Extending single-sing-on Services Institutions 1 X login WAYF 2 Y login
Extending single-sing-on Services Institutions 1 X login WAYF 2 Y login
Extending single-sing-on Services Institutions 1 X login WAYF 2 Y login
Extending single-sing-on Services Institutions 1 X login WAYF 2 Y login HEIMAT - transparent login to federation from local SSO
The LMS as dashboard • Service collections, also external services, via federated access
The LMS as dashboard • Service collections, also external services, via federated access
Citizens' login service
Citizens' login • All >18 years (with a bank account) • 3.5 mio people (out of 5.5 mio) Commercial services DK bank login Citizens' login service Public/gov services
Citizens' login • All >18 years (with a bank account) • 3.5 mio people (out of 5.5 mio) Commercial services DK bank login Citizens' login service Public/gov services
External (strong) authentication Services Institutions 1 X login WAYF 2 Y login
External (strong) authentication Services Institutions 1 X login WAYF 2 Y login
External (strong) authentication Services Institutions 1 X login WAYF 2 Y login
External (strong) authentication Services Institutions 1 X login WAYF 2 Y login Enrolment of students Password reset self service Expensive services ...
Level of Assurance • Classification of authentication strength • Classification of trust-levels
Strength of authentication • Initial authentication • Login session • Follow national / EU / USA standard ?
Shibboleth Services Institutions WAYF Shib 1.2 Shib 1.3 X 1 SAML1.1 login WAYF Shib 2 SAML 2 Y 2 login WAYF
Protocol translation Services Institutions 1 X SAML2 Shib 1.3 WAYF CAS SAML2 2 Y
Protocol translation Services Institutions p 1 h X p L M SAML2 Shib 1.3 A S e e l WAYF d p i m s n i i s CAS SAML2 2 Y http://rnd.feide.no/simplesamlphp
Multi-protocol support SAML 2.0 as Service Provider • SAML 2.0 as Identity Provider • Shiboleth 1.3 as Service Provider • Shiboleth 1.3 as Identity Provider • A-Select as Service Provider • A-Select as Identity Provider • CAS for remote authentication • OpenID Provider support (experimental) • OpenID Consumer support (experimental) • WS-Federation as a Service Provider • LDAP, Multi-LDAP • SQL • InfoCard • PAPI as Service Provider • PAPI as Identity Provider
SAML2 profiles
SAML2 profiles
SAML2 profiles http://saml2int.org/
Attributes
$
Attribute release profiles
Set or calculated attributes
Set or calculated attributes • (Schac)HomeOrg (ruc.dk) Services Institutions 1 X login WAYF 2 Y login
Set or calculated attributes • (Schac)HomeOrg (ruc.dk) Services Institutions • (Schac)YearOfBirth 1 X login WAYF 2 Y login
Set or calculated attributes • (Schac)HomeOrg (ruc.dk) Services Institutions • (Schac)YearOfBirth 1 X login WAYF • (eduPerson)TargetedID 2 Y login
SchacHomeOrg
SchacHomeOrg Services Institutions Inst2.dk 1 X login WAYF 2 Y login
Recommend
More recommend