Copyright JNT Association 20051Optional www.ukfederation.org.uk Copyright JNT Association 2007 1 Joining the UK Access Management Federation 4th April.

Slides:



Advertisements
Similar presentations
Athens and Shibboleth ® : the choices Phil Leahy Athens Product Manager.
Advertisements

Shibboleth and UKAMF-FEAR not as scary as it sounds! Rhys Smith Cardiff University.
Joint Information Systems Committee 01/04/2014 | | Slide 1 Connecting People to Resources The JISC Access Management Strategy Nicole Harris Programme Manager.
Eduserv Athens Federations David Orrell Eduserv Athens Technical Architect.
ASPiS - Architecture for a Shibboleth-Protected iRODS System Mark Hedges, Tobias Blanke Centre for e-Research, Kings College London Adil Hasan, Jens Jensen.
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
Joint Information Systems Committee Connecting People to Resources Federated Access Management within the UK Nicole Harris Senior Services Transition Manager,
Stimulating and Supporting Innovation in Learning RSC Wales – Supporting Programmes of Development.
Specialist Colleges Connecting to JANET © JNT Association 2003 Connecting Specialist Colleges To JANET Steve Percival UKERNA.
Copyright JNT Association 2006 The JANET Roaming Service.
JISC Metaleth Project Athens, Shibboleth and the University of Bristol 29 th January 2007.
Joint Information Systems Committee 19/05/2015 | | Slide 1 Connecting People to Resources The UK Access Management Federation Nicole Harris Programme Manager.
Joint Information Systems Committee 19/05/2015 | | Slide 1 Voyage of the UK JISC Federation: Shibbolising the UK’s Research, Higher and Further Education.
Technical Review Group (TRG)Agenda 27/04/06 TRG Remit Membership Operation ICT Strategy ICT Roadmap.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
Copyright JNT Association 20051OptionalCopyright JNT Association 2006 UK Access Management Federation update to TF-EMC2.
Joint Information Systems Committee 04/06/2015 | | Slide 1 Mark Williams Services Outreach, JISC federated access management London.
Agenda Project beginnings and funding. Purpose of the federation. Federation members. Federation protocols. Special features in our federation. Pilot.
Electronic Authentication for Flexible Learning Workshop Presentation (5 August 2003) Chris Connolly, CEO, Galexia Consulting.
Copyright JNT Association 20051OptionalCopyright JNT Association 2007 Overview of the UK Access Management Federation Josh Howlett.
Shibboleth & IMPETUS 1.What are they? 2.Demo. Shibboleth - A system to support the sharing of Web resources among organisations IMPETUS - Infrastructure.
Shibboleth access management: a replacement for Athens and more? Mark Norman and Christian Fernau OUCS 21 June 2007.
SWITCHaai Team Federated Identity Management.
Module 10: Designing an AD RMS Infrastructure in Windows Server 2008.
Athens Building Communities Ed Zedlewski & Lyn Norris UKSG, Warwick, April 2002.
1 everything about. 2 “A FREE online service for UK HE and FE institutions to share, reuse and repurpose electronic learning and teaching resources”.
To identity federation and beyond! Josh Howlett JANET(UK) HEAnet 2008.
Becta’s story… Federated identity. About Becta Becta is the government agency leading the national drive to ensure the effective and innovative use of.
Ray Collins27th September 2005LGfL Project – workshop report1 LGfL Project Report Proof of Principle of the Shibboleth Authentication & Authorisation Infrastructure.
Federated Identity Management in New Zealand Sat Mandri Service Manager TNC15 REFEDs Meeting, 14 th June 2015.
The InCommon Federation The U.S. Access and Identity Management Federation
PERSEU S : Portal-enabled Resources via Shibbolized End-user Security 3 May 05Spring 2005 Internet2 Member meeting 1 News from the ‘misty’ Albion: Shibboleth.
Supporting further and higher education AA(A) – What does it mean to the service provider? Alan Robiette, JISC Development Group.
Carol Tullo, The National Archives 14 April 2011 The Checks and Balances of a Transparent Public Sector World of Information.
Copyright JNT Association 2005Copyright JNT Association An Introduction to Access Management and the UK Federation Simon Cooper.
TNC 2008 JANET(UK) Shibboleth on Windows Trial TNC May 2008 Louis Searchwell Please note that the Shibboleth installer for Windows described in this presentation.
Helsinki Institute of Physics (HIP) Liberty Alliance Overview of the Liberty Alliance Architecture Helsinki Institute of Physics (HIP), May 9 th.
© The JNT AssociationTNC, DTU, Lyngby, Denmark 23 May Rock IT 2007 Combining Music, Web 2.0 and Videoconferencing in UK and European Schools Rob.
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
The UK Access Management Federation for education and research John Chapman, Project Adviser, Technical Policy & Standards.
Name Position Organisation Date. What is data integration? Dataset A Dataset B Integrated dataset Education data + EMPLOYMENT data = understanding education.
MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters.
Federated Access Management The Motherwell Experience Carole Gray.
Copyright JNT Association 20051Optional Copyright JNT Association The UK federation Mark Tysom, JANET(UK) 9 October 2007.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Towards a Unified Authentication, Authorisation and Accounting Infrastructure Patrick Kirk Chief Technical Officer (YHGfL) Lifelong Learning Infrastructure.
The UK Access Management Federation John Chapman Project Adviser – Becta.
Copyright JNT Association 20051Optional Copyright JNT Association The UK federation TNC - 22 nd May 2007 Mark Tysom, UKERNA.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
1 Identities and Federation: The Next IT Wave (The Canadian Access Federation) Rick Bunt President The Canadian University Council of CIOs (CUCCIO)
Federated Identity Fundamentals Ann Harding, SWITCH Cambridge July 2014.
Shibboleth Use at the National e-Science Centre Hub Glasgow at collaborating institutions in the Shibboleth federation depending.
Data protection—training materials [Name and details of speaker]
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Project Moonshot Daniel Kouřil EGI Technical Forum
Jisc/Janet AIM Update Dr Rhys Smith May Agenda Where we are And where we’re going.
Designing Identity Federation Policy, the right way Marina Vermezović, Academic Network of Serbia TNC2013 conference 4 May 2013.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
John O’Keefe Director of Academic Technology & Network Services
InCommon Steward Program: Community Review
e-Infrastructure Workshop 28th March 2006, University of Leeds
ESA Single Sign On (SSO) and Federated Identity Management
TNC - 22nd May 2007 Mark Tysom, UKERNA
UK Access Management Federation
UK Federation 101 Ian A. Young EDINA, University of Edinburgh (and the UK Federation) Internet2 Fall Member Meeting, 7 Dec Shibboleth Development.
Protecting Privacy with Federated AA
Presentation transcript:

Copyright JNT Association 20051Optional Copyright JNT Association Joining the UK Access Management Federation 4th April 2007 Mark Tysom, UKERNA

Copyright JNT Association 20052Optional Copyright JNT Association What is the UK Federation? Benefits Eligibility Suggested approach Methods of participation Application process Membership Overview

Copyright JNT Association 20053Optional Copyright JNT Association What is the UK Federation? A set of Rules that binds members: –Make accurate statements to other members –Keep federation systems and data secure –Use personal data correctly (inc. DPA1998) –Resolve problems within the Federation Not by legal action –Assist Federation Operator and other members

Copyright JNT Association 20054Optional Copyright JNT Association What is it used for? Allows a browser user to access protected online resources based on information asserted by their home organisation. Allows providers of online resources to control access to their services.

Copyright JNT Association 20055Optional Copyright JNT Association The UK Federation Launched November 2006 For UK schools, FE, HE and research Organisations and providing online services to these sectors Funded by JISC and Becta Operational management by UKERNA

Copyright JNT Association 20056Optional Copyright JNT Association What are the benefits? –Centrally funded –Access to resources from anywhere –Provides consistency across the whole of education for AuthN & AuthZ –Can be used to protect internal resources –At least one less password to remember –Improves the user experience –Facilitates sharing of content and collaboration across sectors

Copyright JNT Association 20057Optional Copyright JNT Association Who is eligible to join? Colleges and universities Local Authorities with responsibility for the schools sector Research council funded establishments Other publicly funded bodies subject to support from relevant authorities Commercial and other organisations providing online services to these sectors

Copyright JNT Association 20058Optional Copyright JNT Association Considerations Review your identity management strategy –for example, how many directories you have and who owns them? Build the business case JISC will cease to centrally fund Athens in July 2008

Copyright JNT Association 20059Optional Copyright JNT Association Suggested approach

Copyright JNT Association Optional Copyright JNT Association The six steps 1.Review ID management strategy 2. Develop user directories: to hold user’s status/entitlements/etc 3.Authentication development: implement an institutional web authentication system

Copyright JNT Association Optional Copyright JNT Association The six steps 4. Implement compatible Identity provider software linked to organisational directory and authentication systems 5.Join the federation: apply for membership and sign up to federation rules. 6. Deployment and roll out: staff training, user guides, etc.

Copyright JNT Association Optional Copyright JNT Association Participation –In-house Deploy own IdP infrastructure –Out-source Purchase IdP service from a third party

Copyright JNT Association Optional Copyright JNT Association Pros and cons: In-house –Benefits Retain strategic control over ID management Convergence of internal/external ID management Easier to comply with data protection regulations –Considerations May require significant effort to consolidate authentication and authorisation infrastructure New technology to learn and deploy

Copyright JNT Association Optional Copyright JNT Association Pros and cons: Outsourced –Benefits Enables participation in the Federation with less effort than taking the in-house route –Considerations Effort required to manage user information Both the organisation and outsourcing third party must be federation members User experience may be impaired – less intuitive Diminution of strategic control

Copyright JNT Association Optional Copyright JNT Association What do I need to do to join? Identify your host organisation (the legal body that will sign the rules of membership) Arrange for your host organisation to sign the rules of membership and nominate –Executive liaison who agrees, on behalf of the organisation, to be bound by the rules of membership –Management liaison who registers entities Obtain an X.509 server certificate Once membership accepted, management liaison can register entities Details of the entity added to federation metadata

Copyright JNT Association Optional Copyright JNT Association Support JANET Customer Services Helpdesk: - Joining the federation - Registering entities - Trouble shooting metadata Internet 2 team and Shibboleth community: - general Shibboleth and Shib-related queries

Copyright JNT Association Optional Copyright JNT Association Current Membership 22 institutional IdPs 13 SPs 18 in the pipeline

Copyright JNT Association Optional Copyright JNT Association Further Information Website – lists

Copyright JNT Association Optional Copyright JNT Association Questions? Website – lists