en:index:documentation:sp:proxy:how_to_manage_access_to_a_service

Restricting access to the service

The AAI provides advanced functionality to restrict access to the service based on some specified rules. One of these rules can be a requirement of membership in at least one of the specified organizational units (groups). Following is the description of setting up such a requirement.

In general, you have to take these steps:

  1. Create organizational units (see How to create a group)
  2. Assign users to the units
  3. Create links (see How to create a resource)
  4. Configure units to gain access to the service (see How to assign groups)
  5. Update service configuration (see Enable membership check)

In the following descriptions, some words might appear you can be unfamiliar with

  1. Facility - representation of the service in the AAI
  2. organization / virtual organization - an organizational unit that is on the top of the hierarchy, contains groups
  3. group - organisational unit, can be nested under an organisation as well as under a group, contains users
  4. resource - link between the group and facility

How to create a group

  1. Open the link https://perun.aai.cesnet.cz/ and log in with your AAI account.
  2. Click the button “Access management” in the side navigation. You will be presented with a table containing organizations. You can select the organization you wish to use. If you do not have any, you can use entry with the short_name einfra or name CESNET e-infrastruktura.
  3. From the overview, click the “Groups” tile. You will see a list of the groups. This page also contains a button “Create”. Click it and you will be presented with a dialogue for creating a new group.
  4. Fill in the name and description. Then submit the dialogue.
  5. Your group is ready to be used. You can add new managers, users, set up an application form…

How to create a resource

  1. Open the link https://perun.aai.cesnet.cz/ and log in with your AAI account.
  2. Click the button “Facility management” in the side navigation. You will be presented with a table containing facilities. Select the facility representing the service you wish to configure.
  3. Click “Resources” tile. Now you should see a list of resources that are created for this facility. This page also contains a button “Create”. Click it and you will be presented with a dialogue for creating the resource.
  4. Fill in the name, description and select which organization the resource is for.
  5. Your resource is created and is ready to be linked with groups.

How to assign groups

Please select the process according to your role. Choose one of the options:

  • I am a group/VO manager
  1. Open the link https://perun.aai.cesnet.cz/ and log in with your AAI account.
  2. Click the button “Facility management” in the side navigation. You will be presented with a table containing facilities. Select the facility representing the service you wish to configure.
  3. Click on the “Resources” tile. You will now see all the resources associated with your service.
  4. In the “Assigned groups” you can manage what groups are associated with this resource.
  5. Click on the “Add” button and select what groups should be associated with this resource.
  • I am not a group/VO manager

Please notify the relevant facility manager to contact the VO manager.

  • I don´t know my role

Please contact the support team at login@cesnet.cz.

Enable membership check

  1. In the SPReg application (https://spreg.aai.cesnet.cz/spreg/) navigate to the detail of your service.
  2. Click on the “Modify settings button”.
  3. Under the “Access control” category, enable the “Check group membership” option
  4. You can also enable “Allow registrations to the service”. This will trigger behavior, that if the user is not allowed to access the service, he/she will be offered to register to gain access. Registration can be configured via the two options following.
  5. - If you fill in the registration URL, users will be redirected to this specified URL.
  6. - If you select “Delegate registration to the AAI” option, user will be offered to register into the groups assigned to the resources of the service (facility). Please note that only the groupswith application form configured will be used. If no such group exists, users will be redirected to a page stating they are not authorized to access the service.
  7. Submit the form. AAI operators will review your request. After it is approved, configuration will be reflected in the service settings and access will be restricted.
Last modified:: 2020/12/16 12:30