A Campus Perspective on Directory Services NMI Testbed Workshop April 8, 2003 Landy Manderson Lead Software/Network Specialist User Services, UAB Telecommunications.

Slides:



Advertisements
Similar presentations
UAB NMI Testbed Program: Integrated Directory Services  Grid Computing UAB Middleware Team.
Advertisements

FSU Directory Project The Issue of Identity Management Jeff Bauer Florida State University
From Chad to LDAP Twenty Years of Authorization, Authentication, and Directory Services at UAB Landy Manderson User Services UAB Telecommunications University.
Red Hat Linux Network. Red Hat Network Red Hat Network is the environment for system- level support and management of Red Hat Linux networks. Red Hat.
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
June 1, 2001 Enterprise Directory Service at College Park David Henry Office of Information Technology University of Maryland College Park
Middleware & Enterprise Services at College Park David Henry Office of Information Technology November 16, 2001.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Exchange server Mail system Four components Mail user agent (MUA) to read and compose mail Mail transport agent (MTA) route messages Delivery agent.
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
Content Customer Context Customization Community Virtual Mentor.
SBC/GOLD 2004 Peter Knott, Germany Section Information Sources for IEEE Volunteers Peter Knott Electronic Communications IEEE Germany Section.
SIMI: ISO Perspective Al ISO CSU Northridge
E-Business: Intra-Business E-Commerce
Account Management, The Next Generation Unified Directories at the Rochester Institute of Technology Dan Tobin Matt Campbell.
Darrel S. Huish Katherine J. Ranes Arizona State University Lessons Learned During the First Year of myASU, a Large Institution Portal Copyright Darrel.
Access e-Portal and Your . How to Access e-Portal for My Personal Information?
Data Center and Network Planning and Services Mark Redican IET CCFIT Update Feb 13, 2012.
Understanding Active Directory
IT Advisory Committee April 27, Agenda BlazerNet Portal project status report Terry Tatum Student System updateSheila Sanders Grants.gov updateKevin.
Information Technology Services Technical Support Services Summer 2009 Accomplishments Fall 2009 Current Projects.
Managing Client Access
Module 4 Managing Client Access. Module Overview Configuring the Client Access Server Role Configuring Client Access Services for Outlook Clients Configuring.
Introduction to Active Directory December 10th, pm Daniels 407.
Update to TIMGroup January Outline Introduction Where are we now? Where are we going? What can be done to prepare? What are the options?
BASIC NETWORK CONCEPTS (PART 6). Network Operating Systems NNow that you have a general idea of the network topologies, cable types, and network architectures,
Turkey IDA Info-Day PM Session, September 25, 2003 CIRCA 1 CIRCA : The IDA Collaborative Software Tool Grzegorz Ambroziewicz European Commission - DG Enterprise.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 Georgia State University Case.
Digital Identity Management Strategy, Policies and Architecture Kent Percival A presentation to the Information Services Committee.
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
F. Guilleux, O. Salaün - CRU Middleware activities in French Higher Education.
Welcome to My Tabor Groupwise & My Tabor (LMS) training Student Orientation Fall 2008.
Microsoft Windows 8.1 Enterprise: A brief overview of Microsoft Windows 8 Enhancements. Welcome!
WELCOME NEW FACULTY Information Services & Technology July 2012.
Directory Services at UMass  Directory Services Overview  Some common definitions  What can a directory do or not do?  User Needs Assessment  What.
Information Technology AT A GLANCE ― Faculty Need Help? IT HelpDesk—x8888 website—
University of Missouri-Rolla Computing and Information Services 1 Meg Brady Asst. Director, Client Services Presented to New Faculty Forum,
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
ICT Services for Postgraduate Students Information and Communications Technology July 2008.
Msix.ed.gov. 9. How do I get access to MSIX? School and MEP personnel can request an MSIX account using the "How Do I Get an Account?" link at the bottom.
CS480 Computer Science Seminar Introduction to Microsoft Solutions Framework (MSF)
Top Issues Facing Information Technology at UAB Sheila M. Sanders UAB Vice President Information Technology February 8, 2007.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Identity Management in the Environment of Mendel University in Brno Milan Šorm.
1 Windows 2008 Configuring Server Roles and Services.
UAB Windows 2000 Active Directory Project NMI Workshop 8 April 2003 Dave Green UAB Electrical & Computer Engineering Dept.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 NMI R3 Enterprise Directory Components.
FSU Metadirectory Project The Issue of Identity Management Executive Overview.
Middleware CAMP Day 2. Current Research Research that develops th e…
Operation and Maintenance of APEC Engineer Data Bank (1) Operation and Maintenance of APEC Engineer Data Bank (1) Dr. Hsieh, Shang-Hsien (Patrick) Professor.
Microsoft Azure Active Directory. AD Microsoft Azure Active Directory.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
IBM K-12 PROJECT Update. Project Startup Review of Networks (Chris/Karman) Review of Wireless (Ahlagie) Active Directory Details/Discussions (Chris/Karman)
Microsoft Virtual Academy Preparing for the Windows 8.1 MCSA Module 5: Managing Devices & Resource Access.
FROM MIT KERBEROS TO MICROSOFT ACTIVE DIRECTORY The Pennsylvania State University’s move from a lower case MIT Kerberos realm to a Standard Microsoft Active.
Copyright Statement Copyright Robert J. Brentrup This work is the intellectual property of the author. Permission is granted for this material to.
Be Microsoft’s first and best customer Enabling world-class and predictable customer, client, and partner experience Protecting Microsoft’s physical and.
Attribute Delivery - Level of Assurance Jack Suess, VP of IT
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
SSH. 2 SSH – Secure Shell SSH is a cryptographic protocol – Implemented in software originally for remote login applications – One most popular software.
Virtual Directory Services and Directory Synchronization May 13 th, 2008 Bill Claycomb Computer Systems Analyst Infrastructure Computing Systems Department.
Technology and You!.
Overview of IT at UAB IT Organization Services Provided
CollegeSource Security Application &
Course Content Oracle E-Business Fundamentals
Office of Technology Integration
Five Reasons to Use SharePoint 2013 Communities
Creating a University IT Service Portfolio
Module 8: Implementing Group Policy
Presentation transcript:

A Campus Perspective on Directory Services NMI Testbed Workshop April 8, 2003 Landy Manderson Lead Software/Network Specialist User Services, UAB Telecommunications University of Alabama at Birmingham

Today’s Talk History/Evolution of our campus directory How Middleware efforts helped us Directory Service overview Future plans Closing thoughts

“Stone Age” (ca ) “User Register” created to support ACF2 security system on mainframe Interfaced with employee and student records databases Same ID’s used for after joining BITNET and later Internet Campus printed directory assembled by yearly “census”

“Bronze Age” (ca ) UAB Electronic Phonebook goes online for web forwarding, printed directory Users set up their own aliases (accounts) LDAP configured as mirror, for address book use only Some apps (mostly internal) use EP for authentication

Dawn of our “Iron Age” (ca ) Original impetus for LDAP migration was to support PKI Chose to enhance mirroring of LDAP from qi rather than replacement First testing was with pre-NMI eduPerson schema – finally, some guidance! “LDAP Committee” gave us direction on useful attributes, continuums of association Active Directory enters the picture

“Iron Age” (ca now) Implemented recommendations of “LDAP committee” LDAP migrated to eduPerson schema BlazerIDs/passwords sync’d among different directories (qi, LDAP, AD, Novell), allowing consolidation Number of apps exploding Working with and contributing to NMI

Schema Guidance = Good Thing Existing UAB schema was arbitrary, terribly out-of-date Really too much flexibility in LDAP Standard schema lacking important attributes useful to Educational institutions Opportunity to bring over additional data to support new apps

Continuums of association EmployeesStudents Job applicantAdmissions applicant Job offer extendedAccepted for enrollment HiredEnrolled On leaveNot taking classes TerminatedDropped out RetiredGraduated

The Numbers 26,000+ employees (four different orgs) 56,000+ students (15,500 enrolled) 54,000+ alumni 115,000+ persons in directory 1,500 entities (schools, departments, services, offices, centers, etc.)

The Diagram qi “Official sources” Employees (HURS, HSF, VIVA, EFH) Students Organizational Hierarchy Course info (stu/instr) forwarding “User-input” Alias/BlazerID/password Personal info update ‘Unofficial’ entities Org listings (“bluepages”) VPN ResNet SMTP relay LDAP AD Admin apps Student portals NMI For people and entities alike! Wi-Fi PAM CEDS Libraries Printed Phonebook Computer labs DFS dirXML Desktop Exchange Call Center WebCT clients Official Sources

The Applications For everyone at UAB: addresses · free UAB and Web site (WWW) accounts · Lister Hill Library (LHL) Virtual Desktop · download of certain UAB site-licensed software · access to the UAB Virtual Private Network (VPN) For employees: · alerts from various online administrative applications (e.g., purchase order queue notifications) · update of departmental information in the UAB Electronic Phonebook · login access to some departmental networks and services (with more on the way) · to receive important information ed from your department, school and designated UAB support areas (some of this is already being done, with more applications being discussed) · inter- and intracampus videoconferencing access (under development) · numerous other online administrative and employee portal applications (e.g., Data Warehouse, STEPS) which are currently being deployed, tested, procured, or developed For students: · access to the ResNet residence hall network · some departmental computer labs (with more on the way) · WebCT online courses · DARS Degree Audit system (when it comes online) · class mailing lists, and to receive important information ed from your department, school, and designated UAB support areas · other student online portals which are currently in testing or under development For faculty/researchers, in addition to the employee services listed above: · WebCT online course shell management (tentatively for Fall semester) · automatically generated/managed class mailing lists · grant information/submission (under development) · online grade posting (under development) · DARS Degree Audit system (when it comes online)

What’s Next? Continue bringing new apps, resources on board CampusCards, BlazerID education New HR/Finance systems coming online NMI R2 eval just finished, R3 soon –Push for more continuum, student, entity attributes in eduPerson –Middleware roadmap, validation tools –Do some inter-institutional stuff! “LDAP Committee” still needs to fully address continuum, privacy granularity, workflow What about PKI?

Closing Thoughts Really helps to have a couple of decades of experience with identity management and resource security! Right place, right time At any given time, any given technology has a bleeding, leading and very long trailing edge –This is true for feeder systems, Internet protocols, server software, user interfaces –Middleware can help

More Closing Thoughts Great to finally have some guidelines for attribute schema and population But … more work needs to be done That said, technical considerations are just the tip of the iceberg: –Privacy –Ongoing management, education –Who owns the data? –Continuums of association –Who can vouch for X? –Beware the L-word when committees involved!

Links UAB Electronic Phonebook: ldap://ldap.uab.edu BlazerID Resources: Schema descriptions: