Agenda Introductions Brief review of our project charge Brief background on UCTrust and Shibboleth Brief review of Existing Campus Wireless Authentication Discussion of design Issues, for example: Required (and optional?) identity attributes Access to guest's campus's Identity Provider (IdP) system before authentication Next steps Future meetings
How Shibboleth Works - Simple Version User browses to Target Target asks user's institution's IdP for (e.g.) Affiliation Origin returns "Student" (for example) to Target Target returns requested information to user
How Shibboleth Works - Simple Version (User requests to view last month's issue of Science.) Institution's Shibboleth Origin Science Magazine Target
How Shibboleth Works - Simple Version Science asks the user's institution, "What is this person's affiliation with you?" Institution's Shibboleth Origin Science Magazine Target
How Shibboleth Works - Simple Version The user's institution answers, "This person is a student here." Institution's Shibboleth Origin Science Magazine Target
How Shibboleth Works - Simple Version The table of contents for last month's Science is returned to the user. Institution's Shibboleth Origin Science Magazine Target
How Shibboleth Works - Real Version Target must determine the user's institition before contacting the Origin (WAYF) Origin must authenticate the user before it can provide any attributes Target is not allowed to observe the authentication process
How Shibboleth Works (Outdated)