[[PageOutline]] == Project Number == 1734 == Project Title == Leveraging Emergent Federated Activities[[BR]] a.k.a. LEFA === Technical Contacts === '''PI:''' Kenneth J. Klingenstein, Internet2 [mailto:kjk@internet2.edu][[BR]] Steven Carmody, Brown University [mailto:Steven_Carmody@brown.edu][[BR]] === Participating Organizations === [http://www.internet2.edu Internet2][[BR]] Ann Arbor, MI [http://www.brown.edu Brown University][[BR]] Providence, RI === GPO Liaison System Engineer === [mailto:vthomas@geni.net Vic Thomas] == Scope == The work will focus on enabling GENI for federated identity, developing options for supporting virtual organizations within the GENI community, brokering GENI's international requirements at the middleware layer, providing white papers on critical GENI topics in which the Internet2 middleware community has established expertise, requirements gathering for federated authentication/authorization and attribute aggregation across the GENI clusters, and on working closely with other peer proposals investigating related themes. === Current Capabilities === === Milestones === [[MilestoneDate(LEFA: S2.a Federation technologies within ORCA)]] [[BR]] [[MilestoneDate(LEFA: S2.b Demo at GEC 7)]] [[BR]] [[MilestoneDate(LEFA: S2.c Begin PlanetLab Engagement)]] [[BR]] [[MilestoneDate(LEFA: S2.d White paper on the federation knot in GENI)]] [[BR]] == Project Technical Documents == LEFA []Annual Review slides === Quarterly Status Reports === [wiki:LEFA-QSR-1Q10 March 2010 Status Report] LEFA Project Status Report Period: April 2010 – June 2010 I. Major accomplishments Developed an approach to interacting with portal-based access controls in GENI. A. Milestones achieved The federation knot paper continues to circulate. The distinctions and relationships between federated identity and federated control planes are being sharpened in the GENI community. B. Deliverables made Setting up demo for GEC8. II. Description of work performed during last quarter A. Activities and findings • Worked with ORCA and central IT staff at Duke to implement Shibboleth environment for ORCA staff to explore and learn from. • Worked with Planetlab deployer in Romania to incorporate Shibboleth IDP into Plantelab node. • Worked with BBN staff discussing Shibboleth, its model, and how it could be incorporated into GENI security architecture and add value. • Working with PMO and Duke to define and develop demo for GEC8. • Working with various people to begin implementing the set of services that will comprise the demo. • Participated and presented in the NSF FIRE workshop at Princeton in May. • Discussed the GENI opportunities and impacts with leading research universities CIOs in May. B. Project participants Ken Klingenstein (internet2), Principal Investigator: project direction, federation analysis, white paper development, participant in GENI CF discussions, liaison with Steve Sch of Cobham and service as project laison to the GPO Steven Carmody (Brown University), Senior IT Architect at Brown University and Project Manager of Internet2's Shibboleth Project: focus on engagement with ORCA and Planetlab on technical issues C. Publications (individual and organizational) D. Outreach activities E. Collaborations ORCA control framework. A federated Planetlab in Romania. F. Other Contributions ================================ LEFA Project Status Report Period: July 2010 –Sept 2010 I. Major accomplishments. Demonstrated the use of identity federation and enterprise group control to manage many aspects of ORCA at GEC8. A. Milestones achieved. Established a proof of concept that federated identity and group access controls can manage GENI experiments. B. Deliverables made. The demo at GEC8 illustrated not only the use of federated identity but also the use of groups for access control. Worked with the Cobham group and introduced them to COmanage and the issues and approaches to attribute creation at the enterprise and at the cluster/experiment level. The federation knot paper continues to draw comments. II. Description of work performed during last quarter A. Activities and findings • Worked with ORCA and central IT staff at Duke to implement Shibboleth/Grouper environment and to integrate Shibboleth with the ORCA portal. • Developed demo showing authentication at the home campus and use of group memberships within CoManange to manage permissions at the GENI portal. • Worked with TIED deployer to integrate Shibboleth with their attribute-based access control libraries. • Held ongoing discussions with GPO on identity management and access issues. • Delivered demo at GEC8. B. Project participants Ken Klingenstein (Internet2), Principal Investigator: project direction, federation analysis, white paper development, participant in GENI CF discussions, liaison with Steve Schwab of Cobham and service as project liaison to the GPO. Steven Carmody (Brown University), Senior IT Architect at Brown University and Project Manager of Internet2's Shibboleth Project: focus on engagement with ORCA and Planetlab on technical issues. C. Publications (individual and organizational) D. Outreach activities E. Collaborations ORCA control framework. TIED project for Linking Attributes to policy engines for access control. Cobham integrated. F. Other Contributions Has provided GPO with advice on identity management activities in other venues, including government. === Spiral 2 Connectivity === === Related Projects === [http://shibboleth.internet2.edu/ Shibboleth][[BR]] [http://www.incommonfederation.org/ InCommon][[BR]]