Salesforce

Ebook Central Admin: Authentication Options - START HERE

« Go Back

Information

 
TitleEbook Central Admin: Authentication Options - START HERE
SummarySummary of Authentication options available to Ebook Central customers.
Content
NOTE: This article is intended for new Ebook Central customers only. If you are migrating to Ebook Central from MyiLibrary, EBL, or ebrary, please first visit this help article for upgrading customers..

Patron experience is optimal with Single Sign-On (SSO) authentication options. 
Benefits of SSO:
  • Patrons sign in just once and it gains them access to the Ebook Central patron site and signs them into their personal Ebook Central account. Additionally, patrons are signing in with credentials they use to access other electronic resources from your institution, so they likely know their credentials well.
  • There is no need to proxy links for off-campus users. Ebook Central does the routing.
How SSO works from a patron perspective:
  • Upon arrival at the Ebook Central patron site, patron is passed to your institution's authentication page (EZproxy, OpenAthens, or Shibboleth) to sign in. If the patron has already signed in there during their current browser session, they won't need to sign in again.
  • Once patron is successfully authenticated there, they are passed back to Ebook Central with a unique identifier.
  • Ebook Central uses that unique identifier to automatically sign them into their personal account. This gives the patron access to their bookshelf and allows them to copy, print, and download.
 
Ebook Central supports a range of SSO and non-SSO authentication options for the patron platform.
 
1.  EZproxy SSO - an SSO option
  • For more information about how EZproxy SSO works  >See more
  • To implement EZproxy SSO, please contact the Technical Support Team.
    • The team will give you the custom stanza to add to your EZproxy config file
    • You'll need to give the team your EZproxy URL
    • The team will make the necessary changes to your site configuration
  • Note, along with this we can also authorize your on-campus IPs to allow users coming from there to browse before signing in.  We call this enabling "anonymous access".

2.  OpenAthens - an SSO option
  • To implement OpenAthens, please contact the Technical Support Team.
    • You'll need to give the team your OpenAthens entity ID (preferred) and organisation identifier
    • The team will make the necessary changes to your site configuration
  • Note, along with this we can also authorize your on-campus IPs to allow users coming from there to browse before signing in.  We call this enabling "anonymous access".
 
3.  Shibboleth - an SSO option
  • See Shibboleth federations supported
  • To implement Shibboleth, please contact the Technical Support Team.
    • You'll need to give the team your Shibboleth Entity ID
    • The team will make the necessary changes to your site configuration
  • Ebook Central requires you to pass any one of the following three attribute combinations:
             eduPersonTargetedID
        or  eduPersonPrincipalName
        or  eduPersonPersistentID and eduPersonScopedAffiliation
That is, we only need eduPersonScopedAffiliation if you send eduPersonPersistentID instead of either of the first two.
  • Note, along with this we can also authorize your on-campus IPs to allow users coming from there to browse before signing in.  We call this enabling "anonymous access".
4. SAML - an SSO option
  • See details of Ebook Central Admin: Authentication, SAML
  • SAML enables you to use your own directory service (such as LDAP or Active Directory) for single-sign-on to Ebook Central.
  • To implement SAML SSO, please contact the Technical Support Team.
    • This setup involves some custom setup work and testing, and will need to be coordinated with our developers.
  • Note, along with this we can also authorize your on-campus IPs to allow users coming from there to browse before signing in.  We call this enabling "anonymous access".

5.  Patron Login - an authentication method hosted by Ebook Central
  • Each patron has their own username and password (their 'patron login') that, once created, will (by default) give them access to the Ebook Central site from anywhere (this option can be turned off) and also signs them into their personal account.
  • To create a personal account (i.e., a 'patron login'), the patron must either be IP authenticated (including use of simple proxied links or VPN), be given approval by an admin, or an admin can pre-create the accounts for patrons  >See more
  • To make changes to the default settings, please contact the Technical Support Team.
  • Note, along with this we can also authorize your on-campus IPs to allow users coming from there to browse before signing in.  We call this enabling "anonymous access".

6.  IP authentication (including use of simple proxied links where the IP of the proxy is authenticated)
  • IP authentication allows users to browse without first signing in. It must still be used along with either Patron Login or one of the SSO authentication options above to allow users to sign in to their individual accounts.
  • For Patron Login, IP authentication can be required either:
    • Only the first time - for the patron to create a personal account.  Then (by default) after that the patron can gain access to the site from anywhere just by signing in with that username and password.
    • Or, the patron can be required to always access via the authorized IPs
  • To add or change IP addresses, please contact the Technical Support Team.
  • These are not the only IP settings you can view in LibCentral; for more information, see Ebook Central Admin: IP Restrictions in LibCentral
    7.  VPN (Virtual Private Network)
    • VPN is a form of IP authentication - we authenticate the IP address of your VPN
    • See IP authentication details above
    • Note, Ebook Central does *not* work with URL-rewriting VPN
    8.  Barcode - an authentication method hosted by Ebook Central
    • We support alphanumeric barcodes of at least 8 characters
    • Can be supplied as a list or a pattern  (e.g. 4#a###,4#b###,4#c###)
    • Note, along with this we can also authorize your on-campus IPs to allow users coming from there to browse before signing in.  We call this enabling "anonymous access".
    • Please contact the Technical Support Team for setup or for barcode range changes.

    We want to help ensure the best authentication method for your environment. Our Ebook Central technical team is available to answer any questions. Please contact the Technical Support Team by submitting your query on this form.
    URL NameEbook-Central-Authentication-Options
    Created Date2022-06-30 21:02

    Powered by