Federated Access Management: Core Skills for Identity Providers
Federated Access Management (FAM) - for both internal and external resources - offers a secure, scalable and user friendly environment for organisations to manage and verify the online identity of their own members.
This two day workshop, developed with JISC funding, focuses on the technical requirements for organisations joining the UK Access Management Federation and acting as their own Identity Provider (IdP). Participants will be able to use the technology for themselves and explore the core skills and practical steps required to deploy it within their organisation.
For many academic institutions, the end of JISC funding for Athens access is a key driving factor in the decision to join the UK AMF, however the infrastructure required for FAM also allows much wider uses of the technology - both within and between organisations. These include management of access to shared resources, without replicating or exchanging user accounts and the deployment of genuine web-based single-sign-on (SSO) solutions.
Topics:
- What is Federated Access Management (FAM)?
- Why is FAM different and what does it offer?
- The UK Access Management Federation - what it does and how to join
- Technical infrastructure - including Apache, Tomcat and Java
- Linux or Windows? - options for both platforms
- Secure authentication - SSL, certificates and https
- What are Shibboleth and SAML? - installation and configuration
- Authentication, authorisation and attributes
- Who else to involve - why deploying FAM is not just a technical task
- Where to get further support and guidance
Who is it for?
The training has been developed for staff responsible for institutional access to online resources and/or the management of user authentication.
Technical staff will have the opportunity to see the systems working for real and explore the components that make them work. Non-systems staff will be able to gain an effective overview of the technical set-up required and how it fits in to an overall strategy for effective access management.
Ideally participants will need to be comfortable with basic administration of computer systems (installing software etc.) as well as having some general knowledge about internet networking and identity management principles.
By the end of the workshop participants will have:
- Discussed the current position of their own organisation with regards to Federated Access Management
- Reviewed the technical and administrative steps required to join the UK Access Management Federation
- Appreciated the position of the technical infrastructure as one part of an institutional strategy for access management
- Reviewed the core skills required for an in-house IdP deployment
- Investigated open source technologies for IdP deployment on both Windows and Linux platforms
- Seen a complete Shibboleth-based IdP build
- Examined the configuration of a Shibboleth-based IdP to work with the UK AMF
- Explored XML files for Shibboleth configuration and the release of attributes
Scheduled workshops
No workshops scheduled at this time.