Project

General

Profile

Actions

CSSO » History » Revision 70

« Previous | Revision 70/87 (diff) | Next »
Lutz Suhrbier, 08/23/2010 06:14 PM


Community Single Sign-On (CSSO) security infrastructure

The aim of EDIT's Community Single Sign-On (CSSO) security infrastructure is integrating various EDIT service providers into the platform such as registered users of the EDIT community may access these services using a single EDIT identity only. Simultaneously, the CSSO security infrastructure respects the requirements of many biodiverity service providers to remain the sovereigns of their resources and services offered. That means, service providers may define and enforce individual access control policies in order to protect their resources, i.e. enable or prevent certain users or groups from accessing specific services.

Technologically, EDIT's CSSO Security Infrastructure bases on the OASIS Security Assertion Markup Language (SAML)":http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security standard family. The main benefits of SAML include a secure attribute exchange framework, several open source implementations, privacy-preserving access to individually protected online resources and a federation concept. In particular, this federation concept perfectly matches the requirements regarding the creation of a single sign-on platform for more or less closed communities like e.g. taxonomic experts within EDIT. Beside others, the EDIT federation currently consists of about 2000 taxonomic experts registered in an SAML Identity Provider (IdP) and several SAML Service Providers (SP) instances like e.g. "EDITExpertNet

While, the vision is to extend the CSSO concept from EDIT to the whole biodiversity community someday, this document will present an outline to any available information regarding the existing CSSO release.


EDIT Federation

General Information::

Provides general information about the EDIT Federation.

How to become an EDIT user ?::

Provides a detailed description on how users can be registered to the EDIT federation.

How to become an EDIT Service Provider ?::

Provides a detailed description on how EDIT institutions can implement services using the Single Sign-On features within the EDIT federation.

Current EDIT Federatoin members::

Gives an overview of the EDIT services currently connected to CSSO.

Common Set of EDIT Federation Attributes::

Describes the user attributes currently transmitted to EDIT Service Providers from the EDIT Identity Provider.


Anything below is currently work in progress. Sorry

CSSO Infrastructure

CSSO Technical Overview ::

Provides general information about the EDIT security components.

Identity Provider (IdP)

OpenSSO General Information::

Service Provider (SP)

Shibboleth General Information::

Shibboleth Management Tools::

The Shibboleth Protocol::

Certification Authorities

Freie Universität Berlin (FUB-CA) Certification Authority ::

WP 5.7 Certification Authorities ::

Shibboleth Proxy

Shibboleth Proxy General Information::


User Guides

OpenSSO

OpenSSO User Documentation ::

Certificate Handling

The "Invalid Security Certificate Problem"::

Firefox: How to import CA certificates ::

Firefox: How to handle invalid security certificates ? ::

Internet Explorer: How to import CA certificates ::

Internet Explorer: How to handle invalid security certificates ? ::


Installation Guides

OpenSSO

OpenAM (OpenSSO) based Identity Provider (IdP) Installation on Debian Lenny ::

OpenSSO Federation Setup ::

OpenSSO Installation (with Debian Etch) ::

Shibboleth

Shibboleth Service Provider (SP) v2.3.x Installation on Debian Lenny ::

Shibboleth Identity Provider (IdP) Setup on Debian Etch ::

Shibboleth Service Provider (SP) v2.x Installation on Debian Etch ::

Shibboleth Service Provider (SP) Installation on Debian Etch ::

Shibboleth Service Provider (SP) Installation on Microsoft Windows ::

SimpleSAMLphp

SimpleSAMLphp Installation (Debian Etch) ::

SpringSSO

Integrating Spring Framework into CSSO ::

Xen

BGBM Xen server documentation ::

Debian Linux

Debian Linux Installation Guide ::

Apache

Apache2 Installation on Debian Etch::

Apache MySQL Authentication for Debian Etch::

Drupal

Drupal5 Installation on Debian Etch::

Drupal::

Java

SUN JDK5 Installation on Debian Etch::

Maven2

Apache Maven 2 Installation on Debian Etch::

MySQL

MySQL Installation on Debian Etch::

Postfix

Postfix Installation (Debian Etch)::

PostgreSQL

PostgreSQL Installation on Debian Etch::

SQLite

SQLite Installation on Debian Etch::

Subversion

Subversion Installation on Debian Etch::

Mirroring Subversion Repositories::

Tomcat6

Tomcat6 Installation on Debian Etch::

Trac

Trac Installation on Debian Etch::

Mirroring Trac::


Miscellaneous

Licenses used by CSSO 3rd party components ::

Initial Plannings of the Community Single Sign-On (CSSO) Security Infrastructure ::

Updated by Lutz Suhrbier over 13 years ago · 70 revisions