June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University.

Slides:



Advertisements
Similar presentations
1. 2 August Recommendation 9.1 of the Strategic Information Technology Advisory Committee (SITAC) report initiated the effort to create an Administrative.
Advertisements

June 10-15, 2012 Growing Community; Growing Possibilities Benn Oshrin, The Oshrinium, LLC Keith Hazelton, UW-Madison, Internet2 CIFER Community Identity.
Presenter(s): Candace Soderston Matt Sargent Bill Yock Date:November 16, 2011 Time:2:30 to 3:30 pm Help Shape the Future of Open Source Identity and Access.
Copyright Dave Steiner and Jeremy Rosenberg This work is the intellectual property of the authors. Permission is granted for this material to be.
Interface Strategies and Methods.
Prepared by Dept. of Information Technology & Telecommunication, May 1, 2015 DoITT Identity Management Security, Provisioning, Authentication.
VoipNow Core Solution capabilities and business value.
Identity Management Choosing and Using Sun’s Identity Management Suite March 13 th, 2007 Kim Tracy Executive Director University Computing Services Northeastern.
Ellucian Mobile: Don’t text and drive, kids!
Graffiti Reporting A partnership of Local and State Government; My Local Services App enhancements.
CPR Overview 28-April Agenda Introduction Requirements Data Model Services Model Service Providers Implementation Contact Information.
What can PeopleSoft do for You Tools developed at CSU, San Marcos.
Peter Deutsch Director, I&IT Systems July 12, 2005
Page 1Prepared by Sapient for MITVersion 0.1 – August – September 2004 This document represents a snapshot of an evolving set of documents. For information.
Open Source, Community Developed Enterprise Resource Planning Software for Higher Education.
#CONVERGE2014 Session 1304 Managing Telecom Directories in a Distributed or Multi-Vendor Environment David Raanan Starfish Associates.
CIFER Community Identity Framework for Education and Research (CIFERproject.org) An agile, best-of-breed, community-governed, comprehensive IAM solution.
Aegis Identity Software, Inc. presents Trends in Identity and Access Management in Higher Education to US Federations June 20, 2012 Janet Yarbrough – Director.
ENTERPRISE DATA INTEGRATION APPLICATION ARCHITECTURE COMMITTEE OCTOBER 8, Year Strategic Initiatives.
OSIAM4HE Proposed org structure Authored by the strategy and organization team.
Technical Overview of Kuali Rice UC Davis, Information & Educational Technology January 2009.
CIFER Community Identity Framework for Education and Research (CIFERproject.org) An agile, best-of-breed, community-governed, comprehensive IAM solution.
Kuali Rice at Indiana University Rice Setup Options July 29-30, 2008 Eric Westfall.
Frameworks To get on the same page word wise To suggest some useful analytic approaches To identify opportunities for integration.
The rSmart Group Kuali Days Successful Financial System Implementation Indianapolis April 11,
Directory Services at UMass  Directory Services Overview  Some common definitions  What can a directory do or not do?  User Needs Assessment  What.
Open source administration software for education Kuali People Management for the Enterprise (KPME) Welcome! Introductions: Aaron Neal – Indiana University.
- 1 - Roadmap to Re-aligning the Customer Master with Oracle's TCA Northern California OAUG March 7, 2005.
UBC IT Integrated Reporting Governance Committee June 13 th, 2011.
EDUCAUSE – October 2011 Kuali Student Project Update.
Open source administration software for education software development simplified Kuali – IDM Requirements Summary Eric Westfall - Indiana University Matt.
University of Michigan MCommunity Project Liz Salley Product Manager, Michigan Administrative Information Services Luke Tracy
Prepared for IAC Scott Baily, Interim Director of ACNS August 13, 2008.
KUALI IDENTITY MANAGEMENT Provides services for Identity and Access Management in Kuali Integrated Reference Implementations User Interfaces An “integration.
1 Kuali Coeus at UC Irvine Katya Sadovsky
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University.
A Strategic Business Imperative Cypress Management Group Corporation Victor Brown Managing Partner 10/19/20151Managing Master Data © 2009 CMGC.
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
Social Identity Working Group Steve Carmody. Agenda Intro to Using Social Accounts Status and Recent News –Current UT Pilot –Current InCommon Pilot with.
Presenter(s): Candace Soderston Matt Sargent Bill Yock Date:November 16, 2011 Time:2:30 to 3:30 pm Help Shape the Future of Open Source Identity and Access.
Kuali Rice Evolving the Technology Framework for Kuali Applications Brian McGough (Indiana University) Aaron Godert (Cornell University) Warner Onstine.
Kuali Rice A basic overview…. Kuali Rice Mission First and foremost to provide a consistent development framework and common middleware layer for Kuali.
Evaluating Kuali Financials for Your Institution - JA- SIG Conference June 2007 Mike Zackrison, rSmart Bob Ricci, rSmart Tony Potts, rSmart
Identity and Access Management Roadmap Presentations for Committee on Technology and Architecture March 21, 2012 Amy Day, MBA Director of GME IAM Committee.
Enterprise Integration in Sakai 2.4 An overview of what’s new and (hopefully) improved.
June 10-15, 2012 Growing Community; Growing Possibilities Kevin Muller, Fordham University Bill Thompson, Unicon.
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University.
Imagining a Community Source Student Services System Leo Fernig Richard Spencer SOA Workshop Vancouver March 24, 2006.
CIFER (Community Identity Framework for Education and Research) Overview for Prospective Contributors ciferproject.org Bill Yock Director, Enterprise Information.
Lois Brooks Stanford University 25 January 2005 A Higher Education Initiative.
Keeping Up With Moore’s Law 1 Keeping Up With Moore’s Law: Course Management Panel Robert Cartolano Manager, Academic Technologies, Academic Information.
ISC-ASTT PennGroups Central Authorization System (Grouper) June 2009.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Portal Services & Credentials at UT Austin CAMP Identity and Access Management Integration Workshop June 27, 2005.
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UC Davis Eric Westfall, Indiana University.
Oracle SIS and Sakai Integration Linda Feng, Architect Oracle Academic Enterprise Initiative.
Introduction to Terra Dotta Applications Integration with Campus Data Systems for institutions beginning their software implementation.
UBC IT Integrated Reporting Working Committee October 26 th, 2011.
Quarterly Customer Meeting Office 365 License Activation and Office 365 Cloud Services Assessment Status April 2014.
Presenters: Hampton Sublett & Curtis Bray Date: November 15 th, 2011 Time: 2:30 ORGANIZING THE INTEGRATION OF MULTIPLE APPLICATIONS WITH A STAND-ALONE.
Presenters: Hampton Sublett & Curtis Bray Date: November 15 th, 2011 Time: 2:30 ORGANIZING THE INTEGRATION OF MULTIPLE APPLICATIONS WITH A STAND-ALONE.
NHID/mRegistry Workshop | 16 September |1 | Implementation of a National Health ID (NHID) Registry and Index Mark Landry, WHO
OpenRegistry MACE-Dir 5/18/09 1 OpenRegistry Initiative Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University May 2009.
OpenRegistry Jasig Dallas OpenRegistry Initiative Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University March 2009.
OpenRegistry LSM 10/7/09 1 OpenRegistry Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University July 2009.
OpenRegistry: What’s New Jasig San Diego 3/10 1 What’s New With OpenRegistry Scott Battaglia Benjamin Oshrin March 2010.
OpenRegistry Initiative
Identity and Access Management Program Update CIO Council Update
Health Ingenuity Exchange - HingX
Presentation transcript:

June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University

An agile, best-of-breed, community governed, comprehensive IAM solution for higher education 2012 Jasig Sakai Conference2

 Build upon existing open source IAM projects  Create a comprehensive, modular IAM stack  Implement open, standards-based architecture  Reduce ops costs (TCO) through improved integration, automation, QA  Focus on needs, challenges distinctive to HE  Avoid vendor lock-in  Do so by pooling community resources 2012 Jasig Sakai Conference3

4

Central repository of key information about entities belonging to an organization 2012 Jasig Sakai Conference5

6

 Consumer of data – SOR integration  Reconciler of data – ID match and reconciliation  Producer of data – Global unique ID  Organizer of data – standard representation of person profile data  Provider of data – integration with downstream systems/apps  Other key functions: ◦ Administration – merges, data integrity, reporting ◦ Identity lifecycle management 2012 Jasig Sakai Conference7

Why are we involved and what do we need? 2012 Jasig Sakai Conference8

 UC Berkeley and UCSF have merged IAM oversight and strategy  Both have IAM systems which need significant re-vamping and both need a person registry  Other UC schools also looking at IAM replacements  The UC system is moving to a common SOR for HR data (PeopleSoft in the cloud)  Great opportunity for exploring common person registry solutions 2012 Jasig Sakai Conference9

 Homegrown “sync code” handles ID match and basic provisioning  All integration from SORs is via nightly pull from EDW views  Person data stored in LDAP (currently Oracle DSEE), no “person registry” 2012 Jasig Sakai Conference10

2012 Jasig Sakai Conference11

 Replace sync code with something more sustainable in the long run – community development and support model  Opportunity to re-evaluate ID match data  Opportunity to introduce real-time integration with SORs (and hence downstream customers)  More integration options for downstream customers 2012 Jasig Sakai Conference12

 Homegrown, mainframe-based Individual Identifier System (IID) handles ID Match and Person data repo  Creates one global identifier for all Systems of Record upon account creation  Issues many regular batch feeds to downstream systems  Feeds Enterprise Directory Service (OpenDJ), which in turn feeds other downstream customers 2012 Jasig Sakai Conference13

2012 Jasig Sakai Conference14

 Mainframe retiring in about 3 years  Replace IID with something more sustainable in the long run – community development and support model  Opportunity to introduce real-time integration with SORs (and hence downstream customers)  More integration options for downstream customers 2012 Jasig Sakai Conference15

2012 Jasig Sakai Conference16

 Work with CIFER Registry workstream to develop registry solutions that can become part of community supported higher ed suite  Immediate future – decide on ID match solution and hopefully develop new ID match tools in partnership with Kuali  Near term – begin deploying a new Registry solution (jasig’s Open Registry or Penn State’s Central Person Registry)  Medium term – establish standard outbound integration options for the new registry 2012 Jasig Sakai Conference17

2012 Jasig Sakai Conference18

 Shared IAM Services ◦ Focus on identity functionality for the purpose of this discussion  Used by many Kuali projects ◦ but is general enough to be used outside of Kuali apps  Provides access to identity data through APIs  Database-backed reference implementation  Authoritative source for its consumers  An “integration platform” for IAM within Kuali 2012 Jasig Sakai Conference19

 There are a couple of predominant integration patterns for identity in KIM today ◦ Provisioning into the KIM database from SORs ◦ Integration with LDAP (or institution-specific identity stores) via KIM APIs  Furthermore, there are two architectural deployment models for KIM ◦ Bundled ◦ Standalone 2012 Jasig Sakai Conference20

2012 Jasig Sakai Conference21 Kuali Coeus. KIM Either provisioning into database from systems of record, or integration of KIM with directory or similar service LDA P Provisioning Database Provisioning

2012 Jasig Sakai Conference22 KIM Either provisioning into database from systems of record, or integration of KIM with directory or similar service LDA P Provisioning Database Provisioning Kuali Coeus Kuali OLE Some Application Some Other Application

 Kuali is continuing to build out HR and Student System functionality  These are traditionally Systems of Record for identity  ID Match is critical  Institutions can implement only the pieces of Kuali that they want ◦ This means applications like Kuali Student or KPME could be paired with things like PeopleSoft, Banner, Workday, SAP, Banner, etc Jasig Sakai Conference23

 We need to continue to evolve our architecture for identity and access management within Kuali  We have at least 10 major items on our project roadmap related to IAM  Working with others in various communities on a shared project like CIFER just makes sense  Identity registries and ID match are our initial area of focus because they are important when dealing with multiple identity sources 2012 Jasig Sakai Conference24

What are we talking about, what have we done, and what are we going to do? 2012 Jasig Sakai Conference25

 Objective of the Group ◦ Catalog requirements for identity registries ◦ Develop a plan to identify current gaps ◦ Evaluate available identity registry and ID match solutions ◦ Develop, document, and exercise standard APIs for interacting with identity registries  Involved Partners ◦ UC Berkeley, UCSF, Brown, U. Washington, Internet2, Indiana, Kuali, SFU, PSU, Open Registry, Rutgers, others  What are we looking at? ◦ A central, single authority Registry ◦ Identity Match functionality ◦ Working closely with the Provisioning side of CIFER 2012 Jasig Sakai Conference26

2012 Jasig Sakai Conference27

 Identity Registry Functional Model  Core Requirements Evaluation  ID Match ◦ Strawman design for ID match system ◦ Evaluation of OpenEMPI  Evaluations of three different Open Source Identity Registry solutions ◦ OpenRegistry ◦ Penn State’s Central Person Registry (CPR) ◦ Kuali Identity Management (KIM) 2012 Jasig Sakai Conference28

 For identity match ◦ Evaluated OpenEMPI and will decide w/in a month to use or explore other options (integrations, self- written)  For Registry ◦ Evaluated OpenRegistry and CPR ◦ Both fairly well-developed, team feels both are viable candidates  What about KIM? 2012 Jasig Sakai Conference29

 Next Steps ◦ Potential ID Match “task force” ◦ Continued evaluation of registry solutions ◦ Work on shared APIs from SOR’s into a registry ◦ APIs for downstream provisioning  Other Potential Goals ◦ Try and get OR out of incubation status ◦ Work with PSU to fully “open-source” CPR ◦ Increase active community involvement  Other Initiatives ◦ Kuali is doing an evaluation of mapping KIM APIs to CPR ◦ UC is doing architectural evaluations ◦ Both of these groups are eager to move things forward! 2012 Jasig Sakai Conference30

 Your Input ◦ We need your input on the integration points  SORs to Registry  Development of shared APIs  Your Experiences ◦ Have you tackled similar problems in the past? ◦ Have experience with implementation of an identity registry or ID match solution?  Your Help! ◦ If your campus has registry needs, consider getting involved by investing into this effort! 2012 Jasig Sakai Conference31

 Possible future IAM Online  Registries team wiki: ◦  Future Home Page (work-in-progress!): ◦  Send to if you are interested in finding out more info or getting involved in any of the 2012 Jasig Sakai Conference32

For more information contact: 2012 Jasig Sakai Conference33