no unique identification Before GASPAR every service (financial, personnel, student, etc) had its own database no unique identification 14-Sep-18 i.cionca
Steps preparing GASPAR HR service defines a unique ID (SCIPER) 14-Sep-18 i.cionca
Steps preparing GASPAR HR service defines a unique ID (SCIPER) CAMIPRO card used to grant acces to buildings – based on SCIPER and a PIN code 14-Sep-18 i.cionca
Steps preparing GASPAR HR service defines a unique ID (SCIPER) CAMIPRO card used to grant acces to buildings – based on SCIPER and a PIN code students’ identification (SAC) based on SCIPER 14-Sep-18 i.cionca
Steps preparing GASPAR HR service defines a unique ID (SCIPER) CAMIPRO card used to grant acces to buildings – based on SCIPER and a PIN code students’ identification (SAC) based on SCIPER personnel data (BOTTIN) uses SCIPER 14-Sep-18 i.cionca
Steps preparing GASPAR HR service defines a unique ID (SCIPER) CAMIPRO card used to grant acces to buildings – based on SCIPER and a PIN code students’ identification (SAC) based on SCIPER personnel data (BOTTIN) uses SCIPER several OSCAR interactive terminals with CAMIPRO card slots installed at EPFL 14-Sep-18 i.cionca
services HTTP GASPAR CAMIPRO SAC BOTTIN OSCAR SCIPER 14-Sep-18 i.cionca
GASPAR: how to register OSCAR identification= CAMIPRO+PINcode Crypted mail sent to GASPAR with SCIPER and pwd GASPAR 14-Sep-18 i.cionca
GASPAR: how to register web For already existing e-mail accounts: preregister via the web GASPAR 14-Sep-18 i.cionca
GASPAR: how to register web For already existing e-mail accounts: preregister via the web Request for confirmation GASPAR 14-Sep-18 i.cionca
GASPAR: how to register web For already existing e-mail accounts: preregister via the web confirmation GASPAR 14-Sep-18 i.cionca
GASPAR: how to register admin GASPAR 14-Sep-18 i.cionca
GASPAR: how to register GASPAR superuser GASPAR 14-Sep-18 i.cionca
web OSCAR GASPAR admin GASPAR superuser GASPAR 14-Sep-18 i.cionca For already existing e-mail accounts: preregister via the web identification= CAMIPRO+PINcode Crypted mail sent to GASPAR with SCIPER and pwd confirmation Request for confirmation GASPAR admin GASPAR superuser GASPAR 14-Sep-18 i.cionca
GASPAR: identification user’s name (firstname, lastname) and/or SCIPER plus GASPAR password SSL certificate Lost password? OSCAR terminal identification via CAMIPRO card and PIN code – choose a new password contact GASPAR administrator 14-Sep-18 i.cionca
base: e-mail, SSL certificates GASPAR: services base: e-mail, SSL certificates other: SW distribution, network management, students’ services (jobs, rooms, exams results), etc. 14-Sep-18 i.cionca
client application server 1. application URL (http://prest.epfl.ch) 14-Sep-18 i.cionca
client application server YES active sessions valid session Time stamp | SCIPER | IP valid session (SCIPER,IP) YES 2.2 update session 2.3 execute application (SCIPER,IP) client http://prest.epfl.ch 14-Sep-18 i.cionca
application server NO active sessions valid session (SCIPER,IP) Login GASPAR: user: pwd: 2.1 Redirect to GASPAR for identification 14-Sep-18 i.cionca
GASPAR YES application server active sessions Time stamp | SCIPER | IP access restricted to GASPAR’s IP server initiates session 3.1 authentication URL with client’s details (SCIPER, e-mail, unit, IP) valid client & acces rights YES 14-Sep-18 i.cionca
GASPAR YES application server valid client & acces rights 3.2 Redirect to application URL 14-Sep-18 i.cionca
client GASPAR YES application server NO YES 1. application URL http://prest.epfl.ch application server 1. application URL (http://prest.epfl.ch) NO valid session (SCIPER,IP) YES Login GASPAR: user: pwd: 2.2 update session 2.3 execute application (SCIPER,IP) 2.1 Redirect to GASPAR for identification GASPAR access restricted to GASPAR’s IP server initiates session (timestamp, SCIPER,IP) 3.1 authentication URL with client’s details (SCIPER, e-mail, unit, IP) valid client & acces rights YES application 3.2 Redirect to application URL 14-Sep-18 i.cionca
client GASPAR 1. GASPAR URL (https://gaspar.epfl.ch) 14-Sep-18 http://gaspar.epfl.ch 1. GASPAR URL (https://gaspar.epfl.ch) 14-Sep-18 i.cionca
GASPAR application server YES valid client application choice server initiates session access restricted to GASPAR’s IP 2. authentication URL with client’s details (SCIPER, e-mail, unit, IP) active sessions Time stamp | SCIPER | IP 14-Sep-18 i.cionca
GASPAR YES valid client 3. Redirect to application URL 14-Sep-18 i.cionca
client GASPAR application server YES 1. GASPAR URL http://gaspar.epfl.ch 1. GASPAR URL (https://gaspar.epfl.ch) valid client YES application server application choice server initiates session (timestamp, SCIPER,IP) access restricted to GASPAR’s IP 2. authentication URL with client’s details (SCIPER, e-mail, unit, IP) application 3. Redirect to application URL 14-Sep-18 i.cionca
GASPAR administrator of the unit controls users from one or several units manages: GASPAR registrations e-mail accounts access rights to all services manages Access Managers 14-Sep-18 i.cionca
GASPAR Acces Manager controls access rights to one or several services for all users from one or several units Access rights per person and service: access denied or granted (for 1,3,6,12 months or unlimited) 14-Sep-18 i.cionca
yes for the principle (simple HTTP authentication) Exporting GASPAR? yes for the principle (simple HTTP authentication) extra work needed to cope with local data structures 14-Sep-18 i.cionca