Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • Component A - Service provider
  • Component B - Bring order to chaos
  • Component C - Hide my precious treasure

The components are as follows:

ComponentDescriptionWhy did we choose it?Link
RCAuthToken Translation. Used to generate x509 certificates for access to legacy servicesEU wide, sustainable infrastructure componenthttps://rcauth.eu
VOMSAttribute Authority & Membership Management.Pre-existing. Backwards compatibilityhttps://italiangrid.github.io/voms/
EGI-Check-inThe second option for the proxy and membership management componentImplements multiple components, easier maintenance. Product used by other communities.https://www.egi.eu/services/check-in/


COmanage Modules configuration

You need admin privileges to perform the following:

Code Block
languagetext
titleAdd a pipeline
Select <collaboration> -> Configuration -> Pipelines -> Add Pipeline

See screenshot below for configuration settings

Image Added

Code Block
languagetext
titleAdd Organisational Identity Source
Select <collaboration> -> Configuration -> Organisational Identity Sources -> Add Organisational Identity Source


See screenshots below for configuration settings

Image Added

Image Added

Code Block
languagetext
titleCreate RCAuth Enrollment Flow
Select <collaboration> -> Configuration -> Enrollment Flows -> Add Enrollment Flow


See screenshots below for configuration settings

Image Added

Image Added

EnvironmentIssuer DN
AARC pilot (e.g. LS AAI, WLCG){{/O=AARC/OU=AAI-Pilot/CN=AARC Simple Demo CA}}
Production{{/DC=eu/DC=rcauth/O=Certification Authorities/CN=Research and Collaboration Authentication Pilot G1 CA}}


Code Block
languagetext
titleAdd and Configure VOMs Provisioning Plugin
Select <collaboration> -> Configuration ->  Provisioning Targets -> Add Provisioning Target

See screenshots below for configuration settings

Image Added


Image Added


Image Added


Code Block
languagetext
titleCreate DARIAH Enrollment Flow

Architecture

This section will provide 2 important parts:

  • Graphic representations of pilot architecture

  • Graphic representations of workflow

  • Lists of all components of related pilot

AARC BPA version:

Image Added


Use Cases

This section should explain how this pilot works through use cases (at least 2).

...

(Here's a valid example LINK)


User links x509 certificate to user's COmanage profile and gives access to SP if the user belongs to an authorized group



Code Block
languagetext
titleCreate DARIAH Enrollment Flow
Select <collaboration> -> Configuration -> Enrollment Flows -> Add Enrollment Flow


Code Block
languagetext
titleConfigure DARIAH Enrollment Flow
linenumberstrue
<Name>, e.g. Confirm request for accessing EGI resources
<Status> => Active
<Petitioner Enrollment Authorization => Authenticated User
<Identity Matching> => None
<Email Confirmation Mode> => None
<Terms and Conditions Mode> => Explicit Consent
<Finalization Redirect URL> => The URL of the enrollment petition to follow. For this case the enrollment to follow is the RCAuth enrollment

See screenshots below for configuration settings

Image Added


See screenshots below for co persons profile after finishing DARIAH Enrollment

Image Added


Image Added


Demo Videos  can be found here

  • User accessing Dariah service
  • Expunging a user from Group Management Framework removes the user from VOMS as well

Further information

Last part contain a list of information, link or anything related to the pilot that was not mentioned in ahead seciton.