OpenAthens LA 2.0: a joined-up approach to identity

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    OpenAthens LA 2.0: a joined-up approach to identity - Presentation Transcript

    1. OpenAthens LA 2.0: A joined-up approach to identity OpenAthens workshops, May 2009 David Orrell, Eduserv david.orrell@eduserv.org.uk www.eduserv.org.uk
    2. Overview • Local authentication • Product background and goals • Architecture • Configuration processes • Roadmap and future developments
    3. What is OpenAthens LA? Software to enable federated access to internal and external Web resources
    4. Federated identity Service Providers Identity Provider (resources)
    5. Federated identity Service Providers Identity Provider (resources) Control Policy Subscriptions Management
    6. Running an identity provider System IT Services administrator Identity provider Librarian Configuration User-repository
    7. Our top 3 priorities for OpenAthens LA 2.0...
    8. Our top 3 priorities for OpenAthens LA 2.0...
    9. 1) Ease of installation, configuration & maintenance • Web-based administration • Built-in diagnostics and statistics
    10. 2) Support for multiple, Open Standards
    11. 3) Adaptable and extendable • Modular architecture • Open APIs – write your own extensions
    12. OpenAthens LA 2.0 • Administration control...
    13. OpenAthens LA 2.0: administration System administrator Administration Runtime server(s) server Runtime Model Librarian User-repository Staff / students
    14. OpenAthens LA 2.0: administration Administration server Model history Admin application(s) Model
    15. OpenAthens LA 2.0 • Runtime flexibility...
    16. OpenAthens 'Atacama' platform Protocol modules
    17. OpenAthens LA 2.0: modules • Authentication • Data-store connectors OpenAthens LA runtime • Identity protocols (SAML, OpenID Platform etc) • Attribute Webserver release policies • Custom attributes • …
    18. Runtime installation • Runtime connects to administration server • Multiple runtimes can point to the same server and model – Load-balancing – High availability Administration Runtime server(s) server Apache runtime Model
    19. Runtime installation • Install Apache module (mod_openathens) • Point runtime at administration console – ...in httpd.conf OAConfig http://admin.example.ac.uk/OalaAdmin/Publish/0/Apache
    20. Authentication • Built-in – LDAP – OpenAthens MD • Custom – Apache (eg. mod_authnz_ldap) – Kerberos – Windows domain – PHP, Perl... – ...or multiple methods
    21. Built-in authentication 1) Configure authentication providers in GUI 2) Configure runtime to use named provider <Location /oala/sso> AuthType OpenAthens:ldap require valid-user </Location>
    22. Custom authentication 1) Configure runtime to use custom provider – eg. mod_auth_..., PHP, mod_perl <Location /oala/sso> AuthType OpenAthens:php require valid-user </Location> 2) Write authentication provider ... $auth = new OALACustomAuth($userId); $auth->establishSession();
    23. Data handling Organisation boundary User-categories: Authenticated user Attributes Staff, students... User data Services, Federations, Partners Affiliates, alumni... Release policy
    24. Data-stores and user-categories • Enable organisation and description of users • Users may grouped be in multiple categories – ...but must be in at least one • Categories may be assigned by rules – ...or may be assigned explicitly • Attributes are assigned to categories
    25. Attribute types • LDAP • SQL database – MySQL – Microsoft SQL Server • Fixed value • Derived – eg. eduPersonTargetedID • Scripted
    26. Attribute release • Control flow of data leaving organisation • Control which attributes are sent to which service providers • Should only disclose minimum required “Release attribute x to everyone” “Release attribute y to service z”
    27. Thank you! david.orrell@eduserv.org.uk
    28. OpenAthens LA 2.0: release schedule July 2009: Sept 2009: Oct/Nov 2009: June 2009: .NET runtime .NET runtime 2.1 advisory Beta release alpha release GA release group March 2009: July 2009: end July 2009: Jan 2010: Initial Alpha Test VM images OpenAthens LA 2.0 2.1 release Apache GA release
    29. 2.1 release • Librarian console • Integrated statistics/diagnostics • More built-in authn options – including OpenID • More supported federations

    + EduservEduserv, 5 months ago

    custom

    457 views, 0 favs, 3 embeds more stats

    David Orrell, Identity Systems Architect at Eduserv more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 457
      • 418 on SlideShare
      • 39 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 11
    Most viewed embeds
    • 37 views on http://www.eduserv.org.uk
    • 1 views on http://www.eduserv.co.uk
    • 1 views on http://sysurl.systranet.com

    more

    All embeds
    • 37 views on http://www.eduserv.org.uk
    • 1 views on http://www.eduserv.co.uk
    • 1 views on http://sysurl.systranet.com

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories