The old Indico instance is available at http://indico-memoria.rnp.br
30 November 2020 to 1 December 2020
Zoom Coordinates
America/New_York timezone

Session

XSEDE's Perspective on Token Assurance for Authentication and Authorization

1 Dec 2020, 09:05
Zoom Coordinates

Zoom Coordinates

Join Zoom Meeting https://cmu.zoom.us/j/95682797458 For passcode, contact: dsimmel@psc.edu filus@psc.edu Meeting ID: 956 8279 7458 Dial by your location +1 267 831 0333 US (Philadelphia) +1 786 635 1003 US (Miami) +1 929 205 6099 US (New York) +1 301 715 8592 US (Washington D.C) +1 312 626 6799 US (Chicago) +1 470 250 9358 US (Atlanta) +1 470 381 2552 US (Atlanta) +1 646 518 9805 US (New York) +1 651 372 8299 US (St. Paul) +1 253 215 8782 US (Tacoma) +1 346 248 7799 US (Houston) +1 602 753 0140 US (Phoenix) +1 669 219 2599 US (San Jose) +1 669 900 6833 US (San Jose) +1 720 928 9299 US (Denver) +1 971 247 1195 US (Portland) +1 206 337 9723 US (Seattle) +1 213 338 8477 US (Los Angeles) Meeting ID: 956 8279 7458 Find your local number: https://cmu.zoom.us/u/acnDsIhJso Join by SIP 95682797458@zoomcrc.com Join by H.323 162.255.37.11 (US West) 162.255.36.11 (US East) 221.122.88.195 (China) 115.114.131.7 (India Mumbai) 115.114.115.7 (India Hyderabad) 213.19.144.110 (Amsterdam Netherlands) 213.244.140.110 (Germany) 103.122.166.55 (Australia) 209.9.211.110 (Hong Kong SAR) 64.211.144.160 (Brazil) 69.174.57.160 (Canada) 207.226.132.110 (Japan) Meeting ID: 956 8279 7458

Conveners

XSEDE's Perspective on Token Assurance for Authentication and Authorization

  • Lee Liming (XSEDE, University of Chicago, Globus)
  • Derek Simmel (XSEDE, Pittsburgh Supercomputing Center)
  • Brian Hom (XSEDE, San Diego Supercomputer Center)
  • Jim Basney (National Center for Supercomputing Applications)

Description

As XSEDE migrates its services, such as SSH and Globus Connect, from X.509 certificates to OAuth tokens, we must maintain an appropriate level of assurance for access to XSEDE resources. XSEDE has adopted IGTF assurance for X.509 certificates and REFEDS assurance for InCommon/eduGAIN SAML assertions, and the comparability between IGTF and REFEDS assurance levels (IGTF DOGWOOD/ASPEN to REFEDS low and IGTF BIRCH/CEDEAR to REFEDS medium) has enabled consistency across XSEDE authentication and authorization services. As an AEGIS participant, XSEDE is evaluating AARC-G048 ("Guidelines for Secure Operation of Attribute Authorities and other issuers of access-granting statements") as it applies to OAuth token issuers such as CILogon/SciTokens and Globus.

In this panel, XSEDE staff will discuss project needs related to levels of assurance for OAuth tokens, the current state of OAuth implementation efforts (e.g., XSEDE OAuth SSH and Globus Higher Assurance Levels), and a new XSEDE IAM Policy under development. The panelists will also discuss interoperability requirements and solicit community input.

Presentation Materials

Building timetable...