Presentation is loading. Please wait.

Presentation is loading. Please wait.

Michael Ghens Information Systems Specialist Santa Barbara City College.

Similar presentations


Presentation on theme: "Michael Ghens Information Systems Specialist Santa Barbara City College."— Presentation transcript:

1 Michael Ghens Information Systems Specialist Santa Barbara City College

2 How do we allow Faculty, Staff and Students from another institution access Santa Barbara City College’s Wi-Fi with verification without creating local accounts. Both Santa Barbara City College and CSU Channel Islands have Shibboleth Identity Solutions and belong to the InCommon Federation

3 Both SBCC and CSUCI belong to Incommon Federation Which allows secure exchange of metadata The InCommon Federation is the U.S. education and research identity federation, providing a common framework for trusted shared management of access to on-line resources. Through InCommon, Identity Providers can give their users single sign-on convenience and privacy protection, while online Service Providers control access to their protected resources.

4 On SBCC’s Side Aruba Wireless Infrastructure: Aruba Controller Active Directory Shibboleth LDAP XML

5 Metadata agreements with CSUCI What attributes to be provided (UID, SN, givenName,Mail). Create Shibbolized Captive Portal for Aruba Controller Set up embedded Shibboleth directory service Create Backend authentication logic Log user logins

6 Apache web server Shibboleth module PHP Embedded Directory Service Configuring Aruba for external authentication (XML add_user after user verification)

7 Used Syslog to capture success/failure Centralized Syslog server Graylog2 Log Manager

8 Mar 8 12:45:15 wfsp FEDAUTH[701]: ************* logged in with role: student from: https://mckinley.csuci.edu/idp/shibboleth Mar 8 13:20:22 wfsp FEDAUTH[1428]: ************* logged in with role: student from: https://mckinley.csuci.edu/idp/shibboleth Mar 8 13:45:42 wfsp FEDAUTH[2044]: ************* logged in with role: student from: https://mckinley.csuci.edu/idp/shibboleth 2013-03-08 12:45:15 INFO Shibboleth-TRANSACTION [120519]: uid (1 values) 2013-03-08 12:45:15 INFO Shibboleth-TRANSACTION [120519]: sn (1 values) 2013-03-08 12:45:15 INFO Shibboleth-TRANSACTION [120519]: givenName (1 values) 2013-03-08 12:45:15 INFO Shibboleth-TRANSACTION [120519]: mail (1 values) 2013-03-08 12:45:15 INFO Shibboleth-TRANSACTION [120519]: } 2013-03-08 13:20:22 INFO Shibboleth-TRANSACTION [120521]: New session (ID: _7a2287c22a43d1dce53e1fb566fa9b67) with (applicationId: default) for principal from (IdP: https://mckinley.csuci.edu/idp/shibboleth) at (ClientAddress: 10.1.65.53) with (NameIdentifier: _e73e638370aa1e8fe3fa89ae77087838) using (Protocol: urn:oasis:names:tc:SAML:2.0:protocol) from (AssertionID: _5d8800710f2611c58a7156cefa8e1a83 )

9

10

11

12 Aruba Controller Captive Portal SBCC Login CSUCI IDP Yes No Internet

13 Session Time Outs Coordination of infrastructure changes A more relax captive portal rules

14 Eduroam Active Directory Peering Radius

15


Download ppt "Michael Ghens Information Systems Specialist Santa Barbara City College."

Similar presentations


Ads by Google