Reading Time: < 1 minute
A man teaching adult students in a classroom

Shibboleth Training for Authentication & Access Management

Gain the essential skills to deploy, configure, and manage Shibboleth open source software to support secure, standards-based login and access control across institutional and federated environments.

Shibboleth Training Overview

This comprehensive Shibboleth training program is designed for IT professionals responsible for deploying, managing, and maintaining identity and access management solutions within the Research & Education community. Shibboleth is a widely adopted open-source software suite that provides Single Sign-On (SSO) and attribute exchange capabilities, forming the backbone of federated identity systems like InCommon Federation.

Through a blend of theoretical concepts and practical, hands-on exercises, participants will learn the intricacies of Shibboleth Identity Provider (IdP) and Service Provider (SP) installation, configuration, and integration with existing identity infrastructure.

Course Snapshot

Delivery: Virtual, Instructor-Led

Duration: 5 days (11 hours total)

Times: 2 – 4 p.m. ET

Upcoming Training Dates:

  • September 14-18, 2026

Price: 

$2,000 – InCommon Participants

$2,500 – Non-Participants

 

Register

 

 

What You’ll Learn

  • Understand Shibboleth basics, architecture, IdP, SP, and metadata.
  • Plan, install, and configure IdP on Linux, integrating with identity stores.
  • Manage IdP operations and some advanced IdP topics.
  • Integrate SP, including planning and internal business decisions for federation.
  • Install and configure SP, integrating with web applications.
  • Manage SP operations and some advanced SP tasks.
  • Understand and manage SAML 2.0 protocol flows.
  • Implement troubleshooting techniques for IdP and SP.
What to Expect
  • Access to course materials in Canvas
  • Access to a course slack channel with instructors and peers
  • Blend of self-paced learning and daily office hours
  • Access to one-to-one support for class exercises and assignments
  • Live SAML Metadata Configuration Manager Demo
  • A Capstone Project
  • Digital Completion Badge
  • Ongoing community support and shared learning
  • Hands-on exercises with a secure virtual environment
Who Should Attend
  • System administrators and engineers responsible for deploying or managing IAM infrastructure.
  • Identity and Access Management (IAM) practitioners working with federated identity.
  • IT staff supporting applications that require Single Sign-On (SSO) via SAML.
  • Anyone involved in connecting their institution to the InCommon Federation.
Pre-Requisites
  • Familiarity with the Linux command line.
  • Basic understanding of networking concepts (DNS, firewalls, HTTP/HTTPS).
  • Experience with web servers (e.g., Apache, Nginx) and Java environments.
  • Basic knowledge of identity management concepts (e.g., LDAP, user directories).

Course Content

Overview – An introduction to Shibboleth, The Trusted Access Platform, and how federated SSO works. A review of SAML messages, components, and metadata as well as entity attributes.

Identity Provider (IdP) Planning, Installation, Configuration & Operations – Learn about IdP integration including authentication sources and attribute stores. Plan, install, configure, test, and operate the Shibboleth IdP using Docker containers on a virtual machine.

Service Provider (SP) Planning, Installation, Configuration & Operations – Review considerations for SP planning including metadata and IdP discovery. Understand SP packaging and architecture, then install, configure, test, and operate Shibboleth SP software.

Advanced Topics – Apply what you’ve learned to activities relevant to your institution such as configuring multi-factor authentication (MFA) with Duo, implementing simple access control using intercept flows (AuthZ), customizing the IdP login page, and working with additional protocols and integrations.

SP Advanced Tasks – After completing the core SP lifecycle, explore advanced technical activities such as exploring some HTTPD configuration directives and running a Discovery Service.

Capstone Assignment – Complete a capstone exercise that integrates an Identity Provider directly with a Service Provider, mirroring scenarios you may encounter with campus or cloud applications.

Meet Your Instructors

Paul Riddle

SENIOR IAM ARCHITECT, UNIVERSITY OF MARYLAND – BALTIMORE COUNTY

Paul Riddle

Paul Caskey

IAM ARCHITECT, INTERNET2

Paul Caskey

Shibboleth Training FAQs

Questions about Shibboleth Training?

Our team is here to provide guidance and help you navigate your training options. Reach out to us directly!

Ready to Boost Your Skills in Other TAP Software?

Explore all of our Trusted Access Platform software component training options to broaden your skills.