Download presentation
Presentation is loading. Please wait.
Published byPhilippa Craig Modified over 9 years ago
1
eduPerson is only part of the answer Leeds University David Holdsworth & Ray Powell http://www.personal.leeds.ac.uk/~ecldh/xlm4he/
2
XLM4HE project X.509 — identification LDAP — authorisation Middleware — incompatibilities for Higher Education — scalability, cost Part of Internet2/JISC collaboration in UK 2
3
Shibboleth Architecture DRAFT 3
4
Resource Provider’s Web Server XLM4HE Middleware XLM4HE Interactions http://129.11.152.25/xlm4heWeb site has step-by-step version 4
5
An Example in which Futile Operations On-Line (FOOL) to provide access to their on-line educational product called the Department of Futile Studies negotiates with a content provider called F-Systems 5
6
4. LDAP search : baseDN = namespace (i.e. FOOL ) certNum = certificate serial number certSign = certificate signer FOOL is requested attribute 4 University F-Systems 6
7
7. LDAP searchResponse : DN = whatever policy specifies FOOL = user’s status in accessing FOOL 7 University F-Systems 7
8
Shibboleth Equivalent 1 SHAR redirects browser to AA giving handle and product name (i.e. FOOL ) 1.0 00565d61-301c-1b1c-0010a4908950 newman.leeds.ac.uk 991702501 http:/www.f-systems.co.uk/futility.html 0015d1f1-307c-1b1c-9581-0010a4908950 FOOL 8
9
Shibboleth Equivalent 2 AA redirects browser to SHAR giving YES or NO 1.0 00565d61-301c-1b1c-0010a4908950 aa.iss.leeds.ac.uk 991702561 FOOL yes 9
10
Vanilla Shibboleth AA redirects browser to SHAR giving eduPerson attributes 1.0 00565d61-301c-1b1c-0010a4908950 aa.psu.edu 991702561 rshuey@psu.edu staff employee member 10
11
Trust Target must trust university to answer honestly –Trust already needed to believe attributes Target must check that AA is trusted for requested product –i.e. there is a contractual relationship –could be global list of trusted AAs 11
12
Conclusions Shibboleth has decision at target Attributes (eduPerson) sent to target Uniformity of eduPerson usage at all institutions is needed XLM4HE has decision at university Attribute release to target is minimal Simplicity at the target end More Trust of university is needed, but there has to be trust in either case. 12
13
Recommendation Include both mechanisms in Shibboleth architecture Let experience see whether decision is best at University or Resource Provider More information: http://129.11.152.25/xlm4he/ 13
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.