Presentation is loading. Please wait.

Presentation is loading. Please wait.

TERENA TF-EMC2 15 feb 2011 Dyonisius Visser

Similar presentations


Presentation on theme: "TERENA TF-EMC2 15 feb 2011 Dyonisius Visser"— Presentation transcript:

1 AAI @ TERENA TF-EMC2 15 feb 2011 Dyonisius Visser visser@terena.rg www.terena.org

2 Slide 2 Where it all started ›REFEDS Wiki ›Dog food ›MediaWiki + SimpleSAMLphpAuth ›One SP ›Accumulated ~ 20 bilateral IdPs

3 AuthZ – sort of Slide 3 ›You’re in, if your IdP sends eduPersonEntitlement= ‘urn:mace:rediris.es:entitlement:wiki:tfemc2’

4 Next SP comes along ›TACAR ›Will need to contact several IdPs again to exchange metadata  ›3 rd SP ›4 th SP etc etc Slide 4

5 Too many IdP-SP combinations ›Difficult to manage: Slide 5

6 New approach: proxy ›Create one SP to connect as many IdPs as … ›“Hide” all our other SPs behind that ›SPs can all have one statically configured IdP ›So no need to have a disco on each SP ›External IdPs only do business with a single TERENA SP Slide 6

7 Slide 7

8 WordPress etc FileSender CORETACAR Sympa Event reg My.terena.org LinkedIn Yahoo Google Slide 8 OpenID Twitter MySpace † Windows Live SimpleSAMLphp Secretariat IdP LDAP Refeds wiki Confluence SimpleSAMLphp SP Proxy SimpleSAMLphp Bridge Guest IdPs… eduGAIN 3 more federations 15 more bilaterals… SURFfed AAI@EduHR ??????? IdP SP

9 ?????? = Globally unique ID ›Generate globally unique identifier for ALL users that could possibly come in ›Pick first available attr name+value from: ›eduPersonTargetedID ›eduPersonPRincipalName ›Openid/Twitter/FB/Myspace/windowslive/linkedin ›Append !IdP ›Result + demo: https://tnc2011.core.terena.orghttps://tnc2011.core.terena.org ›(PG table) Slide 9

10 Pre-login user provisioning ›Invitation system (demo) Slide 10

11 TO Do ›Central user repository (LDAP/SQL) ›Central group repository (DIY/Grouper/SURF/?) ›Profile page to manage your data (SWICTH’s javascript side bar/?) ›Account linking (Login4life,David? ) ›Consent dialog upon first login ›-> Cherry pickin’ from community Slide 11

12 Automated IdP checks? Slide 12 All configured IdPs IdPS that have our metadata IdPs that have our metadata and that send usable attrs

13 Issues encountered ›Changing your SP metadata at remote parties takes a long time ›So don’t start with 1K keys ›Non-federated users – guest accounts? ›Too many guest options now Slide 13


Download ppt "TERENA TF-EMC2 15 feb 2011 Dyonisius Visser"

Similar presentations


Ads by Google