Back to Volume
Paper: Integrating Single Sign-On into the STScI Archive: Lessons Learned
Volume: 512, Astronomical Data Analysis Software and Systems XXV
Page: 93
Authors: Alexov, A.; Abney, F.; Kyprianou, M.; Levay, K.; Zahn, J.
Abstract: The Space Telescope Science Institute (STScI) migrated a handful of web services to a Single Sign-On (SSO) solution in 2014, using the Shibboleth and CAS software solutions. SSO was implemented in order to consolidate usernames and passwords used for a variety of web services, to improve security at STScI and to better the user experience. It took an additional year to integrate the STScI Archive into the SSO Framework, including multiple web services and a non-web service authentication back end which allowed for one set of user credentials. The SSO Framework was expanded to allow external users to register with STScI and use those SSO credentials to access multiple services at STScI, including the Archive. We took great care in migrating and informing over 13,000 STScI Archive users of their new SSO credentials and new user interfaces. We coordinated help desks between IT, the instrument science groups and the Archive to have a successful, seamless transition of the STScI Archive users to their new SSO credentials. We outline our SSO architecture, hurdles, lessons learned and implementation solutions which we have taken in order to migrate STScI's Archive services to using SSO.
Back to Volume