the i-trust federation: federating the university of illinois
DESCRIPTION
Keith Wessel Identity Management Service Manager University of Illinois at Urbana-Champaign. The I-Trust Federation: Federating the University of Illinois. Goals and Challenges. Goal: retire legacy web sign-on service and replace with Shibboleth - PowerPoint PPT PresentationTRANSCRIPT
The I-Trust Federation:Federating the University of Illinois
Kei th Wesse lIden t i t y Management Serv ice ManagerUn ivers i ty o f I l l i no is a t U rbana-Champaign
• Goal: retire legacy web sign-on service and replace with Shibboleth
• The challenge: U of Illinois’ three campuses maintain their own user and password stores and IDPs. Old Web SO allowed for inter-domain authentication for services used by users from multiple campuses.
Goals and Challenges
• Federate the three campuses.
• Use existing IDPs and user/password stores.
• Put a Shib SP on each service that currently uses the legacy system.
• Services that need to allow access to users from multiple campuses can point to a centralized discovery service.
The solution
• We have over 500 service providers behind the legacy system.
• Many allow access to users from more than one campus.
• Even with delegated SP administration, this would be costly and labor-intensive.
• This is also overkill to get SP data to the university’s three IDPs.
• If an SP needs to federate beyond the university, such as with another university, we will work with them to manually enter them in InCommon.
Why not put everyone in InCommon?
• Initial case was to simply get SSO functional and metadata circulating between the three campuses.
• Before we even announced it, our software webstore folks were asking questions.
• By adding other universities, community colleges and K-12 users, our software webstore could sell to more users and get larger discounts.
• State library consortium is also interested with the value of resource sharing through federation.
• We had these cases brought to us. After launch, we expect a lot more.
The business case
1. Identify technical and management resources from each campus.
2. Agree that Urbana campus, the largest, will take the lead.
3. Compare attributes being released by all three IDPs to build and approve a list of common attributes.
4. Standardize names of federation attributes.
5. Set up common platform for maintaining and disseminating metadata and attribute release
Planning
• Discovery Service: Shibboleth project’s centralized discovery service is offered for SPs needing to allow access to all three campuses
• Metadata management and dissemination: Australian Access Federation’s Federation Registry.
• Metadata signing: Shibboleth project’s xmlsectool
Nuts and bolts
• An extensible, open web application that provides a central point of registration, management and reporting for identity and service providers participating in a standards compliant SAML 2 identity federation.
• Management for all aspects of SAML 2 compliant Identity and Service Providers• SAML 2.x compliant metadata generation• Additional assistance for Shibboleth IDP and SP administrators including automated Attribute
Filter generation• Public registration for Organizations, Identity Providers and Service Providers that are new to
the federation• Organizations can have any number of IDP and SP owned by them (service only organizations
are popular with publishers for example)• A personalized dashboard view of the federation for all users• A cross browser (including mobile devices) HTML5 compliant user interface which can be
branded for deploying organizations.• Multilingual capable• A fully customizable workflow engine to handle registrations and other critical federation
changes• In-depth reporting to gain insight to the workings of the entire federation• Federation integrated, automatically provisioned user accounts with fine grained access control
Federation Registry
Federation Manager Dashboard
9 – © 2012 Internet2
Create Service Provider
10 – © 2012 Internet2
Create Service Provider:description
11 – © 2012 Internet2
Create Service Provider:SAML configuration
12 – © 2012 Internet2
Create Service Provider:cert if icate
13 – © 2012 Internet2
Create Service Provider:attr ibutes
14 – © 2012 Internet2
Create Service Provider:submit
15 – © 2012 Internet2
Approving a new Service Provider
16 – © 2012 Internet2
• Bring community colleges, K-12 schools and others on-board.
• Federation-wide single logout: a big one to attack, but lots of requests already.
• Standardizing requests for two-factor authentication when needed.
Future plans
• Australian Access Federation: wiki.aaf.edu.au/federationregistry2
• Contact for more on I-Trust: Keith Wessel, [email protected]
Resources