adding institution support in sfx for shibboleth sso
DESCRIPTION
Adding institution support in SFX for Shibboleth SSO. Michael Zach, Jan Krajíc, Jiří Pavlík. Charles University in Prague Computer Science Centre. What is this about?. SFX consortia shared instance off-campus access Shibboleth SSO eduID.cz (Czech academic identity federation) - PowerPoint PPT PresentationTRANSCRIPT
Adding institution support in SFX for Shibboleth SSO
Michael Zach, Jan Krajíc, Jiří Pavlík
Charles University in PragueComputer Science Centre
What is this about?
● SFX
● consortia
● shared instance
● off-campus access
● Shibboleth SSOo eduID.cz (Czech academic identity federation)
o CESNET (Czech Education and Scientific NETwork)
Past presentations
● Jiri Pavlik:o Shibboleth session at Ghent, 2010
a plan for setting up
o Shibboleth SSO - Charles University case study, Haifa 2011 set up description
Uniform Information Gateway (UIG)
● National portal of library network in Czech Republic (www.jib.cz)
● project of Czech National Library & Charles University in Prague (*2003)
● 30 registered libraries
● MetaLib Plus and MetaLib search engine & Primo Central Index
● 1 SFX instance, using institutes feature
UIG - SFX set up
● institutes● library proxies (EZProxy)● Czech National Library Identity Provider● e-journals and e-books AZ for registered
organisations● Google Scholar registration
UIG - SFX institutes
● On / off-campus accesso no IP ranges
● activation targets for:o DEFAULT & INSTITUTEo & Authentication note
availability info for everybody
institutional AZ Listsinstitutional exportsinstitutional Proxiesinstitutional GS
UIG - SFX set up
The solution
● SFX is not supporting institutes feature for off-campus access
● our local solution → pull-down menu in SFX menu
The solution
Libraries
(by CESNET)
Single Sign-On
From inside
● Perl script (institutes.cgi)● Perun - Identity and Access Management System
o perun.cesnet.cz
● cookie “sfx_institute”
● iframe in a template
Affected templates
../templates/simplified_template1/sfxmenu.tmpl
../templates/simplified_template1/mobile/sfxmenu.tmpl
Future development
● Enhancement Requesto Assigning Identity providers to institutes as proxy
more than one IdP per instanceo Including name of institute into Auth. note
● Future of UIGo transformation UIG into new Central Portal of
Libraries→ Discovery system
Sharing
● implementation support into global SFX?
● Code Share
Michael Zach, [email protected]
“Thank you. Questions”