<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/wordpress-mu-1.2.5" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments for JISC Access Management Team</title>
	<link>http://access.jiscinvolve.org</link>
	<description>moving towards federated access management</description>
	<pubDate>Thu, 24 Jul 2008 06:06:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=wordpress-mu-1.2.5</generator>

	<item>
		<title>Comment on Futures Event - Identity and access management by Andy Powell</title>
		<link>http://access.jiscinvolve.org/2008/07/02/futures-event-identity-and-access-management/#comment-1426</link>
		<dc:creator>Andy Powell</dc:creator>
		<pubDate>Wed, 02 Jul 2008 15:21:54 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/07/02/futures-event-identity-and-access-management/#comment-1426</guid>
		<description>Note that David Orrell's presentation is available at:

http://www.slideshare.net/eduservfoundation/identity-future-directions</description>
		<content:encoded><![CDATA[<p>Note that David Orrell&#8217;s presentation is available at:</p>
<p><a href="http://www.slideshare.net/eduservfoundation/identity-future-directions" rel="nofollow" onclick="javascript:urchinTracker ('/outbound/comment/www.slideshare.net');">http://www.slideshare.net/eduservfoundation/identity-future-directions</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Opinions Wanted by Max Hammond</title>
		<link>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1221</link>
		<dc:creator>Max Hammond</dc:creator>
		<pubDate>Thu, 12 Jun 2008 13:59:22 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1221</guid>
		<description>&lt;blockquote&gt;At a discussion I was at yesterday with senior IS/IT managers, several people suggested that institutional managers would benefit from sharing ideas on how to secure buy-in, budget and staff time to develop their access management solutions. Various “trojan horses” were discussed as ways of getting the issue onto the table: lifelong learning networks, phsyical ID card access systems, and so on: various ways of selling the internal benefits of FAM. Perhaps there could be further opportunities for sharing these sorts of experience in confidence?&lt;/blockquote&gt;

The &lt;a href="http://www.jisc.ac.uk/media/documents/themes/accessmanagement/cc297d001-1.0%20business%20case%20toolkit.pdf" rel="nofollow"&gt;Business case toolkit&lt;/a&gt; and &lt;a href="http://www.jisc.ac.uk/media/documents/themes/accessmanagement/cc297d002-1.0%20case%20studies%20supplement.pdf" rel="nofollow"&gt;supporting case studies&lt;/a&gt; which we prepared may provide some help in this regard.</description>
		<content:encoded><![CDATA[<blockquote><p>At a discussion I was at yesterday with senior IS/IT managers, several people suggested that institutional managers would benefit from sharing ideas on how to secure buy-in, budget and staff time to develop their access management solutions. Various “trojan horses” were discussed as ways of getting the issue onto the table: lifelong learning networks, phsyical ID card access systems, and so on: various ways of selling the internal benefits of FAM. Perhaps there could be further opportunities for sharing these sorts of experience in confidence?</p></blockquote>
<p>The <a href="http://www.jisc.ac.uk/media/documents/themes/accessmanagement/cc297d001-1.0%20business%20case%20toolkit.pdf" rel="nofollow" onclick="javascript:urchinTracker ('/outbound/comment/www.jisc.ac.uk');">Business case toolkit</a> and <a href="http://www.jisc.ac.uk/media/documents/themes/accessmanagement/cc297d002-1.0%20case%20studies%20supplement.pdf" rel="nofollow" onclick="javascript:urchinTracker ('/outbound/comment/www.jisc.ac.uk');">supporting case studies</a> which we prepared may provide some help in this regard.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Opinions Wanted by Scott Wilson</title>
		<link>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1217</link>
		<dc:creator>Scott Wilson</dc:creator>
		<pubDate>Wed, 11 Jun 2008 14:45:31 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1217</guid>
		<description>At CETIS we were planning to do some consultation with the eLearning community to develop scenarios for exploring the use of oAuth; that would potentially be something that could feed into  the programme planning. However, we weren't planning on doing this until September.</description>
		<content:encoded><![CDATA[<p>At CETIS we were planning to do some consultation with the eLearning community to develop scenarios for exploring the use of oAuth; that would potentially be something that could feed into  the programme planning. However, we weren&#8217;t planning on doing this until September.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Opinions Wanted by Malcolm Teague</title>
		<link>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1192</link>
		<dc:creator>Malcolm Teague</dc:creator>
		<pubDate>Thu, 05 Jun 2008 12:36:33 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1192</guid>
		<description>I would like to support the suggestion of more work on account linking, particularly at the interface between Education and Research and other sectors. My interest of course is the interface with the NHS and as you know we are in discussions with the National Library for Health in England about the opportunities presented by SAML based federated access management. At the moment though this is about joint working with the two (at least)separate accounts for staff and students working across the two sectors but the holy grail is that the resource entitlements are merged seamlessly in some way.</description>
		<content:encoded><![CDATA[<p>I would like to support the suggestion of more work on account linking, particularly at the interface between Education and Research and other sectors. My interest of course is the interface with the NHS and as you know we are in discussions with the National Library for Health in England about the opportunities presented by SAML based federated access management. At the moment though this is about joint working with the two (at least)separate accounts for staff and students working across the two sectors but the holy grail is that the resource entitlements are merged seamlessly in some way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Opinions Wanted by Amber Thomas, JISC</title>
		<link>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1191</link>
		<dc:creator>Amber Thomas, JISC</dc:creator>
		<pubDate>Thu, 05 Jun 2008 08:26:17 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1191</guid>
		<description>At a discussion I was at yesterday with senior IS/IT managers, several people suggested that institutional managers would benefit from sharing ideas on how to secure buy-in, budget and staff time to develop their access management solutions. Various "trojan horses" were discussed as ways of getting the issue onto the table: lifelong learning networks, phsyical ID card access systems, and so on: various ways of selling the internal benefits of FAM. Perhaps there could be further opportunities for sharing these sorts of experience in confidence?</description>
		<content:encoded><![CDATA[<p>At a discussion I was at yesterday with senior IS/IT managers, several people suggested that institutional managers would benefit from sharing ideas on how to secure buy-in, budget and staff time to develop their access management solutions. Various &#8220;trojan horses&#8221; were discussed as ways of getting the issue onto the table: lifelong learning networks, phsyical ID card access systems, and so on: various ways of selling the internal benefits of FAM. Perhaps there could be further opportunities for sharing these sorts of experience in confidence?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Opinions Wanted by Alistair Young</title>
		<link>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1185</link>
		<dc:creator>Alistair Young</dc:creator>
		<pubDate>Wed, 04 Jun 2008 09:21:30 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1185</guid>
		<description>What do you mean by "toolkits across the community"? Are we allowed into the core code? i.e. to get rid of the griffin page. A lot of sites would like to customise/brand/document the error displayed by an SP. A small enhancement to the Shibboleth profile could provide that. Is that level of shibboleth code access allowed?</description>
		<content:encoded><![CDATA[<p>What do you mean by &#8220;toolkits across the community&#8221;? Are we allowed into the core code? i.e. to get rid of the griffin page. A lot of sites would like to customise/brand/document the error displayed by an SP. A small enhancement to the Shibboleth profile could provide that. Is that level of shibboleth code access allowed?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Opinions Wanted by Alistair Young</title>
		<link>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1184</link>
		<dc:creator>Alistair Young</dc:creator>
		<pubDate>Wed, 04 Jun 2008 09:19:42 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1184</guid>
		<description>How about remote access management for electronic resources. With Athens, quite fine grained access could be done using permission sets, by institutional staff. With the move to shibboleth, that dynamic capability has gone. Allowing institutional staff to create sub collections of resources based on attributes and values, without having to go through a manual process of phoning the supplier and explaining it and having to go through them to update the attributes/collections.</description>
		<content:encoded><![CDATA[<p>How about remote access management for electronic resources. With Athens, quite fine grained access could be done using permission sets, by institutional staff. With the move to shibboleth, that dynamic capability has gone. Allowing institutional staff to create sub collections of resources based on attributes and values, without having to go through a manual process of phoning the supplier and explaining it and having to go through them to update the attributes/collections.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Opinions Wanted by Cal Racey</title>
		<link>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1183</link>
		<dc:creator>Cal Racey</dc:creator>
		<pubDate>Wed, 04 Jun 2008 08:10:15 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1183</guid>
		<description>Development of toolkits across the community would be very desirable. Once an institute has deployed shibboleth successfully they largely have to figure out how to use it themselves. Shibboleth has many different usage patterns and is usable in many different programming languages, making this a very complex decision, with little information in the community on how to do it.  I would like to see example code and configuration for the major web application programming languages (java, php, .net, python, ruby, perl)when used on apache, IIS, and via connectors like mod_proxy/fastcgi. The examples could be how to consume shib headers, how to use lazy sessions, how to use session initiators to direct users to different wayfs in one app(eg "Americans login here, Brits here"),  how to give meaningful error messages to  unauthenticated users that enable them to remedy the problem, how to use shib to set up an application specific sessions (one of the easiest integration techniques). What the implications are about session timeouts e.g. if your session timesout in a long wiki edit all the editing is lost (shib relogin kills post data).</description>
		<content:encoded><![CDATA[<p>Development of toolkits across the community would be very desirable. Once an institute has deployed shibboleth successfully they largely have to figure out how to use it themselves. Shibboleth has many different usage patterns and is usable in many different programming languages, making this a very complex decision, with little information in the community on how to do it.  I would like to see example code and configuration for the major web application programming languages (java, php, .net, python, ruby, perl)when used on apache, IIS, and via connectors like mod_proxy/fastcgi. The examples could be how to consume shib headers, how to use lazy sessions, how to use session initiators to direct users to different wayfs in one app(eg &#8220;Americans login here, Brits here&#8221;),  how to give meaningful error messages to  unauthenticated users that enable them to remedy the problem, how to use shib to set up an application specific sessions (one of the easiest integration techniques). What the implications are about session timeouts e.g. if your session timesout in a long wiki edit all the editing is lost (shib relogin kills post data).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Opinions Wanted by Andy Powell</title>
		<link>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1182</link>
		<dc:creator>Andy Powell</dc:creator>
		<pubDate>Wed, 04 Jun 2008 07:43:27 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/06/03/opinions-wanted/#comment-1182</guid>
		<description>The "user experience" of OpenID interactions is well recognised as being an area that needs more work - hence the development of services like Clickpass and so on.  I guess that the same can be said of the Federation.  On that basis, funding activities that develop innovative approaches to hiding the R/SP-&#62;[WAYF]-&#62;IdP-&#62;R/SP chain or that simply try to make recommend good practice in this area might be worthwhile?

Andy.</description>
		<content:encoded><![CDATA[<p>The &#8220;user experience&#8221; of OpenID interactions is well recognised as being an area that needs more work - hence the development of services like Clickpass and so on.  I guess that the same can be said of the Federation.  On that basis, funding activities that develop innovative approaches to hiding the R/SP-&gt;[WAYF]-&gt;IdP-&gt;R/SP chain or that simply try to make recommend good practice in this area might be worthwhile?</p>
<p>Andy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on BT in trouble? by alan</title>
		<link>http://access.jiscinvolve.org/2008/04/03/bt-in-trouble/#comment-970</link>
		<dc:creator>alan</dc:creator>
		<pubDate>Wed, 07 May 2008 17:54:44 +0000</pubDate>
		<guid>http://access.jiscinvolve.org/2008/04/03/bt-in-trouble/#comment-970</guid>
		<description>The development and testing of systems such as phorm is worrying. As information providers via our web pages we feel that it essential that users can be certain that the minimal personal details that they provide to us in using our search pages is not used in such a way. Any feeling that a users privacy is being invaded by improper use will have a hugely detrimental impact on any business relying on the medium of the world wide web.</description>
		<content:encoded><![CDATA[<p>The development and testing of systems such as phorm is worrying. As information providers via our web pages we feel that it essential that users can be certain that the minimal personal details that they provide to us in using our search pages is not used in such a way. Any feeling that a users privacy is being invaded by improper use will have a hugely detrimental impact on any business relying on the medium of the world wide web.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
