Jump to content

How familiar are you with Identity Federation/SSO?  

7 members have voted

  1. 1. How familiar are you with Identity Federation/SSO?

    • Never heard of it
      0
    • Heard of it
      4
    • Have considered it
      2
    • Have used it
      1


Recommended Posts

Posted

Bit of backstory here, the NZ Ministry of Education (MoE) is looking into SSO for MoE resources as currently there is absolutly no unified structure meaning that the average principal requires around eight different usernames and passwords to access the basic set of online services. As you can imagine this amount of passwords with heavy password requirements takes quite a toll on the usability of the systems and to their credit they are looking at ways to improve.

 

At the moment their plans (which are not set in stone) are to work with Google Apps or Live@Edu to get a SAML2.0 compatible identity service avalible for those schools that have it. This should mean a single logon for many MoE sites. The issue is that due to limited funds only one may be developed therby either forcing schools to a single provider to get SSO or isolating them if they want or need to use a different system.

 

My view is that instead of forcing all schools onto a cloud based service that each school should have the option to federate directly from their own servers to the MoE ones if they choose. At first I was looking at AD Federation Services for the Windows side but apparently this does not work quite right with their existing SAML2.0 based services and they don't want to alter them. I have looked around and found a couple of promising opensource candidates that will interface with LDAP and provide compliant SAML federation.

 

My questions are:

 

Has anyone used Identity Federation in their schools/environments?

 

Has anyone found or used any opensource Federation providers on Windows, Linux or OSX?

 

Does any other country or provider offer such a federation service at the moment?

 

Do you think that I am on the right track or should I just submit to the cloud?

 

Any feedback would be appreciated.

Posted

There were a lot of big words that confused me in the post above, so I hope this isn't completely off topic:

 

We use Google Apps to provide our staff with Email/Docs/Talk/Calendars etc...

I am currently setting up Directory Sync so our Active Directory sync's with our Google Apps accounts and then we use Google Apps as an OpenID provider for other services like Moodle/Joomla etc...

 

So in theory it's only one username/password so long as the software uses OpenID?

  • Thanks 1
Posted
Have a look at Shibboleth. Shibboleth®

 

This has been on the RealSoon ™ radar in .uk for some time.

 

Thanks, that was one of the promising candidates that I found and its interesting to hear that this has at least been considered in the UK also.

 

There were a lot of big words that confused me in the post above, so I hope this isn't completely off topic:

 

We use Google Apps to provide our staff with Email/Docs/Talk/Calendars etc...

I am currently setting up Directory Sync so our Active Directory sync's with our Google Apps accounts and then we use Google Apps as an OpenID provider for other services like Moodle/Joomla etc...

 

So in theory it's only one username/password so long as the software uses OpenID?

 

Thats right, Google Apps offers a OpenID provider allowing you to use your uploaded account data to authenticate with other sources that allow for OpenID authentication. In the scenario above the MoE looks to be choosing to use the SAML protocol which is somewhat simmilar to OpenID. What they are proposing as far as I can tell is tying various MoE resources back to either Live@Edu or Google Apps and using these as a SAML provider (after further reading they apear to be commited to working with both). This way if you have a cloud service setup then you can use the one logon across many MoE sites (eventually).

 

My issue with this is it effectivly mandates the use of these providers and allowing schools to endpoint their own authentication as well would be better overall.

 

I am now thinking (thanks to what I have read) that if the MoE were able to provide a central trusted Confederated Identity server which could trust and proxy all of the school Federated Identity servers then this single core server could then be setup to be trusted by the various providers so the school would only have to setup a single trust link as opposed to many. Currently I have not actually found out if such a thing (confederated identity server) exists but I remain hopeful.

Posted

Hi SYNACK,

 

I was researching topics that involved SAML/Federated Identity/SSO and I ran across your posting. I would suggest checking out Ping Identity. They provide a SAML based secure internet single sign-on solutions for web applications. Let me know if you'd like more info. Thanks!

Posted

Hi SYNACK

 

Only just spotted this. Many National Education Network resources are Shibboleth enabled and a number of 3rd party content providers also have access Shibboleth enabled. Within EMBC we have access to Education City, Encyclopedia Brittanica and a number of other tools. Within the UK it is through the UK Access Management Federation which also has a list of those accredited to the service as application / service providers.

  • Thanks 1
Posted
Hi SYNACK

 

Only just spotted this. Many National Education Network resources are Shibboleth enabled and a number of 3rd party content providers also have access Shibboleth enabled. Within EMBC we have access to Education City, Encyclopedia Brittanica and a number of other tools. Within the UK it is through the UK Access Management Federation which also has a list of those accredited to the service as application / service providers.

 

Thanks GD, exactly the kind of thing that I was after :D

Posted
SYNACK - If you have time, I would like to speak with you further regarding your project and organization. Ping Identity currently works with the NZ Government and can provide some insight and references to their current Federation implementation. If you would like to get more details and further discuss the relationship between the NZ Government and Ping, please feel free to contact me to facilitate conversations. Thanks!
  • 2 weeks later...
Posted (edited)
Post edited due to unauthorised advertising. Please note that as per our AUP only forum sponsors may use the forums in a commercial capcity. Edited by Dos_Box
  • 4 weeks later...
Posted

We've currently got and IDP in place and are testing with some service providers. We are also implementing a synthetic scope so that we can act as an IDP for other schools in the area. All very nice and works well but I think service providers are waiting to see if this takes off before jumping on the band wagon.

 

I went to FAM10 in cardiff and there were only 4 service providers (1 of them did university content). Can anyone reccomend a good SP for content that is 'Shibbolised'. We've got J2e and Britannica on board. Tried MS Dreamspark but students still have to provide thier Windows Live ID (thus defeating the single sign on).

 

Also has anyone used shibboleth for any other purpose than an IDP to get Single Sign on Access to a content provider.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...