Ask Christos, Marcus and Uros to add stuff
|
#Enter the persons who are participating in the team that works on this Activity - delete this line after using the template#
|
|
Some systems cannot be federated easily per se (e.g. like non-web services, such as login to remote *nix machines, ...) need user accounts to be provisioned before they can login. We have a prototype of an instant deployment tool (FEUDAL). It facilitates provisioning of user accounts on a per VO basis. It makes use of rabbit-MQ to instantly deploy provisioning and deprovisioning events. Feudal is based on OIDC: It is an OIDC client, and it simply transports the information of the /userinfo endpiont along. Feudal is based on the concept of VOs (or authorisation Groups), i.e. the end services provide the information which VOs it supports. Feudal web fronted will only display services for provisioning to a given user based on his VO membership. Feudal features deprovisioning and comes with a REST interface for programmatic use. |
|
|
Feudal should make it easy for
|
Not enough resource providers interested? |
#How do data protection and privacy impact the Activity? Think about e.g. handling of personal data of users - delete this line after using the template# FEUDAL receives all those information (via AccessToken and Userinfo Endpoint) that the OP releases. This is typically:
This information is stored in FEUDAL until users are deprovisioned on all resources (i.e. until the business relation is terminated). The Audit Log lifetime is specified by an admin via logrotate. This information is passed on to the ressources that support a given VO. This is done according to GDPR |
#Please describe here the set of criteria that the product must meet in order to be considered finished. - delete this line after using the template# <Enter here> |
#How are the results of the Activity intended to be used? If this requires further engagement, can you describe how you intent to sustain it? - delete this line after using the template# <Enter here> |
#Please provide pointers to completed and intermediary results of this activity - delete this line after using the template# |
Date | Activity | Owner | Minutes |
---|---|---|---|
January 1, 2017 | Kickoff meeting | ||