Establishing an AAI service in DFN
Ulrich Kähler, DFN-Verein kaehler@dfn.de Jürgen Rauschenbach, DFN-Verein jrau@dfn.de
Establishing an AAI service in DFN Ulrich Khler, DFN-Verein - - PowerPoint PPT Presentation
Establishing an AAI service in DFN Ulrich Khler, DFN-Verein kaehler@dfn.de Jrgen Rauschenbach, DFN-Verein jrau@dfn.de Events and plans March 2006: 1. Meeting of an advisory group and early adopters: Libraries, GRIDs, eLearning,
Ulrich Kähler, DFN-Verein kaehler@dfn.de Jürgen Rauschenbach, DFN-Verein jrau@dfn.de
Events and plans
Libraries, GRIDs, eLearning, service provider
f2f meetings and videoconf´s on different items
basic documents ready (Policy, contracts, service agreements, etc)
establishment of central services, pilot operation
Contracts and start of service
Seite 3
Drivers
much focussed on Shibboleth
towards Shibboleth
HS in Saxonia
Tasks of the DFN-Verein
community
central operational tasks
Seite 6
DFN-Verein
participants of DFN- AAI.
DFN-AAI
S1 A1 A... A2 An Sn S2 DFN S...
DFN-Frame contract DFNAAI
Service agreement
DFNFernsprechen DFNInternet Policy
Attribute schema Operational components
contractual concept
Attachments:
Certificates (fees)
Quality preconditions for IdM
security levels, avoidance of abuse
changes close to the real event
Documentation, Logging
back-up systems
Seite 9
DFN-AAI schema discussion
now, (others have the state „recommended“):
– sn (surname) (from Person) – email (from inetOrgPerson) – eduPersonPrincipalName (from eduPerson) – eduPersonScopedAffiliation – eduPersonEntitlement – eduPersonTargetedID
could be mapped
Seite 10
Usage of certificates
– Operation of Shibboleth – Authentification of the web servers offering these services – Authentification of users
Seite 11
Zertifikate in der DFN-PKI
400 800 1.200 1.600 2.000 11.05 12.05 01.06 02.06 03.06 04.06 05.06 06.06 07.06 08.06 09.06 10.06 A n z a h l Z e r t i f i k a t e Summe Zertifikate Classic Zertifikate Grid Zertifikate
Seite 12
Kontakt
Questions around DFN-AAI: E-Mail: aai@dfn.de