{"id":4671,"date":"2012-04-23T16:20:38","date_gmt":"2012-04-23T14:20:38","guid":{"rendered":"https:\/\/wpethzprd.ethz.ch\/id\/?p=4671"},"modified":"2012-04-25T10:45:27","modified_gmt":"2012-04-25T08:45:27","slug":"single-sign-on-switchaai-shibboleth-2","status":"publish","type":"post","link":"https:\/\/blogs.ethz.ch\/id\/2012\/04\/23\/single-sign-on-switchaai-shibboleth-2\/","title":{"rendered":"Single Sign-on \/ SWITCHaai \/ Shibboleth"},"content":{"rendered":"<p>Expressions frequently used at ETH. What do they really mean?<!--more--><\/p>\n<p>Basically it&#8217;s all about one single <a href=\"http:\/\/en.wikipedia.org\/wiki\/Authentication\" target=\"_blank\">authentication<\/a> for multiple related, but independent software systems.<\/p>\n<h3>Single Sign-on<\/h3>\n<p>ETH Zurich academic web applications support <a href=\"http:\/\/en.wikipedia.org\/wiki\/Single_sign-on\" target=\"_blank\">single sign-on<\/a> (SSO) whereby a single action of user authentication and <a href=\"http:\/\/en.wikipedia.org\/wiki\/Authorization\" target=\"_blank\">authorization<\/a> allows access to all systems without having to log in again at each of them.<\/p>\n<p>More ITS applications with single sign-on (Shibboleth):<\/p>\n<ul>\n<li><a href=\"http:\/\/www.people.ethz.ch\" target=\"_blank\">People Search<\/a><\/li>\n<li><a href=\"https:\/\/www.lehrbetrieb.ethz.ch\/raumanfrage\/login.view?lang=en\" target=\"_blank\">Room Request<\/a><\/li>\n<li><a href=\"http:\/\/www.mystudies.ethz.ch\/index_en\" target=\"_blank\">myStudies<\/a><\/li>\n<li>\n<div><a href=\"http:\/\/www.addresses.ethz.ch\" target=\"_blank\">Addresses and Personal Data<\/a><\/div>\n<\/li>\n<li><a href=\"http:\/\/www.sms.ethz.ch\" target=\"_blank\">SMS-Gateway<\/a><\/li>\n<li><a href=\"https:\/\/blogs.ethz.ch\/english\/\" target=\"_blank\">blogs.ethz.ch<\/a><\/li>\n<li><a href=\"http:\/\/docendo.ethz.ch\/\" target=\"_blank\">docendo.ethz.ch<\/a><\/li>\n<li><a href=\"http:\/\/sympa.ethz.ch\/\" target=\"_blank\">sympa.ethz.ch<\/a><\/li>\n<li>ETH Zurich employee-portal (from October 2012, Web Relaunch)<\/li>\n<li>ETH Zurich student-portal(from October 2012, Web Relaunch)<\/li>\n<li>and many more ETH Zurich applications with single sign-on (Shibboleth) capability<\/li>\n<\/ul>\n<p>View posts &#8222;Single sign-on at ETH&#8220; <a href=\"https:\/\/blogs.ethz.ch\/id\/2011\/10\/18\/single-sign-on-at-eth\/\" target=\"_blank\">https:\/\/blogs.ethz.ch\/id\/2011\/10\/18\/single-sign-on-at-eth\/<\/a> and &#8222;New expanded version of web application Room Request&#8220; <a href=\"https:\/\/blogs.ethz.ch\/id\/2011\/12\/21\/new-expanded-version-of-web-application-room-request\/\" target=\"_blank\">https:\/\/blogs.ethz.ch\/id\/2011\/12\/21\/new-expanded-version-of-web-application-room-request\/<\/a>.<\/p>\n<h3>Shibboleth<\/h3>\n<p>Technical implementation is done with <a href=\"http:\/\/en.wikipedia.org\/wiki\/Shibboleth\" target=\"_blank\">Shibboleth<\/a> &#8211; an open source product used by <a href=\"http:\/\/www.switch.ch\/aai\/\" target=\"_blank\">SWITCHaai<\/a>. The <a href=\"http:\/\/www.switch.ch\/\" target=\"_blank\">SWITCH<\/a> foundation has been operating the Swiss universities research network since 1987 and currently also manages its AAI components (Authentication and Authorization Infrastructure).<\/p>\n<h3>SWITCHaai \u2013 the key that connects students and the university<\/h3>\n<p>SWITCHaai is the leading national authentication and authorisation infrastructure in the tertiary education sector. Previously students had to log on with a handful of user names and passwords if they wished to use services (courses, databases, e-journals, libraries etc.) provided by other universities. Today, thanks to SWITCHaai, a single login to the &#8222;Home-Organisation&#8220; (e.g. ETH Zurich) is all that is required to access participating universities.<\/p>\n<p><a href=\"https:\/\/blogs.ethz.ch\/id\/files\/2012\/04\/Auswahl_Switchaai_ETH.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.ethz.ch\/id\/files\/2012\/04\/Auswahl_Switchaai_ETH-285x300.png\" alt=\"\" width=\"285\" height=\"316\" \/><\/a><\/p>\n<p>The home-organization is in charge of login authentication and is also responsible for managing and updating user data which it provides to participating service providers.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/blogs.ethz.ch\/id\/files\/2012\/04\/Einloggen_Switch_ETH.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.ethz.ch\/id\/files\/2012\/04\/Einloggen_Switch_ETH-300x165.png\" alt=\"\" width=\"300\" height=\"165\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>Internet cafes \/ public computer labs\/ shared workstations<\/h3>\n<p>Single sign-on implemented by the ITS uses authentication <a href=\"http:\/\/en.wikipedia.org\/wiki\/HTTP_cookie\" target=\"_blank\">cookies<\/a> to register successful authentication. Once the session has expired, a browser session lasts about 30 minutes, you must log in again. Depending on browser settings cookies may continue to exist even after you have closed the browser.<\/p>\n<p>Always use the log-out link upon terminating your session. If you share your workplace with others be sure to delete your session cookies and close all browser windows after completing your work. This will prevent further access to your applications.<\/p>\n<p>Instructions on how to delete cookies can be found at <a href=\"http:\/\/www.rektorat.ethz.ch\/applications\/sso\/index_EN\" target=\"_blank\">http:\/\/www.rektorat.ethz.ch\/applications\/sso\/index_EN<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Expressions frequently used at ETH. What do they really mean?<\/p>\n","protected":false},"author":292,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1285],"tags":[],"class_list":["post-4671","post","type-post","status-publish","format-standard","hentry","category-news-english"],"_links":{"self":[{"href":"https:\/\/blogs.ethz.ch\/id\/wp-json\/wp\/v2\/posts\/4671","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.ethz.ch\/id\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.ethz.ch\/id\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/id\/wp-json\/wp\/v2\/users\/292"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/id\/wp-json\/wp\/v2\/comments?post=4671"}],"version-history":[{"count":0,"href":"https:\/\/blogs.ethz.ch\/id\/wp-json\/wp\/v2\/posts\/4671\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.ethz.ch\/id\/wp-json\/wp\/v2\/media?parent=4671"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/id\/wp-json\/wp\/v2\/categories?post=4671"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/id\/wp-json\/wp\/v2\/tags?post=4671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}