Shibboleth

Recent blog entries tagged with Shibboleth.

Register for CAMP Workshops on Shibboleth 2.0 and Distributed Services

Created by Colleen Luckett (EDUCAUSE) on April 17, 2008

CAMP logo

 

 

CAMP Shibboleth 2.0: Hands-on Technical Workshop (May 13-15)

The CAMP Shibboleth 2.0: Hands-on Technical Workshop will complement the June 2007 Shibboleth CAMP by providing attendees with technical installation and configuration experience with Shibboleth version 2.0. Developed for campuses new to Shibboleth and those with existing implementations interested in upgrading to the 2.0 release, the workshop will offer attendees the chance to:

June CAMP Workshops to Focus on Shibboleth and Secure Collaboration

Created by Colleen Luckett (EDUCAUSE) on April 04, 2007
NMI-EDIT logoTwo upcoming CAMP workshops (detailed below) in Portland, Oregon, CAMP Shibboleth: Flexible Web-Based Authentication and Authorization and Advanced CAMP: Scaling Secure Collaboration, will focus on middleware deployment.

CAMP Shibboleth: Flexible Web-Based Authentication and Authorization

(June 25–27)
Overview: This CAMP will offer concrete practice and real-world experience from institutions running Shibboleth in production for controlling access to both on- and off-campus services. Participants will learn the answers to questions such as:
  • What is Shibboleth and how does it work?
  • What is the business case for it and how can I sell it on my campus?
  • What is the migration path to support intercampus Web SSO in the future?
  • How much identity management infrastructure do I need?
  • How can I use Shibboleth to simplify my application deployment and maintenance?
Higher education IT managers, project managers, middleware architects, and systems analysts involved at a technical, management, or stakeholder level in supporting Web-based services will benefit most from this workshop. Register before May 29 for low, early-bird rates.

EDUCAUSE2006 Podcast: Voyage of the U.K. JISC Federation

Created by Carie Lee Page (EDUCAUSE) on March 24, 2007

In this 42-minute recording from the 2006 EDUCAUSE Annual Conference, we'll hear from Nichole Harris, Ross MacIntyre, and John Pashoud in a session entitled Voyage of the U.K. JISC Federation: Shibbolizing the U.K.'s Research, Higher, and Further Education. They will share their diverse approaches to adopting Shibboleth software for federated access management.

An Interview with Andy Newman

Created by Matt Pasiewicz (EDUCAUSE) on December 18, 2006
In this 13 minute recording, we'll hear from Yale University's Andy Newman to gather his thoughts on a range of identity management issues.


This interview is provided courtesy of CNI and was recorded at their 2006 Fall Task Force Meeting.  The Coalition for Networked Information (CNI) is an organization dedicated to supporting the transformative promise of networked information technology for the advancement of scholarly communication and the enrichment of intellectual productivity.  You can learn more about CNI at their web site, http://www.cni.org

An Interview with Cliff Lynch

Created by Matt Pasiewicz (EDUCAUSE) on December 18, 2006
In this 51 minute recording, we'll hear from CNI's Cliff Lynch.  Listen in has he shares some thoughts on cyberinfrastructure, patents, and much more..


This interview is provided courtesy of CNI and was recorded at their 2006 Fall Task Force Meeting.  The Coalition for Networked Information (CNI) is an organization dedicated to supporting the transformative promise of networked information technology for the advancement of scholarly communication and the enrichment of intellectual productivity.  You can learn more about CNI at their web site, http://www.cni.org

An Interview with David Walker

Created by Matt Pasiewicz (EDUCAUSE) on December 18, 2006
In this 14 minute recording, George Brett hosts David Walker for an interview on, among other things, a range of issues related to identity management.

An Interview with Douglas Van Houweling

Created by Matt Pasiewicz (EDUCAUSE) on October 19, 2006

The attached recording provides coverage of a 20 minute interview with Internet2 President and CEO, Douglas Van Houweling.  Listen in as he shares thoughts on cybersecurity, cyberinfrastructure, CALEA, data curation and much more. 

See also:

Shibboleth security vulnerability

Created by Stuart Yeates (University of Oxford) on June 27, 2006

A security vulnerability has been found in the Shibboleth from the Internet2. If you are running Shibboleth in anger, update to the latest version immediately. From the wiki page:

The cause of the bug is the many-to-one mapping of header names to CGI variable names due to upcasing and replacement of some separator characters with underscores. It's exacerbated by the fact that different web servers use different rules, particularly with regard to how non-alphanumeric characters are handled. Some are turned to underscores, and some are left alone, resulting in strange or even technically invalid CGI variable names.

The unpredictability makes it difficult to prevent a client from sending a creatively malformed header that will map to an expected CGI variable reserved by an application for a particular user attribute. The techniques used to "clear" client-sent headers that might conflict were inadequate.

E2005 Podcast: Leveraging Guest Accounts

Created by Podcaster (EDUCAUSE) on March 30, 2006
This 47 minute recording provides coverage of the 2005 EDUCAUSE Annual Conference Session entitled Leveraging Guest Accounts for Ubiquitous Web Sign-On System Acceptance.

June CAMP Workshop on Shibboleth and Web Single Sign-On

Created by Elisa Coghlan (EDUCAUSE) on March 29, 2006
A June Campus Architectural Middleware Planning (CAMP) workshop will focus on Internet2's Shibboleth Project and its use for Web single sign-on in both local applications and federated environments. The workshop will be held June 26–28 in Burlington, Vermont.