UPortal Meets Campus-wide Login at UBC Paul Zablosky ITServices The University of British Columbia Slide 1.

Slides:



Advertisements
Similar presentations
Access management for repositories: challenges and approaches for MAMS James Dalziel Professor of Learning Technology and Director, Macquarie E-Learning.
Advertisements

CNRIS CNRIS 2.0 Challenges for a new generation of Research Information Systems.
Federal Student Aid Technical Architecture Initiatives Sandy England
© 2006 IBM Corporation IBM Software Group Relevance of Service Orientated Architecture to an Academic Infrastructure Gareth Greenwood, e-learning Evangelist,
Migrating to uPortal 2 at UBC Paul Zablosky University of British Columbia Copyright Paul Zablosky This work is the intellectual property of the.
UPortal: A framework for the Personalization of Library Services John Fereira: Programmer/Analyst Cornell University Mann Library.
Identity and Access Management IAM. 2 Definition Identity and Access Management provide the following: – Mechanisms for identifying, creating, updating.
Virtual Observatory Single Sign-on U.S. National Virtual Observatory National Center for Supercomputing Applications Ray Plante, Bill Baker.
Identity and Access Management IAM A Preview. 2 Goal To design and implement an identity and access management (IAM) middleware infrastructure that –
Implementing ORCID at Chalmers Researcher identifications and ORCID – national implementations, Helsinki Jonas Gilbert Chalmers library
System Architecture University of Maryland David Henry Office of Information Technology December 6, 2002.
CAMP Med Mapping HIPAA to the Middleware Layer Sandra Senti Biological Sciences Division University of Chicago C opyright Sandra Senti,
UPortal Ken Weiner JA-SIG, IBS
SOA – Development Organization Yogish Pai. 2 IT organization are structured to meet the business needs LOB-IT Aligned to a particular business unit for.
Digital Identity Management Strategy, Policies and Architecture Kent Percival A presentation to the Information Services Committee.
FSU’s Portal Project Secure Applications in Blackboard Jeff Bauer Office of Technology Integration 5/24/2005.
TNC2004 Rhodes 1 Authentication and access control in Sympa mailing list manager Serge Aumont & Olivier Salaün May 2004.
SOFTWARE REUSABILITY AJAYINDER SINGH CSC What is Software Reuse Software reuse is the process of implementing or updating software systems using.
Helsinki Institute of Physics (HIP) Liberty Alliance Overview of the Liberty Alliance Architecture Helsinki Institute of Physics (HIP), May 9 th.
Shibboleth Update Michael Gettes Principal Technologist Georgetown University Ken Klingenstein Director Interne2 Middleware Initiative.
Michael Ghens Information Systems Specialist Santa Barbara City College.
SharePoint Security Fundamentals Introduction to Claims-based Security Configuring Claims-based Security Development Opportunities.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: November 2009.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: July 2008 Updated: February 2011.
FSU’s Portal Project Secure Login in Blackboard Jeff Bauer Office of Technology Integration 4/26/2005.
Single Sign-On in the Danish Educational Sector Per Thorboll Deputy director UNI-C.
VO. VOMS 1. Authentication2. Credentials 3. Authentication Client Resource.
Imagining a Community Source Student Services System Leo Fernig Richard Spencer SOA Workshop Vancouver March 24, 2006.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
New Developments in Access Management: Setting the Scene Alan Robiette JISC Development Group JISC-CNI Conference, June 2002.
February, TRANSCEND SHIRO-CAS INTEGRATION ANALYSIS.
Identity Management and Enterprise Single Sign-On (ESSO)
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Portal Services & Credentials at UT Austin CAMP Identity and Access Management Integration Workshop June 27, 2005.
1 Active Directory Service in Windows 2000 Li Yang SID: November 2000.
Rendering Syndicated Library Content in an Institutional Portal: Integrating MyLibrary into uPortal John Fereira: Cornell University Eric Lease Morgan:
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
WebISO, Single Sign-On & Authorization General Overview Shelley Henderson Project Manager, Grid Software USC Information Services Copyright.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
De Rigueur - Adding Process to Your Business Analytics Environment Diane Hatcher, SAS Institute Inc, Cary, NC Falko Schulz, SAS Institute Australia., Brisbane,
1 EDUCAUSE Mid-Atlantic Regional Conference Top Strategies for Working with Stakeholders: Synopses of Recommendations from the Identity Management Summit.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
THE CAMPUS IDENTITY SYSTEM Lucy Lynch, NSRC. Learning Objectives Discovering the key role campus networks play in trusted identities for R&E Authoritative.
Information Technology  © 2001 The Trustees of Boston College   Slide 1 Call to Action! Bernard W. Gleason JA-SIG uPortal Conference Vancouver, British.
Understand User Authentication LESSON 2.1A Security Fundamentals.
Building Business Transformation Capabilities Our perspective on the building blocks, structure and critical success factors to impact change Gillian.
Alain Bethuyne Web Security Architect BNPParibas Fortis
How to Use Social Media, Identity Management, and Your Campus Portal to Efficiently and Effectively Communicate with Students Sarah Alpert, Senior Project.
Introduction to The Rational IT Model
EGI Updates Check-in Matthew Viljoen – EGI Foundation
Identity and Access Management Challenges in uPortal
Identity Management and Authorization
SaaS Application Deep Dive
Welcome to the 20th Anniversary of the IUG
Umbrella authentication
Current Campus Issues – From My Horizon
Jumpstart Solution: Novell Active Information Portal
Identity Management and Authorization
Enterprise Single Sign-On
Solutions for federated services management EGI
ESA Single Sign On (SSO) and Federated Identity Management
PREPARED BY: RIDDHI PATEL (09CE085)
HIMSS National Conference New Orleans Convention Center
ATIS’ Service Oriented Networks (SON) Activity
Supporting Institutions Towards a Shibbolized Infrastructure
Portals, uPortal, and the Meteor Channel
Migrating to uPortal 2 at UBC
JAAS AuthN Tokens in uPortal and Beyond
Luminis Platform Workshop Creating a Personal User Experience
eIDAS-enabled Student Mobility
Presentation transcript:

uPortal Meets Campus-wide Login at UBC Paul Zablosky ITServices The University of British Columbia Slide 1

The Portal and the Institution Introducing a portal to an institution Fitting a portal to existing infrastructure Technical Organizational Functional Institutional Identities and Roles Slide 2

About UBC Departments, Services, Customers Individual service mandates Diverse identity repositories Diverse authentication mechanisms Slide 3

Institutional Services Institutional E-Business Spanning constituencies Individual-centred Portals Slide 4

The Problem Diverse identities No unifying service Slide 5

So what can a Portal do? Expose the problem A target for the solution Slide 6

Solution Components Identity repository Authentication service (CWL) Links between the two Slide 7

The Institution needs Central identity repository Institution-wide “ID’s” Central authentication service Central “Roles” repository Slide 8

The Portal framework Needs Access to: A mechanism for authentication of principals (logins) A repository of roles associated with each login An immutable key associated with each login name Slide 9

The Portal is a repository for: The user’s layout and channel set Profile information (customize) What roles enable access to each channel (authorize) Slide 10

The Channel Applications Need Access to: A mechanism for proxy authentication (SSO) Roles associated with the current login An immutable key for the current login A key for each channel instance Identity information (for personalization) Profile information (for customization) Ticket service Slide 11

The Framework Doesn’t Need The portal framework does not needs access to: The User’s name Identity information Slide 12

What is the Campus-wide Login? Institution-wide login names Authentication Connection to identity repositories Central roles repository Single signon Slide 13

Architecture uPortal CWL UBC Identity myUBC Layouts Profiles Channels CWL Login Names Roles UBC People Affiliations Job Functions Channel applications Slide 14 Identity HR Information Student Information

Limitations in the models We have users We have logins We have roles Slide 15:

Implementation with Uportal 1.6 Modified roles support Replaced keys Modified authentication to use external service Added channel-roles channel Added ticket support Slide 16

Problems Problems mainly with transition All users need to subscribe to CWL Parallel running (move from two old principals to one new principal) Call 3 different authentication services Channels still use old ID’s Slide 17

Ticket Support in the CWL In the Portal Framework In the channels Supports Single-Signon proxy authetication for channels services referenced by channels Slide 18

Why are we doing all this? Identities and Roles are fundamental Institution wide Authentication Authorization and privacy Slide 19

Lessons Learned Fitting uPortal to existing conventions Architecture: What’s in and what’s out Local decisions Theory doesn’t always have the scope of the real world It’s not hard to do, technically Slide 20

Conclusion Architectural design goal Maintain clean interfaces to embedded services so that they can be locally replaced with external services Slide 21

Visit us at my.ubc.ca Slide 22: Paul.Zablosky@ubc.ca