Download presentation
Presentation is loading. Please wait.
1
Identity Management: Shibboleth Activity Update
Authentication and Authorization in the ADR
2
Alliance Member Institutions
University of Colorado Boulder, Denver (Downtown/Anschutz Medical Campus), Colorado Springs Colorado State University Fort Collins University of Northern Colorado University of Denver Regis University Colorado College Denver Public Library University of Wyoming Colorado School of Mines
3
Shifting Paradigms
4
Shifting Paradigms
6
Screenshots of Institutional Fez Portal Main Pages
19
FezACML Authorization
LEVELS Community Collection Record Primary Content File Datastream ROLES Lister Viewer Creator Editor Approver Commentor Comment Viewer Archival Master Viewer OBJECT CLASSES/ ATTRIBUTES AD Fez eduPerson
28
Leaving the librarians with a BIG question…
30
What do we put here?
31
What do we put here? Should I put staff or employee? Is this attribute available? What’s the OrgUnitDN for the Physics Department? For Alumni Relations?
32
Configurations and Sign-ons
Authentication Configurations and Sign-ons
37
Shib LDAP
38
eduPerson Attributes eduPersonAffiliation eduPersonEntitlement eduPersonNickname eduPersonOrgDN eduPersonOrgUnitDN eduPersonPrimaryAffiliation eduPersonPrimaryOrgUnitDN eduPersonPrincipalName eduPersonScopedAffiliation eduPersonTargetedID
39
Attribute Considerations
eduPersonScopedAffiliation Technically “scope” is a security domain. Institutions need to define and publish available scopes. (e.g. vs. Can multiple apply? (Use scope to get more granular)?
40
Attribute Considerations
eduPersonEntitlement Value is a URI (either URL or URN). Could be a name or locator of the “allowed” resource: Or could be a name of a “resource attribute” about the user: urn:mace:colorado.edu:course:psyc:1200:student
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.