It is interesting that a few mails from this list found their way to
my Inbox again. QC Co-Lab is looking at finally finishing up MODAC and
getting it integrated with a payment service (WePay).
The other day I was listening to PaulDotCom Security Weekly Ep. 248
(
http://pauldotcom.com/2011/06/pauldotcom---security-weekly---67.html)
and they had one of the developers of the Shibboleth project on
(
http://shibboleth.internet2.edu/). Shibboleth is an extensible,
privacy aware, authentication platform, similar to OpenID (but far
expanded). One of the issues we ran into with trying to use OpenID is
that the data provided was fixed and not easy to extend. Shibboleth
fixes this.
Built on SAML, Shibboleth is currently be used by universities and
research centers to solve the same problem we were working on here. It
allows it's users to travel between trusted universities using a
single sign-on, and bring with them variable credentials such as
qualifications and research team affiliations. I haven't dug into this
too deeply to see what all is involved, but it appears as though this
would be an excellent fit for what we are trying to achieve in the
hackerspace community.
Has anyone ever worked with or used Shibboleth or SAML before?
Chris Cooper
QC Co-Lab