Joining the UK Access Management Federation for Education and Research
Summary of procedure
Early application for membership of the UK Access Management Federation is advised so that once you are ready to participate in the federation, the application process is already completed. Once you are a member, you can take advantage of the many benefits the federation offers. Membership is free and involves a simple administration process.
For further information on joining, please click on the following links. If you have javascript enabled, clicking on the "[+]" symbols will expand each section. Otherwise, click on the section title to be taken to a page with the same content.
[+] Apply for membership
- A senior officer at an eligible organisation makes a formal application in writing to JANET(UK) to join the federation (full details) and agrees to be bound by the federation rules of membership.
- JANET(UK) replies with an approval e-mail verifying contact details.
NB: Where an applicant intends to use an outsourced provider (see participation options), both the applicant and the external organisation providing the outsourcing service must become members of the federation and the management liaison of the requesting organisation must provide additional outsourced provider information.
[+] Participation options
Once an organisation has joined the federation, there are various options for participation.
In-house
Run and support identity management in-house.There are two options for following this route:
- implement the technology wholly through the organisation.
- implement the technology using a third party. This option is particularly useful for those organisations who do not have the internal resource or expertise to deploy the initial technical requirements but would like to maintain ultimate control of their user authentication.
Outsourced
Organisational identity management provision is handled by a third party.
The application process for outsourced IdPs will need to be followed if taking this route.
There are a variety of organisations who offer outsourced and/or in-house support services.
Schools
The recommended approach for schools is to join via the Local Authorities (England & Wales) or Regional Broadband Consortia in England, Classroom 2000 in Northern Ireland and Learning & Teaching, Scotland. However, schools may join the federation independently.
[+] Register entities
Entity registration
Once an organisation’s application for membership has been approved, and the option for participation determined, the organisation (or outsourced IdP/SP on behalf of the organisation) may register any number of identity provider and service provider entities.
Shibboleth 1.3
In order to install a Shibboleth 1.3 IdP or SP:
- You install Shibboleth 1.3 IdP or SP software
- You obtain a suitable X.509 server certificate
- Your Management Liaison e-mails a registration request to the federation helpdesk to register Shibboleth 1.3 IdP or register Shibboleth 1.3 SP entities
- You are sent an e-mail confirming that the technical description of each registered entity has been published in the federation metadata
- You download the metadata and modify your Shibboleth configuration to match it (described in Setup 1.3 IdP or Setup 1.3 SP).
Details of Shibboleth 1.3 entity registration are available for the above steps.
Shibboleth 2
In order to install a Shibboleth 2 IdP or SP:
- You install Shibboleth 2 IdP or SP software
- You obtain a suitable X.509 server certificate
- You make changes appropriate to your installation to the standard Shibboleth 2 configuration files, as described in set up Shibboleth 2 IdP or set up Shibboleth 2 SP
- Your Management Liaison e-mails a registration request to the federation helpdesk to register Shibboleth 2 IdP or register Shibboleth 2 SP entities
- You are sent an e-mail confirming that the technical description of your registered entity has been published in the federation metadata.
Details of Shibboleth 2 entity registration are available for the above steps.
Upgrading from Shibboleth 1.3 IdP to Shibboleth 2 IdP
Here is some documentation to assist those wishing to upgrade a Shibboleth 1.3 IdP installation to Shibboleth 2 IdP.
[+] Summary of application and registration process
A diagram (
447Kb) is available which summarises the steps to be carried out by technical and administrative staff when an organisation applies to join the UK federation.
