Guest monkeyx Posted July 15, 2008 Posted July 15, 2008 (edited) Whilst this is not a single sign on project as such, I have from time to tiime wish I had more time to look at the Fedora Directory Server Project. It seems to offer an LDAP/AD/Group synchronisation which is more of a MetaDirectory style solution. I have also previously looked at Home | DirectSSO whilst investigating typo3 CMS. Has anyone ever installed/used the Fedora System? As it look a promising approach for any system that supports ldap. PS also http://openid.net/ Edited July 15, 2008 by monkeyx
cookie_monster Posted July 15, 2008 Posted July 15, 2008 I haven't used this but what about Active Directory Federation Services? It might be more focused on web technologies. Single Sign-On: A Developer's Introduction To Active Directory Federation Services http://www.microsoft.com/windowsserver2003/r2/identity_management/adfswhitepaper.mspx
CyberNerd Posted July 15, 2008 Posted July 15, 2008 @monkeyX take alook at freeIPA, I suspect some day we'll replace our aging ActiveDirectory with this - unless the LA come to the rescue and offer us all MSCE's for Microsoft when they install their shibbolised MSAD Main Page - Free IPA
srochford Posted July 15, 2008 Posted July 15, 2008 I've not seen the Citrix solution before - it does look good but it looks as if it's just an automated way of remembering all the passwords (it talks about pre-provisioning secondary credentials). Anything with Citrix in the name tends to be expensive (but you do get what you pay for :-)) so other solutions might be better. Lots of software can have LDAP authentication - Moodle does, for example, and it's relatively easy to do it so it ought to be an option in other packages (I think the MIS system we use has an LDAP option although we're not using it at the moment) I'd guess it's worth talking to suppliers to see if they can do LDAP although it's going to be much harder for things external to you - handling secure collection of usernames and passwords isn't always easy and this is where Shibboleth comes in. If only I could understand where I start with it (but we have registered as an IdP so I'd guess that almost counts as a start!)
torledo Posted July 15, 2008 Posted July 15, 2008 (edited) @cookie, monkey - thanks for the info.... didn't think about the Active Directory and Fedore directory 'add-ons' for SSO and federation. I'd imagine ADFS only plays nice with other M$ apps, the Fedora directory server - on the surface atleast - seems more promising. I believe the commercial Redhat directory server is based on the Netscape Directory Server which was highly scalable and truly 'enteprrise'...if fedora directory is the community project of that particular product it can only be good imo. @steve - great minds and all that...i was just about to ask cybernerd about 'where to start' when it comes to shibboleth. Edited it because i assumed he would point me in the direction of the shiboleth bit at internet2 (and quite rightly so) but my brains starting to hurt at this time of the evening and i'd want the idiots guide to shibboleth 101 ;0) with examples of using apps we all know, love, hate and abuse - i'm thinking moodle, groupwise, exchange, sharepoint, asterisk etc Can you have one identity/SSO solution for both internal and web facing stuff or is it as simple LDAP for inside/LAN, shibboleth for outside/WAN. Edited July 15, 2008 by torledo
maniac Posted July 15, 2008 Posted July 15, 2008 (edited) I think part of the problem in achieving single sign on in most schools is the in-flexibility of active directory itself. Now imagine if AD would let you 'validate' users from another source, say shibboleth for example. My old LEA used shibboleth for it's e-mail authentication, so every user in every school within that LEA has a valid account on its shibboleth server. It is also planning to use it for it's LEA wide VLE which is in the works at the moment. What would have been great is if my local AD server would also talk to the LEAs shibboleth server, and allow me to select accounts that I would like to allow onto my network. I could still assign them group memberships and manage the account locally within my AD environment, but shibboleth can provide the authentication method behind the scenes, which means the same username and password can then be used for everything! If they then moved schools within the LEA, I could de-valicate their account within my AD, and the next school can validate it on theirs. Also pupils that attend more than one school, 6th formers for example, could be validated at both schools. That way services that tie into AD like moodle and exchange can also use the same username and password. If all these different authentication services could actually talk to each other behind the scenes, then we'd be onto a winner! Mike. Edited July 15, 2008 by maniac
localzuk Posted July 15, 2008 Author Posted July 15, 2008 As I have said earlier, the issue here is that we currently have vast amounts of passwords. Many services are provided by external people (our LEA, Capita, private software companies etc...). To get them all linked in would a) cost a fortune and b) actually be impossible in a short timeframe. I understand 100% that in the long term, federated logins etc... are the goal. But we are talking at least 5 years, probably more. In the mean time, the problem still exists, with more login boxes appearing all the time. So whilst a citrix sso solution may seem quick and dirty, that is precisely what is needed, until proper SSO is actually attainable.
CyberNerd Posted July 15, 2008 Posted July 15, 2008 I understand 100% that in the long term, federated logins etc... are the goal. But we are talking at least 5 years, probably more. it's been running since 2006 UK Federation Information Centre | Home / Home browse
maniac Posted July 15, 2008 Posted July 15, 2008 Seems like there is also shibboleth/active directory interoperability: Internet2, the foremost U.S. advanced networking consortium, has developed Shibboleth™, the widely-deployed federated authentication architecture. In support of Windows Server 2003 R2 release, Internet2 is extending Shibboleth to provide interoperability with Microsoft's Active Directory Federation Services (ADFS), allowing sites using ADFS to participate in the rapidly growing number of Shibboleth-based federations worldwide, such as InCommon™ From here: Windows Server 2003 R2 Partners and interesting project here: shibboleth-on-windows Apoligies for almost hijacking this thread, as none of the above really answers localzuk's origenal question, although I think it is relevant. Mike.
localzuk Posted July 15, 2008 Author Posted July 15, 2008 it's been running since 2006 UK Federation Information Centre | Home / Home browse It may well be running but I don't see it being implemented within schools, within the programs that we use, within our LEA services and within RBC's any time soon. Those are still many years off.
CyberNerd Posted July 15, 2008 Posted July 15, 2008 still, a lot of colleges and councils have already signed up as identity providers UK Federation Information Centre | Documents / MemberList browse
torledo Posted July 17, 2008 Posted July 17, 2008 Have been doing a fair bit of reading on this over the last couple of days, and it appears that there are a few options under the ESSO (enterprise SSO) that can help with what localzuk is trying to do.... one of the more interesting ones i've come across is opensso....a community project led by Sun to develop an ESSO system based on their Java identitiy Access Manager commercial product. Don't know how easy it is to setup, configure and develop but it can't hurt to download the source and give it a whirl. Other than that, no products stick out other than citrix and novell (securelogin) which have already been mentioned. As for federation, which is what LEA's/RBC's are dealing with, it's really about moving to standards based techniques...the terminology differs (for instance how ADFS and Shibboleth refer to 'identity providers' differs) but the goal is to build applications and token authentication schemes to be standard compliant - particularly see parties going down the route of SAML and the WS-* stack. For us, like localzuk, a WebSSO project within the enterprise is more of a priority than the idea of intra-enterprise federation. WebSSO being the most obvous part of an identity and access management solution - and that's more than enough to be getting started with.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now