Shibboleth FAQs

  1. What is Shibboleth?
  2. Why would Shibboleth benefit UBC users?
  3. How does it work?
  4. Will an external institution be able to view my CWL account credentials?
  5. What do I (as a prospective Shibboleth service provider) need to do to integrate with UBC IT's Shibboleth Identity Provider?
  6. What is a Shibboleth identity federation?
  7. Which identity federation does UBC IT's Identity Provider belong to?
  8. How do I log out of Shibboleth?

 

  1. What is Shibboleth?
    Shibboleth
    is an open-source initiative which facilitates sharing of resources between institutions.  Shibboleth allows users from one institution to access resources at another without making the user log in at the external institution..
  2. Why would Shibboleth benefit UBC users?
    UBC users will be able to access prequalified Shibboleth-enabled applications with their Campus-Wide Login (CWL) accounts. 
  3. How does it work?
    When a user tries to login to a Shibboleth-enabled application, Shibboleth Identity Provider to send limited details about the user to the Shibboleth Service Provider. An example of details forwarded is the affiliation of the user at UBC (e.g. Faculty, Staff or Student).  The Shibboleth Service Provider will authorize access based on the details forwarded. CWL passwords, employee numbers, student numbers or any identifying information is not forwarded to Shibboleth.
  4. Will an external institution be able to view my CWL account credentials?
    Users will login with their CWL account credentials on a web-page hosted by UBC. The password will not be viewable by a Shibboleth Service Provider.
  5. What do I (as a prospective Shibboleth service provider) need to do to integrate with UBC IT's Shibboleth Identity Provider?
    To integrate with UBC-IT's Shibboleth Identity Provider, you will be required to have a Shibboleth-enabled application which uses a Shibboleth Service Provider that belongs to the Canadian Access Federation. To initiate the integration please complete the Shibboleth integration sign-up form and you will be contacted by a UBC-IT staff member.
  6. What is a Shibboleth identity federation?
    A Shibboleth identity federation is made up of a group of organizations who trust one another and would like to allow users in one organization to access resources in another. All parties in the federation agree on a common set of acceptable authorization attributes for users, and a schema to describe them.
  7. Which identity federation does UBC IT's Identity Provider belong to?
    UBC-IT's Shibboleth Identity Provider belongs to the Canadian Access Federation established by the Canadian University Council of Chief Information Officers (CUCCIO).
  8. How do I log out of Shibboleth?
    To terminate the session, users must close the browser. As with all Single Sign-On products, to follow security recommendations, users must shut-down their browser sessions when terminating access to a Shibboleth integrated application.