Identity management and federation
Liberty Alliance
Identity management and allowing a unique identification to access different services (thanks to identity federation) have become major stakes. Liberty Alliance consortium designed a set of open specifications and protocols aiming to standardise identity management and federation. Those protocols, relying now on SAML 2.0, allow to set "Circles of Trust" within which a user identify only once (Single Sign On) but where his privacy is perfectly preserved.
Entr'ouvert is a member of the Liberty Alliance consortium.
How to make you application speak "Liberty" within a "Circle of Trust" ?
To add Liberty support to your web applications, we offer a set of Liberty Alliance certified (including the SAML 2.0 certification) products. Those solutions are free software (released under the GPL license) and we provide a complete range of services around them to help you, if necessary, in their deployment. Our solutions are used in some important projects. They are designed to build a complete Identity management and federation solution for companies or administrations.
Lasso
Corner stone of our solutions, Lasso is a Library that manages Liberty Alliance exchanges and that can be used to "Libertyse" (which means add the support for Liberty Alliance protocols) any service;
Larpe
Larpe is a reverse-proxy allowing any web service to communicate with the service provider supporting Liberty Alliance protocols, without having to modify the service itself.
mod_mellon
mod_mellon is an Apache module based on Lasso and developped within the norvegian academic projet Feide. This module allows a very quick integration of an application within a Circle of Trust.
Authentic, the Identity Provider
The IdP is the most important part of a Circle of Trust.The identity provider guarantees the user identity to all the service providers within the circle. If you don't own your own identity provider you can download and freely install Authtentic, our IdP based on Lasso.
Respect of the CNIL recommendations
Liberty Alliance exchanges are made in optimal security and privacy conditions in regards with signature and encryption. And more particularly, because there is not any user unique identifier in circulation within the system. This is a major stake the CNIL is very vigilant on. Datas about the user can never be exchanged between two service providers without the user consent.