What is Shibboleth?

Shibboleth GriffinShibboleth is a new web authentication system being adopted by thousands of colleges, universities, government agencies, and businesses. Shibboleth requires users to only login once for access Shibboleth-protected websites and other web-based resources. Once logged in, the Shibboleth user will be allowed to access all the Shibboleth-protected resources their credentials allow without having to log in again until they shutdown their browser.

What do I need to know?

  • Once you log onto any Shibboleth-protected site through Brown's Shibboleth login, your credentials travel with you until you exit your browser.
  • As your Shibboleth credentials become a part of your current browser session, always be sure to exit your browser completely to prevent others from accessing resources that are only for you.
  • You will need to log into Shibboleth again if you exit or restart your browser.
  • For additional security, you may need to re-authenticate if you change your IP address or your session times out. This may happen when switching wireless locations, changing how you connect to the internet, or if browser session lasts a few hours.
  • Some sites or services will allow you to log out of their particular resource, but does not terminate the sharing of your Shibboleth credentials. Again, the only way to completely log out is to exit your browser.
  • Do not enter your login credentials to an un-trusted resource. Always confirm the site you are logging into before providing your credentials. If you are not sure of the site’s authenticity contact the resource provider for confirmation. Shibboleth's login page is https://sso.brown.edu/idp/Authn/UserPassword. WebAuth's login page begins with: https://web-auth.brown.edu/BrownTicket

What about WebAuth?

The WebAuth system will begin phasing out in Fall 2009. The information above only applies to Shibboleth. Although the two login pages look similar, the Shibboleth login page can be identified by the Shibboleth griffin.

Why the change to Shibboleth?

Shibboleth's authentication system is set up to allow users across institutions to share information securely. In the future, it will be possible for a researcher at Brown to grant co-researchers from other institutions (that also use Shibboleth) access to their Confluence wiki and vice versa. As Shibboleth expands it will become even easier for researchers and students from different institutions to share information securely while still prohibiting access from outsiders.

