Return to parent thread

Shibboleth

Shibboleth is an implementation of SAML in use by many higher education institutions and is required by Internet2. This thread discusses the investigation of Shibboleth for use in DfR and how it could fit in the implementation.and service.

Issues

How do we handle institutions that don't have Shibboleth?

Design

(Editable source DfR Auth Interactions)
(Editable source Auth for Management Console)
(Editable source Auth for DuraCloud)

Components

Identity Provider (IdP)

Identity Provider Discovery Service

Service Provider (SP)

Client

Discussion

  1. Need to retain userId in association with content throughout DfR interactions
  2. Shib not necessary with internal "system" interactions
  3. May be necessary to allow non-shib authN for internal calls
Questions
  1. How does authN between islandora and fedora currently work?
  2. Would Islandora be interested in using/leveraging DuraCloud groups from DuraSpace LDAP with Fedora policies

h4. Related Materials

  1. CAS
  2. SAML
  3. Spring-Security
  4. Shibboleth
  5. OAuth



Return to parent thread