GatorAid: Identity Management at the University of Florida Mike Conlon Director of Data Infrastructure

Slides:



Advertisements
Similar presentations
Credentialing, Levels of Assurance and Risk: What’s Good Enough Dr. Michael Conlon Director of Data Infrastructure University of Florida.
Advertisements

Identity Management at the University of Florida Mike Conlon, Director of Data Infrastructure University of Florida, Gainesville, Florida Background Identity.
Planning: Project Readiness and Costs Mike Conlon Director of Data Infrastructure University of Florida Copyright Michael Conlon, This work is the.
Copyright Dave Steiner and Jeremy Rosenberg This work is the intellectual property of the authors. Permission is granted for this material to be.
Copyright Tom Parker, Ron DiNapoli, Andrea Beesing, Joy Veronneau This work is the intellectual property of the authors. Permission is granted for.
LDAP-Enabled Privacy at The University of Notre Dame EduCAUSE conference, October 2002 Brendan Bellina Office of Information Technologies University of.
On Beyond Z Building a Directory Service educause presentation #074 University of Colorado at Boulder Deborah Keyek-Franssen Marin Stanek Paula J. Vaughan.
Directories at the University of Florida Mike Conlon Director of Data Infrastructure University of Florida.
Copyright Dickinson College This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
Andrea Eastman-Mullins Information & Technology Coordinator University of North Carolina, Office of the President Teaching and Learning with Technology.
1 Extending Authenticated Online Services with "Friend Accounts" at Washington State University Brian Foley Technology Architect/Application Developer.
Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.
Copyright Jill M. Forrester This work is the intellectual property of the author. Permission is granted for this material to be shared for non- commercial,
February 2006 copyright Michael Welch, Blinn College This work is the intellectual property of the author. Permission is granted for this material to be.
UCB Enterprise Directory Services. Directory Services – Project History  Requirements defined  Project commission & goals articulated  Project teams.
June 1, 2001 Enterprise Directory Service at College Park David Henry Office of Information Technology University of Maryland College Park
Identity and Access Management IAM A Preview. 2 Goal To design and implement an identity and access management (IAM) middleware infrastructure that –
Directory Services Project University of Colorado at Boulder.
The Homegrown Single Sign On (SSO) Project at UM – St. Louis.
Identity Management: The Legacy and Real Solutions Project Overview.
Copyright Statement © Jason Rhode and Carol Scheidenhelm This work is the intellectual property of the authors. Permission is granted for this material.
Making the Pieces Fit Together Barbara Draude, Director, Academic and Instructional Technology Services Middle Tennessee State University Lisa Rogers,
Copyright Anthony K. Holden, This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
Turning Information Into Action: Enterprise Reporting at Columbia University Maria E. Mosca, Director Student Information Systems Columbia University in.
1 Outsourcing Student & Other Collaboration Services Wendy Woodward Director, Technology Support Services Copyright Wendy Woodward This work.
Putting the We in… We are Penn State! Copyright [Carol Findley, Lisa Dibert] [2003]. This work is the intellectual property of the authors. Permission.
CAMP Med Mapping HIPAA to the Middleware Layer Sandra Senti Biological Sciences Division University of Chicago C opyright Sandra Senti,
Identity Management – Why and How Experiences at CU-Boulder Copyright Linda Drake, Director of Development and Integration, University of Colorado, Boulder,
EDUCAUSE April 25, 2006Enforcing Compliance with Security Policies … Enforcing Compliance of Campus Security Policies Through a Secure Identity Management.
1 No More Paper, No More Stamps: Targeted myWSU Communications Lavon R. Frazier April 27, 2005 Copyright Lavon R. Frazier, This work is the intellectual.
Moving Your Paperwork Online University of California, Irvine presents PayQuest Copyright UC,Irvine This work is the.
NERCOMP Managing Campus Affiliates Managing Campus Affiliates Faculty? Student? Faculty? Student? Staff? Criss Laidlaw Director of Administrative.
UF Directory Training Project Leader: Warren Curry, Information Systems Project Directory Web Site:
Middleware Deployment Issues Jack Suess, CIO, UMBC
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 Georgia State University Case.
The UF Directory Project Project Leader: Warren Curry, Information Systems Project Project Web Site:
Office of Information Technology Balancing Technology and Privacy – the Directory Conundrum January 2007 Copyright Barbara Hope and Lori Kasamatsu 2007.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 Shibboleth Pilot Local Authentication.
EDUCAUSE Midwest Regional March 24, 2003 Copyright Ann West This work is the intellectual property of the author. Permission is granted for this.
Uniting Cultures, Technology & Applications A Case Study University of New Hampshire.
Welcome to CAMP: Charting Your Authentication Roadmap Mike Grady Senior Technology Architect and Strategist Campus Information Technologies and Educational.
GatorLink Password Management Policy March 31, 2004.
USERS Implementers Target Communities NMI Integration Testbed The NMI Integration Testbed NMI Participation Developed and managed by SURA Evaluate NMI.
U.S. Department of Agriculture eGovernment Program July 15, 2003 eAuthentication Initiative Pre-Implementation Status eGovernment Program.
PubCookie Strategy and Tactics Mike Conlon Director of Data Infrastructure University of Florida.
Erie 1 BOCES / WNYRIC eBOCES applications Visit us at:
Identity and Access Management Roadmap Presentations for Committee on Technology and Architecture March 21, 2012 Amy Day, MBA Director of GME IAM Committee.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 NMI R3 Enterprise Directory Components.
Copyright © 2003, The University of Texas at Austin. This work is the intellectual property of the author. Permission is granted for this material to be.
Digital Diversity: Multi- institutional Access to Distributed Course Resources Barry Ribbeck UT HSC - Houston.
A Word from the Sponsors NMI-EDIT comprises Internet2 and EDUCAUSE –NSF Middleware Initiative (NMI)-Enterprise and Desktop Integration Technologies Consortium.
Welcome to Base CAMP: Enterprise Directory Deployment Ken Klingenstein, Director, Internet2 Middleware Initiative Copyright Ken Klingenstein This.
Copyright Statement Copyright Robert J. Brentrup This work is the intellectual property of the author. Permission is granted for this material to.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Quickly Establishing A Workable IT Security Program EDUCAUSE Mid-Atlantic Regional Conference January 10-12, 2006 Copyright Robert E. Neale This.
NSF Middleware Initiative and Enterprise Middleware: What Can It Do for My Campus? Renee Woodten Frost Internet2/University of Michigan.
WebISO, Single Sign-On & Authorization General Overview Shelley Henderson Project Manager, Grid Software USC Information Services Copyright.
Bringing it All Together: Charting Your Roadmap CAMP: Charting Your Authentication Roadmap February 8, 2007 Paul Caskey Copyright Paul Caskey This.
NMI-EDIT and Rice University Federated Identity Management: Managing Access to Resources in Texas Barry Ribbeck Director System Architecture and Infrastructure.
NSF Middleware Initiative and Enterprise Middleware: What Can It Do for My Campus? Mark Luker, EDUCAUSE Copyright Mark Luker, This work is the intellectual.
Windows Active Directory – What is it? Definition - Active Directory is a centralized and standardized system that automates network management of user.
University of Southern California Identity and Access Management (IAM)
Julian Hooker Assistant Managing Director Educause Southwest
John O’Keefe Director of Academic Technology & Network Services
Copyright Notice Copyright Bob Bailey This work is the intellectual property of the author. Permission is granted for this material to be shared.
University of Southern California Identity and Access Management (IAM)
Identity Management at the University of Florida
Managing Enterprise Directories: Operational Issues
UF Directory Coordinator Training
Presentation transcript:

GatorAid: Identity Management at the University of Florida Mike Conlon Director of Data Infrastructure

Copyright Notice Copyright Mike Conlon This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.

NMI-EDIT Consortium Comprises Internet2, EDUCAUSE, and SURA  NSF Middleware Initiative (NMI)-Enterprise and Desktop Integration Technologies Consortium (EDIT) Funded by NSF Middleware Initiative  E-science and research Researches and develops inter-institutional Identity and Access Management tools  Shibboleth for example Guided by MACE – Middleware Architecture Committee for Education  Group of R&E IT architects from US and Europe

One Slide About UF 49,000 students in Gainesville Fl 15,000 distance, continuing and executive students $2.0 Billion annual budget, $475 million in research -- growing at 9% per year, Health Sciences – 58% of research 140 academic departments in 23 colleges Land grant – extension in all 67 counties The Gators, Lady Gators, Gatorade

One Slide About UF Technology 500 IT professionals across campus Very decentralized Estimated $90 million in annual IT spending Over 300 servers 30,000 devices on the open network AD, NDS, iPlanet, OpenLDAP, Kerberos Directory Project PeopleSoft implementation (Finance, HR, Warehouse, Portal)

Identity Management Identity management is authoritative association of people with identifiers such as ID numbers and ID cards and access credentials such as usernames/passwords. Identity management is fundamental for providing secure authentication and authorization services.

Old Process/ New Process Old process: System administrator gives out accounts on a local system. Varying degrees of local identity management, no referencing across systems New Process: Identity is established by trained coordinators and maintained centrally. Systems use authoritative sources for identity, credentials and authorization.

You need a Directory Authentication, Authorization, Directory identified as key problems to solve at UF in August 2000 Community effort to solve the directory problem at UF sources for contact information. Limited sharing. Information Systems, Academic Technology, Health Science Center, Registrar, Data Center involved from the beginning UF read, studied NMI documents – roadmap, early harvest, Metadirectory practices, identifier mappings

What we had to work with GatorLink – Kerberos-based authentication mechanism since Unsponsored campus LDAP and NDS. DB2-based registry of people information used by some administrative systems. Many feeds to the registry, few from the registry. Adhoc integration.

UF Directory Project Started an adhoc planning group August 2000 Ken Klingenstein visit April 2001 Parallel effort to replace SSN merged August 2001 Finished report September 2001 Began implementation October 2001 Deployed new directory January 23,

Directory Project Deliverables New Registry – 140 tables New LDAP schema (eduPerson, eduOrg) New IDs – UFID and UUID GatorLink tied to UFID 50,000 new Gator One cards 1,500 applications modified New self-service apps New directory coordinator apps New APIs for directory-enabling business processes 800 directory coordinators identified and trained

UF Directory – Architecture Three major interfaces One data store One set of APIs About 50 message queues Each app receives consistent data

Directory Coordinators Establish Identity Each new faculty or staff member is entered into the directory by their local directory coordinator. This creates a new directory entry with a new UFID Student UFIDs are created by directory processes initiated by the Registrar HR and Registrar update authoritative values for registry attributes

Goals for Authentication Services Tie authentication to identity – all system access should be attributable to a UFID Provide a single credential (GatorLink) environment, regardless of access technology Support enterprise system sign on, LAN sign on, web sign on with same credential and same support for identity attribution

Five Projects Web Initial Sign On – 2002/2003 Portal –2002/2003 Password Management – 2003/2004 UF Active Directory – 2004/2005 Account Management

Web Initial Sign On (WebISO) at UF UF developed a local WebISO solution in 1998 – GLAuth GLAuth provides a secure cookie-based Kerberos authenticated system GLAuth is simple to install on Apache web servers (Linux and Windows) Legacy SIS and admin applications use GLAuth providing single credential access to these systems In 2002, augmented GLAuth to support Windows, integrated portal, WebCT, Legacy Admin to use GLAuth. Subsequent grad school applications, athletic applications, career resource center, colleges and departments

Portal Implementation Implemented PeopleSoft/Oracle Enterprise Portal in 2002/2003 Identity changes in directory are synched into portal and into HR and Finance for SSO Portal provides GLAuth cookie for links to university services Portal provides authorization platform for enterprise systems

Authorization Concept Directory has “affiliations” for each person. Affiliations role up to eduPerson affiliations and to primary affiliation Affiliations imply authorizations Authorization is based on roles Some roles can be algorithmically determined by affiliations Additional roles are assigned by traditional access request processes

Entity, Role and Service

Role Management Roles are assigned algorithmically using processes accessing directory message queues Roles are also assigned following request based on university policy Department Security Coordinators use the portal Access Request System (ARS) Individuals can view their roles from the portal

My Roles Every portal user can access their role information using My Roles All roles are listed with descriptions

My Access History Every portal user can access their access history Suspicious access is referred to the university security team and potentially law enforcement

Password Management Password management policies are determined by user roles – each role has a related password policy Five password policies govern reset, use of hints, password age Each users’ GatorLink password management policy is the strongest policy required by the users’ roles All GatorLink accounts have strong passwords Password changing is done using portal screens Kerberos, AD, NDS are updated in real-time

UF Active Directory UFAD accounts are built from directory message queues Contact information in UFAD is populated from the directory UFAD accounts use GatorLink usernames and passwords OUs are populated based on the value of a “Network Managed By” attribute in the directory – directory coordinators assign the value Accounts are provisioned centrally, rights are managed locally

Authentication Architecture Authentication begins with identity Automated processes populate the portal, HR, FI Portal login produces cookie for WebISO Middleware updates additional authentication services Kerberos, AD, NDS supported

Current Status All major enterprise systems (WebCT, WebMail, SIS, PeopleSoft, Legacy) use GatorLink authentication attributable to UFID All major college/unit web sites use attributable authentication 25% of all desktops use attributable authentication (NDS and UFAD). By summer of 2006, over 50% of desktops will use attributable authentication (full Health Science Center implementation)

Current Project – Account Management Create a formal lifecycle and state chart for GatorLink computer accounts Increase the name space from 8 to 16 characters Consolidate/replace legacy apps for acct mgt into the portal Introduce web services – account state changes will be available to subscribing service providers Go live mid-September 2005

Future Work Directory/identity integration with VOIP services Directory/identity integration with building access services PeopleSoft/Oracle Campus Community will be implemented with go-live Summer 2006 Legacy systems maintaining authorization information will be reimplemented using roles Direct access to the directory via APIs will be replaced with messaging infrastructure

For More Information