欢迎来到麦多课文档分享! | 帮助中心 海量文档,免费浏览,给你所需,享你所想!
麦多课文档分享
全部分类
  • 标准规范>
  • 教学课件>
  • 考试资料>
  • 办公文档>
  • 学术论文>
  • 行业资料>
  • 易语言源码>
  • ImageVerifierCode 换一换
    首页 麦多课文档分享 > 资源分类 > PPT文档下载
    分享到微信 分享到微博 分享到QQ空间

    Internet2 WebISO Project.ppt

    • 资源ID:376587       资源大小:118KB        全文页数:13页
    • 资源格式: PPT        下载积分:2000积分
    快捷下载 游客一键下载
    账号登录下载
    微信登录下载
    二维码
    微信扫一扫登录
    下载资源需要2000积分(如需开发票,请勿充值!)
    邮箱/手机:
    温馨提示:
    如需开发票,请勿充值!快捷下载时,用户名和密码都是您填写的邮箱或者手机号,方便查询和重复下载(系统自动生成)。
    如需开发票,请勿充值!如填写123,账号就是123,密码也是123。
    支付方式: 支付宝扫码支付    微信扫码支付   
    验证码:   换一换

    加入VIP,交流精品资源
     
    账号:
    密码:
    验证码:   换一换
      忘记密码?
        
    友情提示
    2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
    3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
    4、本站资源下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。
    5、试题试卷类文档,如果标题没有明确说明有答案则都视为没有答案,请知晓。

    Internet2 WebISO Project.ppt

    1、Internet2 WebISO Project,RL “Bob“ Morgan, University of Washington,Topics,How it came to be Project status WebISO defined Project goals Architecture/Interface,How it came to be,Shibboleth project assumption: every campus has intra-campus web authentication startling discovery: not true The MACE way:

    2、 do something about it brief search for likely sharable implementations U of Washingtons “pubcookie“ chosen as starting point project started to make “appropriate progress“ now looking at architectural issues,WebISO project status,Its live: web: http:/middleware.internet2.edu/webiso/ email: mace-web

    3、isointernet2.edu, 40 on list phone calls: bi-weekly, 3:30PM ET Tuesdays active work on refining project goals Pubcookie distribution 10 sites with code, 1 non-UW deployment (CMU), a few pending; BSD-style license CMU-contributed changes being incorporated freely-available distribution posted shortly

    4、,WebISO defined,Organizational web-based sign-on system Typically includes: single sign-on (only “type something“ once to access multiple targets) use of standard authentication backend (LDAP, Kerberos, NIS, NT, etc) keep passwords away from application web servers (have them only entered into “webl

    5、ogin“ server) “Most reinvented technology of the 90s“,WebISO components,Module for application webservers check for authentication info on request, if not found redirect browser to weblogin server interpret authentication info, pass to web application Weblogin server accept redirected request, promp

    6、t for userid/password (or other authn method) return browser to target webserver, with authn info Message format for appserver weblogin,The pubcookie story,“Just another webiso“ written in C Apache, MS-IIS target web servers Apache-based weblogin Kerberos 5 backend built-in, others possible in produ

    7、ction since 1999 web-based documentation signed/encrypted messages, sent using cookies works with almost all browsers,Pubcookie planned improvements,better docs, clearer installation procedures more authentication backends, pluggable X.509 client cert authn, Kerberos client authn variable-length SSO

    8、 session support per-user, per-server settings “blinded“ userids easier/automatic key management authn tokens in URLs (cross-DNS-domains) robustness, quality assurance, modularity . many require rethinking, justification, threat model,Project goals,Not just pubcookie enhancement/support Work with pa

    9、rtner projects to ensure meeting requirements: uPortal (http:/mis105.mis.udel.edu/ja-sig/uportal/) Open Knowledge Initiative (http:/mit.edu/oki) Shibboleth Define architecture and interface to which multiple webiso implementations can conform,WebISO architecture + interface,Application interface man

    10、y issues similar to Shibboleth target arch webisos typically supply plain old userid what about authorization data? what about privacy protection? forced/step-up authentication app specifying authn method (pubcookie supports both Kerberos and SecurID) app selectively turning off SSO session manageme

    11、nt e.g., “single sign-off“ from all apps at once,Webiso design centers,Webiso implementations differ in approach support for admin apps: high security/control support for student-run apps: simplicity, ease of install/support assume local software on client (eg Kerb plugin) cross-DNS-domain support r

    12、equired assume underlying authn infra (Kerb, X.509) support home-grown apps, package apps, static pages Can one package do it all?,Application interface 2,The 3-tier problem (aka delegation) seen by many app servers that need to access backend services (eg IMAP) on behalf of user seen by all portals

    13、 that act as intermediaries many sites implement “practical“ solutions can webiso provide a standard approach? will any solution be dependent on underlying delegation technology, eg Kerberos or X.509? is this a WebISO project problem?,Conclusion,WebISO project up and running Pubcookie code available Architecture/interface issues engaged Sites still reinventing, so need is there Partner projects need support http:/middleware.internet2.edu/webiso/,


    注意事项

    本文(Internet2 WebISO Project.ppt)为本站会员(tireattitude366)主动上传,麦多课文档分享仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知麦多课文档分享(点击联系客服),我们立即给予删除!




    关于我们 - 网站声明 - 网站地图 - 资源地图 - 友情链接 - 网站客服 - 联系我们

    copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
    备案/许可证编号:苏ICP备17064731号-1 

    收起
    展开