Shibboleth: Early Experience at OSU Scott Cantor October 28, 2002 Scott Cantor October 28, 2002.

Slides:



Advertisements
Similar presentations
OhioNET EZProxy Service
Advertisements

Designing, Deploying and Managing Workflow in SharePoint Sites Steve Heaney Product Development Manager OBS
The Internet2 NET+ Services Program Jerry Grochow Interim Vice President CSG January, 2012.
ELAG Trondheim Distributed Access Control - BIBSYS and the FEIDE solution Sigbjørn Holmslet, BIBSYS, Norway Ingrid Melve, UNINET, Norway.
Access management for repositories: challenges and approaches for MAMS James Dalziel Professor of Learning Technology and Director, Macquarie E-Learning.
1 The IIPC Web Curator Tool: Steve Knight The National Library of New Zealand Philip Beresford and Arun Persad The British Library An Open Source Solution.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
UC Irvine’s Pre-Shib Attribute Setup PH / QI Directory Provides Authoritative Attribute Store –Had both Faculty / Staff and Student Information UCI’s Campus.
Shibboleth: EBSCOhost implementation Lech Wojtowicz Director of Software Development EBSCO Publishing Access 2003 October 3, 2003.
Academic Services Interactive Media Managing the Web with Java JA-SIG Winter 2002 Robert Sherratt Academic Services, Interactive Media.
CONNECT as an Interoperability Platform - Demo. Agenda Demonstrate CONNECT “As an Evolving Interoperability Platform” –Incremental addition of features.
Massachusetts Institute of Technology Page 1 Open Knowledge Initiative CSG - Princeton, 05/07/03.
Campus Management Portal and Online Higher Education Cardean Learning Group.
Project Shibboleth Update, Demonstration and Discussion Michael R Gettes Duke University (on behalf of the entire shib team!!!) June.
Barracuda Load Balancer Server Availability and Scalability.
Module 10: Designing an AD RMS Infrastructure in Windows Server 2008.
Web Development Process Description
AAF Middleware update February Presented by Terry Smith Technical Manager and Heath Marks Manager.
SitePublisher Agency Rollout Strategy. TeamSite Today 92 parent sites 46,000 pages 273,000 files.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 Shibboleth Pilot Local Authentication.
March 19, Open Knowledge Initiative: The Saga Unfolds Mike Barker Lois Brooks Jeff Merriman.
Global Customer Partnership Council Forum | 2008 | November 18 1IBM - GCPC MeetingIBM - GCPC Meeting IBM Lotus® Sametime® Meeting Server Deployment and.
Portal Strategies and Issues at Georgetown Common Solutions Group Winter Meeting Duke University January 10, 2001.
M i SMob i S Mob i Store - Mobile i nternet File Storage Platform Chetna Kaur.
An XMPP (Extensible Message and Presence Protocol) based implementation for NHIN Direct 1.
11/16/2012ISC329 Isabelle Bichindaritz1 Web Database Application Development.
Directories, Databases and Decisions A CTO’s view of Enterprise Management Solutions.
Philadelphia Area SharePoint User Group Building Customer/Partner Extranets Designing a Secure Extranet with Sharepoint 2007 Russ Basiura RJB Technical.
Migrating myUWindsor to Liferay Sanjay Chitte Shawn DenHartogh.
University of Wisconsin System HRS Project Update to ITC November 19, 2010.
Office Suite Recommendation the “white collar” productivity revolution By David Heise Monday, December 11, 2000.
Shibboleth: Installation and Deployment Scott Cantor July 29, 2002 Scott Cantor July 29, 2002.
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Riva Managed Identity Integration for Active Directory and Novell ® GroupWise ® Aldo Zanoni CEO, Managing Director Omni Technology Solutions
Internet2 CAMP Shibboleth Scott Cantor (Hey, that’s my EPPN too.) Tom Dopirak Scott Cantor (Hey, that’s my.
Real Life Solution, Real Life Problems: A-Select, An Open Source Federated Identity Management Solution An Identity 1.0 story Maarten Koopmans SURFnet,
Shibboleth: An Introduction
Internet2 Middleware Initiative Shibboleth Ren é e Shuey Systems Engineer I Academic Services & Emerging Technologies The Pennsylvania State University.
Shibboleth Access Management System Walter Hoehn & David Millman, Columbia University.
Outsourcing Student at USC Institute for Computer Policy and Law Cornell University, August 2008 Asbed Bedrossian Director of Enterprise Applications.
US of A and A Activities Ken Klingenstein, Director Internet2 Middleware Initiative.
Open Borders Project The new Open Borders Project — A merger of the old Open Borders (Project 2) and Connecting and Discovering Content (Project 10)
Shibboleth: Status and Pilots. The Golden Age of Plywood.
Project Shibboleth Update, Demonstration and Discussion Michael Gettes May 20, 2003 TERENA Conference, Zagreb, Croatia Michael Gettes.
Shibboleth: Installation and Deployment Scott Cantor July 29, 2002 Scott Cantor July 29, 2002.
Windows Role-Based Access Control Longhorn Update
UMBC’s WebAuth Robert Banz – UMBC
Shibboleth: OSU Early Adoption Scenarios Scott Cantor April 10, 2003 Scott Cantor April 10, 2003.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
The UW-Madison IAM Experience Building our Dream Home Presented by Steve Devoti, Senior IT Architect © 2007 Board of Regents of the University of Wisconsin.
Shibboleth at USMAI David Kennedy Spring 2006 Internet2 Member Meeting, April 24-26, 2006 – Arlington, VA.
Shibboleth 1.2 Technical Overview “So you thought 1.1 was complicated…” Scott Cantor The Ohio State University and Internet2 Scott Cantor.
WSO2 Identity Server 4.0 Fall WSO2 Carbon Enterprise Middleware Platform 2.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Authentication and Authorisation for Research and Collaboration Heiko Hütter, Martin Haase, Peter Gietz, David Groep AARC 3 rd.
Building and Implementing An Identity Management Roadmap John Taylor Manager, IT Security & Service Continuity Phil Hall Security Consultant Apologies.
Collaboration and Federated Identity Two powerful forces being leveraged – the rise of federated identity – the bloom in collaboration tools, most particularly.
Shibboleth Identity Provider Version 3
Single Sign-On Led by Terrice McClain, Jen Paulin, & Leighton Wingerd
Shibboleth Project at GSU
Ask A Librarian in the Blackboard Environment
CNI Spring 2006 Task Force Meeting
Introduction How to combine and use services in different security domains? How to take into account privacy aspects? How to enable single sign on (SSO)
Scott Cantor April 10, 2003 Shibboleth and PKI Scott Cantor April 10, 2003.
Supporting Institutions Towards a Shibbolized Infrastructure
Signet & Privilege Management
Shibboleth: Status and Pilots
Presentation transcript:

Shibboleth: Early Experience at OSU Scott Cantor October 28, 2002 Scott Cantor October 28, 2002

2 Funding and Interconnections No OSU funding explicitly supporting work Tasked with supporting an Ohio Board of Regents grant to develop a platform for competency-based learning (partnership with Apple and WebCT) Shibboleth a SSO umbrella for deployment of content alongside library resources and WebCT/Blackboard/Angel

3 Expectations and Motivations Personal stake in design and development More comprehensive testing vs. contrived developer testing Scope work needed to deploy as SSO solution Demonstrate LMS/Library integration Extend access to research projects beyond university

4 General Timeline Summer ’02: Deploy alpha origin using existing SSO service, assess data situation Fall ’02: Deploy alpha targets on library’s reverse proxy (ezproxy), OBR development server, LMS testbeds, other local applications (eg. Peoplesoft) Fall ’02: Participate in I2 pilot with external library vendors

5 General Timeline Winter ’03: Migrate to 1.0 code base Winter ’03: Assess functionality gaps in code, expected time line for enhancements from I2, and scope of work for deployment Winter ’03: Produce a plan for deployment with funding request attached Spring ’03: Go / no go (no go leads to “interesting” decisions on existing SSO system)

6 Origin Site Alpha Deployment Approach Hosting Handle Service behind existing SSO service, so user experience is (mostly) identical between Shibboleth applications and existing applications Provides clear migration strategy from Handle Service behind SSO to Handle Service as SSO once code supports it

7 Origin Site Alpha Deployment Issues Java made installation simple, but immediately had problems with LDAP (mixture of code issues and local issues), so very limited attributes Need for cleaner extension mechanisms in AA for custom attributes and caching OSU’s LDAP service not ready for use, not being actively developed or enhanced at the present time Comparing scope of work to build out LDAP or use RDBMS with Shibboleth AA

8 Alpha Target Deployments Proxying Resources Main Library rolling out ezproxy as an off- campus access solution Advised library on ezproxy authentication interface using one time username/passwords Deployed second proxy with Shibboleth as proof of concept and an OBR project resource “Real” deployment with proxy would use a routing script to detect on-campus access and bypass proxy, already part of library’s production proxy

9 Alpha Target Deployments Internal Application Development Deployed Windows port of alpha code to OBR grant development server to support applications being developed Extended code being reused for project to support EPPN-based authorization

10 Alpha Target Deployments Learning Management Systems Grant includes assessment of multiple LMS platforms (WebCT, Blackboard, Angel) for compliance with IMS standards and future support for competency-based instruction WebCT Vista price increase forcing reassessment of LMS platform choices Angel providing on-site test platform, worked with vendor to support Shibboleth using ISAPI port produced by me for EBSCO (almost working) WebCT provided a working demo using Shibboleth with external authentication API, not yet used for grant

11 Alpha Target Deployments 800 Pound Gorilla Parallel, unrelated activity investigating rollout of Peoplesoft self-service components Some existing ERP-related services (Brio) use campus SSO service already Common need for improved data to feed Shibboleth and new Peoplesoft applications Tentative plan to prototype use of Shibboleth as SSO and authorization feed for Peoplesoft, making Shibboleth deployment a component of ERP infrastructure (“follow the money”)

12 Internet2 Shibboleth Pilot Progress Participating in the formal pilot program, but somewhat under the radar (see funds, none) Vendors providing direct access with Shibboleth fit seamlessly alongside local resources OSU access to EBSCO works as of late September OCLC another possible test Many databases licensed and accessed through OhioLink consortium, constraining additional choices until they can be persuaded to participate

13 Internet2 Shibboleth Pilot “Wow, the technology was easy…” Access to EBSCO worked within minutes of the “try this URL” from company. Understanding the contractual picture took days, and is still only imperfectly understood. We have to understand what Shibboleth means today in order to explore tomorrow. Does emulating existing policies help with migration, or undermine the business case?

14 Internet2 Shibboleth Pilot Next Steps Interesting pilots require immediate consideration of how to subset users and communicate this to vendors (affiliation vs. entitlements vs. multiple origin sites) Need to send knowledge gained back to MACE-Dir to explore directory implications Need to engage campus resources for wider testing (“I built it, are they coming?”)

15 Shibboleth at OSU Next Steps Always viewed as a means to migrate from proprietary Web-ISO system to open standard, with federated features a bonus Shibboleth 1.0 is not going to be a great Web- ISO, but I believe it is the right design to build on Document and scope the road from point A to point B Point A isn’t sustainable, but funds are scarce, so check back in a year (and see if we’re at B or A-1)