Single Sign On Single sign on, more than a single step. Robert Stockton,

Slides:



Advertisements
Similar presentations
MFA for Business Banking – Security Questions with 2nd Request Multifactor Authentication: Quick Tip Sheets Note to Financial Institutions: We are providing.
Advertisements

MFA for Business Banking – Security Code Multifactor Authentication: Quick Tip Sheets Note to Financial Institutions: We are providing these QT sheets.
MFA for Business Banking – Security Questions with Reset Multifactor Authentication: Quick Tip Sheets Note to Financial Institutions: We are providing.
Athens and Shibboleth ® : the choices Phil Leahy Athens Product Manager.
Directorate of Learning Resources Accessing electronic journals from off-campus This causes lots of headaches, but dont despair, heres how to do it! If.
E-books and E-journals Off-campus This presentation will show you how to log in and access Oxford Brookes Library e-books and e-journals when youre off.
Next Generation Athens Services Ed Zedlewski UK e-Science Town Meeting, London, 11 April 2005.
E-books and E-journals Off-campus This presentation will show you how to log in and access Oxford Brookes Library e-books and e-journals when youre off.
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
How-to Use iLab Solutions software within Auckland Science Analytical Services in the Faculty of Science, the University of Auckland Auckland Science Analytical.
SIMS Learning Gateway Ben Jones – Product Manager.
Novell iChain ® 2.x Configuration Using the Web Server Accelerator Wizard Cary Andrews Senior Software Engineer Novell, Inc.
OSCARS - Support for Remote Users 8 September 2006 Information & Library Services and The University of Greenwich Gateway Maggie.
Single Sign-On 1. What is Single Sign-On? 2 The Florida Department of Education (FLDOE) Single Sign-On (SSO) provides a simpler way for educators to access.
TRIRIGA Anywhere 10.4 Beta Registration Steps
Alumni Authentication… Explained Robert Scaysbrook – OpenAthens UK Account Manager.
Hosted Exchange The purpose of this Startup Guide is to familiarize you with ExchangeDefender's Exchange and SharePoint Hosting. ExchangeDefender.
Developments in Access and Identity Management Phil Leahy – Athens Product Manager.
Introductory Meeting. Why are we here? RIP FrontPage Versions prior to 2003 will not work with Windows7 No longer supported by Microsoft You can still.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Integrating with UCSF’s Shibboleth system
Password Recovery Via Customer Care. Account Detail Via Customer Service. Account Configuration With Our Experts. You Want Recover All information.
Library Services welcomes Postgraduate Researchers Gerald Watkins Library Services Subject Advisor (Government and Society; Social Policy)
Simplify TeleHealth - Copyright 2012 Emerge.MD inc - Confidential Single Sign On via Active Directory Federation Services 4.6 Release (March 2014) Updates.
Milestone SAP Portal Learning at the Lakes August 12, 2009.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Amber Johnson U.S. Department of Education WVASFAA Fall 2015 Conference October 29, 2015 FSA ID: The FSA PIN Replacement.
Adxstudio Portals Training
MassHealth Medicaid Management Information System (MMIS) Provider Online Service Center (POSC) Technical Upgrade January 13, 2016.
Message Validation, Processing, and Provisioning System (MVPS) Access for Jurisdictions User has SAMS User ID Center for Surveillance, Epidemiology, and.
KC-ROLO Project Kidderminster College Repository Of Learning Objects Graham Mason & Ed Beddows.
The world’s libraries. Connected. Setup and management of OCLC Services accounts for access to WorldShare ® Interlibrary Loan OCLC Training and Support.
Slavko Kukrika MVP Connect Windows 10 to the Cloud – Cloud Join.
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Business Objects XIr2 Windows NT Authentication Single Sign-on 18 August 2006.
Step 1 Lead Notifications Dear Partner, New leads have been assigned to your organization based on customer preference and are available for you.
1 Logging into the new PCard (PaymentNet) System: PAYMENTNET * Introduction * May use IE 8.0 or greater or Firefox * Do not.
Installing and Configuring Moodle. Download Download latest Windows Install package from Moodle.orgMoodle.org.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Justin Scheitlin Daisey Fahringer
Shibboleth and eLibrary
INFORMATION TECHNOLOGY NEW USER ORIENTATION
E-Safety Briefing
Single Sign-On Led by Terrice McClain, Jen Paulin, & Leighton Wingerd
Authentication Interact Cloud.
Welcome.
Materials Engineering Product Data Management (ePDM)
Multi-Factor Authentication (MFA)
Shibboleth Implementation in EZproxy
How To Use As Another Account On Gmail
Cloud Connect Seamlessly
What is Google Classroom?
ESA Single Sign On (SSO) and Federated Identity Management
Multifactor Authentication & First Time Login
How to create a Parent PowerSchool ID and Access Student Pages
GALILEO & OpenAthens: 21st Century Authentication for GALILEO Participating Libraries Christopher Holly Director of SaaS Innovation, EBSCO
GALILEO & OpenAthens: 21st Century Authentication for GALILEO Participating Libraries Christopher Holly Director of SaaS Innovation, EBSCO
TaxSlayer Multi-Factor Authentication
The Smarter Balanced Assessment Consortium
Office 365 Identity Management
E-Invoicing for Network Access Customers
INFORMATION TECHNOLOGY NEW USER ORIENTATION
Contact Groups.
MSC Online Training Handbook
The OpenAthens Admin Dashboard provides a high-level snapshot of account activity and resource usage, along with shortcuts to other areas of the Admin.
The first time you login in to the upgraded system, please select ‘Forgotten your password?’ to reset your password before using the system.
Student user guide for getting started with Microsoft
Presentation transcript:

Single Sign On Single sign on, more than a single step. Robert Stockton,

Introduction The initial plan: Single Sign-on for all our resources Remove students having to sign in again to Athens as they forget and believe some resources are not available Allow direct links to material from VLE Single point of contact for resources for staff and students Provide a platform for Context aware personalised messages for staff and students

Challenges No budget for ‘high end connect it all together solutions’ Limited knowledge in house Didn’t want to break anything on the way!

Original Setup Services in multiple locations Not always obvious what we provide Many logon boxes to use, encourages people to type credentials in anywhere they see a logon box Mixture of: LDAP authentication Athens DA authentication ADFS Proprietary logons

Moodle (ADFS) Student records Panopto ClickView Staff Directory Logins…Logins…Logins…! Security: we are teaching users to use any box they get presented with. Student Downloads

Initial working diagram

Outdated original AthensDA Setup, which used a WAYF Student / Staff Attempt to Access Resource Wrexham Glyndwr My Athens Portal Is the user authorised? (Open Athens) Yes No Show Resource via browser to the user Authenticated against AD via a classic ASP page hosted at Glyndwr

The vision Centralise authentication services in one place Remove multiple login box’s Standardise username presentation: some times we or just student ID without details Entry credential once only Improve security, build a platform for 2 Factor Auth

So where next We approached ProofID for some guidance and consultancy They advised there was no single solution (without buying a expensive commercial product) which would provide SAML2 and ADFS intergration at the time. We decided to move forward with SAML2 for Library resources and Moodle so links between the two worked better when providing click through reading lists etc. We implemented SAML2 using ProofID (Salford software) but had issues and delays and also needed to move all SP’s from Athens federation to the Shib federation. In the process of talking to Eduserve about moving. Eduserve now promised they had a single solution which married ADFS and SAML2, not on the table when we started with ProofID.

So back to Eduserv The solution would use ADFS for authentication for the SAML2 process. Killing two birds with one stone. Create ADFS linked with Open Athens SAML2 Create a user portal with OpenAthens SP which would be the landing logon for all users

Our setup with Athens and ADFS and Athens SP Student / Staff ADFS Trust Setup between Our ADFS and OpenAthens Federation and UK access Management Federation Attribute release Username Attempt to access a resource SAML token exists? Access Glyndwr Resource Example Open athens etc No Yes Show resource Access Portal site Athens SP Attempt to Access Portal

Project go live date Project Start date June 2015 Beta testing completed August 2015 Go live date was for Sept 15/16 academic year Go live now this summer ready for 16/17 Why the delay?

Problems – ADFS Personalisation When logging into a resource via an OpenAthens an ID (5 digit number) is attached to the account. This identifies users in external resources. Initial thought that this would affect all our resources – thankfully only three resources were affect First Attempt to go live - We didn’t realise that the legacy OpenAthens ID would be a problem, Reversed out change (quickly) - Added an attribute into Active Directory with the old ID - Released this via ADFS Second Attempt to go live - DawsonEra – Worked Successfully - ScienceDirect – Worked Successfully - Refworks – Unsuccessful – Reversal Required Third Attempt to go live -Looked at options launch with a dual login (Old and new Athens) to get around Refworks problem of not allowing two ID’s. This was not a runner in the end. Needed to fix Refworks issue.

Refworks Refworks has personalization i.e. user account for those that use it. Changing token ID would orphan accounts Students have left for the summer so no asking them to archive references during handover. This has taken since Nov 2015 to resolve with constant chasing Refworks didn’t support standard attributes so we could not seamlessly use old DA attribute and new ADFS attribute to keep bookmarks 5 digit ID code with DA now we use new ID code. Other SP’s such as Dawsons Era and Science direct worked fine. We not want to loose all student refworks details (would not look good) Refworks has given us a list of accounts with name and address (some are private not university) They have not actual Student ID with the account. We had to manually logon to several thousand accounts, export references ready to import after handover!

Delays with the project – Athen SP We had to wait for our test environment to be setup (month, had to move ADFS in their registration space) It took some time to work out the flow of traffic to the new MyUni Portal (Dev time month) Configuration issues – not knowing the Athens SP product All these did add to the delay of the project

Other issues We are going to be the first institute to switch over from Athens DA to ADFS authentication (Over 40 institutions in the UK still using DA) Always nice to be the first? Eduserv had their own technical issues implementing the test environment

So where are we now myuni.glyndwr.ac.uk Centralised Portal without SSO

Simplified logon for ADFS users Modified ADFS logon script Users of ADFS no longer have to type in or staff with They can just type in S or staffname and password. See Technet: Advanced Customization of AD FS Sign-in Pages

Have we finished? No… But we’re almost there SSO planed to all be working by July

What next - The future Location specific headers - Wrexham - Wrexham - London - London - Staff - Staff Customised information to all our students and staff Multi-Factor Authentication with ADFS to improve security

Questions ?