Si

Shibboleth Identity Provider 5

Azure Application Infrastructure

SAML 2.0 single sign on for federations, with signing keys minted on your own machine

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

Shibboleth Identity Provider is the SAML 2.0 identity provider used across research and education federations and in the public sector. It authenticates people against your own directory and issues signed SAML assertions to the services they sign in to, so one sign in works everywhere you federate. It is open source under the Apache License 2.0.

Why the cloudimg image

An identity provider signs assertions with a private key, and every service that trusts it trusts that key, so a key shared across an image would let any buyer impersonate any other. This image ships no installed identity provider at all: first boot runs the software's own installer and mints this machine's signing key, encryption key, sealer and published metadata. Two machines from the image were compared before release and all nineteen per machine secrets differed. A co-located directory and a self test service provider let you prove a sign in in the first minute, a per machine TLS certificate is generated at first boot, and it is paired with a deployment guide and 24/7 support.

Common uses

  • Single sign on across a research or education federation
  • SAML authentication for public sector services
  • A standards based identity provider in front of your existing directory

See it running

Real screenshots taken while testing this image against its deployment guide.

Shibboleth Identity Provider 5 screenshot 1 Shibboleth Identity Provider 5 screenshot 2 Shibboleth Identity Provider 5 screenshot 3 Shibboleth Identity Provider 5 screenshot 4