Система единого входа Shibboleth и федеративная идентификация
Shibboleth (software)
Shibboleth: единый вход для сетей и интернета. SAML-аутентификация, федеративная идентификация, управление доступом. Безопасный вход через организации.
Сравнивайте с английским: нажмите на абзац — оригинал откроется в окне. Кнопка EN под абзацем показывает его прямо в тексте.
Содержание
Введение
Система интернет-идентификации
Internet identity system
Shibboleth — это система единого входа для компьютерных сетей и Интернета. Она позволяет пользователям входить в различные системы, управляемые федерациями разных организаций или учреждений, используя единую учётную запись. Такие федерации часто представляют собой университеты или государственные организации. Инициатива Shibboleth Internet2 разработала архитектуру и реализацию с открытым исходным кодом для управления идентификацией и федеративной идентификации, основанной на аутентификации и авторизации (или контроле доступа) с использованием языка разметки утверждений безопасности (SAML). Федеративная идентификация обеспечивает обмен информацией о пользователях между доменами безопасности в рамках федерации. Это позволяет осуществлять единый вход в различные домены и избавляет поставщиков контента от необходимости поддерживать собственные имена пользователей и пароли. Поставщики идентификационной информации (Identity Providers, IdP) предоставляют данные о пользователях, а поставщики услуг (Service Providers, SPs) используют эти данные для предоставления доступа к защищённому контенту.
Shibboleth is a single sign on log in system for computer networks and the Internet. It allows people to sign in using just one identity to various systems run by federations of different organizations or institutions. The federations are often universities or public service organizations. The Shibboleth Internet2 middleware initiative created an architecture and open source implementation for identity management and federated identity based authentication and authorization (or access control) infrastructure based on Security Assertion Markup Language (SAML). Federated identity allows the sharing of information about users from one security domain to the other organizations in a federation. This allows for cross domain single sign on and removes the need for content providers to maintain usernames and passwords. Identity providers (IdPs) supply user information, while service providers (SPs) consume this information and give access to secure content.
История
Проект Shibboleth вырос из Internet2. Сегодня проект управляется консорциумом Shibboleth. Два из наиболее популярных программных компонентов, управляемых консорциумом Shibboleth, — это Shibboleth Identity Provider и Shibboleth Service Provider, оба из которых являются реализациями SAML. Проект был назван в честь идентификационной фразы, использовавшейся в Библии (Книга Судей), поскольку ефремитяне не могли произносить звук «ш». Проект Shibboleth был начат в 2000 году для упрощения обмена ресурсами между организациями с несовместимыми инфраструктурами аутентификации и авторизации. Архитектурные работы проводились более года до начала разработки программного обеспечения. После разработки и тестирования Shibboleth IdP 1.0 был выпущен в июле 2003 года, а затем в августе 2005 года — Shibboleth IdP 1.3. Версия 2.0 программного обеспечения Shibboleth стала крупным обновлением, выпущенным в марте 2008 года. Она включала в себя как компоненты IdP, так и SP, но, что более важно, Shibboleth 2.0 поддерживал SAML 2.0. Протоколы Shibboleth и SAML разрабатывались примерно в одно и то же время. С самого начала Shibboleth был основан на SAML, но там, где SAML оказывался недостаточным, Shibboleth находил импровизированные решения, и разработчики Shibboleth реализовывали функции, компенсирующие отсутствие возможностей в SAML 1.1. Некоторые из этих функций впоследствии были включены в SAML 2.0, и в этом смысле Shibboleth внес вклад в развитие протокола SAML. Возможно, наиболее важным вкладом стал протокол Shibboleth AuthnRequest. Поскольку протокол SAML 1.1 изначально был ориентирован на IdP, Shibboleth разработал простой протокол запроса аутентификации на основе HTTP, который превратил SAML 1.1 в протокол, ориентированный на SP. Этот протокол был впервые реализован в Shibboleth IdP 1.0 и впоследствии усовершенствован в Shibboleth IdP 1.3. Развивая эту раннюю работу, Liberty Alliance представил полностью расширенный протокол AuthnRequest в Liberty Identity Federation Framework. В конечном итоге Liberty ID FF 1.2 был передан в OASIS, который лег в основу стандарта OASIS SAML 2.0.
The Shibboleth project grew out of Internet2. Today, the project is managed by the Shibboleth Consortium. Two of the most popular software components managed by the Shibboleth Consortium are the Shibboleth Identity Provider and the Shibboleth Service Provider, both of which are implementations of SAML. The project was named after an identifying passphrase used in the Bible (Judges ) because Ephraimites were not able to pronounce "sh". The Shibboleth project was started in 2000 to facilitate the sharing of resources between organizations with incompatible authentication and authorization infrastructures. Architectural work was performed for over a year prior to any software development. After development and testing, Shibboleth IdP 1.0 was released in July 2003. This was followed by the release of Shibboleth IdP 1.3 in August 2005. Version 2.0 of the Shibboleth software was a major upgrade released in March 2008. It included both IdP and SP components, but, more importantly, Shibboleth 2.0 supported SAML 2.0. The Shibboleth and SAML protocols were developed during the same timeframe. From the beginning, Shibboleth was based on SAML, but, where SAML was found lacking, Shibboleth improvised, and the Shibboleth developers implemented features that compensated for missing features in SAML 1.1. Some of these features were later incorporated into SAML 2.0, and, in that sense, Shibboleth contributed to the evolution of the SAML protocol. Perhaps the most important contributed feature was the legacy Shibboleth AuthnRequest protocol. Since the SAML 1.1 protocol was inherently an IdP first protocol, Shibboleth invented a simple HTTP based authentication request protocol that turned SAML 1.1 into an SP first protocol. This protocol was first implemented in Shibboleth IdP 1.0 and later refined in Shibboleth IdP 1.3. Building on that early work, the Liberty Alliance introduced a fully expanded AuthnRequest protocol into the Liberty Identity Federation Framework. Eventually, Liberty ID FF 1.2 was contributed to OASIS, which formed the basis for the OASIS SAML 2.0 Standard.
Архитектура
Shibboleth — это веб-технология, реализующая профили артефактов и передачи атрибутов SAML, включая компоненты поставщика удостоверений (IdP) и поставщика услуг (SP). Shibboleth 1.3 имеет собственное техническое описание, архитектурный документ и документ соответствия, основанные на спецификациях SAML 1.1.
Shibboleth is a web based technology that implements the artifact and attribute push profiles of SAML, including both Identity Provider (IdP) and Service Provider (SP) components. Shibboleth 1.3 has its own technical overview, architectural document, and conformance document that build on top of the SAML 1.1 specifications.
Шибболет 2.0
Shibboleth 2.0 базируется на стандартах SAML 2.0. IdP в Shibboleth 2.0 должен выполнять дополнительную обработку для поддержки пассивных и принудительных запросов на аутентификацию в SAML 2.0. SP может запрашивать у IdP определенный метод аутентификации. Shibboleth 2.0 обеспечивает расширенные возможности шифрования.
Shibboleth 2.0 builds on SAML 2.0 standards. The IdP in Shibboleth 2.0 has to do additional processing in order to support passive and forced authentication requests in SAML 2.0. The SP can request a specific method of authentication from the IdP. Shibboleth 2.0 supports additional encryption capacity.
Атрибуты
Контроль доступа в Shibboleth осуществляется путем сопоставления атрибутов, предоставляемых поставщиками удостоверений (IdP), с правилами, определенными поставщиками услуг (SP). Атрибут – это любая информация о пользователе, такая как "член данной группы", "Алиса Смит" или "лицензия по договору А". Идентичность пользователя рассматривается как атрибут и передается только при явном запросе, что обеспечивает конфиденциальность пользователя. Атрибуты могут быть реализованы на Java или получены из каталогов и баз данных. Чаще всего используются стандартные атрибуты X.520, но новые атрибуты могут быть определены произвольно, при условии, что они понимаются и интерпретируются одинаково IdP и SP в ходе транзакции.
Shibboleth's access control is performed by matching attributes supplied by IdPs against rules defined by SPs. An attribute is any piece of information about a user, such as "member of this community", "Alice Smith", or "licensed under contract A". User identity is considered an attribute, and is only passed when explicitly required, which preserves user privacy. Attributes can be written in Java or pulled from directories and databases. Standard X.520 attributes are most commonly used, but new attributes can be arbitrarily defined as long as they are understood and interpreted similarly by the IdP and SP in a transaction.
Доверие
Доверие между доменами реализуется с использованием криптографии с открытым ключом (часто просто сертификатов сервера TLS) и метаданных, описывающих провайдеров. Использование передаваемой информации регулируется соглашениями. Федерации часто используются для упрощения этих взаимоотношений путем объединения большого числа провайдеров, согласующихся на использование общих правил и контрактов.
Trust between domains is implemented using public key cryptography (often simply TLS server certificates) and metadata that describes providers. The use of information passed is controlled through agreements. Federations are often used to simplify these relationships by aggregating large numbers of providers that agree to use common rules and contracts.
Разработка
Shibboleth – это программное обеспечение с открытым исходным кодом, распространяемое по лицензии Apache 2. Многие расширения были разработаны другими сообществами.
Shibboleth is open source and provided under the Apache 2 license. Many extensions have been contributed by other groups.
Усыновление
Во многих странах мира были созданы федерации для формирования инфраструктуры доверия для обмена информацией с использованием программного обеспечения SAML и Shibboleth. Многие крупные поставщики контента поддерживают доступ на основе Shibboleth. В феврале 2006 года Совместный комитет по информационным системам (JISC) советов по финансированию высшего образования Англии, Шотландии, Уэльса и Северной Ирландии объявил о переходе от системы аутентификации Athens к системе управления доступом, основанной на технологии Shibboleth. С тех пор комитет пересмотрел свою позицию и теперь поддерживает решение для федеративного управления доступом, а не сам Shibboleth.
Federations have been formed in many countries around the world to build trust structures for the exchange of information using SAML and Shibboleth software. Many major content providers support Shibboleth based access. In February 2006, the Joint Information Systems Committee (JISC) of the Higher Education Funding Councils of England, Scotland, Wales and Northern Ireland announced that it would move from the Athens authentication system to an access management system based on Shibboleth technology. Since then it has updated its position and is endorsing a federated access management solution rather than Shibboleth itself.