Security Middleware Update IS Development Staff Forum December 8, 2004.

Slides:



Advertisements
Similar presentations
Implementing Tableau Server in an Enterprise Environment
Advertisements

How to Set Up a System for Teaching Files, Conferences, and Clinical Trials Medical Imaging Resource Center.
College An insight Into the College VLE Graham Mason
CUMREC, 2004 Copyright: Ian Taylor, Rupert Berk, Heidi Berrysmith; This work is the intellectual property of the authors. Permission is granted for.
Campus Based Authentication & The Project Presented By: Tim Cameron National Council of Higher Education Loan Programs.
Network Redesign and Palette 2.0. The Mission of GCIS* Provide all of our users optimal access to GCC’s technology resources. *(GCC Information Services:
Emory University Case Study I2 Day Camp November 5, 2010 John Ellis & Elliot Kendall.
Prepared by Dept. of Information Technology & Telecommunication, October 24, 2005 Enterprise Directory Services and Identity Management.
John Langsford 13 September 2006 CI Implementation Project.
Beispielbild Shibboleth, a potential security framework for EDIT Lutz Suhrbier AG Netzbasierte Informationssysteme (
Network Redesign and Palette 2.0. The Mission of GCIS* Provide all of our users optimal access to GCC’s technology resources. *(GCC Information Services:
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
UCLA’s Shibboleth Plan Shibboleth is an integral part of UCLA’s Enterprise Directory & Identity Management Infrastructure (EDIMI) Project Integrate with.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Peter Deutsch Director, I&IT Systems July 12, 2005
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
Academic Services Interactive Media Managing the Web with Java JA-SIG Winter 2002 Robert Sherratt Academic Services, Interactive Media.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
To Authentication and Beyond An update on C&C’s authentication-related middleware services UW Computing Support Staff Meeting December 16, 2004
Effort in hours Duration Over Weeks Or Months Inception Launch Web Lifecycle Methodology Maintenance Phases Copyright Wonderlane Studios.
ASTRA Authorization Management at the University of Washington Rupert Berk Lead, Security Middleware CAMP, Denver, June 27, 2005.
The Access Management Puzzle: Putting the Pieces Together Identity and Access Management at the UW Ian Taylor Manager of Security Middleware University.
Authenticating REST/Mobile clients using LDAP and OERealm
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Administrative Information Systems Shibboleth: The Next Generation ISIS Technical Information Session for Developers Datta Mahabalagiri March
National Finance Center’s 2008 Customer Forum EmpowHR 9.0 Billy Dantagnan Teracore.
Brian Arkills Software Engineer, LDAP geek, AD bum, Senior Heckler, and Associate Troublemaking Officer State of Windows Services at the UW.
Shibboleth-intro-dec051 Shibboleth A Technical Overview Tom Scavo NCSA.
Financials – Phase II Kick-Off Meeting September 11, 2008 Brenda Bolander, State Comptroller Michael Grisser, Project Manager.
ARC312. Security Policy Governance Audit Reporting Analysis Data Quality Directory Logon Mobility Provisioning Development Access Control Authentication.
AAF Middleware update February Presented by Terry Smith Technical Manager and Heath Marks Manager.
Oracle Application Express 3.0 Joel R. Kallman Software Development Manager.
The University of Wisconsin University Directory Service UDS A repository of people information Has been in production for about a year. Serves White pages,
Maturation & Convergence in Authentication & Authorization Services in US Higher Education: Keith Hazelton, Sr. IT Architect, University.
Module 8 Configuring and Securing SharePoint Services and Service Applications.
Penn Groups PennGroups Central Authorization System June 2009.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Building Secure, Flexible and Scalable Environments using LDAP - SANS Orlando Sacha Faust PricewaterhouseCoopers
Mellon Year 1 Review Michael J. Halm Alex Valentine.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
Shibboleth: An Introduction
JISC Middleware Security Workshop 20/10/05© 2005 University of Kent.1 The PERMIS Authorisation Infrastructure David Chadwick
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
January 9, 2002 Internet2 WebISO Project RL "Bob" Morgan, University of Washington.
Information Technology Current Work in System Architecture January 2004 Tom Board Director, NUIT Information Systems Architecture.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
February, TRANSCEND SHIRO-CAS INTEGRATION ANALYSIS.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
System/SDWG Update Management Council Face-to-Face Flagstaff, AZ August 22-23, 2011 Sean Hardman.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Current Middleware Picture Tom Barton University of Chicago Tom Barton University of Chicago.
CERN IT Department CH-1211 Genève 23 Switzerland t Single Sign On, Identity and Access management at CERN Alex Lossent Emmanuel Ormancey,
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
© 2013 IBM Corporation Accelerating Product and Service Innovation Service Virtualization Testing in Managed Environments Michael Elder, IBM Senior Technical.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Services for Distributed e-Infrastructure Access Tiziana Ferrari on behalf.
International Planetary Data Alliance Registry Project Update September 16, 2011.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
October 2014 HYBRIS ARCHITECTURE & TECHNOLOGY 01 OVERVIEW.
Alain Bethuyne Web Security Architect BNPParibas Fortis
Architecture Review 10/11/2004
City-wide Active Directory Project Town Hall II
ESA Single Sign On (SSO) and Federated Identity Management
Open Source Web Initial Sign-On Packages
Shibboleth Deployment Overview
Office 365 Development July 2014.
Presentation transcript:

Security Middleware Update IS Development Staff Forum December 8, 2004

History, Purpose, Scope Formed July, 2003 by C&C Directors Consolidate & integrate related projects –ASTRA –Pubcookie –Person Registry –White Pages Authorization, Authentication, Directories Identity Management at UW (and beyond)

The Art of Identity Management Presenter: Nathan Dors Contact:

Identity Management? “Identity management is the set of business processes, and a supporting infrastructure, for the creation, maintenance, and use of digital identities.” - The Burton Group (market research firm specializing in enterprise IT infrastructure) How does this compare with, and fit into, our conception of middleware?

Basic functions of IdM ReflectData of interest from SoR JoinMatch identity across SoR CredentialNetID, passwd, SecurID Manage Affil/GroupsBasic/flat AuthZ info Manage PrivilegesStructured AuthZ info ProvisionFor apps w/ attitude DeliverGet AuthZ info to app AuthenticateCheck identity claim AuthorizeMake allow/deny decision LogTrack usage for audit Source: Keith Hazelton, Univ of Wisconsin

IdM functions & big picture Reflect Join Credential Deliver (AuthN) Provision AuthZ Mng Grps Mng Priv Log Source: Keith Hazelton, Univ of Wisconsin; Tom Barton, Univ of Chicago

Communities for delivery Source: Keith Hazelton, Univ of Wisconsin

Services to Communities What is the reach of our middleware componentry? Pubcookie UW.EDS.Person ASTRA Shibboleth

Person Registry v2.0 for “Nantucket” Presenter: Anne Hopkins Contact:

Nantucket = Person Registry + EDS Person Registry (Shuksan) Windows Server App COM/.NET UW.Eds.Person EDS LDAP QUERY EDS PERSON QUERY Event Queue Manager PUBLISH PERSON DATA REALTIME Person Registry Backend Enterprise Directory Service IMPORT / UPDATE DATA DATA SOURCES QUEUE UPDATES FOR EDS Mango Data Dump (LDIF) BULK LOAD PERSON DATA

Nantucket Status In Beta Now: –UW.EDS.Person –EDS Person Data infrequently refreshed Pre-Production, end of Jan ‘05 –Nightly refresh of EDS Person Data Production release, Spring ‘05 –Real-time updates of EDS Person Data Questions to:

Enterprise Directory Services Presenter: Brad Greer Contact:

The Big Picture

What is EDS? The Enterprise Directory Service (EDS) provides for the publishing and retrieval of data items that are deemed to be of 'enterprise' interest. EDS directories are designed to be secure, scalable, based on standard protocols (LDAP), have no scheduled downtime, and able to accept real-time updates from multiple data sources.

What Is EDS- Part II EDS is not an application. EDS is a collection of data (directories), documentation, middleware - and a team of people to assist Developers in writing their applications. EDS also provides documentation and design help for C&C teams to Publish data into EDS directories.

Status? There are 4 Projects/Directories in-progress which include: –People (PersonReg) Plan to have nightly updates in production by end of January. Real-time updates will be implemented at future date. –Whitepages (staffdir, UWDir, staff/faculty dir) Production Server switchover to OpenLDAP planned for 12/22/04 –Groups (mod_uwa) New server hw ordered, Groups project working on design for migration to OpenLDAP. Servers to all use OpenLDAP (RH Linux) Dev, Eval, Production servers setup.

Status part II ISDev Certificate for directory access has been deployed and updated to all IS Dev workstations via nebula. UW.EDS.Person middleware component in beta test until EDS servers go into production (static data) EDS public web site under construction: www/computing/eds

EDS Web Site Organization EDS Directories Overview – there are now 4 directories! App Developer Info (LDAP+Middleware) –UW.EDS.Person - Design Doc/API/Examples –WhatamI V1 docs linked –Mod_uwa docs linked Data Publisher Info (TBD) Software –UW.EDS.Person middleware (people) –Whatami – link to info (people) –Mod_uwa - apache module (groups) –UWDir - VB application (whitepages) –Staffdir - perl script (whitepages)

Native LDAP or Middleware? Either can be used to access EDS directories Native LDAP requires more in-dept understanding of directory schema, authentication (certificates), LDAP protocol. Support for native LDAP will be less comprehensive than with middleware. UW.EDS.Person middleware provides object pooling, simple programming model, logging, and transparent server failover.

UW.EDS.Person Object What data is exposed in UW.EDS.Person 2.0? · UWRegID · UWPriorRegID · UWNetID · UWPriorNetID · UWEmployeeID · UWDevelopmentID · UWStudentSystemKey · UWStudentID · UWPersonRegisteredName · DisplayName · UWTest More details and usage examples on Web Site.

ASTRA Authorization Service Presenter: Rupert Berk Contact:

ASTRA: Usage Since Launch

ASTRA: Clients in Production SAGE Ariba System Administration E-Procurement Online Work Leave System Affirmative Action Department Tools for Time Schedule FS-Works Employee Self-Service

ASTRA: Recent Progress (2004) Technical –Microsoft.NET API –Web Service API Non-C&C or non-Windows clients –Automated PI import from FIN for FDI (eval) –Improved developer documentation Business –Door-to-door identification of departmental Delegators

ASTRA: Clients in Development Financial Desktop Space Inventory Management System Online Accident Reporting System Year End Tax Form VEBA PUC Maintenance Application Vendor Payment System

ASTRA: Current Work Technical –New API to allow apps to update span- of-control data –New monitoring tools –New configuration tools –New reconciliation mechanisms –New web interface Richer, more effective inquiries Integrated search and edit Context-sensitive help Business –More strategic identification of departmental Delegators

ASTRA: Clients in Discussion MyGradProgram Online Payroll Update System UW Project Tracker Cognos Tools (Data Warehouse) Keynes Applications (PAS, FIN, etc.)

ASTRA: Future plans Technical –More granular access control (multiple spans-of-control) –Separate development paths –Convert UI completely to.NET –Create administrative tools for developers –Use high-availability, high speed data store: EDS

ASTRA: People ASTRA Team –Ian Taylor, Manager –Rupert Berk, Project Manager –Heidi Berrysmith, Client Support, Business Analyst –Steve Suh, Developer –Ann Testroet, Developer –Aram Pierce, Developer ASTRA Advisory Group ASTRA USER Group

Pubcookie & Shibboleth Update Presenter: Nathan Dors Contact:

Pubcookie New functionality –POST-based cross-dns-domain messaging –Custom login messages –Keyserver supports wildcard certs –Keyserver supports Subject Alt Names Release info –3.2.0-beta1 available now (Unix/Apache only) –Running on production-test weblogin

Custom login messages Example: ESS login

Et tu, Pubcookie 3.1.1? The “Back to the Future” version –Some use on campus and UWMITS –Has showstoppers for ITI-AP deployment –Hence, not available on IS systems … sorry folks. Functionality of interest –“Variable” session reauthentication; e.g., “if user authenticated within N minutes, don’t re-prompt for password”

Shibboleth An architecture, project, and software for standards-based, federated login UW is a Shibboleth “Identity Provider” (IdP) –Running Shibboleth IdP 1.2 –User authentication by Pubcookie/weblogin –User attributes from ancestral EDS Group directory –Working with initial Server Providers –Participating in InCommon (R&E) federation; “authenticate locally, act federally”