---+ Authentication: Single-Sign-On (SSO) Single sign-on authentication means that you login once to a VO site or service and can then access any other VO site or service without repeating the authentication process. Conventional wisdom is that this should be done with digital signatures, but the standards for these signatures allow many different approaches. A [[http://www.ivoa.net/Documents/latest/SSOAuthMech.html][specification for the authentication mechanisms]] that the VO should use is now an IVOA Recommendation. ---++ Specification The next aspects of the security infrastructure to consider are the delegation mechanism and community services and trust model: * [[http://www.ivoa.net/Documents/cover/CredentialDelegation-20080715.html][Credential Delegation Protocol v1.0]] * [[http://wiki.ivoa.net/internal/IVOA/IvoaGridAndWebServices/trust-model-v0.1.html][Draft of specification for trust model and community operations]]. ---++ Discussion * [[SsoRFC][Discussion page for the v1.0 specifications]] * [[SSO20RFC][Discussion page for the v2.0 specifications]] * [[SSO21RFC][Discussion page for the v2.1 specifications]] ---++ History * Original SingleSignOnProposal * [[http://www.ivoa.net/Documents/latest/SSOintro.html][IVOA note introducing the profiles]]. * [[http://wiki.ivoa.net/internal/IVOA/IvoaGridAndWebServices/ivoa-auth-mech-0.2.doc][V0.2 draft of authentication-mechanism standard]] * [[http://wiki.ivoa.net/internal/IVOA/IvoaGridAndWebServices/ivoa-auth-mech-0.3.doc][V0.3 draft of authentication-mechanism standard]] * [[http://www.ivoa.net/Documents/PR/GWS/SSOAuthMech-PR-1.01-20070906.doc][PR version of authentication-mechanism standard]] * [[http://wiki.ivoa.net/internal/IVOA/IvoaGridAndWebServices/ivoa-delegation-0.1.pdf][Delegation protocol v0.1]] ---++ Related material * [[http://wiki.ivoa.net/internal/IVOA/IvoaGridAndWebServices/shibboleth-review-v0.1.html][Review of the Shibboleth system]]. * [[http://wiki.ivoa.net/internal/IVOA/IvoaGridAndWebServices/security-architecture-v0.1.html][Proposed security architecture]] * [[SecurityRegistryMetadata][Registry metadata relating to security: initial proposal]] <!-- * Set ALLOWTOPICRENAME = IVOA.TWikiAdminGroup -->
This topic: IVOA
>
WebHome
>
IvoaGridAndWebServices
>
SecurityHome
>
Authentication_SSO
Topic revision: r1 - 2020-06-02 - GiulianoTaffoni
Copyright © 2008-2025 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki?
Send feedback