Supporting Institutions Towards Better Access Management - PowerPoint PPT Presentation

1 / 13
About This Presentation
Title:

Supporting Institutions Towards Better Access Management

Description:

UKeduPerson Study has touched on this (reports today) RUGIT Council Meeting, 18-Jun-2004 ... http://www.angel.ac.uk/SECURe/deliverables/documentation2/evaluate.html ... – PowerPoint PPT presentation

Number of Views:41
Avg rating:3.0/5.0
Slides: 14
Provided by: itserv5
Category:

less

Transcript and Presenter's Notes

Title: Supporting Institutions Towards Better Access Management


1
Supporting Institutions Towards Better Access
Management
  • John Paschoud
  • SECURe Project, LSE Library

2
contents
  • Shibboleth status (vs Athens)
  • Issues for Institutions
  • Scoping the problem
  • Assembling resources
  • A pilot support service
  • Monitoring progress
  • Long-term Support

3
Shibboleth Status
  • V1.2 available May 2004
  • Relatively straightforward to install, provided
    there is good web services understanding and
    middleware infrastructure (authentication,
    directories, webISO)
  • Target - works with Apache and IIS targets Java
    origins.
  • V2.0 likely to include portal support (incl
    PERSEUS development of uPortal toolkit)
  • Work underway on some of the essential management
    tools such as attribute release managers, target
    resource management, etc.
  • Can take between 3 hours and 3 years to install
  • How much infrastructure (core middleware) do you
    already have?

provided there is good web services understanding
and middleware infrastructure
4
Shibboleth Status
  • V1.2 available May 2004
  • Relatively straightforward to install, provided
    there is good web services understanding and
    middleware infrastructure (authentication,
    directories, webISO)
  • Target - works with Apache and IIS targets Java
    origins.
  • V2.0 likely to include portal support (incl
    PERSEUS development of uPortal toolkit)
  • Work underway on some of the essential management
    tools such as attribute release managers, target
    resource management, etc.
  • Can take between 3 hours and 3 years to install
  • How much infrastructure (core middleware) do you
    already have?

5
Implications for UK infrastructure
  • No dependency on a VERY LARGE centralised
    database
  • Need for implementation of a national WAYF
    service
  • better than current end-user interface model
  • (new WAYF options being developed)
  • Lower shared costs?
  • (but greater costs devolved to institutions)

6
Benefits to Institutions
  • Much easier Inter-Domain Integration
  • With other campuses
  • With off-campus vendor systems
  • Integration with other campus systems,
    intradomain
  • LMS
  • Med School
  • Ability to manage access control at a
    fine-grained level
  • Allows personalization, without releasing
    identity
  • Implement Shibboleth once
  • And then just manage attributes that are released
    to new targets
  • How much do we spend, now, on piecemeal access
    management???

7
Implications (problems?) for Institutions
  • Less duplicated end-user admin than with Athens
  • (similar to AthensDA)
  • Need for agreement on role attributes (eduPerson)
    for end-user description
  • Many dont yet have standards-based supporting
    services (SSO, enterprise directories)
  • (but new costs would largely replace improve,
    rather than add-to, existing ad-hoc AM mechanisms)

8
Shibboleth Architecture (still photo, no moving
parts)
9
LSE/SECURe AM infrastructure
http//www.angel.ac.uk/SECURe/deliverables/documen
tation/
10
Scoping the need
  • HE support
  • Documents, Helpdesk, Installation support
  • Existing services (OMII etc)
  • FE support
  • Managed services?
  • Existing support services (InfoNet etc)
  • Survey of directory management policies
    technologies used
  • UKeduPerson Study has touched on this (reports
    today)

11
Assembling resources
  • What can (and cant) be re-used from US CAMP
    programme?
  • Outputs from AAA projects (SECURe etc)
  • http//www.angel.ac.uk/SECURe/deliverables/documen
    tation2/evaluate.html
  • Models materials from other European adopters
    (SWITCH etc)

12
A pilot support service
  • Costed planned by end AY 2004/05
  • Operating for AY 2005/06 only
  • Opportunity to try different approaches with
    early-adopter institutions
  • Close working with DSPs

13
Monitoring progress
  • Continuous self-evaluation feedback from
    early-adopters
  • Establishing national measures of Shibbolization
  • Refining estimates of resources and timescale for
    full transition to new MwI

14
Foundations for long-term support
  • Assessment of long-term support need evidence
    from HE FE
  • Recommendations for long-term support service,
    incl cost-benefit case
  • Outline plan for service
  • Resources to be used by service
Write a Comment
User Comments (0)
About PowerShow.com