • 7. Bridging InCommon and IGTF •  Translating mechanism and policy across higher education and grid trust federations !"#$%"&'()*+& & !"#$%%&'()*'(#$+*,-&).'/#0&-1#23#%-+4*&)'/#$4(#'%-4-1)%#&'5)-4/#
  • 8. 100+ InCommon Research and Scholarship Identity Providers Arizona State University Boston University Brookhaven National Laboratory Brown University California Institute of Technology California State Polytechnic University, Pomona California State University, Fresno California State University, Fullerton Carleton College Carnegie Mellon University Clemson University Colorado School of Mines Colorado State University Columbia University Cornell University Florida International University George Mason University Georgia Institute of Technology GPN (Great Plains Network) Indiana University Indiana University of Pennsylvania Internet2 Iowa State University Johns Hopkins Kansas State University Lawrence Berkeley National Laboratory Lehigh University LIGO Scientific Collaboration Louisiana State University LTERN (Long Term Ecological Research Network) Massachusetts Institute of Technology Montana State University - Bozeman New York University North Carolina State University Northwestern University Ohio State University Ohio Technology Consortium (OH-TECH) Oregon State University Pomona College Purdue University Main Campus Reed College Rice University Rockefeller University Rutgers, The State University of New Jersey San Diego State University Southern Illinois University Southern Methodist University Stevens Institute of Technology Stony Brook University Syracuse University Texas A & M University The University of Arizona Towson University Tufts University University At Albany, State University of New York University of Alabama at Birmingham University of Alaska Statewide System University of Arkansas University of California, Davis University of California, San Francisco University of California, Santa Cruz University of California-Irvine University of California-Los Angeles University of Central Florida University of Chicago University of Cincinnati Main Campus University of Colorado at Boulder University of Dayton University of Florida University of Hawaii University of Houston Libraries University of Illinois at Chicago University of Illinois At Springfield University of Illinois at Urbana-Champaign University of Iowa University of Kansas University of Maryland Baltimore University of Maryland Baltimore County University of Maryland College Park University of Massachusetts Amherst University of Michigan University of Minnesota University of Missouri System University of Nebraska-Lincoln University of North Carolina at Chapel Hill University of Oregon University of Pennsylvania University of Pittsburgh University of South Florida University of Southern California University of Utah University of Vermont University of Virginia University of Washington University of Wisconsin-Madison University of Wisconsin-Milwaukee Utah State University Utah Valley University Vanderbilt University Virginia Polytechnic Institute and State University Weill Cornell Medical College West Virginia University Western Michigan University Wheaton College (MA) Yale University id.incommon.org/category/research-and-scholarship
  • 11. Multiple Levels of Assurance •  CILogon Silver CA –  InCommon Silver IDs –  IGTF accredited February 2011 •  CILogon Basic CA –  “Basic” InCommon IDs –  IGTF accredited June 2014 •  Google Authenticator provides second authentication factor
  • 13. Security Updates SHA-1 SSL OAuth 1.0 OpenID 2.0 SHA-2 TLS OAuth 2.0 OpenID Connect
  • 14. Fifteen years of securing cyberinfrastructure 2000 20102001 2002 2003 2004 2005 2006 2007 2008 2009 October 2001 Support for certificate- based authentication added by Daniel Kouril and Miroslav Ruda for the European DataGrid project. December 2001 MyProxy version 0.4.1 was released, adding support for Globus Toolkit 2.0. July 2002 NSF Middleware Initiative MyProxy Project collaborative project with Marty Humphrey at the University of Virginia began. April 2003 The NSF Middleware Initiative (NMI) issued its third software release, the first NMI release to include MyProxy. April 2004 Condor-G 6.7.0 was released, including support for managing credentials with MyProxy. October 2005 MyProxy used in LTER Grid demonstration. TeraGrid '06 "Managing Credentials on the TeraGrid with MyProxy" February 2007 Inca 2.0 was released with support for MyProxy. February 2009 MyProxy passed independent vulnerability assessment. June 2009 CILogon project started. September 2009 New CILogon Service provided bridge between InCommon and Grid authentication. MyProxy is part of the Globus Toolkit and is included in Fedora and Debian Linux operating system package repositories. MyProxy is used by many grid projects including CILogon, OSG, and XSEDE. February 2006 GridShib-CA was released, demonstrating MyProxy use with InCommon. July 2003 MyProxy was used in the NEESgrid MOST experiment. MyProxy was funded primarily by: via NLANR NSF Middleware Initiative NCSA Core Award TeraGrid STCI Core MyProxy Team at NCSA (current and past): Jim Basney (lead) Bill Baker Randy Butler Shiva Shankar Chetan Patrick Duda Mike Freemon Terry Fleury Zhenmin Li Jason Novotny Venkat Yekkirala Von Welch MyProxy Community Collaborators and Contributors: Jarek Gawor (ANL) Monte Goode (LBNL) Marty Humphrey (UVa) Daniel Kouril (CESNET, CZ) Alexandre Lossent (CERN) Neill Miller (ANL) Miroslav Ruda (CESNET/EGEE) Steve Traylen (CERN/EGEE) Benjamin Temko (IU) Steven Tuecke (ANL) Naotaka Yamamoto (AIST) April 2000 MyProxy 0.1 was released. November 2000 A web-based grid portal using MyProxy for authentication debuted at SC2000. June 2008 NERSC deployed authentication for their Grid resources using MyProxy CA. September 2006 NVO used MyProxy with PubCookie for web single sign-on. September 2005 ESG used PURSE, built on MyProxy, for user authentication. May 2005 FusionGrid deployed replicated MyProxy for grid portals and credential renewal. August 2006 MyProxy 3.6 was released, including support for VOMS authorization. September 2005 MyProxy 3.0 was released, with contribution from LBNL adding certificate authority capability. October 2014 MyProxy 6.1 was released. This was the 61st release of MyProxy. 20152011 2012 2013 2014 February 2012 OAuth for MyProxy v1.0 was released, providing an OAuth- compliant web interface to MyProxy. November 2011 Globus Online supported OAuth interface to XSEDE MyProxy server. June 2012 "An Online Credential Repository for the Grid: MyProxy" was selected as one of the best papers of the IEEE HPDC conference's 20 years. June 2013 OAuth for MyProxy passed independent vulnerability assessment. September 2014 Globus Toolkit 6.0 included MyProxy 6.0. January 2015 CILogon Service passed XSEDE acceptance tests.