Download presentation
Presentation is loading. Please wait.
Published byAbigayle James Modified over 9 years ago
1
2004 © SWITCH 1 Shibboleth in Switzerland Internet2 Spring Meeting 2004 Thomas Lenggenhager lenggenhager@switch.ch Overview SWITCH & SWITCHaai Project SWITCHaai Federation Virtual Home Organizations Shibbolizing WebCT with the AAI-Portal
2
2004 © SWITCH 2 SWITCH SWITCH – The Swiss Education & Research Network a foundation of the federal and regional governments provides connectivity redundant dark-fiber based backbone and network services for Swiss universities AAI, video conference, mail gateways, … 12 universities 110’000students47’000 faculty & staff 7 universities of applied sciences 36’000students17’000 faculty & staff Swiss population ~ 7 million http://www.switch.ch/
3
2004 © SWITCH 3 SWITCHaai SWITCHaai – Authentication & Authorization Infrastructure Shibboleth selected as architecture in mid 2003 current status: migration from pilot to production service 5 Home Organizations at bigger universities SWITCH HomeOrg & Virtual Home Organization (VHO) 3 e-learning resources in use by students public demo resources http://www.switch.ch/aai/demo/ http://www.switch.ch/aai/
4
2004 © SWITCH 4 SWITCHaai Federation SWITCH acts as federation service provider Federation membership based on signed service agreements
5
2004 © SWITCH 5 Virtual Home Organization – VHO Problem: Users without a shibbolized Home Org What shall they do? Solution: Virtual Home Organization The exception, not the rule! Minimal information Clearly marked as special users through swissEduPersonHomeOrganizationType = vho use of entitlement attribute for authorization Project/resource oriented Users managed by the project/resource owner One user might have multiple identities
6
2004 © SWITCH 6 The AAI-Portal Developed by an e-learning project in Switzerland needs user management easy authorization control for various applications concept with back-end adaptors uses Apache, PHP and MySQL is open source http://aai-portal.sourceforge.net/ was the first shibbolized application in Switzerland
7
2004 © SWITCH 7 Shibboleth-enabled WebCT Servers AAIportal 0.9.5 WebCT CE Adaptor WebCT Vista Adaptor WebCT Vista WebCT CE Shibboleth once per session session itself
8
2004 © SWITCH 8 Shibbolized WebCT-login process e-ticket =hash of WebCT URL, UserID & shared secret with WebCT WebCT IMS API 1) Shibboleth protected login 4) Automatic WebCT login with e-ticket AAIportal 3) Redirect with e-ticket WebCT Vista Adaptor WebCT Vista Shibboleth 2) Create/modify user course membership WebCT Standard API once per session session itself
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.