Jump to content

Recommended Posts

Guest monkeyx
Posted (edited)

Whilst this is not a single sign on project as such, I have from time to tiime wish I had more time to look at the Fedora Directory Server Project. It seems to offer an LDAP/AD/Group synchronisation which is more of a MetaDirectory style solution.

 

I have also previously looked at Home | DirectSSO whilst investigating typo3 CMS.

 

Has anyone ever installed/used the Fedora System? As it look a promising approach for any system that supports ldap.

 

PS also http://openid.net/

Edited by monkeyx
Posted

I've not seen the Citrix solution before - it does look good but it looks as if it's just an automated way of remembering all the passwords (it talks about pre-provisioning secondary credentials). Anything with Citrix in the name tends to be expensive (but you do get what you pay for :-)) so other solutions might be better.

 

Lots of software can have LDAP authentication - Moodle does, for example, and it's relatively easy to do it so it ought to be an option in other packages (I think the MIS system we use has an LDAP option although we're not using it at the moment)

 

I'd guess it's worth talking to suppliers to see if they can do LDAP although it's going to be much harder for things external to you - handling secure collection of usernames and passwords isn't always easy and this is where Shibboleth comes in. If only I could understand where I start with it (but we have registered as an IdP so I'd guess that almost counts as a start!)

Posted (edited)

@cookie, monkey - thanks for the info....

 

didn't think about the Active Directory and Fedore directory 'add-ons' for SSO and federation. I'd imagine ADFS only plays nice with other M$ apps, the Fedora directory server - on the surface atleast - seems more promising. I believe the commercial Redhat directory server is based on the Netscape Directory Server which was highly scalable and truly 'enteprrise'...if fedora directory is the community project of that particular product it can only be good imo.

 

@steve - great minds and all that...i was just about to ask cybernerd about 'where to start' when it comes to shibboleth. Edited it because i assumed he would point me in the direction of the shiboleth bit at internet2 (and quite rightly so) but my brains starting to hurt at this time of the evening and i'd want the idiots guide to shibboleth 101 ;0) with examples of using apps we all know, love, hate and abuse - i'm thinking moodle, groupwise, exchange, sharepoint, asterisk etc

 

Can you have one identity/SSO solution for both internal and web facing stuff or is it as simple LDAP for inside/LAN, shibboleth for outside/WAN.

Edited by torledo
Posted (edited)

I think part of the problem in achieving single sign on in most schools is the in-flexibility of active directory itself. Now imagine if AD would let you 'validate' users from another source, say shibboleth for example. My old LEA used shibboleth for it's e-mail authentication, so every user in every school within that LEA has a valid account on its shibboleth server. It is also planning to use it for it's LEA wide VLE which is in the works at the moment.

 

What would have been great is if my local AD server would also talk to the LEAs shibboleth server, and allow me to select accounts that I would like to allow onto my network. I could still assign them group memberships and manage the account locally within my AD environment, but shibboleth can provide the authentication method behind the scenes, which means the same username and password can then be used for everything! If they then moved schools within the LEA, I could de-valicate their account within my AD, and the next school can validate it on theirs. Also pupils that attend more than one school, 6th formers for example, could be validated at both schools.

 

That way services that tie into AD like moodle and exchange can also use the same username and password. If all these different authentication services could actually talk to each other behind the scenes, then we'd be onto a winner!

 

Mike.

Edited by maniac
Posted

As I have said earlier, the issue here is that we currently have vast amounts of passwords. Many services are provided by external people (our LEA, Capita, private software companies etc...). To get them all linked in would a) cost a fortune and b) actually be impossible in a short timeframe.

 

I understand 100% that in the long term, federated logins etc... are the goal. But we are talking at least 5 years, probably more.

 

In the mean time, the problem still exists, with more login boxes appearing all the time.

 

So whilst a citrix sso solution may seem quick and dirty, that is precisely what is needed, until proper SSO is actually attainable.

Posted

Seems like there is also shibboleth/active directory interoperability:

 

Internet2, the foremost U.S. advanced networking consortium, has developed Shibboleth™, the widely-deployed federated authentication architecture. In support of Windows Server 2003 R2 release, Internet2 is extending Shibboleth to provide interoperability with Microsoft's Active Directory Federation Services (ADFS), allowing sites using ADFS to participate in the rapidly growing number of Shibboleth-based federations worldwide, such as InCommon™

 

From here: Windows Server 2003 R2 Partners

 

and interesting project here: shibboleth-on-windows

 

Apoligies for almost hijacking this thread, as none of the above really answers localzuk's origenal question, although I think it is relevant.

 

Mike.

Posted

Have been doing a fair bit of reading on this over the last couple of days, and it appears that there are a few options under the ESSO (enterprise SSO) that can help with what localzuk is trying to do....

 

one of the more interesting ones i've come across is opensso....a community project led by Sun to develop an ESSO system based on their Java identitiy Access Manager commercial product.

 

Don't know how easy it is to setup, configure and develop but it can't hurt to download the source and give it a whirl.

 

Other than that, no products stick out other than citrix and novell (securelogin) which have already been mentioned.

 

As for federation, which is what LEA's/RBC's are dealing with, it's really about moving to standards based techniques...the terminology differs (for instance how ADFS and Shibboleth refer to 'identity providers' differs) but the goal is to build applications and token authentication schemes to be standard compliant - particularly see parties going down the route of SAML and the WS-* stack.

 

For us, like localzuk, a WebSSO project within the enterprise is more of a priority than the idea of intra-enterprise federation. WebSSO being the most obvous part of an identity and access management solution - and that's more than enough to be getting started with.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...