Identity and Access Management for Federated Resource Sharing: Shibboleth Stories



Similar documents
Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department

A Shibboleth View of Federated Identity. Steven Carmody Brown Univ./Internet2 March 6, 2007 Giornata AA - GARR

Licia Florio Project Development Officer Identity Federations in Europe

Federated Identity Management. Willem Elbers (MPI-TLA) EUDAT training

Shibboleth User Verification Customer Implementation Guide Version 3.5

Biometric Single Sign-on using SAML Architecture & Design Strategies

Federated Identity Management and Shibboleth. Noreen Hogan Asst. Director Enterprise Admin. Applications

Biometric Single Sign-on using SAML

Identity Management. Manager, Identity Management. Academic Technology Services. Michigan State University Board of Trustees

IAM, Enterprise Directories and Shibboleth (oh my!)

Using Shibboleth for Single Sign- On

SAML SSO Configuration

DAMe Deploying Authorization Mechanisms for Federated Services in the eduroam Architecture

Federated Identity Management Solutions

How Single-Sign-On Improves The Usability Of Protected Services For Geospatial Data

CERN Single Sign On solution

Shibboleth Configuration in Tübingen

Shibboleth N-Tier Support. Chad La Joie

Federations 101. An Introduction to Federated Identity Management. Peter Gietz, Martin Haase

Title: A Client Middleware for Token-Based Unified Single Sign On to edugain

Federated Identity Management

Web based single sign on. Caleb Racey Web development officer Webteam, customer services, ISS

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

The saga of WebFTS and Federated Identity

OSOR.eu eid/pki/esignature Community Workshop in Brussels, 13. November 2008 IT Architect Søren Peter Nielsen - spn@itst.dk

Toward campus portal with shibboleth middleware

Shibboleth Identity Provider (IdP) Sebastian Rieger

Collaboration in the Cloud. Niels van Dijk, SURFnet, CAMP, Nov , San Francisco

Flexible Identity Federation

Federated AAA middleware and the QUT SSO environment

Enabling Federation and Web-Single Sign-On in Heterogeneous Landscapes with the Identity Provider and Security Token Service Supplied by SAP NetWeaver

Protect Everything: Networks, Applications and Cloud Services

Разработка программного обеспечения промежуточного слоя. TERENA BASNET Workshop, November 2009 Joost van Dijk - SURFnet

Federated Identity Management

HP Software as a Service

S P I E Information Environments Shibboleth and Its Integration into Security Architectures. EDUCAUSE & Internet 2 Security Professionals Conference

Standards and Guidelines for. Information Technology. Infrastructure, Architecture, and Ongoing Operations

Evaluation of different Open Source Identity management Systems

DocuSign Single Sign On Implementation Guide Published: March 17, 2016

Federated Identity for Cloud Computing and Cross-organization Collaboration

Getting Started with Single Sign-On

External and Federated Identities on the Web

New Single Sign-on Options for IBM Lotus Notes & Domino IBM Corporation

The Primer: Nuts and Bolts of Federated Identity Management

Integrating Apex into Federated Environment using SAML 2.0. Jon Tupman Portalsoft Solutions Ltd

Keeping access control while moving to the cloud. Presented by Zdenek Nejedly Computing & Communications Services University of Guelph

Introducing Shibboleth

The Primer: Nuts and Bolts of Federated Identity Management

Identity opens the participation age. Dr. Rainer Eschrich. Program Manager Identity Management Sun Microsystems GmbH

OpenSSO: Simplify Your Single-Sign-On Needs. Sang Shin Java Technology Architect Sun Microsystems, inc. javapassion.com

Federated Identity: Leveraging Shibboleth to Access On and Off Campus Resources

GFIPM Implementation Guide Version 1.0

Research and Implementation of Single Sign-On Mechanism for ASP Pattern *

Cloud Standards. Arlindo Dias IT Architect IBM Global Technology Services CLOSER 2102

An Oracle White Paper Dec Oracle Access Management Security Token Service

Connecting Web and Kerberos Single Sign On

Middleware integration in the Sympa mailing list software. Olivier Salaün - CRU

Authentication Integration

AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle

IBM Tivoli Federated Identity Manager V6.2.2 Implementation. Version: Demo. Page <<1/10>>

Copyright 2012, Oracle and/or its affiliates. All rights reserved.

Digital Identity and Identity Management Technologies.

Authentication Context Classes for Levels of Assurance for the Swedish eid Framework

Integrating Multi-Factor Authentication into Your Campus Identity Management System

About Me. Software Architect with ShapeBlue Specialise in. 3 rd party integrations and features in CloudStack

HP Software as a Service. Federated SSO Guide

How To Manage Identity On A Cloud (Cloud) With A User Id And A Password (Saas)

IGI Portal architecture and interaction with a CA- online

Computer Systems Security 2013/2014. Single Sign-On. Bruno Maia Pedro Borges

Get Success in Passing Your Certification Exam at first attempt!

SAML Federated Identity at OASIS

Getting Started with Single Sign-On

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

Transcription:

Identity and Access Management for Federated Resource Sharing: Shibboleth Stories http://arch.doit.wisc.edu/keith/apan/ apanshib-060122-01.ppt Keith Hazelton (hazelton@doit.wisc.edu) Sr. IT Architect, University of Wisconsin-Madison Internet2 Middleware Architecture Committee for Education (MACE) APAN, Tokyo, 22-Jan-06

Topics http://arch.doit.wisc.edu/keith/apan /apanshib-060122-01.ppt Thesis: Growing adoption of SAML for AuthNZ between parties in Education & Research SAML & Shibboleth Evidence for thesis NRENs and licensed resource providers Beijing University / Harvard / U Wisconsin: Collaborative Development of the China History Biographical Database Shibboleth, SAML, WS-*, Grids: Coming developments 2

Security Assertion Markup Language SAML (OASIS Security Services TC) 1.1 and 2.0 ratified Support for end-to-end, application-level security Complements transport- and message-level security XML schema around authentication and authorization Addresses a key requirement in federated environments One (or more) Identity Provider (IdP) parties asserting Authentication/Attribute/Authorization information Different party, a service provider (SP), relying on this information to provide a service or access to a resource 3

The federated access scenario SWITCH AuthN/AuthZ Infrastructure (AAI) Site 4

Shibboleth: A SAML Implementation for Research & Education Developed by Internet2 with assistance from NSF Current version: Shibboleth 1.3, supports SAML 1.1 Shibboleth is a software suite implementing SAML It is also a profile of SAML (profiles support interop.) It is also an active global community engaged in open source development and support http://shibboleth.internet2.edu 5

Evidence for the thesis: SHIB / Athens Athens: UK-wide service Managing higher ed <=> vendor licenses for access to digital resources Providing a shared authentication service for all UK higher ed users; Joint Information Services Committee (JISC) decision to shift from proprietary AuthN to Shib 6

Evidence for the Thesis: SHIB / Athens EduServ service provider currently offers an Athens-Shib gateway (bi-directional) JISC rewriting contracts: Vendors must be shib service providers at contract renewal. Transition to be complete by 1/1/2007 7

Evidence for the Thesis: BECTA Supports IT needs of K-12 in UK 3,000,000 users Now recommending adoption of Shibboleth for Federated Identity and Access Management http://www.becta.org.uk/corporate/display.cfm?section=22&id=4665 8

More evidence: Europe/Australia/US NREN consortium: Vendor resources as Shibboleth SPs Finland, Denmark, Germany Switzerland Netherlands, Belgium France Spain UK, Australia, US; Discussions w. Greece, Hungary, NREN-scale Shib feds in test or production Coordinating approaches to vendors on Shibbing their resources 9

Beijing University / Harvard / U Wisconsin: China History Biographical Database Well-established international collaborative to maintain and expand a database of tens of thousands of historical figures from China's imperial past. Currently exploring possible shift from file exchange model to federated application model Exploratory Shibboleth pilot project underway 10

Beijing University / Harvard / U Wisconsin: China History Biographical Database In pilot, content experts at Beijing University ( 北 大, PKU) would access: Shib-protected Web applications at Harvard that query/update the database PKU would be the Identity Provider Service Provider would be Harvard PHP/MySQL app running under Apache/Tomcat 11

Shibboleth at Beijing University (PKU) Slides courtesy of PKU sponsor, Prof. ZHANG Bei ( 张 蓓 ) Initial contacts at APAN in Taipei in August Work began in earnest after CANS meeting in December in Shenzhen 12

A glance at PKU Shibboleth internet2.edu InQueue WAYF PKU Campus Network Client Identity Provider {foo}.pku.edu.cn Service Provider {bar}.pku.edu.cn Attribute Repository {dir}.pku.edu.cn (LDAP server) 13

PKU in InQueue Both our IdP and SP have joined InQueue of Internet2 Our IdP has been successfully tested with https://wayf.internet2.edu/inqueue/sample.jsp To authenticate with our IdP, choose Peking University Test Install on the InQueue WAYF service page The redirection of client from SP to IdP can go with/without WAYF Currently working on fully utilizing the attribute exchange mechanisms provided by Shibboleth 14

Future steps at PKU Configure IdP to authenticate end-users with our Web SSO solution Deploy Shibboleth within PKU Co-operate with other educational institutions Establish a federation within CERNET Provide membership management Set up our own WAYF service 15

Shibboleth, SAML, WS-*, Grids: Coming attractions Initial MS federation support available in Active Directory Federation Services (ADFS) Essentially a WS-Sec, WS-Fed profile, but not published A Shib-ADFS gateway is in Beta Shib adds an end-point in IdP that can interoperate with a MS ADFS system Communicates via WS-Security ADFS components comparable to Shib IdP & SP Use Shib IdP in conjunction with ADFS SP & viceversa 16

17

18

Shibboleth, SAML, WS-*, Grids: Coming attractions Shib 2.0 Beta expected in May, 2006 Formal release by end of summer Will support SAML 2.0 Will address the N-Tier problem Constrained delegation model Seeking to work with various standards bodies 19

Shibboleth, SAML, WS-*, Grids: Coming attractions OpenSAML 2.0 well underway Shib 2.0 will have an AuthN engine because it is necessary to meet SAML 2.0 requirements Watch shibboleth-dev@internet2.edu mailing list for a list of features Linking attributes from multiple identity providers Shib 2.0 code will support Shib 1.3 endpoints Will include a pure Java implementation Takes Shib beyond simple web app scenarios 20

Shibboleth, SAML, WS-* SAML 1.1 profile included in WS-Sec Interfederation gateway products available, more coming Demoed at Catalyst 2005 SAML tokens included in WS-Sec payloads to carry AuthNZ information 21

The state of play with WS-* SAML in wide use in production environments WS-Sec is out & in use, but what of WS-*? WS Trust, WS Federation in particular Complexity is their hallmark 22

The state of play with WS-* WS-* Still in flux Open source implementations lacking True inter-vendor interoperability not yet within reach Specifications don't provide it Only profiles of specifications can WS-* profiles don't yet exist 23

Q & A 24