Cargando…

CERN Single Sign On Solution

The need for Single Sign On has always been restricted by the absence of cross platform solutions: a single sign on working only on one platform or technology is nearly useless. The recent improvements in Web Services Federation (WS-Federation) standard enabling federation of identity, attribute, au...

Descripción completa

Detalles Bibliográficos
Autor principal: Ormancey, Emmanuel
Lenguaje:eng
Publicado: 2007
Materias:
Acceso en línea:https://dx.doi.org/10.1088/1742-6596/119/8/082008
http://cds.cern.ch/record/1054179
_version_ 1780912976059957248
author Ormancey, Emmanuel
author_facet Ormancey, Emmanuel
author_sort Ormancey, Emmanuel
collection CERN
description The need for Single Sign On has always been restricted by the absence of cross platform solutions: a single sign on working only on one platform or technology is nearly useless. The recent improvements in Web Services Federation (WS-Federation) standard enabling federation of identity, attribute, authentication and authorization information can now provide real extended Single Sign On solutions. Various solutions have been investigated at CERN and now, a Web SSO solution using some parts of WS-Federation technology is available. Using the Shibboleth Service Provider module for Apache hosted web sites and Microsoft ADFS as the identity provider linked to Active Directory user, users can now authenticate on any web application using a single authentication platform, providing identity, user information (building, phone...) as well as group membership enabling authorization possibilities. A typical scenario: a CERN user can now authenticate on a Linux/Apache website using Windows Integrated credentials, and his Active Directory group membership can be checked before allowing access to a specific web page.
id cern-1054179
institution Organización Europea para la Investigación Nuclear
language eng
publishDate 2007
record_format invenio
spelling cern-10541792022-08-17T13:36:51Zdoi:10.1088/1742-6596/119/8/082008http://cds.cern.ch/record/1054179engOrmancey, EmmanuelCERN Single Sign On SolutionComputing and ComputersThe need for Single Sign On has always been restricted by the absence of cross platform solutions: a single sign on working only on one platform or technology is nearly useless. The recent improvements in Web Services Federation (WS-Federation) standard enabling federation of identity, attribute, authentication and authorization information can now provide real extended Single Sign On solutions. Various solutions have been investigated at CERN and now, a Web SSO solution using some parts of WS-Federation technology is available. Using the Shibboleth Service Provider module for Apache hosted web sites and Microsoft ADFS as the identity provider linked to Active Directory user, users can now authenticate on any web application using a single authentication platform, providing identity, user information (building, phone...) as well as group membership enabling authorization possibilities. A typical scenario: a CERN user can now authenticate on a Linux/Apache website using Windows Integrated credentials, and his Active Directory group membership can be checked before allowing access to a specific web page.CERN-IT-Note-2007-006oai:cds.cern.ch:10541792007-09-03
spellingShingle Computing and Computers
Ormancey, Emmanuel
CERN Single Sign On Solution
title CERN Single Sign On Solution
title_full CERN Single Sign On Solution
title_fullStr CERN Single Sign On Solution
title_full_unstemmed CERN Single Sign On Solution
title_short CERN Single Sign On Solution
title_sort cern single sign on solution
topic Computing and Computers
url https://dx.doi.org/10.1088/1742-6596/119/8/082008
http://cds.cern.ch/record/1054179
work_keys_str_mv AT ormanceyemmanuel cernsinglesignonsolution