Technical Developments within the UK Access Management Federation

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Technical Developments within the UK Access Management Federation - Presentation Transcript

    1. UK federation development Access Management Transition Meeting, 30 May 2007. Josh Howlett, UKERNA.
    2. Overview
      • Improving Discovery
      • Extending our use of metadata
      • Shibboleth 2.0
      • Other access management products
      • Inter-federation
      • Integration with eduroam
    3. Discovery
      • What is the ‘discovery problem’?
        • SAML 1.x
          • ‘ IdP-first’ only
          • Intended for small numbers of known partners; discovery is managed by the application.
        • Shibboleth 1.x
          • Shibboleth Authentication Request Profile is ‘SP-first’.
          • Intended for large numbers of possible partners; discovery is typically managed by the WAYF service.
        • WAYF issues: usability and scalability
    4. Discovery
      • Service Provider side discovery
        • Preferred approach.
        • SPs know their customers.
        • Shibboleth 2.0 SP will probably provide some assistance.
      • Discovery service
        • Enables an SP to hand over discovery to a third-party.
        • Potential for use of heuristics such as IP address of user agent.
    5. Metadata
      • What is federation metadata?
          • “ In architecture, a keystone is the stone at the top of an arch. It the supporting element for the entire arch — without it the arch would collapse.” – Wikipedia
        • Functions
          • A directory of federation participants – where ?
          • A description of their capabilities – what ?
          • Establishment of technical trust – who ?
    6. Metadata
      • Trust
        • PKI trust (today)
          • Entity metadata gives the claimed “KeyName”.
          • The “KeyName” must match that given in an entity’s certificate, issued by a trusted CA.
        • Problems
          • Trust validation is expensive and contains redundancy.
          • PKI can be difficult  support problems.
          • Some SAML 2.0 features (eg. attribute encryption) require access to entities’ public keys.
    7. Metadata
      • Trust
        • Direct key operation
          • Public keys embedded directly in metadata (or wrapped within certificate in metadata).
          • Available in Shibboleth 1.3+.
        • Hybrid operation
          • Use both PKI trust and direct key.
          • Currently in testing; may be made more widely available in the future.
    8. Shibboleth 2.0
      • Shibboleth 2.0
        • Virtually a complete re-write.
        • Support for (some of) SAML 2.0
          • Web SSO and Single Log-out profiles.
          • Additional capabilities likely in future releases.
        • IdP
          • More powerful ARP expression.
          • Scripting for enhanced attribute resolution.
    9. Other AM solutions
      • Shibboleth is the recommended AM software.
        • Designed for education and research.
      • Many other SAML implementations exist.
      • The moves towards Shibboleth 2.0 and SAML 2.0 should improve interoperability.
      • We need to understand more about these other products and their suitability.
    10. Shibboleth on Windows
      • Shibboleth IdP currently runs on Windows, although installation is complex.
      • Windows installer is in development.
      • We’re looking for:
        • Ideas, wish lists, etc.
        • Guinea pigs.
    11. Inter-federation
      • Multiple emerging federations for education and research.
      • Diverse policy and technological strategies.
      • Use cases
        • Reduce burden on publishers
        • Facilitate cross-federation access to resources such as wikis, VLEs, etc.
    12. Inter-federation
      • Inter-federation
        • Leveraged federation
          • Group within a group
        • Federation peering
          • Bilateral agreement
        • Confederation
          • Federation of federations
    13. Integration with eduroam
      • RAGS
        • Experimental out-sourced IdP using eduroam for authentication.
      • RADIUS-SAML
        • Internet2 proposal to use SAML for eduroam authorisation.
    14. Thank you for your attention
      • Any questions, ideas or requirements?

    + JISC.AMJISC.AM, 3 years ago

    custom

    1620 views, 0 favs, 0 embeds more stats

    Presentation at the JISC Access Management Transiti more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 1620
      • 1620 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 37
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories