SIMI: ISO Perspective Al ISO CSU Northridge
The Challenge Provide service for searching and browsing of information that is “fast” Secure access Authentication/authorization Secure the database Audit and compliance
Secure Access OpenLDAP offers several mechanisms to protect the security of the data it stores access control lists connection encryption password hashing
Secure Access Authentication Two categories of users of the directory infrastructure Authentication required Public Secure connection (SSL) Encryption Authorization Restrict access to certain attributes Limit applications access to what is required Public Access control lists (ACL)
Authentication required Mail Peoplesoft Portal Peoplefinder Self Service Tools Samba - File Sharing Wireless Webct
Portal Services Modem, VPN Wireless Servers & Desktops Instant Messaging Calendaring File Services uDrive (etc.) vDrive Course Scheduling Specialized Web Services VOIP List Serve Databases PeopleFinder Degree Planning IdM Web Utilities P O R T A L CSUN’s IdM Policy Business Processes Directory ID Reconciliation Web Services
Public Provides unauthenticated access to a subset of attributes in the directory User/application can retrieve a max of 20 records Accessible on campus - behind firewall Used by Mail clients
Public Provides unauthenticated access to a subset of attributes in the directory User/application can retrieve a max of 20 records Accessible on campus - behind firewall Used by LDAP directory search in mail Peoplefinder