Download presentation
Presentation is loading. Please wait.
Published byAubrey Griffith Modified over 9 years ago
1
Shibboleth Akylbek Zhumabayev September 2008
2
Agenda Introduction Description WS Standards WS-Federation Picture Grid Security GridShib References 2
3
Introduction Started in 2000 by Internet2/MACE Current version: 2.0 (March 19, 2008) http://shibboleth.internet2.edu Open source (Apache2 license) Large projects in 15 countries 3
4
Description Purpose: cross-domain access control Authentication: single sign-on (SSO) Authorization: attribute-based Additional feature: user privacy Platform: SOA - WS technologies Standard: WS-Federation 4
5
WS Standards XML, SOAP, WSDL, UDDI – no comments WS-Addressing: stateful resource behind WS XML-Encryption, XML-Signature: basic security WS-Security: how to carry secure data WS-Policy: how to define settings WS-Trust: how to manage tokens WS-Federation: how to process SAML token 5
6
WS-Federation Contributors: IBM, Microsoft etc. Purpose: cross-domain identity portability Current version: 1.1 (December, 2006) Carrier: SAML token Domain trust: WS-Trust Trust carrier: X.509 6
7
Picture user@X Identity Provider Identity Provider Service Provider Service Provider WAYF LDAP System Domain X Domain Y 1 2 3 Attributes 4 WS-Federation Username/password 7
8
Grid Security GSI: X.509 Certificates Client System CA MyProxy X.509 Entity Certificate Proxy Certificate Certificates 8
9
GridShib user@X Identity Provider Identity Provider GridShib WAYF LDAP System Domain X Grid System 1 2 3 Attributes Profile 4 WS-Federation X.509 9
10
References 1. Website: http://shibboleth.internet2.edu 2. Short introduction: http://iamsect.ncl.ac.uk/deliverables/docs/practical_access/index.html#id2462832 3. Technical Overview: http://grid.ncsa.uiuc.edu/presentations/shibboleth-intro-dec05.ppt 4,5. Integration with Grid: http://www.globus.org/toolkit/presentations/gridshib-pki06-final.pdf http://grid.ncsa.uiuc.edu/GridShib/presentations/GridShib-uk-april05.ppt 6. SAML introduction: https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/2a563903-0b01-0010-b9a1-d3875ff74b32 7. Use Case (article in IEEE): "ShibGrid: Shibboleth Access for the UK National Grid Service" Spence, D.; Geddes, N. http://ieeexplore.ieee.org.ezproxy.rit.edu/iel5/4090056/4090057/04090093.pdf?tp=&arnumber=4090093&isnumber= 4090057 10
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.