Provisioning of Services Authentication Requirements

Slides:



Advertisements
Similar presentations
EARLY CHILDHOOD Early Childhood Whats new? All early childhood evaluations will be completed at the local school. This includes Child.
Advertisements

Office of Labor-Management Standards (OLMS)
Help File For User Creation Click the “Course” button for Creating/Add User.
HRMS 8.9 Upgrade Person Model. Introduction One of the significant changes to HRMS with the upgrade to 8.9 is the new Person Model. This course provides.
EAuthentication Before accessing the Delphi eInvoicing System, you must be an authenticated user. This authentication process is called eAuthentication.
Provisioning of Services Authentication Requirements David Henry Office of Information Technology University of Maryland
Technical Primer: Identifiers Internet2 Base CAMP Boulder, Colorado June, 2002.
Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.
UCB Enterprise Directory Services. Directory Services – Project History  Requirements defined  Project commission & goals articulated  Project teams.
June 1, 2001 Enterprise Directory Service at College Park David Henry Office of Information Technology University of Maryland College Park
Middleware & Enterprise Services at College Park David Henry Office of Information Technology November 16, 2001.
UCB Enterprise Directory Services. Directory Services – Project History  Requirements defined  Project commission & goals articulated  Project teams.
Directory Services Project University of Colorado at Boulder.
System Architecture University of Maryland David Henry Office of Information Technology December 6, 2002.
David Henry, CSG - May, 2000 University of Maryland LDAP Directory David Henry Office of Information Technology University of Maryland College Park
NERCOMP Managing Campus Affiliates Managing Campus Affiliates Faculty? Student? Faculty? Student? Staff? Criss Laidlaw Director of Administrative.
NAMS Account Activation Training. 2 What is NAMS? The NASA Account Management System is NASA’s centralized process for requesting and maintaining accounts.
GFP in the IUID Registry – A Basic Look Walt Clark, CPPM Raytheon IIS.
9/10/2015 What’s New? Edline at Valley View!! Joyce Potempa Technology Department presentation to Building Support Staff February 2, 2010 Institute Day.
University of Michigan Enterprise Directory Services Appendix A Conceptual Architecture.
1 Expiration Notification. Jon Finke Rensselaer Polytechnic Institute.
Directory Object Management Frank Grewe Office of Information Technology University of Minnesota
Erie 1 BOCES / WNYRIC eBOCES applications Visit us at:
Submitting Course Outlines for C-ID Designation Training for Articulation Officers Summer 2012.
Binghamton University Dual Diploma Programs: Online Application Instructions.
REQUEST TEASE ACCESS INDICATOR 7 Steps to Request Access to Indicator 7 through TEASE (Texas Education Agency Secure Environment) Data Collection TEA.
Last update 21/01/ :05 LCG 1Maria Dimou- cern-it-gd Current LCG User Registration, VO management and Authorisation Procedures VOMS workshop
Internet2 Base CAMP Topics in Middleware: Authentication.
Introduction to Terra Dotta Applications Integration with Campus Data Systems for institutions beginning their software implementation.
Business Objects XIr2 Windows NT Authentication Single Sign-on 18 August 2006.
Attendance & Grading 1.Logging In & Navigating the Mail Menu 2.Viewing & Printing Your Attendance Roster 3.Creating TBA Schedules 4.Positive Attendance.
California State University, Los Angeles Department of Public Health PH 4960 Internship Course Policies and Site Information Advisor: Behjat A. Sharif,
OPS Requirements Specification and Analysis Dustin Larson Bryan Campbell Charles Sears.
Justin Scheitlin Daisey Fahringer
Microsoft Imagine Academy
Centralizing and Automating the Management of Special Identities
Hiring Manager onboarding
Achieving Academic Success
FUTURE STUDENTS WEBPAGE NAVIGATION AND STEPS TO ENROLL
California State University, Los Angeles Department of Public Health
IT Services for Students Community College of Rhode Island
IT Services for Students Community College of Rhode Island
HPCMP New Users’ Guide “How Do I Obtain a User Account?”
Microsoft Imagine Academy
TwinEngines Discharges
Outreach Trainer Portal
Bursar Office Fall Semester 2018
2016 File Maker pro training for Summer program hiring
How to Request and Use a Textbook Voucher
Flowserve Distributor Online Store & Portal
Flowserve Distributor Online Store & Portal
F-1 OPT Workshop.
Applying to a Selective ADMISSION program
INFORMATION TECHNOLOGY NEW USER ORIENTATION
Identity Management at the University of Florida
Starting Page.
“Welcome to M.A.P.S. Advocate Training for 2017 Qualifications” Sponsored by: Westmoreland County Wellness Coordinator Westmoreland County MAPS Enhancers.
INFORMATION TECHNOLOGY NEW USER ORIENTATION
Managing Enterprise Directories: Operational Issues
Request Form You gain access to the Request Form from your intranet set-up by your IT dept. Or the internet via either our desktop launcher icon. Or a.
OPT Optional Practical Training Lindsey W. Hill
Welcome to the ABC Bakers webinar on Scheduling a FCFS Booth
txConnect – A Parent’s View
Registration Waitlist Process Overview
MIT Case Study Notes Paul B. Hill
Onboarding New Employees
Canvas introduction for students
Waitlist Registration Process Overview
Division of Engineering Computing Services
Presentation transcript:

Provisioning of Services Authentication Requirements David Henry Office of Information Technology University of Maryland dhenry@umd.edu

Provisioning of Accounts For what services are "shell accounts" used? For what services are other provisioning methods used and what are they? Most provisioning is via “shell accounts” Some services are pre-provisioned Time and Attendance system for timesheet, automatically provisioned, based on presence in HRS Student registration system and personal information management, based on presence in SIS Some services are provisioned upon initial use Umail - presence in the directory means user can “activate” the account automatically upon first use, which establishes home directory, password file entry, etc. New email system will require activation via web page prior to first use

Provisioning (cont.) How are enterprise accounts created/deleted? Everyone gets an employeenumber Never changes Includes student applicants, visiting/adjunct faculty, volunteers, other affiliates Used as part of the DN in our directory Initially tied to SSN, but allows for SSN changes Eight digits plus check digit Everyone gets a Directory ID/ Unique ID Alphanumeric up to 8 characters Is assigned initially first initial, first 7 characters of last name (e.g. dhenry); digits used to make unique (e.g. jjohnso2) Vanity Ids are supported User may request a change up to once a year. When retired, ID won’t be reassigned for 12 months Some specific Ids are reserved forever

Provisioning (cont.) Entries are added Entries are deleted Faculty/Staff: Upon entry in HR system, includes future appointments Students: Upon “acceptance with letter sent” Others: May be sponsored by any of a number of approved offices. Entries are deleted Faculty/Staff: 210 days after separation (an attribute is established to indicate a termination date for those apps that care) Students: After start of second semester of non-registration, treating summer as a semester. Others: Renewed annually by sponsor

Provisioning (cont.) How are other services provisioning mechanisms managed? Lots of ways Lots of admins How do you advise apps developers on which identifiers to use? Use the employeenumber as internal ID (if possible) Use the Directory ID for user auth’n Don’t use empno or SSN

Provisioning (cont.) How are the identifiers for an individual's multiple accounts managed? Currently, they’re not. In some cases, ID’s depend on the directory ID or another system. Passwords? Don’t ask.

Provisioning (cont.) System to manage IDs in cooperative Admins User Centrally register their system/service Indicate characteristics of eligibility (LDAP filter?) Specify mechanism for notifications (new account request, userid change, account delete, etc.) User Goes to a central web page to see the systems and services they may request Activate systems/services System Notify registered systems/services of change events E-Mail, URL (with Auth’n), Script

Authentication Practices What levels of services require what initial types of identity proofing? UNIX shell accounts require in-person proofing w/student ID card Privileged accounts require f2f Access to certain information requires signed statement re: appropriate use What mechanisms are used for authentication? Native authentication mechanism Kerberos LDAP compare

Authn (cont.) What is the hope for intercampus standards? There needs to be some hope. Shady Grove Campus Combination of system institutions All Faculty, Staff, and Students are from one of the other campuses. Courses from any campus apply. So far everything is handled by exception.

David Henry OIT University of Maryland That’s IT David Henry OIT University of Maryland