Tower

Identity and Access Management
(IAM - Shibboleth)

May 26, 2008

Rationale

The university's existing home-grown, cookie-based authentication system (GLAuth) has security problems and must be replaced. In addition, the university needs to support federated authentication services for interaction with contracted service providers. Existing authentication systems do not support the most prevalent web servers on campus, Apache and IIS for Windows and Linux. Finally, the university needs to enable its departments and units to consume enterprise attributes for authorization of access in an efficient, scalable and secure manner. Shibboleth has been identified as an appropriate system for addressing these needs. By integrating Shibboleth with existing credential and attribute stores, we will be able to meet the four identified challenges.

Goals

Project Sponsor

Impact

End users will see a single place to sign on. All existing cookie-based authentication will be replaced including GLAuth and CoSign. This will impact over 100 departments and units using these technologies. Enterprise system work will be needed on several major systems. This work varies in complexity but will be transparent to the user.

Lab work will begin in February. A working development model will be in place in March. Preliminary assertions will be identified in March. Implementation of assertions will begin in May. Production infrastructure will be in place in July. Testing will be completed in August. Production services will be available in September. An enterprise system roadmap will be developed during the planning phase along with a roadmap for sunsetting GLAuth and CoSign services.

Contacts

Presentations

Early Beta Testing: Shibboleth Training Camp

OIT Units

Chief Information Officer , Academic Technology, Computing and Networking Services , Network Services, Telecom

Services

Students, Faculty, Staff

Committees

IT Advisory Committee, Academic Technology, Data Infrastructure, High-Performance Computing, Network Infrastructure, Information Security Management, Ad Hoc

Projects

UF Exchange, High Performance Computing, AT Grid, Active Directory Project, Microsoft Campus Agreement, Shibboleth, more...

Policies

Acceptable Use (AUP), IT Security, IT Strategic Plan, Disabled Access Computing Policy, more...

System Status

Bridges Status, CNS Reported Issues, Gatorlink Mail, ISIS, Outgoing Mail, Network Status, Webadmin Sites, Webmail

Training

Students, Faculty, Staff, Other Resources

Topics of Interest

Charging for Dial Up Services, Gatorlink Eligibility, Email/Gatorlink Configuration, Connecting to UF , IT Reports

Text-only Version

Search: