0
OpenAthens LA 2.0 – Connecting to the UK Federation Richard Annett – May 2009
UK Federation <ul><li>Join The Federation </li></ul><ul><li>Registering the Identity Provider </li></ul><ul><ul><li>Single...
Core Attributes  <ul><li>EduPerson TargetedID </li></ul><ul><ul><li>Opaque user id. </li></ul></ul><ul><li>EduPerson Scope...
Service Provider <ul><li>Specific Attribute requirements </li></ul><ul><ul><li>http:// www.ukfederation.org.uk/content/Doc...
Configuring the Runtime <ul><li>Tell the run time where to find the configuration </li></ul><ul><ul><li>http://example.com...
Architecture Run time Admin Server Service Provider End User LDAP Database Data Stores
Configuration <ul><li>Admin Console </li></ul><ul><ul><li>Authentication </li></ul></ul><ul><ul><ul><li>LDAP </li></ul></u...
Lets do it! <ul><li>Service Providers (I can use!) </li></ul><ul><ul><li>JiscMail </li></ul></ul><ul><ul><ul><li>eduPerson...
The visiting Lecturer <ul><li>You don’t want them in your directory </li></ul><ul><li>But they require access to your onli...
Upcoming SlideShare
Loading in...5
×

Open Athens LA: Connecting to the UK Federation

905

Published on

Richard Annett, Federated Identity Specialist at Eduserv, talks about connecting to the Uk Federation.

Published in: Education, Technology
0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total Views
905
On Slideshare
0
From Embeds
0
Number of Embeds
3
Actions
Shares
0
Downloads
5
Comments
0
Likes
0
Embeds 0
No embeds

No notes for slide

Transcript of "Open Athens LA: Connecting to the UK Federation"

  1. 1. OpenAthens LA 2.0 – Connecting to the UK Federation Richard Annett – May 2009
  2. 2. UK Federation <ul><li>Join The Federation </li></ul><ul><li>Registering the Identity Provider </li></ul><ul><ul><li>Single Sign Service endpoints </li></ul></ul><ul><ul><li>X.509 Certificate </li></ul></ul><ul><ul><li>Scope </li></ul></ul>
  3. 3. Core Attributes <ul><li>EduPerson TargetedID </li></ul><ul><ul><li>Opaque user id. </li></ul></ul><ul><li>EduPerson Scoped affiliation </li></ul><ul><ul><li>Member </li></ul></ul><ul><ul><li>Staff </li></ul></ul><ul><ul><li>Student </li></ul></ul><ul><ul><li>... </li></ul></ul><ul><li>EduPerson Entitlement </li></ul><ul><ul><li>When nothing else will do! </li></ul></ul><ul><li>EduPerson Principal Name </li></ul><ul><ul><li>Unique ID. E.g first.last@example.com </li></ul></ul>
  4. 4. Service Provider <ul><li>Specific Attribute requirements </li></ul><ul><ul><li>http:// www.ukfederation.org.uk/content/Documents/AttributeUsage </li></ul></ul><ul><li>Registering </li></ul><ul><ul><li>Being a federation member is not enough. You must have an agreement with the resource provider </li></ul></ul>
  5. 5. Configuring the Runtime <ul><li>Tell the run time where to find the configuration </li></ul><ul><ul><li>http://example.com/OalaAdmin/Publish/ukfederation/0/Apache </li></ul></ul><ul><li>Enable the templates </li></ul><ul><li>Protect the Login Location </li></ul>
  6. 6. Architecture Run time Admin Server Service Provider End User LDAP Database Data Stores
  7. 7. Configuration <ul><li>Admin Console </li></ul><ul><ul><li>Authentication </li></ul></ul><ul><ul><ul><li>LDAP </li></ul></ul></ul><ul><ul><li>Data stores </li></ul></ul><ul><ul><ul><li>LDAP </li></ul></ul></ul><ul><ul><ul><li>Relational Database </li></ul></ul></ul><ul><ul><li>User categories </li></ul></ul><ul><ul><li>Attributes </li></ul></ul><ul><ul><li>Federation </li></ul></ul>
  8. 8. Lets do it! <ul><li>Service Providers (I can use!) </li></ul><ul><ul><li>JiscMail </li></ul></ul><ul><ul><ul><li>eduPersonTargetedID </li></ul></ul></ul><ul><ul><li>Internet2 Wiki </li></ul></ul><ul><ul><ul><li>eduPersonPrincipalName </li></ul></ul></ul><ul><ul><li>UK Federation Test SP 1 </li></ul></ul><ul><ul><ul><li>None . But lets assume the following </li></ul></ul></ul><ul><ul><ul><ul><li>eduPersonScopedAffiliation </li></ul></ul></ul></ul><ul><ul><ul><ul><li>eduPersonEntitlement </li></ul></ul></ul></ul><ul><ul><li>UK Federation Test SP 2 </li></ul></ul>
  9. 9. The visiting Lecturer <ul><li>You don’t want them in your directory </li></ul><ul><li>But they require access to your online resources. </li></ul>
  1. A particular slide catching your eye?

    Clipping is a handy way to collect important slides you want to go back to later.

×