Sounds like a fun way to piss of universities who pay for access: Block their gateway!
Sounds like a fun way to piss of universities who pay for access: Block their gateway!
Depends on the journal/resource. Many resources purchased by universities are authenticated by IP. It's less friction for students when trying to access something, and provides psuedo-anonymity.
There is some push to move to something like OpenAthens for all authentication/authorization, but universities do not want to lose the privacy aspect for their students.
Or shibboleth - we treat shib as a gateway to our auth service at this here journal publishing salt mine.
Seems to work well enough - at least, the roof doesn't fall in on us when an IDP entity (federation of universities, et al) goes offline denying their collective users access.
A "have you switched it off and on again" message to the federations IT bods usually works.
I've always wondered how it ended up catching on in seemingly exclusively academia.
I'm guessing in part it's the name, which ordinary people probably find hard to remember, spell, and pronounce. (The original shibboleth "shibboleth" was meant to be hard to pronounce!)
Oh, Scott knows how to configure it, the problem is he's the only one. I'm a developer at the university works/created it at, and anything that needs to use shibb goes through him. Fortunately, he manages all the configuration (I'm assuming because no one else here knows how), requesting shibb for a new site or whatever is dreaded. It's almost a rite of passage for devs to get a scathing email back from him (almost always in less that 5 minutes) because your request wasn't filled out correctly, the worst part is he will only tell you what you screwed up and not give much help (or any) as to how fix it, and then indirectly (or I've heard directly too) to not waste his time.
As a user, shibb isn't really that bad. As a developer, I hate it so much. Scott, from what I can tell, is a strictly Java developer. So that means we're stuck with Apache and a shitload of XML, there exists a module on GitHub to integrate shibb with Nginx which I think literally every dev here I've talked to would love to be using rather than Apache, but that's probably not going to happen here unfortunately. And Apache with all the XML crap wouldn't be all that terrible if the documentation wasn't extremely vague or just plain missing.
I wanted to get some extra information about the user on signin that, according to the docs, would be available but wasn't clear enough that I felt I could just go in to even our staging servers and monkey around with. So, I figured I throw together some docker containers tinker with before I did it on anything real. It took me an entire week, to get a working shibb setup in docker since the docs literally only got me as far as getting things installed before they stopped being helpful. But, I'm now the only one in my department (at least) that knows how to get shibb up from scratch -- but I wouldn't trust it outside development.
Apologies for the rant, but shibb is probably my least favorite thing I have to deal with here -- when you hear the guy that made it works here, you'd at least think we'd get some good/helpful information about it from the source, but he seems quite happy being the only one that knows anything about it.
In that latter case, you're exposing your personal IP to the publisher and your university who validate your login, which is probably logged.
For example, you can also connect to sites via eduroam globally, but your access (I think) depends on the specific location that you're piggybacking. Sometimes you can download stuff, other times you still need to login to your home institution.
I think so. most universities have well known static ips