<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>single sign on on MaisonBisson</title>
    <link>https://maisonbisson.com/tags/single-sign-on/</link>
    <description>Recent content in single sign on on MaisonBisson</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 29 Sep 2009 16:16:16 +0000</lastBuildDate><atom:link href="https://maisonbisson.com/tags/single-sign-on/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Hacking WordPress Login and Password Reset Processes For My University Environment</title>
      <link>https://maisonbisson.com/post/wordpress-user-authentication-hacks/</link>
      <pubDate>Tue, 29 Sep 2009 16:16:16 +0000</pubDate>
      
      <guid>https://maisonbisson.com/post/wordpress-user-authentication-hacks/</guid>
      <description>&lt;p&gt;Any university worth the title is likely to have a very mixed identity environment. At &lt;a href=&#34;http://www.plymouth.edu/&#34;&gt;Plymouth State University&lt;/a&gt; we’ve been pursuing a strategy of unifying identity and offering single sign-on to web services, but an inventory last year still revealed a great number of systems not integrated with either our single sign-on (&lt;a href=&#34;http://en.wikipedia.org/wiki/Authentication&#34; title=&#34;Authentication - Wikipedia, the free encyclopedia&#34;&gt;AuthN&lt;/a&gt;) or authorization systems (&lt;a href=&#34;http://en.wikipedia.org/wiki/Authorization&#34; title=&#34;Authorization - Wikipedia, the free encyclopedia&#34;&gt;AuthZ&lt;/a&gt;, see &lt;a href=&#34;http://en.wikipedia.org/wiki/Authentication#Authentication_vs._authorization&#34;&gt;difference&lt;/a&gt;). And in addition to the many application/system specific stores of identity information (even for those systems integrated into our single sign-on environment), we also use both LDAP and AD (which we try to synchronize at the application level). Worst of all, the entire environment is provisioned solely from our &lt;a href=&#34;http://en.wikipedia.org/wiki/Management_information_system&#34;&gt;MIS database&lt;/a&gt;, which is good if you want to make sure that students and faculty get user accounts, but bad if you want to provision an account for somebody who doesn’t fit into one of those roles.&lt;/p&gt;
&lt;p&gt;The one way relationship between our user accounts and the MIS database also makes it difficult to engage with new users online. If you can’t get an account until you become a student, how do you allow potential students to apply online if all your systems are integrated with single sign-on? And if you can’t authenticate the online identity of your users, how do you set initial passwords into your system? Or allow them to reset a forgotten password online?&lt;/p&gt;
&lt;p&gt;Internet companies never struggled with this issue, as their customers could only approach them online, but most universities built systems around paper applications and have fond (and relatively recent) memories of offering their students their first internet experience. It’s still not unusual for universities to offer their students their campus computing account with a default password based on supposedly secret data shared between the user and the school. But your SSN, birth date, and mother’s name are no longer secret. A proposed change in FERPA policy (see the &lt;a href=&#34;edocket-access-gpo-gov-E8-5790.pdf&#34;&gt;the top of page 15586 in the NPRM&lt;/a&gt;) would have barred the use of “a common form user name (e.g., last name and first name initial) with date of birth or SSN, or a portion of the SSN, as an initial password to be changed upon first use of the system” in systems that store academic data. The final rule excluded that provision, much to the relief of those schools with more lobbying clout than brains.&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>CAS Is A Standard Protocol, Not A Standard Application</title>
      <link>https://maisonbisson.com/post/cas-is-a-standard-protocol-not-a-standard-application/</link>
      <pubDate>Tue, 14 Apr 2009 16:52:09 +0000</pubDate>
      
      <guid>https://maisonbisson.com/post/cas-is-a-standard-protocol-not-a-standard-application/</guid>
      <description>I’m not really part of the Jasig CAS Community (learn more), but I do maintain the wpCAS WordPress CAS client and I’ve started development of a CAS server component for WordPress.</description>
    </item>
    
    <item>
      <title>Identity Management Going Commodity?</title>
      <link>https://maisonbisson.com/post/identity-management-going-commodity/</link>
      <pubDate>Tue, 08 Apr 2008 01:56:30 +0000</pubDate>
      
      <guid>https://maisonbisson.com/post/identity-management-going-commodity/</guid>
      <description>Atlassian’s Crowd SSO and IdM solution has the kind of online pricing you’d expect for word processing software.</description>
    </item>
    
    <item>
      <title>Google Pumps OpenID Too</title>
      <link>https://maisonbisson.com/post/google-pumps-openid-too/</link>
      <pubDate>Sat, 19 Jan 2008 16:21:04 +0000</pubDate>
      
      <guid>https://maisonbisson.com/post/google-pumps-openid-too/</guid>
      <description>Following news that Yahoo! is joining the OpenID fray, it appears Google is dipping a toe in too.</description>
    </item>
    
    <item>
      <title>Yahoo! Pumps OpenID</title>
      <link>https://maisonbisson.com/post/yahoo-pumps-openid/</link>
      <pubDate>Fri, 18 Jan 2008 12:49:44 +0000</pubDate>
      
      <guid>https://maisonbisson.com/post/yahoo-pumps-openid/</guid>
      <description>Ars notes that Yahoo! supports OpenID. Yeah, that OpenID.</description>
    </item>
    
  </channel>
</rss>
