SlideShare a Scribd company logo
OpenConext: Open for Collaboration
Niels van Dijk
Technical Product Manager
SURFnet: the Dutch NREN
• SURFnet is the Dutch National Research & Education
Network (NREN)
– Services, innovation, knowledge
– Not for profit
– Task organisation of Stichting SURF = ICT collaboration of higher
education & research
• A small operation serving a large community:
– 85 employees
– 160 connected institutions
– 1 million end-users
– Turnover 35 million Euro; 1/3 innovation subsidies
SURFnet - We make innovation work 1
OpenConext
SURFnet - We make innovation work 2
OpenConext Vision (2009)
SURFnet - We make innovation work 3
 Create a coherent infrastructure of loosely coupled
collaborative services, based on (emerging) Open
Standards and enabled by access federations
OpenConext Building blocks
SURFnet - We make innovation work 4
 Identity Federations, SAML and attributes
 Create and manage Groups
 OpenSocial (VOOT) API and oAuth
 A piece of middleware (a hub or proxy) that allows centrally managing
interconnects and facilitates application integration
OpenConext Use cases
SURFnet - We make innovation work 5
• Collaboration Platform
• Service Delivery Platform
• Identity Federation hub
United Kingdom – JISCconext (JISC)
A Collabortion platform around email groups, will support about 1
million endusers
Australia (AARnet)
A service delivery for AARnet services in Australia and New Zealand
The Netherlands – SURFconext (SURFnet)
The middleware platform for the national hub-n-spoke Identity
Federation
JISCconext
SURFnet - We make innovation work 6
https://tnc2014.terena.org/core/presentation/15
AARNet
SURFnet - We make innovation work 7
https://tnc2014.terena.org/core/presentation/15
SURFconext
SURFnet - We make innovation work 8
A next generation collaboration
infrastructure that creates new
opportunities to collaborate online
based on a combination of applications
from different providers.
Researchers, educators and students wish to select the tools that best
fit their online collaboration needs. Institutions and Collaborative
Organizations struggle with the integration of self-hosted services
with commercial cloud services. Service providers seek for ways to
make their services easily accessible for users in higher research
and education.
SURFconext is the platform to facilitate these needs.
Collaboration Platform
SURFnet - We make innovation work 9
• Federated Authentication
• Centralized Groups
• Portals
Federated Authentication
Leverages secure, trusted authentication and Single Sign on for
Campus and Cloud applications
Centralized groups
Used for Adhoc collaborations and institutional groups
Portals
Bring together distributed services to provide end-users with a
coherent set of services
Service Delivery Platform
SURFnet - We make innovation work 10
• Federated Authentication
• Attribute based Authorization
• National Procurement & Licencing
Create Trusted Services
By combining Identity Federation, privacy and data protection
regulations and license deal in one contract between Service
Provider and (all) Dutch institutions
Services Dashboard
SURFnet - We make innovation work 11
Commercial Services
SURFnet - We make innovation work 12
eScience Services
SURFnet - We make innovation work 13
Collaborative Organisations
SURFnet - We make innovation work 14
• Groups
• Distributes Services
• Attributes, roles and rights
Groups are core to collaboration
Any collaboration is based on groups. In R&E these groups are
dynamic and international;
Distributed Services
COs collaborate around distributes services. Managing and
maintaining many SP IdP interconnections is tough;
Attributes, roles and rights
Roles and rights are based on Attributes. COs need very different
attributes as compared to the attributes provided by the IdPs.
Example Cases
SURFnet - We make innovation work 15
• WeNMR
• Virtual Campus Hub
WeNMR
Bringing together research teams in the structural biology and life
science area. The project offers a platform integrating services and
streamlining the computational approaches necessary for data
analysis and structural modelling.
Virtual Campus Hub
Create a virtual education portal for a joint programme, consisting
of applications made available by the partners involved in that
programme, and to which all relevant users have seamless access.
WeNMR
SURFnet - We make innovation work 16
• Connect HPC to federation
• Federated Portal
WeNMR and eduGAIN
SURFnet - We make innovation work 17
Partners in Virtual Campus Hub
Concept: virtual education portal for joint
programs
Components of Virtual Campus Hub
1. Inventory of the most important ICT barriers for international
collaboration in education.
2. Demo platform to prove that some of these barriers can be removed:
 Easy access to partners’ applications (FIM)
 More efficient and more flexible setup of online activities or online
participation in regular activities (UC hub)
 Easier collaboration with industry (non-HE IdPs)
3. Vision on how to apply these insights and experiences in concrete
collaboration initiatives (e.g. international joint programs)
Demo portal (proof of concept)
Functionality:
• Access with your own account
to partners’ applications
• Create international groups
(virtual organizations)
• Single sign-on access through
simple website
(https://vch.tue.nl)
12-06-2013
IdPs connected to VCH
2204-10-2012
Enabling international collaboration:
National (NRENs) and European (Géant)
12-06-2013
Results
• Connections realized for several identity providers (IdPs)
and applications (SPs).
• Cloud service (DTU itslearning) connected to VCH
• Scalability of concept shown (by adding extra IdPs)
• Knowledge and experience with respect to using Géant-
eduGAIN
2412-06-2013
OpenConext Building blocks
SURFnet - We make innovation work 25
 Identity Federations, SAML and attributes
 Create and manage Groups
 OpenSocial (VOOT) API and Oauth
 A piece of middleware (a hub or proxy) that allows centrally managing
interconnects and facilitates application integration
Identity Federation
SURFnet - We make innovation work 26
Groups
SURFnet - We make innovation work 27
 Any collaboration involves groups, either ‘AdHoc’, or ‘Institutional’
 OpenConext facilitates the creation of groups of federated users
 Adhoc Groups are managed centrally (Teams)
 Any acceptable user can become a group 'admin‘
 Invite any other users
 Build groups from other groups
 Institutional Groups (Campus or VO) can be provided by external
sources
 Groups provide context for applications (but applications decide on
AuthZ!)
 Groups feature (only) 3 roles (admin, collabmin, member)
 Group + VO Registry -> VO IdP
Attributes
SURFnet - We make innovation work 28
 Attribute & Group information can be provided at logon
 Many scenarios require out of band exchange
 VOOT (http://openvoot.org/voot-2.0.html) REST API, based on OpenSocial
 oAuth2 & oAuth 1 (deprecated)
 Draft SCIM implementation expected in 2014
 SAML attribute query support on the way (both AA and client)
OpenConext – The platform (2009)
SURFnet - We make innovation work 29
 Do not start from Scratch
 Add (a lot of) Glue
SAML Groups Management
Shibboleth SP
(Shibboleth Consortium)
Grouper
(Internet2)
Janus
(WAYF)
SimpleSAMLphp SP
(Feide.no)
Shindig
(Apache)
Corto
(WAYF)
Teams
OpenConext – The platform (Q1 2014)
SURFnet - We make innovation work 30
 Do not start from Scratch
 Add (a lot of) Glue and even more Glue
SAML Groups Management
Shibboleth SP
(Shibboleth Consortium)
Grouper
(Internet2)
Janus
(SURFnet)
SimpleSAMLphp SP
(Feide.no)
Shindig
(Apache)
Group Proxy, API & APIS
Manage
Corto
(WAYF/SURFnet)
SSP libraries
Teams (v2) Log handling & Statistics
OpenConext VM
OpenConext – Overview
SURFnet - We make innovation work 31
OpenConext – Meshing a Hub
SURFnet - We make innovation work 32
Source: Neil Witheridge, AARNet
How OpenConext helps
SURFnet - We make innovation work 33
• Groups
• Distributed Services
• Attributes, roles and rights
Manage and share Groups
OpenConext provides a centralized group provider and allows
linking external group providers;
Centrally manage services and identity stores
SP and IdP connections can be manage centrally, including Access
and Attribute Release Policies;
Use Attributes, roles and rights for Authorization
Manage, transform and filter attributes and group (membership)
both at logon as well as when queried out-of-band.
OpenConext VM
SURFnet - We make innovation work 34
• Run your own OpenConext platform
• CentOS/Redhat, 10 min setup
• For demo, development and playing around
https://github.com/OpenConext/OpenConext-vm
More information
SURFnet - We make innovation work 35
• SURFconext
• OpenConext
SURFconext
 http://www.surf.nl/en/services-and-products/surfconext/index.html
OpenConext
 All of OpenConext is hosted at https://github.com/openconext
 OpenConext support tools and compatible services are available at
https://github.com/openconextapps
Community Website, including documentation
 https://www.openconext.org
Support
 Mailinglists: openconext-users@list.surfnet.nl and openconext-dev@list.surfnet.nl
niels.vandijk[at]surfnet.nl
@cdr80
cdr80
www.surfnet.nl
+31 30 2 305 305
Creative Commons “Attribution” license:
http://creativecommons.org/licenses/by/3.0/
W

More Related Content

What's hot

OASIS Open Stds and FOSS Nov 2019
OASIS Open Stds and FOSS Nov 2019OASIS Open Stds and FOSS Nov 2019
OASIS Open Stds and FOSS Nov 2019
James Bryce Clark
 
TheDisruptory. INNOROBO
TheDisruptory. INNOROBOTheDisruptory. INNOROBO
TheDisruptory. INNOROBO
Skolkovo Robotics Center
 
How Open Data Can Enhance Interactive Television
How Open Data Can Enhance Interactive TelevisionHow Open Data Can Enhance Interactive Television
How Open Data Can Enhance Interactive Television
LinkedTV
 
FITT Toolbox: Cluster Collaboration Platform
FITT Toolbox: Cluster Collaboration PlatformFITT Toolbox: Cluster Collaboration Platform
FITT Toolbox: Cluster Collaboration Platform
FITT
 
Survey of Semantic Media Annotation Tools - towards New Media Applications wi...
Survey of Semantic Media Annotation Tools - towards New Media Applications wi...Survey of Semantic Media Annotation Tools - towards New Media Applications wi...
Survey of Semantic Media Annotation Tools - towards New Media Applications wi...
LinkedTV
 
VideoHypE: An Editor Tool for Supervised Automatic Video Hyperlinking
VideoHypE: An Editor Tool for Supervised Automatic Video HyperlinkingVideoHypE: An Editor Tool for Supervised Automatic Video Hyperlinking
VideoHypE: An Editor Tool for Supervised Automatic Video Hyperlinking
LinkedTV
 

What's hot (6)

OASIS Open Stds and FOSS Nov 2019
OASIS Open Stds and FOSS Nov 2019OASIS Open Stds and FOSS Nov 2019
OASIS Open Stds and FOSS Nov 2019
 
TheDisruptory. INNOROBO
TheDisruptory. INNOROBOTheDisruptory. INNOROBO
TheDisruptory. INNOROBO
 
How Open Data Can Enhance Interactive Television
How Open Data Can Enhance Interactive TelevisionHow Open Data Can Enhance Interactive Television
How Open Data Can Enhance Interactive Television
 
FITT Toolbox: Cluster Collaboration Platform
FITT Toolbox: Cluster Collaboration PlatformFITT Toolbox: Cluster Collaboration Platform
FITT Toolbox: Cluster Collaboration Platform
 
Survey of Semantic Media Annotation Tools - towards New Media Applications wi...
Survey of Semantic Media Annotation Tools - towards New Media Applications wi...Survey of Semantic Media Annotation Tools - towards New Media Applications wi...
Survey of Semantic Media Annotation Tools - towards New Media Applications wi...
 
VideoHypE: An Editor Tool for Supervised Automatic Video Hyperlinking
VideoHypE: An Editor Tool for Supervised Automatic Video HyperlinkingVideoHypE: An Editor Tool for Supervised Automatic Video Hyperlinking
VideoHypE: An Editor Tool for Supervised Automatic Video Hyperlinking
 

Viewers also liked

12 Startup Lessons from Steve Jobs Taught Guy Kawasaki
12 Startup Lessons from Steve Jobs Taught Guy Kawasaki12 Startup Lessons from Steve Jobs Taught Guy Kawasaki
12 Startup Lessons from Steve Jobs Taught Guy Kawasaki
Ricky Haryadi
 
Reading eggs @ jma
Reading eggs @ jmaReading eggs @ jma
Reading eggs @ jmaCoachPineda
 
MSNF presentation
MSNF presentationMSNF presentation
MSNF presentation
bleach10
 
How To Win Friends and Influence People in The Digital Age (Indonesian Lan…
How To Win Friends and Influence People in The Digital Age (Indonesian Lan…How To Win Friends and Influence People in The Digital Age (Indonesian Lan…
How To Win Friends and Influence People in The Digital Age (Indonesian Lan…
Ricky Haryadi
 
Rebranding. How to increase sales woth new design
Rebranding. How to increase sales woth new designRebranding. How to increase sales woth new design
Rebranding. How to increase sales woth new design
Anfiia Reznikova
 
Building a 21st century education
Building a 21st century educationBuilding a 21st century education
Building a 21st century educationCoachPineda
 
PDC - Arquitetura - 001 - A vida, o universo e tudo mais ...
PDC - Arquitetura - 001 - A vida, o universo e tudo mais ...PDC - Arquitetura - 001 - A vida, o universo e tudo mais ...
PDC - Arquitetura - 001 - A vida, o universo e tudo mais ...slides_teltools
 
Software Factory - Overview
Software Factory - OverviewSoftware Factory - Overview
Software Factory - Overviewslides_teltools
 
How To Stay Motivated At Work
How To Stay Motivated At WorkHow To Stay Motivated At Work
How To Stay Motivated At Work
InterQuest Group
 
Petit Déj' "Ergonomie et SEO" organisé par Use Age le 26 Septembre 2013
Petit Déj' "Ergonomie et SEO" organisé par Use Age le 26 Septembre 2013Petit Déj' "Ergonomie et SEO" organisé par Use Age le 26 Septembre 2013
Petit Déj' "Ergonomie et SEO" organisé par Use Age le 26 Septembre 2013
Use Age
 
Wall mart
Wall martWall mart
Wall mart
Shihab Akondo
 
Chap02 fsm-mpssr-ht
Chap02 fsm-mpssr-htChap02 fsm-mpssr-ht
Chap02 fsm-mpssr-htinfcom
 

Viewers also liked (20)

Html 2
Html 2Html 2
Html 2
 
Html 4
Html 4Html 4
Html 4
 
Untitled Presentation
Untitled PresentationUntitled Presentation
Untitled Presentation
 
12 Startup Lessons from Steve Jobs Taught Guy Kawasaki
12 Startup Lessons from Steve Jobs Taught Guy Kawasaki12 Startup Lessons from Steve Jobs Taught Guy Kawasaki
12 Startup Lessons from Steve Jobs Taught Guy Kawasaki
 
Reading eggs @ jma
Reading eggs @ jmaReading eggs @ jma
Reading eggs @ jma
 
700-3
700-3700-3
700-3
 
700-4
700-4700-4
700-4
 
MSNF presentation
MSNF presentationMSNF presentation
MSNF presentation
 
How To Win Friends and Influence People in The Digital Age (Indonesian Lan…
How To Win Friends and Influence People in The Digital Age (Indonesian Lan…How To Win Friends and Influence People in The Digital Age (Indonesian Lan…
How To Win Friends and Influence People in The Digital Age (Indonesian Lan…
 
Rebranding. How to increase sales woth new design
Rebranding. How to increase sales woth new designRebranding. How to increase sales woth new design
Rebranding. How to increase sales woth new design
 
Building a 21st century education
Building a 21st century educationBuilding a 21st century education
Building a 21st century education
 
PDC - Arquitetura - 001 - A vida, o universo e tudo mais ...
PDC - Arquitetura - 001 - A vida, o universo e tudo mais ...PDC - Arquitetura - 001 - A vida, o universo e tudo mais ...
PDC - Arquitetura - 001 - A vida, o universo e tudo mais ...
 
Software Factory - Overview
Software Factory - OverviewSoftware Factory - Overview
Software Factory - Overview
 
How To Stay Motivated At Work
How To Stay Motivated At WorkHow To Stay Motivated At Work
How To Stay Motivated At Work
 
Html 1
Html 1Html 1
Html 1
 
Petit Déj' "Ergonomie et SEO" organisé par Use Age le 26 Septembre 2013
Petit Déj' "Ergonomie et SEO" organisé par Use Age le 26 Septembre 2013Petit Déj' "Ergonomie et SEO" organisé par Use Age le 26 Septembre 2013
Petit Déj' "Ergonomie et SEO" organisé par Use Age le 26 Septembre 2013
 
Wall mart
Wall martWall mart
Wall mart
 
700-1
700-1700-1
700-1
 
1 Cert
1 Cert1 Cert
1 Cert
 
Chap02 fsm-mpssr-ht
Chap02 fsm-mpssr-htChap02 fsm-mpssr-ht
Chap02 fsm-mpssr-ht
 

Similar to Sur fnet open-conext-apereo2014

RNP Cloud Infrastructure model, services and challenges
RNP Cloud Infrastructure model, services and challengesRNP Cloud Infrastructure model, services and challenges
RNP Cloud Infrastructure model, services and challenges
EUBrasilCloudFORUM .
 
Open Source Networking Overview
Open Source Networking OverviewOpen Source Networking Overview
Open Source Networking Overview
Eueung Mulyana
 
Presentatie Code Jam Niels van Dijk
Presentatie Code Jam Niels van DijkPresentatie Code Jam Niels van Dijk
Presentatie Code Jam Niels van Dijkkirstenveelo
 
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
NETWAYS
 
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
NETWAYS
 
Whitepaper For Open Gp
Whitepaper For Open GpWhitepaper For Open Gp
Whitepaper For Open Gp
hansfrisvold
 
European Open Science Cloud: Concept, status and opportunities
European Open Science Cloud: Concept, status and opportunitiesEuropean Open Science Cloud: Concept, status and opportunities
European Open Science Cloud: Concept, status and opportunities
EOSC-hub project
 
Fire at Net Futures2015
Fire at Net Futures2015Fire at Net Futures2015
SURFconext, a New Collaboration Paradigm
SURFconext, a New Collaboration ParadigmSURFconext, a New Collaboration Paradigm
SURFconext, a New Collaboration Paradigm
SURFconext
 
The Ascent of Open Science and the European Open Science Cloud
The Ascent of Open Science and the European Open Science CloudThe Ascent of Open Science and the European Open Science Cloud
The Ascent of Open Science and the European Open Science Cloud
Tiziana Ferrari
 
Cultivating Sustainable Software For Research
Cultivating Sustainable Software For ResearchCultivating Sustainable Software For Research
Cultivating Sustainable Software For Research
Neil Chue Hong
 
Fire Brochure 2015
Fire Brochure 2015Fire Brochure 2015
Fire Brochure 2015
Fire Brochure 2015Fire Brochure 2015
Fire Brochure 2015
DiMPro Consulting
 
DI4R 2018 - Ellip: a collaborative workplace for EO Open Science
DI4R 2018 - Ellip: a collaborative workplace for EO Open ScienceDI4R 2018 - Ellip: a collaborative workplace for EO Open Science
DI4R 2018 - Ellip: a collaborative workplace for EO Open Science
terradue
 
Summer school bz_fp7research_20100708
Summer school bz_fp7research_20100708Summer school bz_fp7research_20100708
Summer school bz_fp7research_20100708
Sandro D'Elia
 
CNCF Introduction - Feb 2018
CNCF Introduction - Feb 2018CNCF Introduction - Feb 2018
CNCF Introduction - Feb 2018
Krishna-Kumar
 
Introduction to OpenDaylight
Introduction to OpenDaylightIntroduction to OpenDaylight
Introduction to OpenDaylight
Open Networking Summits
 
EU-funded OPTIMIS Cloud Project - Exploitation & Dissemination
EU-funded OPTIMIS Cloud Project - Exploitation & DisseminationEU-funded OPTIMIS Cloud Project - Exploitation & Dissemination
EU-funded OPTIMIS Cloud Project - Exploitation & DisseminationCsilla Zsigri
 
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
EDINA, University of Edinburgh
 
OpenConext: Authentication & Authorization Infrastructure for Virtual Researc...
OpenConext: Authentication & Authorization Infrastructure for Virtual Researc...OpenConext: Authentication & Authorization Infrastructure for Virtual Researc...
OpenConext: Authentication & Authorization Infrastructure for Virtual Researc...
openconext
 

Similar to Sur fnet open-conext-apereo2014 (20)

RNP Cloud Infrastructure model, services and challenges
RNP Cloud Infrastructure model, services and challengesRNP Cloud Infrastructure model, services and challenges
RNP Cloud Infrastructure model, services and challenges
 
Open Source Networking Overview
Open Source Networking OverviewOpen Source Networking Overview
Open Source Networking Overview
 
Presentatie Code Jam Niels van Dijk
Presentatie Code Jam Niels van DijkPresentatie Code Jam Niels van Dijk
Presentatie Code Jam Niels van Dijk
 
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
 
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
stackconf 2023 | SCS: Buildig Open Source Cloud and Container Infrastructure ...
 
Whitepaper For Open Gp
Whitepaper For Open GpWhitepaper For Open Gp
Whitepaper For Open Gp
 
European Open Science Cloud: Concept, status and opportunities
European Open Science Cloud: Concept, status and opportunitiesEuropean Open Science Cloud: Concept, status and opportunities
European Open Science Cloud: Concept, status and opportunities
 
Fire at Net Futures2015
Fire at Net Futures2015Fire at Net Futures2015
Fire at Net Futures2015
 
SURFconext, a New Collaboration Paradigm
SURFconext, a New Collaboration ParadigmSURFconext, a New Collaboration Paradigm
SURFconext, a New Collaboration Paradigm
 
The Ascent of Open Science and the European Open Science Cloud
The Ascent of Open Science and the European Open Science CloudThe Ascent of Open Science and the European Open Science Cloud
The Ascent of Open Science and the European Open Science Cloud
 
Cultivating Sustainable Software For Research
Cultivating Sustainable Software For ResearchCultivating Sustainable Software For Research
Cultivating Sustainable Software For Research
 
Fire Brochure 2015
Fire Brochure 2015Fire Brochure 2015
Fire Brochure 2015
 
Fire Brochure 2015
Fire Brochure 2015Fire Brochure 2015
Fire Brochure 2015
 
DI4R 2018 - Ellip: a collaborative workplace for EO Open Science
DI4R 2018 - Ellip: a collaborative workplace for EO Open ScienceDI4R 2018 - Ellip: a collaborative workplace for EO Open Science
DI4R 2018 - Ellip: a collaborative workplace for EO Open Science
 
Summer school bz_fp7research_20100708
Summer school bz_fp7research_20100708Summer school bz_fp7research_20100708
Summer school bz_fp7research_20100708
 
CNCF Introduction - Feb 2018
CNCF Introduction - Feb 2018CNCF Introduction - Feb 2018
CNCF Introduction - Feb 2018
 
Introduction to OpenDaylight
Introduction to OpenDaylightIntroduction to OpenDaylight
Introduction to OpenDaylight
 
EU-funded OPTIMIS Cloud Project - Exploitation & Dissemination
EU-funded OPTIMIS Cloud Project - Exploitation & DisseminationEU-funded OPTIMIS Cloud Project - Exploitation & Dissemination
EU-funded OPTIMIS Cloud Project - Exploitation & Dissemination
 
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
Some Academic Sector/NMCA outcomes from the OGC Web Service Shibboleth Intero...
 
OpenConext: Authentication & Authorization Infrastructure for Virtual Researc...
OpenConext: Authentication & Authorization Infrastructure for Virtual Researc...OpenConext: Authentication & Authorization Infrastructure for Virtual Researc...
OpenConext: Authentication & Authorization Infrastructure for Virtual Researc...
 

Recently uploaded

国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
zoowe
 
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
cuobya
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
Arif0071
 
Search Result Showing My Post is Now Buried
Search Result Showing My Post is Now BuriedSearch Result Showing My Post is Now Buried
Search Result Showing My Post is Now Buried
Trish Parr
 
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
3ipehhoa
 
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
cuobya
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
Javier Lasa
 
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
vmemo1
 
Understanding User Behavior with Google Analytics.pdf
Understanding User Behavior with Google Analytics.pdfUnderstanding User Behavior with Google Analytics.pdf
Understanding User Behavior with Google Analytics.pdf
SEO Article Boost
 
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
3ipehhoa
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
Rogerio Filho
 
7 Best Cloud Hosting Services to Try Out in 2024
7 Best Cloud Hosting Services to Try Out in 20247 Best Cloud Hosting Services to Try Out in 2024
7 Best Cloud Hosting Services to Try Out in 2024
Danica Gill
 
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
eutxy
 
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
ufdana
 
How to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptxHow to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptx
Gal Baras
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC
 
Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027
harveenkaur52
 
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
3ipehhoa
 
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdfMeet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Florence Consulting
 
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
keoku
 

Recently uploaded (20)

国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
 
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
 
Search Result Showing My Post is Now Buried
Search Result Showing My Post is Now BuriedSearch Result Showing My Post is Now Buried
Search Result Showing My Post is Now Buried
 
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
 
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
 
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
 
Understanding User Behavior with Google Analytics.pdf
Understanding User Behavior with Google Analytics.pdfUnderstanding User Behavior with Google Analytics.pdf
Understanding User Behavior with Google Analytics.pdf
 
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
 
7 Best Cloud Hosting Services to Try Out in 2024
7 Best Cloud Hosting Services to Try Out in 20247 Best Cloud Hosting Services to Try Out in 2024
7 Best Cloud Hosting Services to Try Out in 2024
 
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
 
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
 
How to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptxHow to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptx
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
 
Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027
 
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
 
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdfMeet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
 
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
 

Sur fnet open-conext-apereo2014

  • 1. OpenConext: Open for Collaboration Niels van Dijk Technical Product Manager
  • 2. SURFnet: the Dutch NREN • SURFnet is the Dutch National Research & Education Network (NREN) – Services, innovation, knowledge – Not for profit – Task organisation of Stichting SURF = ICT collaboration of higher education & research • A small operation serving a large community: – 85 employees – 160 connected institutions – 1 million end-users – Turnover 35 million Euro; 1/3 innovation subsidies SURFnet - We make innovation work 1
  • 3. OpenConext SURFnet - We make innovation work 2
  • 4. OpenConext Vision (2009) SURFnet - We make innovation work 3  Create a coherent infrastructure of loosely coupled collaborative services, based on (emerging) Open Standards and enabled by access federations
  • 5. OpenConext Building blocks SURFnet - We make innovation work 4  Identity Federations, SAML and attributes  Create and manage Groups  OpenSocial (VOOT) API and oAuth  A piece of middleware (a hub or proxy) that allows centrally managing interconnects and facilitates application integration
  • 6. OpenConext Use cases SURFnet - We make innovation work 5 • Collaboration Platform • Service Delivery Platform • Identity Federation hub United Kingdom – JISCconext (JISC) A Collabortion platform around email groups, will support about 1 million endusers Australia (AARnet) A service delivery for AARnet services in Australia and New Zealand The Netherlands – SURFconext (SURFnet) The middleware platform for the national hub-n-spoke Identity Federation
  • 7. JISCconext SURFnet - We make innovation work 6 https://tnc2014.terena.org/core/presentation/15
  • 8. AARNet SURFnet - We make innovation work 7 https://tnc2014.terena.org/core/presentation/15
  • 9. SURFconext SURFnet - We make innovation work 8 A next generation collaboration infrastructure that creates new opportunities to collaborate online based on a combination of applications from different providers. Researchers, educators and students wish to select the tools that best fit their online collaboration needs. Institutions and Collaborative Organizations struggle with the integration of self-hosted services with commercial cloud services. Service providers seek for ways to make their services easily accessible for users in higher research and education. SURFconext is the platform to facilitate these needs.
  • 10. Collaboration Platform SURFnet - We make innovation work 9 • Federated Authentication • Centralized Groups • Portals Federated Authentication Leverages secure, trusted authentication and Single Sign on for Campus and Cloud applications Centralized groups Used for Adhoc collaborations and institutional groups Portals Bring together distributed services to provide end-users with a coherent set of services
  • 11. Service Delivery Platform SURFnet - We make innovation work 10 • Federated Authentication • Attribute based Authorization • National Procurement & Licencing Create Trusted Services By combining Identity Federation, privacy and data protection regulations and license deal in one contract between Service Provider and (all) Dutch institutions
  • 12. Services Dashboard SURFnet - We make innovation work 11
  • 13. Commercial Services SURFnet - We make innovation work 12
  • 14. eScience Services SURFnet - We make innovation work 13
  • 15. Collaborative Organisations SURFnet - We make innovation work 14 • Groups • Distributes Services • Attributes, roles and rights Groups are core to collaboration Any collaboration is based on groups. In R&E these groups are dynamic and international; Distributed Services COs collaborate around distributes services. Managing and maintaining many SP IdP interconnections is tough; Attributes, roles and rights Roles and rights are based on Attributes. COs need very different attributes as compared to the attributes provided by the IdPs.
  • 16. Example Cases SURFnet - We make innovation work 15 • WeNMR • Virtual Campus Hub WeNMR Bringing together research teams in the structural biology and life science area. The project offers a platform integrating services and streamlining the computational approaches necessary for data analysis and structural modelling. Virtual Campus Hub Create a virtual education portal for a joint programme, consisting of applications made available by the partners involved in that programme, and to which all relevant users have seamless access.
  • 17. WeNMR SURFnet - We make innovation work 16 • Connect HPC to federation • Federated Portal
  • 18. WeNMR and eduGAIN SURFnet - We make innovation work 17
  • 19. Partners in Virtual Campus Hub
  • 20. Concept: virtual education portal for joint programs
  • 21. Components of Virtual Campus Hub 1. Inventory of the most important ICT barriers for international collaboration in education. 2. Demo platform to prove that some of these barriers can be removed:  Easy access to partners’ applications (FIM)  More efficient and more flexible setup of online activities or online participation in regular activities (UC hub)  Easier collaboration with industry (non-HE IdPs) 3. Vision on how to apply these insights and experiences in concrete collaboration initiatives (e.g. international joint programs)
  • 22. Demo portal (proof of concept) Functionality: • Access with your own account to partners’ applications • Create international groups (virtual organizations) • Single sign-on access through simple website (https://vch.tue.nl) 12-06-2013
  • 23. IdPs connected to VCH 2204-10-2012
  • 24. Enabling international collaboration: National (NRENs) and European (Géant) 12-06-2013
  • 25. Results • Connections realized for several identity providers (IdPs) and applications (SPs). • Cloud service (DTU itslearning) connected to VCH • Scalability of concept shown (by adding extra IdPs) • Knowledge and experience with respect to using Géant- eduGAIN 2412-06-2013
  • 26. OpenConext Building blocks SURFnet - We make innovation work 25  Identity Federations, SAML and attributes  Create and manage Groups  OpenSocial (VOOT) API and Oauth  A piece of middleware (a hub or proxy) that allows centrally managing interconnects and facilitates application integration
  • 27. Identity Federation SURFnet - We make innovation work 26
  • 28. Groups SURFnet - We make innovation work 27  Any collaboration involves groups, either ‘AdHoc’, or ‘Institutional’  OpenConext facilitates the creation of groups of federated users  Adhoc Groups are managed centrally (Teams)  Any acceptable user can become a group 'admin‘  Invite any other users  Build groups from other groups  Institutional Groups (Campus or VO) can be provided by external sources  Groups provide context for applications (but applications decide on AuthZ!)  Groups feature (only) 3 roles (admin, collabmin, member)  Group + VO Registry -> VO IdP
  • 29. Attributes SURFnet - We make innovation work 28  Attribute & Group information can be provided at logon  Many scenarios require out of band exchange  VOOT (http://openvoot.org/voot-2.0.html) REST API, based on OpenSocial  oAuth2 & oAuth 1 (deprecated)  Draft SCIM implementation expected in 2014  SAML attribute query support on the way (both AA and client)
  • 30. OpenConext – The platform (2009) SURFnet - We make innovation work 29  Do not start from Scratch  Add (a lot of) Glue SAML Groups Management Shibboleth SP (Shibboleth Consortium) Grouper (Internet2) Janus (WAYF) SimpleSAMLphp SP (Feide.no) Shindig (Apache) Corto (WAYF) Teams
  • 31. OpenConext – The platform (Q1 2014) SURFnet - We make innovation work 30  Do not start from Scratch  Add (a lot of) Glue and even more Glue SAML Groups Management Shibboleth SP (Shibboleth Consortium) Grouper (Internet2) Janus (SURFnet) SimpleSAMLphp SP (Feide.no) Shindig (Apache) Group Proxy, API & APIS Manage Corto (WAYF/SURFnet) SSP libraries Teams (v2) Log handling & Statistics OpenConext VM
  • 32. OpenConext – Overview SURFnet - We make innovation work 31
  • 33. OpenConext – Meshing a Hub SURFnet - We make innovation work 32 Source: Neil Witheridge, AARNet
  • 34. How OpenConext helps SURFnet - We make innovation work 33 • Groups • Distributed Services • Attributes, roles and rights Manage and share Groups OpenConext provides a centralized group provider and allows linking external group providers; Centrally manage services and identity stores SP and IdP connections can be manage centrally, including Access and Attribute Release Policies; Use Attributes, roles and rights for Authorization Manage, transform and filter attributes and group (membership) both at logon as well as when queried out-of-band.
  • 35. OpenConext VM SURFnet - We make innovation work 34 • Run your own OpenConext platform • CentOS/Redhat, 10 min setup • For demo, development and playing around https://github.com/OpenConext/OpenConext-vm
  • 36. More information SURFnet - We make innovation work 35 • SURFconext • OpenConext SURFconext  http://www.surf.nl/en/services-and-products/surfconext/index.html OpenConext  All of OpenConext is hosted at https://github.com/openconext  OpenConext support tools and compatible services are available at https://github.com/openconextapps Community Website, including documentation  https://www.openconext.org Support  Mailinglists: openconext-users@list.surfnet.nl and openconext-dev@list.surfnet.nl
  • 37. niels.vandijk[at]surfnet.nl @cdr80 cdr80 www.surfnet.nl +31 30 2 305 305 Creative Commons “Attribution” license: http://creativecommons.org/licenses/by/3.0/ W