MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters.

Slides:



Advertisements
Similar presentations
Athens and Shibboleth ® : the choices Phil Leahy Athens Product Manager.
Advertisements

Shibboleth and UKAMF-FEAR not as scary as it sounds! Rhys Smith Cardiff University.
Shibboleth at Cardiff University Lindsay Roberts Project Manager – Shibboleth Implementation Phase 2.
Options for integrating the JANET Roaming Service (JRS) and Shibboleth Tim Chown University of Southampton (UK) JISC Access Management.
Joint Information Systems Committee 01/04/2014 | | Slide 1 Connecting People to Resources The JISC Access Management Strategy Nicole Harris Programme Manager.
PERSEUS : Portal-enabled Resources via Shibbolized End-user Security 16 May 2005JISC Core Middleware Programme Meeting, Loughborough 1 PERSEUS Project.
Joint Information Systems Committee 01/04/2014 | slide 1 Support e-Research at JISC Access Management and Security Joint Information Systems CommitteeSupporting.
Eduserv Athens Federations David Orrell Eduserv Athens Technical Architect.
FAME-PERMIS Project University of Manchester University of Kent London, July 2006.
ASPiS - Architecture for a Shibboleth-Protected iRODS System Mark Hedges, Tobias Blanke Centre for e-Research, Kings College London Adil Hasan, Jens Jensen.
Next Generation Athens Services Ed Zedlewski UK e-Science Town Meeting, London, 11 April 2005.
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
JISC Metaleth Project Athens, Shibboleth and the University of Bristol 29 th January 2007.
Copyright JNT Association 20051Optional Copyright JNT Association Joining the UK Access Management Federation 4th April.
1 Issues in federated identity management Sandy Shaw EDINA IASSIST May 2005, Edinburgh.
EDINA 20 th March 2008 EDINA Geo/Grid - Security Prof. Richard O. Sinnott Technical Director, National e-Science Centre University of Glasgow, Scotland.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
Copyright JNT Association 20051OptionalCopyright JNT Association 2007 Overview of the UK Access Management Federation Josh Howlett.
Shibboleth & IMPETUS 1.What are they? 2.Demo. Shibboleth - A system to support the sharing of Web resources among organisations IMPETUS - Infrastructure.
Alumni Authentication… Explained Robert Scaysbrook – OpenAthens UK Account Manager.
Administrative Information Systems Shibboleth: The Next Generation ISIS Technical Information Session for Developers Datta Mahabalagiri March
Developments in Access and Identity Management Phil Leahy – Athens Product Manager.
Shibboleth-intro-dec051 Shibboleth A Technical Overview Tom Scavo NCSA.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Implementing Shibboleth: A Publisher’s Perspective Chris Shillum Vice President, Product Technology Elsevier UKSG Briefing Session 3-4 April 2006.
Australian Access Federation Robert Hazeltine Identity and Access Management Enterprise Systems Office.
PERSEU S : Portal-enabled Resources via Shibbolized End-user Security 3 May 05Spring 2005 Internet2 Member meeting 1 News from the ‘misty’ Albion: Shibboleth.
Mairéad Martin The University of Tennessee September 13, 2015 Federated Digital Rights Management.
Joint Information Systems Committee 18-Jul-2006 | | Slide 1 Change Management for Libraries Session B, 11: :00 John Paschoud and Peter Spring London.
Copyright JNT Association 2005Copyright JNT Association An Introduction to Access Management and the UK Federation Simon Cooper.
I2Q & WMnet Pilot Presented by Jason Rousell – i2Q Jay Neale - i2Q.
Norman Wiseman JISC Head of Programmes Presentation to JISC Authentication Concertation Day March 1999 International Authentication Activities Joint Information.
Shibboleth Update Michael Gettes Principal Technologist Georgetown University Ken Klingenstein Director Interne2 Middleware Initiative.
David L. Wasley Office of the President University of California Shibboleth Safe delivery of reliable authorization data David L. Wasley University of.
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
Shibboleth for Real Dave Kennedy
ShibGrid: Shibboleth access to the UK National Grid Service University of Oxford and STFC.
LGfL Update Stewart Duncan LGfL Technical Manager Ian Lehmann LGfL Operations Manager.
Enabling Collaborations via a Transformative Virtual Organization Platform Dr. Gordon K. Springer University of Missouri-Columbia CS Department Seminar.
Federated Identity and Shibboleth Concepts Rick Summerhill Chief Technology Officer Internet2 GEC3 October 29, 2008 Slides by Nate Klingenstein
Shibboleth: An Introduction
Holly Eggleston, UCSD Shibboleth and Library Resources InCommon Library/Shibboleth Project.
1 Protection and Security: Shibboleth. 2 Outline What is the problem Shibboleth is trying to solve? What are the key concepts? How does the Shibboleth.
OGF22 25 th February 2008 OGF22 Demo Slides Prof. Richard O. Sinnott Technical Director, National e-Science Centre University of Glasgow, Scotland
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Mairéad Martin The University of Tennessee December 16, 2015 Federated Digital Rights Management.
Shibboleth & Grid Integration STFC and University of Oxford (and University of Manchester)
Copyright JNT Association 20051Optional Copyright JNT Association The UK federation TNC - 22 nd May 2007 Mark Tysom, UKERNA.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
Administrative Information Systems Shibboleth Install Session Technical Information Session for Developers Datta Mahabalagiri.
126/02/2016 META ACCESS MANAGEMENT SYSTEM A Ship on the Grid – Interoperability between Shibboleth and the Grid – Dr. Erik Vullings Programme Manager Macquarie.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Shibboleth for Middle Schools James Burger -
Shibboleth Use at the National e-Science Centre Hub Glasgow at collaborating institutions in the Shibboleth federation depending.
ALPSP Effective Customer Authentication 15-Jul The (now… then…) next of Authentication: Shibboleth John Paschoud SECURe Project, LSE Library.
Project Moonshot Daniel Kouřil EGI Technical Forum
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Oracle Virtual Directory
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Shibboleth Architecture
LIGO Identity and Access Management
Federation Systems, ADFS, & Shibboleth 2.0
e-Infrastructure Workshop 28th March 2006, University of Leeds
Federated Digital Rights Management
KC-ROLO Project Kidderminster College – Repository Of Learning Objects
Protecting Privacy with Federated AA
Presentation transcript:

MAT U M A T U Middleware Assisted Take-Up Service For JISC Funded Early Adopters

Eduserv a not-for-profit IT services group. over 10 years experience in access management. funds IT educational initiatives through the Eduserv Foundation. contracted by the JISC to provide the MATU service.

MATU’s Objectives Support JISC core middleware project early adopters Provide a central repository of: –Information –Advice –Training Scope future requirements for institutions adopting shibboleth

MATU Website

Activities To Date Providing –Advice –Technical support –Help in solving problems –Training Forming One-to-one relationships with projects:

Shibboleth Architecture developed by the internet2 middleware community Open source, standards-based protocol based on SAML (an OASIS standard) Neither an authentication nor authorisation scheme Term “shibboleth” also used to refer to: –The project that has managed the development of the architecture and code –The code package, running on a variety of systems, that implements the architecture Internet2 shibboleth web pages – –

Shibboleth Rationalises usernames, passwords, IP addresses, proxy servers etc. Offers a single solution to control resource access both internally and remotely. –Eliminates separate identifiers/passwords for each protected resource. –Provides greater security. –Allows for secure, flexible, anonymous access to resources. –Institution & individual user can control information released to SP. Location independent. Encourages increased take-up of licensed materials. Allows for greater flexibility in controlling access.

The components Resource WAYF Identity Provider Service Provider ACS Assertion Consumer Service Where Are You From HS Handle Service User DB AR Attribute Requester AA Attribute Authority Resource Manager AuthN AuthZ = Shib

The Process Resource WAYF Identity ProviderService Provider 1: Make Request ACS 3: Query User 2: Redirect to WAYF HS 5: Redirect to Handle Service 6: Auth Challenge 7 User DB Credentials 4 AR Handle 8: Pass Handle Handle 9: Request Attributes AA Attributes 10: Return Attributes Resource Manager Attributes Authorize access

Shibboleth/Athens Interoperability. The Athens to Shibboleth Gateway providing Athens-enabled organisations access to Shibboleth- enabled resources. The Shibboleth to Athens Gateway providing Shibboleth-enabled organisations access to Athens- enabled resources.

Road Map to Federated Access Management Institutional Audit Directory Development Authentication Development and Implement IdP Joining the Federation Intuitional Role Out

What Now? What are the advantages of migrating to Shibboleth? What are the risks to institutions of doing nothing? What are the issues that have been thrown up by the current early adopter projects? What about users who have more than one institutional affiliation? What should RSC be advising institutions with regard to Shibboleth/Athens?

Contact Us. MATU Queen Anne House 11 Charlotte Street Bath BA1 2NE Contact us at: View the MATU Website at: