13. ESDIN – Mostly NMCA’s Interactive Instruments Bundesamt für Kartographie und Geodäsie Lantmäteriet National Technical University of Athens IGN Belgium Bundesamt für Eich- und Vermessungswesen Universität Münster EDINA, University Edinburgh National Agency for Cadastre and Real Estate Publicity Romania Helsinki University of Technology IGN France Kadaster Kort & Matrikelstyrelsen Geodan Software Development & Technology 1Spatial The Finnish Geodetic Institute National Land Survey of Finland Institute of Geodesy, Cartography and Remote Sensing Statens kartverk EuroGeographics
25. An INSPIRE Federation? OWS Providers Member State organisations, eg, INSPIRE Points of Contact WMS Key organisations, eg. EEA, JRC WMS WMS WMS WMS WMS WFS WFS WFS WFS WFS WFS Coordinating Centre IdP IdP IdP IdP IdP IdP
26.
27.
28.
29. B. Lawrence, http://www.osdm.gov.au/SBF201011_Lawrence.pdf?ID=1072
30.
31.
32.
Notas do Editor
Better emphasize that this “security guy” does not have all the answers
Make this generic to show the components of a federation
Examples for each of the components Bindings : eg, HTTP Redirect, HTTP POST, HTTP Artifact Binding
Typical series of SAML interactions
Typical series of SAML interactions JRC has done something like this
User attempts to access a Shibboleth-protected resource on the Service Provider (SP) site. User is redirected to the WAYF in order to select their home organisation (IdP). Part of same exchange as 2. IdP ensures that user is authenticated, by whatever means IdP deems appropriate After successful authentication, a one-time handle (a SAML artefact) is generated for this user session. SP uses the handle to request attribute information from the IdP for this user IdP allows or denies attribute information to be made available to this SP Based on the attribute information made available, SP makes authorisation decision, ie, allows or denies the user access to the resource.
Not just SDI, many kinds of information infrastructure require access control Typically, authentication is a pre-requisite. Some use cases where you don’t, eg, public Barriers to interoperability include; cost, vendor lock-in, lack of a support community, not standards based, etc Return later to those last points
But not OSGB
Advantage of working within the processes of a Standards Body
ESDIN contributed Shibboleth No openID, ws-security for catalogue
Link back to profiles and IdP led as opposed to SP led flows
Probably other activity taking place across Europe that I don’t know about. Geonetwork
“ British experience with building standards based networks for climate and environmental research”