10
Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson

Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

Embed Size (px)

Citation preview

Page 1: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

Directory Enabled AuthN/Z at ClemsonDirectory Enabled AuthN/Z at Clemson

LDAP yesterday, Shibboleth tomorrowLDAP yesterday, Shibboleth tomorrow

Jill GemmillBarry Johnson

Jill GemmillBarry Johnson

Page 2: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

Early adopters of DirectoriesEarly adopters of Directories

Since mid 1990’s Event-driven provisioning into/from

directory Developers of DirXML (Novell Identity

Manager) Use of Blackboard as GUI for

collaborative spaces

Since mid 1990’s Event-driven provisioning into/from

directory Developers of DirXML (Novell Identity

Manager) Use of Blackboard as GUI for

collaborative spaces

Page 3: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

Clemson myCLEClemson myCLE

Page 4: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

Auto-provisioned Tools per VOAuto-provisioned Tools per VO

Address Book Blog Tool Calendar Drop Box EDU Assessment

Tool Glossary HomePage

Address Book Blog Tool Calendar Drop Box EDU Assessment

Tool Glossary HomePage

My Files mySQL Database Organization

Portfolio Search Survey Tool Tasks Wiki General Web Space -Etc!

My Files mySQL Database Organization

Portfolio Search Survey Tool Tasks Wiki General Web Space -Etc!

Page 5: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

So, why Shibboleth?So, why Shibboleth?

Placing attributes and also Access Control Roles in Directory became cumbersome to enforce correctly for each application

Had come to conclusion that attribute based access control was needed, and Shibboleth appeared to be best solution available.

Placing attributes and also Access Control Roles in Directory became cumbersome to enforce correctly for each application

Had come to conclusion that attribute based access control was needed, and Shibboleth appeared to be best solution available.

Page 6: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

Shibboleth today at ClemsonShibboleth today at Clemson

Production Shibboleth IdP In use for a few applications, including a

GridShib CA for use in Open Science Grid Plans in place to migrate current

applications to Shibboleth Service Providers

State-wide consortium : Health Sciences South Carolina

Production Shibboleth IdP In use for a few applications, including a

GridShib CA for use in Open Science Grid Plans in place to migrate current

applications to Shibboleth Service Providers

State-wide consortium : Health Sciences South Carolina

Page 7: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

Health Sciences South CarolinaHealth Sciences South Carolina

http://www.healthsciencessc.org/

Page 8: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

HSSC Shibboleth Working GroupHSSC Shibboleth Working Group

Clemson University Greenville Hospital System University

Medical Center Palmetto Health Medical University of South Carolina University of South Carolina Spartanburg Regional Health Care

System

Clemson University Greenville Hospital System University

Medical Center Palmetto Health Medical University of South Carolina University of South Carolina Spartanburg Regional Health Care

System

Page 9: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

Grids Today at ClemsonGrids Today at Clemson

Condor Pool : A campus grid linking over 1700 machines distributed across 27 locations on campus providing a high throughput computing resource for all faculty and students in need of a loosely coupled computer system to run thousands of jobs. Applications from civil engineering, economics and chemistry have already benefited.

Condor Pool : A campus grid linking over 1700 machines distributed across 27 locations on campus providing a high throughput computing resource for all faculty and students in need of a loosely coupled computer system to run thousands of jobs. Applications from civil engineering, economics and chemistry have already benefited.

Page 10: Directory Enabled AuthN/Z at Clemson LDAP yesterday, Shibboleth tomorrow Jill Gemmill Barry Johnson Jill Gemmill Barry Johnson

Grids and Shibboleth…Coming SoonGrids and Shibboleth…Coming Soon

Access to HPC/HTC resources will be authorized using Shibboleth, consistent with other campus applications

Collaboration environments such as myVocs, Sharpe will be used as guides to revising Clemson’s existing access control and provisioning systems.

Access to HPC/HTC resources will be authorized using Shibboleth, consistent with other campus applications

Collaboration environments such as myVocs, Sharpe will be used as guides to revising Clemson’s existing access control and provisioning systems.