Unicon IAM Webinar
CAS, Shibboleth, Grouper
15 September 2016 - 11am Pacific Time (PT)
Mike Grady • Dmitriy Kopylenko • John Gasper
Join from PC, Mac, Linux, iOS or Android:
https://unicon.zoom.us/j/588322739
Or iPhone one-tap (US Toll): +16465588656,588322739# or
+14086380968,588322739#
Or Telephone:
Dial: +1 646 558 8656 (US Toll) or +1 408 638 0968 (US Toll)
Meeting ID: 588 322 739
Welcome
• Community updates
• Unicon contributions
• Q&A
Presenters
Mike Grady
Shibboleth IDP | Shibboleth SP
Dmitriy Kopylenko
CAS
John Gasper
Grouper
Charise Arrowood
MC
Events & Trends
• OpenID Connect Workshop: 22-23, 24-25 Feb 2016 in
Denver, CO
• Open Apereo Conference: 22-25 May 2016 in NYC
• 2016 Internet2 Global Summit: 15–18 May, Chicago, IL
Past Events
• Internet2 2016 Technology Exchange: 25-29 Sept, Miami,
FL
• EDUCAUSE 2016 Annual Conference: 25-28 Oct, Anaheim,
CA
• InCommon Shibboleth Workshop: 27-28 Oct, Long Beach,
CA
• 2017 Internet2 Global Summit: 23–26 Apr, Washington, DC
• 2017 Open Apereo: 4-8 June, Philadelphia, PA
Upcoming Events
IAM Trends
•MFA for Shibboleth, CAS
○Risk-based Adaptive AuthN
•OpenID Connect
•TIER: Packaging, APIs, Person Registry, ...
•SAML Integrations w/ O365 & ADFS
•Metadata Query (MDQ) Protocol
IAM Trends
•IAM in the Cloud
○Hosted SSO services and more
○Unicon’s offering:
https://www.unicon.net/solutions/IAM-cloud
IDP | SP
Mike Grady
Unicon Contributions
News
● Identity Provider V2.4.5, OpenSAML 2.6.6
○ EOL !!!! V2 full End-Of-Life date was July 31, 2016
○ 2.4.4 was last 2.x “minimum safe release”
● Service Provider V2.6.0 Now Available
○ Includes a new version of the Xerces XML parser that addresses
Apache Xerces-C XML Parser library versions
prior to V3.1.4 security vulnerability
Shibboleth Versions
● Latest versions:
○ IdP v3.2.1 (19 Dec 2015)
○ V3.1.1 considered “minimum safe release”
○ SP v2.6.0 (27 June 2016)
● v3.2.0 and v3.2.1 released
○ HTML5 local storage
○ SLO: Front channel SAML and CAS
○ SPNEGO authentication
○ Bug fixes
Now Past End-Of-Life …..
How soon that is a significant problem is unknown,
could be tomorrow, could be months, but you need to
have a plan to upgrade.
Shibboleth 2.x Lifetime
IdP: OpenID Connect
https://github.com/uchicago/shibboleth-oidc
●Authorization/Implicit Flow
●Dynamic Discovery
●Standard/Custom claims
●Certified by OpenID foundation for
University of Chicago
Shib-CAS AuthN v3
https://github.com/Unicon/shib-cas-authn3
● v3.1.0
○ Shibboleth IdP v3.X support
○ Fixed encoding on entityId/service parameters.
● Plan to produce a version where attributes
returned from CAS are available to the IdP,
and the AuthN Context Class w.r.t MFA.
○ Info from CAS coming back is done, now need a
“data connector” to expose it for use within the IdP
Other/Ongoing work
● Hazelcast Storage Service
https://github.com/UniconLabs/shibboleth-hazelcast-storage-service
● Duo Support for IdP v3
https://github.com/Unicon/shib-mfa-duo-auth
●Shib IdP as a Gradle Overlay
https://github.com/UniconLabs/shibboleth-idp-gradle-overlay
● IdP v3 powered by Docker
https://github.com/unicon/shibboleth-idp-dockerized
Other/Ongoing work
● Split Authn
○ Support for users coming from 2 different
Authentication/Attribute sources in distinct config
files, only one or the other used for Authn and
Resolver for any given authentication.
○ Easy to “hard code” attributes based on source
(“role”) chosen. “Role” choice on Login page.
○ Demo with 2 LDAP servers, but should work with
any 2 sources
○ https://github.com/Unicon/ccc-shib-split-authn
Other/Ongoing work
● Coming Soon: Symantec VIP MFA
○ Token Authentication
○ OTP Authentication
○ Push Authentication
○ Risk based Authentication
○ Sponsored by the University of Wisconsin -
Whitewater
○ Work done, but not yet “fully generalized” for open
source
Shib IdP v3.3
● Next version of Shib IdP due by late 2016
● Improvements to logout options and
accessibility aspects of such
● Adding in more built-in support for metadata
filtering, more “conditionals”, etc.
● New login flow(s) allowing combining factors
in what the Shib Dev core team believes will
be a more manageable/predictable way
Shib IdP v3.3
● Looks like an “out-of-the-box” Duo flow will be
part of it
●Unicon will need to determine if our current
Duo plugin should be “retired” or updated for
the new version.
○ Or if there are updates to the supplied one that
make sense to add
● Unicon will need to verify and/or “modify” our
other current authentication flow add-ons
Highlights
Dmitriy Kopylenko
Unicon Contributions
CAS v4.2
● v4.2.5 is the current version
○ Dynamic Plug-N-Play module configuration
○ ADFS/WS-FED delegated authN
○ UIs to manage SSO sessions/statistics
○ BASIC, JWT, Shiro, MongoDB, Stormpath authN
○ Couchbase, Ignite, Infinispan ticket registries
○ ABAC via attributes, time, or Grouper
●See http://jasig.github.io/cas/4.2.x/index.html
CAS v5.0.0
● Tentative release date: October 2016
● Current release: 5.0.0.RC1
● Major features:
○ MFA via DuoSecurity, RADIUS, YubiKey
■ Risk-based adaptive authN
○ SAML2 Web SSO support
○ OAuth/OIDC support
○ Full internal config re-architecture via Spring Boot
○ Java 8
Other/Ongoing work
● Auto config for CAS Java clients
https://github.com/Unicon/cas-client-autoconfig-support
● Delegated SAML authN for CAS 3.5.x
https://github.com/UniconLabs/cas-saml-auth
● Bootstrap CAS via a Gradle overlay:
https://github.com/UniconLabs/cas-strap
Further CAS Resources
● CAS maintenance policy:
https://apereo.github.io/cas/developer/Maintenance-
Policy.html
● Apereo Blog:
https://apereo.github.io/
John Gasper
Unicon Contributions
Grouper v2.3.0
● Can run multiple simultaneous
Loader/Daemon instances
●WS: Manage attribute/permission defs; TIER
authorization
●PSP-NG: New Grouper provisioner
○ LDAP and AD connectors built-in
●Exporting tree to GSH script.
●Lots of patches:
○ API: 24, UI: 8, WS: 5, PSP-NG: 2
Other/Ongoing work
●Internet2 Grouper Dockerized: Composable
images/containers
https://github.com/Unicon/grouper-dockerized
● Grouper-Demo for Docker
https://hub.docker.com/r/unicon/grouper-demo/
● Custom Provisioning Target Form
https://github.com/Unicon/grouper-provisioning-target-ui
● Azure AD (Office 365) Provisioner
https://github.com/Unicon/office365-and-azure-ad-grouper-
provisioner
Docker Demo
Grouper environment
based on the
composable images/container
Questions / Discussion
Mike Grady
mgrady@unicon.net
Dmitry Kopylenko
dkopylenko@unicon.net
John Gasper
jgasper@unicon.net

More Related Content

PDF
stackconf 2021 | First hand experience: How Nextcloud stayed productive durin...
PDF
stackconf 2021 | GitOps: yea or nay?
PDF
stackconf 2021 | Setup Min.io and Open Policy Agent for a multi purpose scien...
PDF
FIWARE Wednesday Webinars - Strategies for Context Data Persistence
PDF
stackconf 2021 | Continuous Security – integrating security into your pipelines
PPTX
FIWARE Wednesday Webinars - How to Debug IoT Agents
PDF
stackconf 2021 | Embracing change: Policy-as-code for Kubernetes with OPA and...
PDF
FIWARE Wednesday Webinars - Short Term History within Smart Systems
stackconf 2021 | First hand experience: How Nextcloud stayed productive durin...
stackconf 2021 | GitOps: yea or nay?
stackconf 2021 | Setup Min.io and Open Policy Agent for a multi purpose scien...
FIWARE Wednesday Webinars - Strategies for Context Data Persistence
stackconf 2021 | Continuous Security – integrating security into your pipelines
FIWARE Wednesday Webinars - How to Debug IoT Agents
stackconf 2021 | Embracing change: Policy-as-code for Kubernetes with OPA and...
FIWARE Wednesday Webinars - Short Term History within Smart Systems

What's hot (12)

PDF
Portable data analysis infrastracture for LHC at INFN -vCHEP2021
PDF
Security: The Value of SBOMs
PPTX
FIWARE Wednesday Webinars - Core Context Management
PDF
Yann Albou & Sébastien Féré - GitOps as a way to manage enterprise K8s and vi...
PDF
Maria Guseva - The solution of merge hell in monorepo
PDF
How to get Away with K8S - Becoming Production
PDF
Making your app soar without a container manifest
PPTX
Hyperledger
PDF
Horizen Quarterly Live Update - 4Q 2019
PDF
Building a dApp on Tezos
PDF
Encode Club workshop slides
PDF
Flogo - A Golang-powered Open Source IoT Integration Framework (Gophercon)
Portable data analysis infrastracture for LHC at INFN -vCHEP2021
Security: The Value of SBOMs
FIWARE Wednesday Webinars - Core Context Management
Yann Albou & Sébastien Féré - GitOps as a way to manage enterprise K8s and vi...
Maria Guseva - The solution of merge hell in monorepo
How to get Away with K8S - Becoming Production
Making your app soar without a container manifest
Hyperledger
Horizen Quarterly Live Update - 4Q 2019
Building a dApp on Tezos
Encode Club workshop slides
Flogo - A Golang-powered Open Source IoT Integration Framework (Gophercon)
Ad

Similar to 2016 09-15 unicon-iam-update (20)

PPTX
Unicon July 2015 IAM Briefing
PPTX
Unicon July 2015 IAM Briefing
PDF
A Love Story with Kubevirt and Backstage from Cloud Native NoVA meetup Feb 2024
ODP
Unicon June 2014 IAM Briefing
PPTX
Identity & Access Management Briefing
PDF
Exploring and Using the Python Ecosystem
PDF
JHipster Code 2020 keynote
PDF
Safe Community Call #13.pdf
ODP
2014 Q4 IAM Open Source Support Program Update
PDF
Quebec - 16 November 2022 - Canada CNCF Meetups.pdf
PDF
Exploring Google APIs with Python
PDF
Workday's Next Generation Private Cloud
PPTX
Shopify - CNCF March 2025 Meetup - Presentation - 26-03-25.pptx
PDF
Continuous Delivery to the Cloud: Automate Thru Production with CI + Spinnaker
PDF
OpenNebulaConf2019 - Welcome and Project Update - Ignacio M. Llorente, Rubén ...
PDF
Go GC: Prioritizing Low Latency and Simplicity
PDF
Apache Beam and Google Cloud Dataflow - IDG - final
PDF
Data Science in the Cloud @StitchFix
PDF
A GitOps Kubernetes Native CICD Solution with Argo Events, Workflows, and CD
PDF
Kubernetes Forum Seoul 2019: Re-architecting Data Platform with Kubernetes
Unicon July 2015 IAM Briefing
Unicon July 2015 IAM Briefing
A Love Story with Kubevirt and Backstage from Cloud Native NoVA meetup Feb 2024
Unicon June 2014 IAM Briefing
Identity & Access Management Briefing
Exploring and Using the Python Ecosystem
JHipster Code 2020 keynote
Safe Community Call #13.pdf
2014 Q4 IAM Open Source Support Program Update
Quebec - 16 November 2022 - Canada CNCF Meetups.pdf
Exploring Google APIs with Python
Workday's Next Generation Private Cloud
Shopify - CNCF March 2025 Meetup - Presentation - 26-03-25.pptx
Continuous Delivery to the Cloud: Automate Thru Production with CI + Spinnaker
OpenNebulaConf2019 - Welcome and Project Update - Ignacio M. Llorente, Rubén ...
Go GC: Prioritizing Low Latency and Simplicity
Apache Beam and Google Cloud Dataflow - IDG - final
Data Science in the Cloud @StitchFix
A GitOps Kubernetes Native CICD Solution with Argo Events, Workflows, and CD
Kubernetes Forum Seoul 2019: Re-architecting Data Platform with Kubernetes
Ad

Recently uploaded (20)

PDF
David L Page_DCI Research Study Journey_how Methodology can inform one's prac...
PDF
Vision Prelims GS PYQ Analysis 2011-2022 www.upscpdf.com.pdf
PDF
Skin Care and Cosmetic Ingredients Dictionary ( PDFDrive ).pdf
PDF
IP : I ; Unit I : Preformulation Studies
PDF
LIFE & LIVING TRILOGY - PART - (2) THE PURPOSE OF LIFE.pdf
PDF
International_Financial_Reporting_Standa.pdf
PDF
Journal of Dental Science - UDMY (2021).pdf
PDF
semiconductor packaging in vlsi design fab
PPTX
Module on health assessment of CHN. pptx
PPTX
Computer Architecture Input Output Memory.pptx
PDF
Journal of Dental Science - UDMY (2022).pdf
PPTX
B.Sc. DS Unit 2 Software Engineering.pptx
PDF
My India Quiz Book_20210205121199924.pdf
PDF
CISA (Certified Information Systems Auditor) Domain-Wise Summary.pdf
PPTX
What’s under the hood: Parsing standardized learning content for AI
PPTX
ELIAS-SEZIURE AND EPilepsy semmioan session.pptx
PPTX
Unit 4 Computer Architecture Multicore Processor.pptx
PDF
FORM 1 BIOLOGY MIND MAPS and their schemes
PPTX
Climate Change and Its Global Impact.pptx
DOCX
Cambridge-Practice-Tests-for-IELTS-12.docx
David L Page_DCI Research Study Journey_how Methodology can inform one's prac...
Vision Prelims GS PYQ Analysis 2011-2022 www.upscpdf.com.pdf
Skin Care and Cosmetic Ingredients Dictionary ( PDFDrive ).pdf
IP : I ; Unit I : Preformulation Studies
LIFE & LIVING TRILOGY - PART - (2) THE PURPOSE OF LIFE.pdf
International_Financial_Reporting_Standa.pdf
Journal of Dental Science - UDMY (2021).pdf
semiconductor packaging in vlsi design fab
Module on health assessment of CHN. pptx
Computer Architecture Input Output Memory.pptx
Journal of Dental Science - UDMY (2022).pdf
B.Sc. DS Unit 2 Software Engineering.pptx
My India Quiz Book_20210205121199924.pdf
CISA (Certified Information Systems Auditor) Domain-Wise Summary.pdf
What’s under the hood: Parsing standardized learning content for AI
ELIAS-SEZIURE AND EPilepsy semmioan session.pptx
Unit 4 Computer Architecture Multicore Processor.pptx
FORM 1 BIOLOGY MIND MAPS and their schemes
Climate Change and Its Global Impact.pptx
Cambridge-Practice-Tests-for-IELTS-12.docx

2016 09-15 unicon-iam-update

  • 1. Unicon IAM Webinar CAS, Shibboleth, Grouper 15 September 2016 - 11am Pacific Time (PT) Mike Grady • Dmitriy Kopylenko • John Gasper Join from PC, Mac, Linux, iOS or Android: https://unicon.zoom.us/j/588322739 Or iPhone one-tap (US Toll): +16465588656,588322739# or +14086380968,588322739# Or Telephone: Dial: +1 646 558 8656 (US Toll) or +1 408 638 0968 (US Toll) Meeting ID: 588 322 739
  • 2. Welcome • Community updates • Unicon contributions • Q&A
  • 3. Presenters Mike Grady Shibboleth IDP | Shibboleth SP Dmitriy Kopylenko CAS John Gasper Grouper Charise Arrowood MC
  • 5. • OpenID Connect Workshop: 22-23, 24-25 Feb 2016 in Denver, CO • Open Apereo Conference: 22-25 May 2016 in NYC • 2016 Internet2 Global Summit: 15–18 May, Chicago, IL Past Events
  • 6. • Internet2 2016 Technology Exchange: 25-29 Sept, Miami, FL • EDUCAUSE 2016 Annual Conference: 25-28 Oct, Anaheim, CA • InCommon Shibboleth Workshop: 27-28 Oct, Long Beach, CA • 2017 Internet2 Global Summit: 23–26 Apr, Washington, DC • 2017 Open Apereo: 4-8 June, Philadelphia, PA Upcoming Events
  • 7. IAM Trends •MFA for Shibboleth, CAS ○Risk-based Adaptive AuthN •OpenID Connect •TIER: Packaging, APIs, Person Registry, ... •SAML Integrations w/ O365 & ADFS •Metadata Query (MDQ) Protocol
  • 8. IAM Trends •IAM in the Cloud ○Hosted SSO services and more ○Unicon’s offering: https://www.unicon.net/solutions/IAM-cloud
  • 9. IDP | SP Mike Grady Unicon Contributions
  • 10. News ● Identity Provider V2.4.5, OpenSAML 2.6.6 ○ EOL !!!! V2 full End-Of-Life date was July 31, 2016 ○ 2.4.4 was last 2.x “minimum safe release” ● Service Provider V2.6.0 Now Available ○ Includes a new version of the Xerces XML parser that addresses Apache Xerces-C XML Parser library versions prior to V3.1.4 security vulnerability
  • 11. Shibboleth Versions ● Latest versions: ○ IdP v3.2.1 (19 Dec 2015) ○ V3.1.1 considered “minimum safe release” ○ SP v2.6.0 (27 June 2016) ● v3.2.0 and v3.2.1 released ○ HTML5 local storage ○ SLO: Front channel SAML and CAS ○ SPNEGO authentication ○ Bug fixes
  • 12. Now Past End-Of-Life ….. How soon that is a significant problem is unknown, could be tomorrow, could be months, but you need to have a plan to upgrade. Shibboleth 2.x Lifetime
  • 13. IdP: OpenID Connect https://github.com/uchicago/shibboleth-oidc ●Authorization/Implicit Flow ●Dynamic Discovery ●Standard/Custom claims ●Certified by OpenID foundation for University of Chicago
  • 14. Shib-CAS AuthN v3 https://github.com/Unicon/shib-cas-authn3 ● v3.1.0 ○ Shibboleth IdP v3.X support ○ Fixed encoding on entityId/service parameters. ● Plan to produce a version where attributes returned from CAS are available to the IdP, and the AuthN Context Class w.r.t MFA. ○ Info from CAS coming back is done, now need a “data connector” to expose it for use within the IdP
  • 15. Other/Ongoing work ● Hazelcast Storage Service https://github.com/UniconLabs/shibboleth-hazelcast-storage-service ● Duo Support for IdP v3 https://github.com/Unicon/shib-mfa-duo-auth ●Shib IdP as a Gradle Overlay https://github.com/UniconLabs/shibboleth-idp-gradle-overlay ● IdP v3 powered by Docker https://github.com/unicon/shibboleth-idp-dockerized
  • 16. Other/Ongoing work ● Split Authn ○ Support for users coming from 2 different Authentication/Attribute sources in distinct config files, only one or the other used for Authn and Resolver for any given authentication. ○ Easy to “hard code” attributes based on source (“role”) chosen. “Role” choice on Login page. ○ Demo with 2 LDAP servers, but should work with any 2 sources ○ https://github.com/Unicon/ccc-shib-split-authn
  • 17. Other/Ongoing work ● Coming Soon: Symantec VIP MFA ○ Token Authentication ○ OTP Authentication ○ Push Authentication ○ Risk based Authentication ○ Sponsored by the University of Wisconsin - Whitewater ○ Work done, but not yet “fully generalized” for open source
  • 18. Shib IdP v3.3 ● Next version of Shib IdP due by late 2016 ● Improvements to logout options and accessibility aspects of such ● Adding in more built-in support for metadata filtering, more “conditionals”, etc. ● New login flow(s) allowing combining factors in what the Shib Dev core team believes will be a more manageable/predictable way
  • 19. Shib IdP v3.3 ● Looks like an “out-of-the-box” Duo flow will be part of it ●Unicon will need to determine if our current Duo plugin should be “retired” or updated for the new version. ○ Or if there are updates to the supplied one that make sense to add ● Unicon will need to verify and/or “modify” our other current authentication flow add-ons
  • 21. CAS v4.2 ● v4.2.5 is the current version ○ Dynamic Plug-N-Play module configuration ○ ADFS/WS-FED delegated authN ○ UIs to manage SSO sessions/statistics ○ BASIC, JWT, Shiro, MongoDB, Stormpath authN ○ Couchbase, Ignite, Infinispan ticket registries ○ ABAC via attributes, time, or Grouper ●See http://jasig.github.io/cas/4.2.x/index.html
  • 22. CAS v5.0.0 ● Tentative release date: October 2016 ● Current release: 5.0.0.RC1 ● Major features: ○ MFA via DuoSecurity, RADIUS, YubiKey ■ Risk-based adaptive authN ○ SAML2 Web SSO support ○ OAuth/OIDC support ○ Full internal config re-architecture via Spring Boot ○ Java 8
  • 23. Other/Ongoing work ● Auto config for CAS Java clients https://github.com/Unicon/cas-client-autoconfig-support ● Delegated SAML authN for CAS 3.5.x https://github.com/UniconLabs/cas-saml-auth ● Bootstrap CAS via a Gradle overlay: https://github.com/UniconLabs/cas-strap
  • 24. Further CAS Resources ● CAS maintenance policy: https://apereo.github.io/cas/developer/Maintenance- Policy.html ● Apereo Blog: https://apereo.github.io/
  • 26. Grouper v2.3.0 ● Can run multiple simultaneous Loader/Daemon instances ●WS: Manage attribute/permission defs; TIER authorization ●PSP-NG: New Grouper provisioner ○ LDAP and AD connectors built-in ●Exporting tree to GSH script. ●Lots of patches: ○ API: 24, UI: 8, WS: 5, PSP-NG: 2
  • 27. Other/Ongoing work ●Internet2 Grouper Dockerized: Composable images/containers https://github.com/Unicon/grouper-dockerized ● Grouper-Demo for Docker https://hub.docker.com/r/unicon/grouper-demo/ ● Custom Provisioning Target Form https://github.com/Unicon/grouper-provisioning-target-ui ● Azure AD (Office 365) Provisioner https://github.com/Unicon/office365-and-azure-ad-grouper- provisioner
  • 28. Docker Demo Grouper environment based on the composable images/container
  • 29. Questions / Discussion Mike Grady mgrady@unicon.net Dmitry Kopylenko dkopylenko@unicon.net John Gasper jgasper@unicon.net

Editor's Notes

  • #3: Unicon's CAS strategy* Participate directly in CAS* Develop open source software on behalf of clients* Inform maintenance development through support. You have to source your support somewhere* In-house staff* Goodwill and engagement of the community* Commercial partner (e.g., Unicon)* (Reality Often combination of these)Unicon's "Cooperative" Support* Cooperates with you, your staff, the community* Support experiences yield improved public documentation* Support-inspired and subscriber-needs-guided open source maintenance development** Directly in and available for adoption with the Jasig CAS softwareThank you to our support subscribers!* Support subscriptions make Unicon maintenance development possible* Support experiences and subscriber input guide Unicon maintenance development towards the worthwhile
  • #7: https://www.incommon.org/shibtraining/
  • #27: https://spaces.internet2.edu/display/Grouper/Grouper+2.3+Release+Announcement https://spaces.internet2.edu/display/Grouper/v2.3+Release+Notes