Presentation is loading. Please wait.

Presentation is loading. Please wait.

EduPerson is only part of the answer Leeds University David Holdsworth & Ray Powell

Similar presentations


Presentation on theme: "EduPerson is only part of the answer Leeds University David Holdsworth & Ray Powell"— Presentation transcript:

1 eduPerson is only part of the answer Leeds University David Holdsworth & Ray Powell http://www.personal.leeds.ac.uk/~ecldh/xlm4he/

2 XLM4HE project X.509 — identification LDAP — authorisation Middleware — incompatibilities for Higher Education — scalability, cost Part of Internet2/JISC collaboration in UK 2

3 Shibboleth Architecture DRAFT 3

4 Resource Provider’s Web Server XLM4HE Middleware XLM4HE Interactions http://129.11.152.25/xlm4heWeb site has step-by-step version 4

5 An Example in which Futile Operations On-Line (FOOL) to provide access to their on-line educational product called the Department of Futile Studies negotiates with a content provider called F-Systems 5

6 4. LDAP search : baseDN = namespace (i.e. FOOL ) certNum = certificate serial number certSign = certificate signer FOOL is requested attribute 4 University F-Systems 6

7 7. LDAP searchResponse : DN = whatever policy specifies FOOL = user’s status in accessing FOOL 7 University F-Systems 7

8 Shibboleth Equivalent 1 SHAR redirects browser to AA giving handle and product name (i.e. FOOL ) 1.0 00565d61-301c-1b1c-0010a4908950 newman.leeds.ac.uk 991702501 http:/www.f-systems.co.uk/futility.html 0015d1f1-307c-1b1c-9581-0010a4908950 FOOL 8

9 Shibboleth Equivalent 2 AA redirects browser to SHAR giving YES or NO 1.0 00565d61-301c-1b1c-0010a4908950 aa.iss.leeds.ac.uk 991702561 FOOL yes 9

10 Vanilla Shibboleth AA redirects browser to SHAR giving eduPerson attributes 1.0 00565d61-301c-1b1c-0010a4908950 aa.psu.edu 991702561 rshuey@psu.edu staff employee member 10

11 Trust Target must trust university to answer honestly –Trust already needed to believe attributes Target must check that AA is trusted for requested product –i.e. there is a contractual relationship –could be global list of trusted AAs 11

12 Conclusions Shibboleth has decision at target Attributes (eduPerson) sent to target Uniformity of eduPerson usage at all institutions is needed XLM4HE has decision at university Attribute release to target is minimal Simplicity at the target end More Trust of university is needed, but there has to be trust in either case. 12

13 Recommendation Include both mechanisms in Shibboleth architecture Let experience see whether decision is best at University or Resource Provider More information: http://129.11.152.25/xlm4he/ 13


Download ppt "EduPerson is only part of the answer Leeds University David Holdsworth & Ray Powell"

Similar presentations


Ads by Google