open id

20
What It Is How It Works Why You Should Care Scott Leslie WCET/BCcampus November 7, 2007

Upload: scott-leslie

Post on 19-Jan-2015

4.619 views

Category:

Technology


1 download

DESCRIPTION

My "What is OpenID" preso for the authentication panel at WCET 2007

TRANSCRIPT

Page 1: Open Id

What It Is

How It Works

Why You Should

Care

Scott LeslieWCET/BCcampus

November 7, 2007

Page 2: Open Id

What is OpenID?

• “De-centralised Single Sign-on for the Web which puts individuals in charge”1

• “OpenID eliminates the need for multiple usernames across different websites”2

1 Powell and Recordon, “OpenID: Decentralised Single Sign-on for the Web,” http://www.ariadne.ac.uk/issue51/powell-recordon/ Last Viewed: Oct 30, 2007.

2 OpenID “What is OpenID” http://openid.net/what/ Last Viewed: Oct 30, 2007

Page 3: Open Id

Say what?

Page 4: Open Id

Let’s try a demo instead…

• http://blog.dataunbound.com/

• http://www.51weeks.com/events/3/presentations/49

Page 5: Open Id
Page 6: Open Id

Some of OpenID’s benefits• Users choose and can control their

OpenID provider• De-centralized - no single server

which every OpenID-enabled service or every user must register

• Users authentication credentials are only stored one place

• Usually an easy to remember URL (e.g. edtechpost.myopenid.com)

Page 7: Open Id

Additional Benefits

• Uses only standard HTTP(S), does not require any special capabilities of the User-Agent or other client software.

Page 8: Open Id

What it is Not

• It does not try to provide trust or distributed authorization solutions

• It will never be a replacement for current on-campus single sign on technologies– But maybe it will be a compliment

Page 9: Open Id

http://www.xmlgrrl.com/blog/archives/2007/03/28/the-venn-of-identity/

Page 10: Open Id

Ok, but why should I care?

Page 11: Open Id

OpenID Providers• 9 million users on LiveJournal.com • AOL - 63 million users got

OpenIDs in one fell swoop• 1 million+ smart card based

OpenIDs issued in Estonia• openid.sun.com – 34,000 Sun

employee issued an OpenID• Microsoft intend to integrate

OpenID into Cardspace

Page 12: Open Id

OpenID Consumers

• Libraries which support it in app development frameworks like Ruby on Rails, Zend PHP, Django Python

• 100s of services & apps which support OpenIDs, cf. https://www.myopenid.com/directory and http://openiddirectory.com/

Page 13: Open Id

Right, but like I said, why should I care?

Page 14: Open Id

Avoid Becoming a Technology Ghetto

http://www.flickr.com/photos/extraketchup/737480991/

Page 15: Open Id

Respect Existing Online Identities

http://www.flickr.com/photos/jimfrazier/1187369664/

Page 16: Open Id

Give User Choice to Merge Campus Life and Online Life

http://www.flickr.com/photos/re100cyber/1435723666/

Page 17: Open Id

Where is it going?• OpenID 2 - differences?

– Addressing ‘phising’ issue– Interop with Identity Selectors like

Cardspace– Attribute Exchange Extension– Works with Yadis– http://openid.net/specs/openid-

authentication-2_0-12.html

• OpenID and SAML• User Centric Identity Interop tests

http://osis.netmesh.org/wiki/I2_Results

Page 18: Open Id

How Higher Ed can work with OpenID?• Become an OpenID provider

– cf. https://login.case.edu/id and https://openid.byu.edu/

– cf. http://www.ja-sig.org/wiki/display/CASUM/OpenID

• Ask yourself – are there applications we provide which could use OpenID?– How about when they become alumni?

Page 19: Open Id

Further Reading

• Sam Ruby – “OpenID for non-SuperUsers”– http://www.intertwingly.net/blog/

2007/01/03/OpenID-for-non-SuperUsers

• Powell and Recordon - “OpenID: Decentralised Single Sign-on for the Web”–

http://www.ariadne.ac.uk/issue51/powell-recordon/

Page 20: Open Id

Thanks

Feel free to contact me at

[email protected]