Presentation is loading. Please wait.

Presentation is loading. Please wait.

The I-Trust Federation: Federating the University of Illinois Keith Wessel Identity Management Service Manager University of Illinois at Urbana-Champaign.

Similar presentations


Presentation on theme: "The I-Trust Federation: Federating the University of Illinois Keith Wessel Identity Management Service Manager University of Illinois at Urbana-Champaign."— Presentation transcript:

1 The I-Trust Federation: Federating the University of Illinois Keith Wessel Identity Management Service Manager University of Illinois at Urbana-Champaign

2 Goal: retire legacy web sign-on service and replace with Shibboleth The challenge: U of Illinois’ three campuses maintain their own user and password stores and IDPs. Old Web SO allowed for inter-domain authentication for services used by users from multiple campuses. Goals and Challenges

3 Federate the three campuses. Use existing IDPs and user/password stores. Put a Shib SP on each service that currently uses the legacy system. Services that need to allow access to users from multiple campuses can point to a centralized discovery service. The solution

4 We have over 500 service providers behind the legacy system. Many allow access to users from more than one campus. Even with delegated SP administration, this would be costly and labor-intensive. This is also overkill to get SP data to the university’s three IDPs. If an SP needs to federate beyond the university, such as with another university, we will work with them to manually enter them in InCommon. Why not put everyone in InCommon?

5 Initial case was to simply get SSO functional and metadata circulating between the three campuses. Before we even announced it, our software webstore folks were asking questions. By adding other universities, community colleges and K-12 users, our software webstore could sell to more users and get larger discounts. State library consortium is also interested with the value of resource sharing through federation. We had these cases brought to us. After launch, we expect a lot more. The business case

6 1.Identify technical and management resources from each campus. 2.Agree that Urbana campus, the largest, will take the lead. 3.Compare attributes being released by all three IDPs to build and approve a list of common attributes. 4.Standardize names of federation attributes. 5.Set up common platform for maintaining and disseminating metadata and attribute release Planning

7 Discovery Service: Shibboleth project’s centralized discovery service is offered for SPs needing to allow access to all three campuses Metadata management and dissemination: Australian Access Federation’s Federation Registry. Metadata signing: Shibboleth project’s xmlsectool Nuts and bolts

8 An extensible, open web application that provides a central point of registration, management and reporting for identity and service providers participating in a standards compliant SAML 2 identity federation. Management for all aspects of SAML 2 compliant Identity and Service Providers SAML 2.x compliant metadata generation Additional assistance for Shibboleth IDP and SP administrators including automated Attribute Filter generation Public registration for Organizations, Identity Providers and Service Providers that are new to the federation Organizations can have any number of IDP and SP owned by them (service only organizations are popular with publishers for example) A personalized dashboard view of the federation for all users A cross browser (including mobile devices) HTML5 compliant user interface which can be branded for deploying organizations. Multilingual capable A fully customizable workflow engine to handle registrations and other critical federation changes In-depth reporting to gain insight to the workings of the entire federation Federation integrated, automatically provisioned user accounts with fine grained access control Federation Registry

9 Federation Manager Dashboard 9 – © 2012 Internet2

10 Create Service Provider 10 – © 2012 Internet2

11 Create Service Provider:description 11 – © 2012 Internet2

12 Create Service Provider:SAML configuration 12 – © 2012 Internet2

13 Create Service Provider:certificate 13 – © 2012 Internet2

14 Create Service Provider:attributes 14 – © 2012 Internet2

15 Create Service Provider:submit 15 – © 2012 Internet2

16 Approving a new Service Provider 16 – © 2012 Internet2

17 Bring community colleges, K-12 schools and others on-board. Federation-wide single logout: a big one to attack, but lots of requests already. Standardizing requests for two-factor authentication when needed. Future plans

18 Australian Access Federation: wiki.aaf.edu.au/federationregistry2 Contact for more on I-Trust: Keith Wessel, kwessel@illinois.edu Resources


Download ppt "The I-Trust Federation: Federating the University of Illinois Keith Wessel Identity Management Service Manager University of Illinois at Urbana-Champaign."

Similar presentations


Ads by Google