Download presentation
Presentation is loading. Please wait.
Published byBrent Franklin Modified over 9 years ago
1
Shibboleth Update January, 2001 Ken Klingenstein, Project Director, Internet2 Middleware Initiative Chief Technologist, University of Colorado at Boulder
2
A word which was made the criterion by which to distinguish the Ephraimites from the Gileadites. The Ephraimites, not being able to pronounce sh, called the word sibboleth. See --Judges xii. Hence, the criterion, test, or watchword of a party; a party cry or pet phrase. - Webster's Revised Unabridged Dictionary (1913):Webster's Revised Unabridged Dictionary (1913)
3
Shibboleth an initiative to analyze and develop mechanisms(architectures, frameworks, protocols and implementations) for inter- institutional authentication and authorization facilitated by Mace (a committee of leading higher ed IT architects) and Internet2 http://middleware.internet2.edu/shibboleth
4
Related Work Previous DLF work OASIS Technical Committee (vendor activity, kicked off this week) UK - Athens and Sparta projects Spain - rediris project
5
Discussion Outline Stage 1 Goals Model Expected Evolution Assumptions Campus and Resource Requirements Issues Project Status/Next Steps
6
Stage 1 - Addressing Three Scenario’s Member of campus community accessing licensed resource Anonymity required Member of a course accessing remotely controlled resource Anonymity required Member of a workgroup accessing controlled resources Controlled by attributes, perhaps including identity
7
Model Local Authentication Local Entity Willing to Make Assertions About the User Attribute/value pairs User has control over disclosure Identity optional “active member of community” “Associated with Course XYZ” Target responsible for Authorization Rules engine Matches contents of credentials against ruleset associated with target object
8
Evolution in Design Survey of deployed web access control implementations Mace-shibboleth discussions movement from a lightweight and casual approach to a more extensible view IBM participation
9
Assumptions “authenticate locally, act globally” the Shibboleth shibboleth Leverage vendor and standards activity wherever possible Disturb as little of the existing campus infrastructure as possible Encourage good campus behaviors Learn through doing Create a marketplace and reference implementations
10
Campus and Resource Requirements campus-wide identifier space campus-wide authentication service Implementation of Eduperson objectclass
11
Issues Personal Privacy (reasonable expectation, laws) Relation to local weblogin (Single Signon) Portals Use of Shibboleth framework by services beyond the web Grid resources and users
12
Project Status/Next Steps Requirements and Scenarios document nearly finished IBM and Mace-Shibboleth are refining architecture and evaluating issues IBM intends to develop an Apache web module Internet2 intends to develop supporting materials (documentation, installation, etc) and web tools (for htaccess construction, filter and access control, remote resource attribute discovery). Technical design complete - April, 2001 Coding... Pilot site start-up - Aug, 2001 Public demo- Internet2 Fall Member Meeting 2001
13
Questions?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.