Shibboleth Project
  • Inter-institutional web authentication and authorization
    • Supporting federated administration
    • Supporting personal/institutional privacy controls
    • Without requiring universal PKI client certificates

  • Why inter-institutional?
    • Already useful academic use cases (course-sharing, library access)
    • Outsourced services (e.g. private-label credit cards)
    • How big can our "local" security domain get?
    • Interaction with other local schools, state, fed

  • Why Web?
    • Many (most?) have web-based authentication running now
    •   (... but they're all different, as survey shows)
    • Interesting new apps are web-based
    • Support other protocols too, later

Internet2 Shibboleth, OASIS Security Services
50th
IETF, March 2001
RL "Bob" Morgan, rlmorgan@ washington.edu