1 Wolfgang Lierz Staff IT-Services / Network & Security Admin ETH-Bibliothek Zurich Integration Primo-Aleph-PDS-SSO- AAI Wolfgang Lierz / IGeLU 2012 Zurich Integration of Aleph/Primo with PDS into larger Shibboleth/SSO environments
2 Integration Primo-Aleph-PDS-SSO-AAI Why Single Sign-On anyway? Wolfgang Lierz / IGeLU 2012 Zurich We have alternatives: -Post-It around display -Post-It below keyboard -Browser password store -KeePass password store -Cloud password store -Facebook login
3 Integration Primo-Aleph-PDS-SSO-AAI Authentication and Authorization Infrastructure Wolfgang Lierz / IGeLU 2012 Zurich Without AAI-SSOWith AAI- SSO First ideas and workshop Project study and pilot Implementation
4 Integration Primo-Aleph-PDS-SSO-AAI AAI in Switzerland Wolfgang Lierz / IGeLU 2012 Zurich
5 Integration Primo-Aleph-PDS-SSO-AAI Authentication with nethz Wolfgang Lierz / IGeLU 2012 Zurich Authentication «Who am I » «nethz» database «nethz-login» HR / Students Administration ETH Zurich members Active Directory LDAP RADIU S AAI (Shibboleth ) Windows Exchange Sharepoint e-pics WLAN eduroam VPN e-collection. Proxy SMS Authorization «What may I do » «Same Sign On » «Single Sign On »
6 Integration Primo-Aleph-PDS-SSO-AAI Aleph in Switzerland Wolfgang Lierz / IGeLU 2012 Zurich ExLibris Aleph v20 (only NEBIS with PDS) 5 Systems Shared User File (SUF) accounts Integration UZH into NEBIS 2013 (INUIT) accounts 200 libraries
7 Goals within current NEBIS/Aleph operation: -eliminate separate individual user registration / activation process at library -enable nethz-userid for ETHZ staff and students -use nethz-attributes of ALL staff and students by Aleph and discontinue separate user management Integration Primo-Aleph-PDS-SSO-AAI AAI-SSO for ETHZ staff and students Wolfgang Lierz / IGeLU 2012 Zurich
8 Integration Primo-Aleph-PDS-SSO-AAI Aleph with nethz / PLIF nightly Aleph (Application) Aleph (Database) nethz SAP nethz AAI Indices PDS (login) Batch / Copy on request User / Copy at Login (at least daily) Batch / triggered by changes Wolfgang Lierz / IGeLU 2012 Zurich
9 Integration Primo-Aleph-PDS-SSO-AAI 2012: AAI-SSO for ETH members Wolfgang Lierz / IGeLU 2012 Zurich Authentication via «native» Aleph login (may disappear 2013) Authentication via «nethz-login» (AAI-SSO) (more selections 2013) Intermediate (PDS) Login page from September 2012 Embedded WAYF
10 (SSL connection) Private customers DB - Attributes from Aleph - Passwords only here New separate Private Customers IDP (at ETHZ) NEBIS/Aleph EAD00 Aleph (Oracle DB) Private customers Indices (Aleph) AAI IDP (operated by Switch) aai-login.libraries.ch PDS (login) with Shibboleth Integration Primo-Aleph-PDS-SSO-AAI 2013: AAI-SSO for private customers EAD50ZAD50UZH50 AAI IDP (at ETHZ) aai-login.ethz.ch (via nethz) WAYF Re(set) password password.libraries. ch (New) registration register.libraries.ch Initial Password other AAI IDPs INUIT future PIN-VHO E-Lending Primo FE e-shelf NEBIS Form for registration Wolfgang Lierz / IGeLU 2012 Zurich
11 Private customers DB - Attributes now HERE - Passwords only here Swiss-wide Private Customers IDP Alma ? AAI IDP (operated by Switch) aai-login.libraries.ch PDS as a separate service WITH attribute retrieval Integration Primo-Aleph-PDS-SSO-AAI Future: ID management outside Ex Libris AAI IDP (at ETHZ) aai-login.ethz.ch (via nethz) WAYF Re(set) password password.libraries. ch (New) registration register.libraries.ch other AAI IDPs Primo FE e-shelf Wolfgang Lierz / IGeLU 2012 Zurich Interface to external Identity Management E-Lending and others
12 For much more details see our report Single Sign On für e-lib.ch und sein Webportal (in German, 2012, 61 p.) e-collection.library.ethz.ch/view/eth:5453 Integration Primo-Aleph-PDS-SSO-AAI Further reading Wolfgang Lierz / IGeLU 2012 Zurich
13 Thanks to: -SSO project team of ETH-Bibliothek -ITS IT-Services of ETH-Bibliothek -ICT services of ETH Zurich -SWITCH AAI team -ELCA Informatik AG, Zürich Integration Primo-Aleph-PDS-SSO-AAI Credits Wolfgang Lierz / IGeLU 2012 Zurich
14 Thank you! Integration Primo-Aleph-PDS-SSO-AAI Questions ? Wolfgang Lierz / IGeLU 2012 Zurich SFX with PDS-SSO-AAI ?
15 Wolfgang Lierz / IGeLU 2012 Zurich DEMO