Showing posts with label identity. Show all posts
Showing posts with label identity. Show all posts

Monday, April 4, 2011

The Australian Government and SSO, Part 2: Electric Boogaloo.

Australia.gov.au is the Australian government’s attempt at single sign-on (SSO) for citizens. According to Australia.gov.au, “Dealing with the Australian Government online just got easier, with a single account to sign on to multiple agencies.” Sound familiar?

Let’s make a Australia.gov.au ID and see if it lives up to the claim!

The signup process: the signup process is convoluted. Step 1 involves agreeing to terms and conditions which is reasonable. Step 2 and 3 involve picking a password and secret questions. Just wait…why are we picking a password before picking a username? Why are we doing this before even entering our names? It’s like an SSO version of Jeopardy where you enter the password first. After completing the signup, you are assigned a username that starts with two letters and followed by six digits.

Australia.gov.au - final step of signup process
What an easy to remember username! (Don’t worry, I changed it before taking a screenshot)

Connecting your Australia.gov.au identity with other agencies: buried in the My Accounts section is a Manage Agency Links page that allows you to use your Australia.gov.au ID with the other government agencies. At the time of writing, there are only three: the Child Support Agency, Centrelink and Medicare Australia.

Australia.gov.au - manage agency links screen

If you choose to link your Australia.gov.au ID with these agencies, you are prompted to enter your already existing username and password for those sites.

 

Australia.gov.au - linking a CSA accountAustralia.gov.au - linking a Centrelink account

Australia.gov.au - linking your Medicare account

The screens prompting you to link your accounts.

It’s important to note that you can only link already existing agency accounts. You must create accounts individually at each government agencies before you can link them together with your Australia.gov.au, which defeats the purpose of single sign-on.

Once you’ve connected a pre-existing agency account, a link to the agency appears in your My Account section. To test, I’ve linked my existing Medicare Online Services account. A link now appears to Medicare Australia.

image

Clicking on this link gives me a…

image

…an error message saying “A SAML error has occurred.” That’s not good! As I am not a customer of the other agencies, I am unable to test the linking feature.

Password management: a minimum password complexity applies to Australia.gov.au IDs. With a single identity, it is important to allow strong passwords which make use of special characters. Unfortunately, some special characters are disallowed.

Other observations: if you forget your username, you are locked out of the service. There is no username recovery process. To change your secret questions, you need to answer a secret question. If you’ve forgotten the answer, you’re unable to change it. You are also unable to login, because you need to answer your secret question with each login.

Verdict: The inability to retrieve a lost username is a showstopper: it is not unreasonable for people to forget their username, especially if they can’t pick it and it consists of random characters and numbers. The same goes with secret questions. While other companies like Facebook, Google and Microsoft are implementing worldwide SSO systems with ease, the Australian Government are reinventing the SSO mistakes of 2006. Australia.gov.au is another disappointing attempt at SSO by the Australian Government, and I have no reason to believe it will improve any time soon.

Tuesday, March 22, 2011

AUSkey compatibility with IE9, Chrome and Firefox.

AUSkey is the Australian Government’s attempt at Internet SSO for businesses. To use it, you need to download AUSkey software, which is available on the AUSkey Software page. At the moment, cross-browser compatibility is restricted to IE9 and Firefox. Here are the browsers I’ve tested so far.

 

AUSkey
1.4.0.3

AUSkey
1.3.18

Windows    
Microsoft Internet Explorer 9 RTM

image

image

Microsoft Internet Explorer 9 RTM (64-bit)

image

image

Google Chrome 10.0.648.151 beta

image

image

Mozilla Firefox 4

image

 

Mozilla Firefox 3.6.15

image

image

Apple    
Safari 5.0.3

image

 
Google Chrome 10.0.648.151 beta

image

 

If you’re using AUSkey 1.3.18, a straight upgrade to 1.4.0.3 works fine. Ensure you close your browsers before installation: the AUSkey installer caused Google Chrome to crash!

EDIT 24/3: Tested AUSkey on my Mac: it works for Google Chrome on Mac, but not Windows.

Tuesday, November 2, 2010

AUSkey: Australian Government’s attempt at SSO

The Australian Government’s Standard Business Reporting program is attempting to roll out single-sign (SSO) on across all Federal government departments and some state government departments.

You know that problem of having too many different usernames and passwords to remember? Single sign-on is the solution to that. The concept behind SSO is that a user should only have one credential to access multiple services from the same entity. AUSkey is the Australian Government’s attempt at SSO.

Using an AUSkey is simple enough. When a user attempts to access a participating government e-service (i.e. the ATO Business Portal), they are prompted to select an AUSkey (digital certificate).

auskey

After selecting a digital certificate, you are prompted for a password.

auskey1

After entering the password and clicking continue, the user is directed to the resource on the participating site.

For reasons unknown, SBR have chosen to use a Java applet to provide the authentication dialog. This Java applet must be installed on each device used to access AUSkey-authenticated systems.

Because an AUSkey might not always have the ability to install the AUSkey client (i.e. corporate environments), there is a ‘install to a USB’ capability. This installs a standalone/portable Firefox browser to a USB drive and preinstalls the AUSkey certificate (the AUSkey browser.exe file is visible but the AUSkey and AUSkey software for USB folders are hidden).

auskey2

The Firefox browser is ATO branded and returns the user string
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-GB; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (AUSkey Mobile Access)

auskey3

My observations so far:

  • The sign-up process is overly complex. True to government form, there are too many unintuitive forms to fill out. People are familiar with the sign up/e-mail confirmation/login concept. AUSkey needs to be as easy to use as Microsoft Windows Live ID for for people to be enthusiastic about it.
  • The AUSkey installer is just as convoluted. The Nullsoft MSI installer crashed upon first run, and appeared to stall repeatedly during the installation.
  • AUSkeys aren’t portable. For an unknown reason, my desktop browser could not find the certificate installed on my USB key. I had to signup for an additional AUSkey.
  • You should be able to use AUSkey without an installer. AUSkey uses Java-based browser plug-ins for the certificate selection. There are methods of requesting client certificates that don’t require Java applets. This is especially important since Microsoft doesn’t include it with Windows 7. and Apple is unlikely to bundle Java with their next MacOS release.
  • Lack of browser support. The AUSkey software does not support Google Chrome or Internet Explorer 9 beta (yes, I know it’s beta! But one of the reasons Microsoft release beta products is to ensure day-one compatibility when the RTM version is released)
  • Lack of multiplatform support. If you’re using Windows or MacOS X, you’re in luck. Linux, iPad, iPhone, Windows Phone 7, Telstra tablet? Sorry guys. I get the feeling SBR developed the user requirements five years ago and haven’t updated them since.
  • Business users only. I’d like to use this on other government websites like Medicare Online. It’s silly that the authentication used to access my medical records is weaker than my tax records. I guess that shows who values IT more.
  • Low amount of participating sites. I thought ASIC would be a number one citizen with AUSkey. If ASIC don’t support AUSkey, I have very little hope for the Department of Fair Trading NSW.
  • The government is competing with…itself. According to the AUSkey website, “You'll no longer need different user IDs and passwords for each government agency that you have to deal with - the one AUSkey will work for all!”. According to the Australia.gov.au website, “Dealing with the Australian Government online just got easier, with a single [Australia.gov.au] account to sign on to multiple agencies”. Perhaps the government are trying a two-prong strategy: AUSkey for business and australia.gov.au ID for citizens? If so, what a waste of infrastructure!

AUSkey is promising but has a lot of progress to make. It will become a more compelling offering when more government online services support it. Until then, I’ll use it once a quarter to authenticate with the ATO for online activity statement submission.

Friday, October 1, 2010

To install FIM portal, the setup needs to run under SharePoint Farm administrator account.

What is it with Microsoft and unintuitive setup error messages? When attempting to install the FIM Service and Portal component of Microsoft Forefront Identity Manager 2010, I received the following error message.

"To install FIM portal, the setup needs to run under SharePoint Farm administrator account with at least Open permission that allows users to open a Web site, list, or folder in order to access items inside that container. Please make sure you are a SharePoint Farm administrator with Open permission then click "Retry". Click "Cancel" to abort setup."

The problem? I was not in the SharePoint Site collection administrators group. To add yourself to this group, open Central Administration (Start > Administrative Tools > SharePoint 3.0 Central Administration), click Application Management, then Site collection administrators. Change the Primary Site Collection Administrator to the account used to install FIM.


Links
Installation Error while configuring FIM Service & Portal, Microsoft TechNet