Content-Type: text/html
Sounds a lot like Shibboleth works to me and we have that service on campus now.
Rick
From: Troy D Murray [mailto:[log in to unmask]]
Sent: Wednesday, March 21, 2012 11:13 AM
To: [log in to unmask]
Subject: Re: Feature Request
In short, OAuth is an "open protocol to allow secure API authorization in a simple and standard method from desktop and web applications." (http://oauth.net/).
OAuth uses the following roles: client (consumer), server (service provider), and resource owner (user).
OAuth uses the following tokens: Request Token (user requesting my app have access to their protected resources) and Access Token (what the user has approved my application to use to ask your server for the users protected resources)
The general idea would be that the current Sentinel Support group, or whatever your new name might be under the reorganization, would be server (service provider). My web or desktop application would be the client (consumer). The employee accessing my web or desktop application would be the resource owner (user).
A use case would work as follows:
Future use of my application by the user wouldn't need to go through all of the Request Token steps listed above, only that the user would login (using your MSU login page) and then my application would use the previously granted Access Token.
I see the benefits of this type of authentication as being as follows:
I hope that explains it well. Let me know if you have questions.
Troy Murray
Michigan State University
College of Medicine
Life Science
1355 Bogue St, B-136D
East Lansing, MI 48824
P: 517-432-2760
F: 517-355-7254
RedHat 5 Certified Technician
RedHat 5 Certified Systems Administrator
HL7 V2.6/2.5 Certified Control Specialist
On Mar 20, 2012, at 2:36 PM, Murphy, Patrick wrote:
Only what I read on the web site last night. It looks like a method of letting others impersonate you.
From: Troy D Murray [[log in to unmask]">mailto:[log in to unmask]]
Sent: Monday, March 19, 2012 6:36 PM
To: Murphy, Patrick
Subject: Re: Feature Request
How much do you know about OAuth?
Troy Murray
Michigan State University
College of Medicine
Life Science
1355 Bogue St, B-136D
East Lansing, MI 48824
P: 517-432-2760
F: 517-355-7254
RedHat 5 Certified Technician
RedHat 5 Certified Systems Administrator
HL7 V2.6/2.5 Certified Control Specialist
On Mar 19, 2012, at 6:27 PM, Murphy, Patrick wrote:
I had not heard of this until your email. Is there something in particular you are looking to implement with this specification?
From: Troy D Murray [log in to unmask]]">[mailto:[log in to unmask]]
Sent: Monday, March 19, 2012 5:11 PM
To: AIS Sentinel Support
Subject: Feature Request
Has their been any discussion on offering OAuth as an option that could be administered by users through something like myid.msu.edu?
Troy Murray
Michigan State University
College of Medicine
Life Science
1355 Bogue St, B-136D
East Lansing, MI 48824
P: 517-432-2760
F: 517-355-7254
RedHat 5 Certified Technician
RedHat 5 Certified Systems Administrator
HL7 V2.6/2.5 Certified Control Specialist