Identity Management and Shibboleth

Recent resources tagged with Identity Management and Shibboleth.

Organizing a Campus Change: Planning for Identity and Access Management Improvements at UF

Added by the EDUCAUSE Librarian
Title:Organizing a Campus Change: Planning for Identity and Access Management Improvements at UF (ID: SER08055)
Author(s):Michael Conlon (University of Florida)
Origin:Presented at Southeast Regional Conferences (06/02/2008)
Type:Presentations/Speeches
Abstract:

Leading change across distributed IT service providers requires extensive engagement. Implementing identity and access management (IAM) changes requires involvement of a broad spectrum of constituents. Using techniques developed during ERP and other large-scale change initiatives, we engage the university community in developing requirements and architecture for successful IAM changes.

View this resource:

UABgrid Identity Infrastructure

Added by the EDUCAUSE Librarian
Title:UABgrid Identity Infrastructure (ID: SER08063)
Author(s):John-Paul Robinson (University of Alabama at Birmingham)
Origin:Presented at Southeast Regional Conferences (06/02/2008)
Type:Presentations/Speeches
Abstract:

This presentation will describe the identity management infrastructure of the UAB grid computing project, known as UABgrid. Its development is based on accomplishments of two NSF middleware projects at UAB, which focused on building NMI-enabled, open source tools for support of collaboration within virtual organizations that span institutional boundaries, are autonomous, and are collections of attributes. The middleware solution is known as myVocs and uses Shibboleth for identity management and attribution distribution, Globus for distributed computations, and GridShib to bind Shibboleth and Globus. UABgrid is now expanding its grid computing components to include metascheduling of jobs across multiple HPC clusters across the Internet.

View this resource:

Beyond Single Sign-On: Advanced Uses for Shibboleth at USC

Added by the EDUCAUSE Librarian
Title:Beyond Single Sign-On: Advanced Uses for Shibboleth at USC (ID: WRC08048)
Author(s):Will Norris (University of Southern California)
Origin:Presented at Western Regional conferences (03/31/2008)
Type:Presentations/Speeches
Abstract:

Hear from one of Shibboleth's developers how USC is using Shibboleth to provide web-based services to federated guests and secure access to Google Apps. Additionally, this presentation will describe the Shibboleth test environment at USC that provides a quicker, easier, and more secure means for departments to integrate their applications.

View this resource:

Federated Identity: Leveraging Shibboleth to Access On- and Off-Campus Resources

Added by the EDUCAUSE Librarian
Title:Federated Identity: Leveraging Shibboleth to Access On- and Off-Campus Resources (ID: MAC08055)
Author(s):Paul Riddle (University of Maryland, Baltimore County)
Origin:Presented at Mid-Atlantic Regional Conferences (01/15/2008)
Type:Presentations/Speeches
Abstract:

More and more institutions are using Shibboleth to address both their on-campus and third-party access requirements. This case study will provide information about federated identity management (specifically, Shibboleth and the InCommon Federation) and how you can get started.

View this resource:

Architecting the Institutional Directory Service: Advanced Issues, Problems, and Solutions

Added by the EDUCAUSE Librarian
Title:Architecting the Institutional Directory Service: Advanced Issues, Problems, and Solutions (ID: EDU07162)
Author(s):Brendan Bellina (University of Southern California) and Robert Banz (University of Maryland, Baltimore County)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

Institutional directory service architects and designers face a number of unique technical challenges in higher education. Directory architects from the University of Southern California and the University of Maryland, Baltimore County, will share lessons learned while developing and implementing directory services at their institutions.

Topics will include designing access controls and institutional object classes; using federation identities, Shibboleth, and administrative tools; managing multiple data sources, members, accounts, and guests; mapping data sources to standard object classes; handling interactive and bulk updates; optimizing and monitoring performance, replication, and integration with external authentication systems; and managing groups and privileges.

The solutions offered are based on 14-plus years of practical experience working with the Netscape/iPlanet/Sun directory products. This seminar will focus on intermediate to advanced issues, and most information will be widely applicable to and suitable for any institutional directory effort.

View this resource:

OpenID: Decentralised Single Sign-on for the Web

Added by the EDUCAUSE Librarian
Title:OpenID: Decentralised Single Sign-on for the Web (ID: CSD5120)
Author(s):Andy Powell (Eduserv) and David Recordon (VeriSign, Inc.)
Source:Ariadne
Origin:Contributed by Organizations or Campuses (04/30/2007)
Type:Articles, Papers, and Reports
Abstract:

"OpenID is a single sign-on system for the Internet which puts people in charge. OpenID is a user-centric technology which allows a person to have control over how their Identity is both managed and used online. By being decentralised there is no single server with which every OpenID-enabled service and every user must register. Rather, people make their own choice of OpenID Provider, the service that manages their OpenID. "

View this resource:

Introduction to Shibboleth and Phases for Deployment

Added by the EDUCAUSE Librarian
Title:Introduction to Shibboleth and Phases for Deployment (ID: CAMP07202)
Author(s):Steven T. Carmody (Brown University)
Origin:Contributed by EDUCAUSE Grant Programs (CAMP) (06/25/2007)
Type:Presentations/Speeches
Abstract:

This session will provide an overview of the Shibboleth System software, its role within an IdM infrastructure, related concepts, the value it provides, and typical implementation sequences. Shibboleth deployment can be separated into three phases: Web SSO authentication, attribute delivery for authorization, and federated authentication/authorization. This session will explore the effect on existing infrastructure and business processes during each phase.

View this resource:

Introduction to Shibboleth Attribute Delivery

Added by the EDUCAUSE Librarian
Title:Introduction to Shibboleth Attribute Delivery (ID: CAMP07216)
Author(s):Hugh Barron Johnson (Clemson University) and Paul Caskey (University of Texas System)
Origin:Contributed by EDUCAUSE Grant Programs (CAMP) (06/25/2007)
Type:Presentations/Speeches
Abstract:

Many applications (even intracampus) derive benefit from “knowing” something about the browser user. This session will provide an overview of Shibboleth as an option for managing the process of making user attribute information available to distributed applications within a campus. We will also review management and technical topics such as developing a governance process for attribute release, creating appropriate policy and business practices, managing attribute release, and using different data sources for the attribute store. Attendees who are not familiar with identity management are encouraged to attend the preworkshop seminar "Introduction to Identity Management: The Big Picture."

View this resource:

Introduction to Shibboleth WebSSO

Added by the EDUCAUSE Librarian
Title:Introduction to Shibboleth WebSSO (ID: CAMP07213)
Author(s):Hugh Barron Johnson (Clemson University) and Keith D. Hazelton (University of Wisconsin-Madison)
Origin:Contributed by EDUCAUSE Grant Programs (CAMP) (06/25/2007)
Type:Presentations/Speeches
Abstract:

Whether you're implementing your first WebSSO or transitioning to a new one, this session will provide a brief introduction to the concept and business case for intra-campus WebSSO, and an overview of Shibboleth as an option for WebSSO technology and what it does. In addition, the presenters will review technical and management topics such as the minimum IdM services required to get started, an introduction to the Shibboleth architecture and flows, an overview of the installation process, bringing the software from pilot to production, the basics of connecting in applications, required skill sets and resources, deployment costs, as well as policy and business processes.Whether you're implementing your first WebSSO or transitioning to a new one, this session will provide a brief introduction to the concept and business case for intra-campus WebSSO, and an overview of Shibboleth as an option for WebSSO technology and what it does.

View this resource:

Technical Topics for Deployed Campuses: Web SSO

Added by the EDUCAUSE Librarian
Title:Technical Topics for Deployed Campuses: Web SSO (ID: CAMP07214)
Author(s):Scott Cantor (The Ohio State University) and William Norris (University of Southern California)
Origin:Contributed by EDUCAUSE Grant Programs (CAMP) (06/25/2007)
Type:Presentations/Speeches
Abstract:

For those campuses that have deployed Shibboleth, this technical session will cover advanced topics such as using campus-wide Web SSO, managing metadata for the Web SSO service, avoiding single points of failure, running in a load-balanced environment, and using multiple replicated LDAP servers. It will also explore advanced Shibboleth configuration recommendations and 2.0 features.

View this resource: