20
www.eduserv.org.uk/ openathens OpenAthens Service Provider Breakout session 1 for Publishers 9 November 2016

Phase one of OpenAthens SP evolution

  • Upload
    eduserv

  • View
    62

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Phase one of OpenAthens SP evolution

www.eduserv.org.uk/openathens

OpenAthens Service ProviderBreakout session 1 for Publishers

9 November 2016

Page 2: Phase one of OpenAthens SP evolution

OpenAthens Service Provider as a service

• Phil Leahy (OpenAthens Service Relationship Manager)• David Orrell (OpenAthens System Architect)• Andy Anderson (OpenAthens Training Manager and QA

Analyst)

Page 3: Phase one of OpenAthens SP evolution

1. Authentication: Providing the best possible end-user experience

2. Single Sign-On: Enabling simple SSO within publishing platforms

3. Establishing standards: Driving common standards for interoperability

4. Facilitating discussions: Providing forums for discussion5. Embracing change: Understanding that change is constant

Page 4: Phase one of OpenAthens SP evolution

www.eduserv.org.uk/openathens

OpenAthens Service Provider9 November 2016

Page 5: Phase one of OpenAthens SP evolution

• Overview of OpenAthens• As an identity provider and a service provider

• How can we improve OpenAthens for publishers?• What we’re doing

Page 6: Phase one of OpenAthens SP evolution

OpenAthens

• Web-based Single Sign-On (SSO) and identity management

• Connect to multiple federations/communities using Open Standards (SAML)

Page 7: Phase one of OpenAthens SP evolution

OpenAthens advantages

• For organisations/users• Single account, seamless access across sites

• For publishers• Integrate once, connect to multiple communities

Page 8: Phase one of OpenAthens SP evolution

OpenAthens OrganisationService Provider

Sign-on using OpenAthens

Attributes

Page 9: Phase one of OpenAthens SP evolution

Attributes

• Where is the user from?• Who is the user (pseudonym)?• User’s role or entitlement• Name/email etc.

Organisation(Identity Provider)

Service Provider

Attributesvia SAML

Page 10: Phase one of OpenAthens SP evolution

OpenAthens OrganisationService Provider

Sign-on using OpenAthens

???

Page 11: Phase one of OpenAthens SP evolution

User authentication in OpenAthens

• 2 routes for organisations• Managed• Local directory integration

• Managed identity as a service• Upload via Web or bulk load• REST APIs

• Self-registration

Page 12: Phase one of OpenAthens SP evolution
Page 13: Phase one of OpenAthens SP evolution

Local directory integration

• OpenAthens can connect existing system• LDAP, ADFS• REST APIs

Page 14: Phase one of OpenAthens SP evolution

OpenAthens SP today

Identityprovider

Identityprovider

Identityprovider

Application

SAML

OASP

Service Provider

Integration API

Environment:Apache, Java, .NET

Configuration

Federation

OpenAthens

Page 15: Phase one of OpenAthens SP evolution

Customer feedback

• Not familiar with concepts of federated identity• Installation and configuration steps unclear• Changes take too long to take effect

• or require contact with Service Desk

Phase 1

Page 16: Phase one of OpenAthens SP evolution

Customer feedback

• Locally installed software required• prefer to use an API

• Integrating with multiple applications is complex• duplication of configuration and registration

• End-user experience inconsistent and confusing

Phase 2

Page 17: Phase one of OpenAthens SP evolution

Single Dashboard

Service Provider Federation

Page 18: Phase one of OpenAthens SP evolution

New Service Provider Dashboard

• Guided setup process• Clearer sign-posting of steps

• Much improved documentation• Near instantaneous updates

• Faster turn-around on testing• Registering for OpenAthens Federation

• No longer necessary!

Page 19: Phase one of OpenAthens SP evolution

Phase 1 available next week!

Questions?

Page 20: Phase one of OpenAthens SP evolution

Intermission