Federated Access implementation: experience of AUCA Library - Kyrgyzstan 4 th -7 th June, 2008, Aberdeen, Scotland Sania Battalova, EIFL Country and FOSS.

Slides:



Advertisements
Similar presentations
Lousy Introduction into SWITCHaai
Advertisements

Grid Initiatives for e-Science virtual communities in Europe and Latin America The VRC-driven GISELA Science Gateway Diego Scardaci.
PERSEUS : Portal-enabled Resources via Shibbolized End-user Security 16 May 2005JISC Core Middleware Programme Meeting, Loughborough 1 PERSEUS Project.
Open Electronic Library – from initiative to reality at the community of Kyrgyz libraries 4 th -7 th June, 2008, Aberdeen, Scotland Sania Battalova AUCA,
Joanna Cooksey, Subject Librarian Oxford Brookes University Logging into Athens: a brief guide.
EVERY CONNECTION has a starting point. EVERY CONNECTION has a starting point. WorldCat Navigator - Authentication Library Hosted Navigator EZproxy and.
Presented by Brad Jacobson The Publisher on the Web Exploiting the new online sales channels.
OhioNET EZProxy Service
EIFL Thursday, December 15 th, 2011 Brook Schofield Project Development Officer Slide 1.
KYRGYZ LIBRARIES INFORMATION CONSORTIUM Experience of the Kyrgyz Libraries on Open Repositories Implementation on Open Repositories Implementation Safia.
New Jersey Digital Video Initiative 1 A Collaborative Project Between &
7th AMICAL Conference June 9-12, 2010 Budapest, Hungary ePortfolio in AUCA: first steps and first results.
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
Remote User Authentication in Digital Libraries
Managing Student Access. What will we cover Registration Options Student Uploads Login Options Alumni Access versus Student Access.
EVERY CONNECTION has a starting point. NetLibrary eAudiobooks An Overview for Washington State Libraries Nathan Downing Field Implementation Specialist.
ELAG Trondheim Distributed Access Control - BIBSYS and the FEIDE solution Sigbjørn Holmslet, BIBSYS, Norway Ingrid Melve, UNINET, Norway.
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
Understanding Active Directory
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
Academic Services Interactive Media Managing the Web with Java JA-SIG Winter 2002 Robert Sherratt Academic Services, Interactive Media.
5 th AMICAL Conference 25 – 28 May 2008 Blagoevgrad, Bulgaria Open Source Applications at AUCA Learning, Teaching and Collaboration.
Shibboleth: Improving Access for Library Users InCommon Library/Shibboleth Project Holly Eggleston, UC San Diego.
Digital Identity Management Strategy, Policies and Architecture Kent Percival A presentation to the Information Services Committee.
AAI with simpleSAMLphp
Unified Student-Centric Authentication and Authorization Nathan Wilder Special Assistant - Technology Office of the CIO.
World Bank, Africa Region, Africa Household Survey Databank - The World Bank - Africa.
Feide is a identity management system on a national level for the educational sector in Norway. Federated Electronic Identity for Norwegian Education Tromsø,
ID Management in University ID Management in University Kenzi Watanabe Saga University, Japan
Introduction to Grouper Part 1: Access Management & Grouper Tom Barton University of Chicago and Internet2 Manager – Grouper Project.
American University of Central Asia Peg Peoples – Director of College Writing Sania Battalova – Director of Information Resources and Technology 8th AMICAL.
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
Copyright JNT Association 2005Copyright JNT Association An Introduction to Access Management and the UK Federation Simon Cooper.
University Web Portals From accessibility to accountability and life-long connectivity. Paul Kim, Ph.D. Chief Technology Officer Stanford University School.
NMI-EDIT CAMP Synopsis, ISCSI Storage Solution, Linux Blade Cluster, And Current State Of NetID By Jonathan Higgins Presentation Template available from.
Access to electronic scientific information: policies, strategies and programmes The Brazilian experience Elenara Chaves Edler de Almeida Brazilian Federal.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
Electronic resources and services to support academic process at AUCA Battalova Sania American University – Central Asia Director of Information Resources.
Electronic data collection system eSTAT in Statistics Estonia: functionality, authentication and further developments issues 4th June 2007 Maia Ennok,
Frank Grewe Office of Information Technology University of Minnesota.
Outsourcing Student at USC Institute for Computer Policy and Law Cornell University, August 2008 Asbed Bedrossian Director of Enterprise Applications.
Holly Eggleston, UCSD Shibboleth and Library Resources InCommon Library/Shibboleth Project.
VETUMA, the web portal for strong authentication Tietotekniikkaosasto Ismo Aulaskari
SAML a mature six year old? Glenn Wearen, Paul Caskey & Josh Howlett.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Holly Eggleston, UCSD Beyond the IP Address: Shibboleth and Electronic Resources InCommon Library/Shibboleth Project.
Federated Shibboleth, OpenID, oAuth, and Multifactor | 1 Federated Shibboleth, OpenID, oAuth, and Multifactor Russell Beall Senior Programmer/Analyst University.
Administrative Information Systems Shibboleth Install Session Technical Information Session for Developers Datta Mahabalagiri.
Exploring Access to External Content Providers with Digital Certificates University of Chicago Team Charles Blair James Mouw.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
ICC eTerms Repository Supporting the PKI infrastructure and secure electronic commerce Janjaap Bos Dublin, June 2000.
Shibboleth for Middle Schools James Burger -
IS 4506 Windows NTFS and IIS Security Features.  Overview Windows NTFS Server security Internet Information Server security features Securing communication.
Tutorial on Science Gateways, Roma, Riccardo Rotondo Introduction on Science Gateway Understanding access and functionalities.
CERN IT Department CH-1211 Genève 23 Switzerland t Single Sign On, Identity and Access management at CERN Alex Lossent Emmanuel Ormancey,
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
The FederID project The First Identity Management and Federation Free Software.
Federated Identity Management at Virginia Tech
Shibboleth Integration Fairfield University
Network Neighborhood? Who’s on Your Wi-Fi?
Shibboleth Implementation in EZproxy
ESA Single Sign On (SSO) and Federated Identity Management
Dartmouth College Status Report
GALILEO Approach and implementation
INFORMATION TECHNOLOGY NEW USER ORIENTATION
INFORMATION TECHNOLOGY NEW USER ORIENTATION
Erasmus Students Welcome Meeting
P.K. Nyame Library Ghana College of Surgeons and Physicians
Presentation transcript:

Federated Access implementation: experience of AUCA Library - Kyrgyzstan 4 th -7 th June, 2008, Aberdeen, Scotland Sania Battalova, EIFL Country and FOSS Coordinator, Kyrgyzstan EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

AUCA Background Information Former American University in Kyrgyzstan - Founded in 1993 – privet Liberal Arts University 11 Degree programs and MBA 1,200 students (40% men and 60% women) – undergraduates and graduate from 15 countries 125 full-time faculty Merged Library/IT Structure

University Library Electronic Resources and Databases – off-campus access Electronic books - Ebrary - Subscribed collection of 35,000 titles of electronic books Electronic periodicals – more then 15,000 titles at 13 databases AUCA digital Library – Open Electronic Repository and the University Documents Archive EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

University On-line Services: Off-campus access to AUCA Library Databases and Archives Library patrons authentication System E-course System (Moodle) E-portfolio System (Mahara) On-line Registration and Students Portal On-line Evaluation Students Career Service Alumni Service System Discussion Forum (for local needs) EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

AUCA Users Authentication System Primary authentication source - Active Directory. Every user is assigned an Active Directory account that they must use to access University services Based on organization units distributed roles for students, employees, guests and administrators. RADIUS (Remote Authentication Dial-in-User Service) - allows authentication realization, authorization and registration, by means of using remote access policies (RAP). LDAP (Lightweight Directory Access Protocol) - application protocol for reading and editing directories over IP network - uses for Off- campus access (EZProxy, ePortfolio authentication and for Federal Access). EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

Why Federated Access in AUCA? For our users – only single window for authentication to access to all services Single Point of access – one Username and Password to access all on-line services Once accessed you dont need to login to all different services The services and data may be located outside the University. Future Cooperation EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

University level (AUCA): For federated authentication and authorization infrastructure internally Consortium level (KLIC): In getting a pilot in Kyrgyzstan Identity Federation started, Library consortium resource providers to use federated authentication and authorization infrastructure Federated Access: from University to Country level EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

Federated Access – University Level – AUCA Experience Selection of SP (Service Provider ) and IdP (Identity Provider) software Selection criteria: MS Windows/Linux, Java/PHP, Shibboleth/simpleSAMLphp University IT staff qualification EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

simpleSAMLphp ( as IdP and SP for AUCAhttp://simplesamlphp.org/ Set up simpleSAMLphp (IdP and SP) - AUCA authorization page createdhttp://login.auca.kg/idp/ For security reasons SSL certificate has been registered free of charge Connection between created IdP and AUCA Active Directory AUCA Idp and SP connection EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

AUCA authorization web- page (AUCA IdP) EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

Challenges New software, no experience Time consuming Coordination between IT offices – IdP and SP set up and local databases, and the University Authentication rules EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

Benefits and the Future Plans Work experience (Shibboleth and simpleSAMLphp) and trained IT staff Promotion Federated Access in AUCA – easy access to on-line service Promotion Federated Access among Kyrgyz Libraries Information Consortium (training sessions for IT staff and librarians) – new way of Kyrgyz libraries cooperation CAREN EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011

Thank you! Contact information: Sania Battalova – EIFL General Assembly 2011 Minsk, Belarus Belarus National Library June , 2011