Multi-Campus Middleware: Technical and Organizational Dimensions A. Michael Berman, Cal Poly Pomona Mark Crase, CSU Office of the Chancellor Kent McKinney,

Slides:



Advertisements
Similar presentations
Project Management Methodology for IT How much is too much? It depends! Copyright John Barden, David Allen, Doug Ryan This work is the intellectual.
Advertisements

1 The Challenges of Creating an Identity Management Infrastructure for the University of California David Walker Karl Heins Office of the President University.
Joint CASC/CCI Workshop Report Strategic and Tactical Recommendations EDUCAUSE Campus Cyberinfrastructure Working Group Coalition for Academic Scientific.
Lynn Ray ISO Towson University Strategic Planning for IT Security Copyright Lynn Ray, This work is the intellectual property rights of the author.
Andrea Eastman-Mullins Information & Technology Coordinator University of North Carolina, Office of the President Teaching and Learning with Technology.
Copyright Jill M. Forrester This work is the intellectual property of the author. Permission is granted for this material to be shared for non- commercial,
February 2006 copyright Michael Welch, Blinn College This work is the intellectual property of the author. Permission is granted for this material to be.
Serving the Research Mission: An Approach to Central IT’s Role Matthew Stock University at Buffalo.
Technical Review Group (TRG)Agenda 27/04/06 TRG Remit Membership Operation ICT Strategy ICT Roadmap.
An Identity Management Vision for California Education A. Michael Berman, Cal Poly Pomona Mark Crase, CSU Office of the Chancellor Copyright A. Michael.
Identity Management: Some Basics Mark Crase, California State University Office of the Chancellor CENIC - March 9, 2011.
SIMI: Secure Identity Management Infrastructure for the CSU A. Michael Berman, Cal Poly Pomona.
Peter Deutsch Director, I&IT Systems July 12, 2005
Identity and Access Management IAM. 2 Definition Identity and Access Management provide the following: – Mechanisms for identifying, creating, updating.
Identity Management: The Legacy and Real Solutions Project Overview.
UWM CIO Office A Collaborative Process for IT Training and Development Copyright UW-Milwaukee, This work is the intellectual property of the author.
INSTITUTE FOR DISTANCE AND DISTRIBUTED LEARNING Three Approaches to Distance Learning Support Services EDUCAUSE 2002 Copyright Bridget Moore and Mark Raby,
Copyright Statement © Jason Rhode and Carol Scheidenhelm This work is the intellectual property of the authors. Permission is granted for this material.
Steve Neiheisel Industry Consultant Creating a Technology Forum for the Whole Campus Presented by Executive Services of Jenzabar (c) Copyright 2006 Jenzabar,
Copyright Dong Chen, This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
3/20/20071 IT Strategy and Leadership in Higher Education: Two Case Studies Case 1: Roberts Wesleyan College. Presented by Pradeep (Peter) Saxena, CIO.
1 EDUCAUSE 2002 IT Support Community Training Model University of Colorado at Boulder.
Copyright Marilyn Drury, Darrell Fremont, Doreen Hayek, This work is the intellectual property of the authors. Permission is granted for this material.
Standardizing a Network Infrastructure: The technology was the easy part! Johanna Madjedi, Director – Communications and Computing Services, ITS, Cal Poly.
Security Issues on Campus: Government Initiatives Rodney J. Petersen University of Maryland Educause/Internet2 Security Task Force Copyright Rodney J.
1 Institutions as Allies in the Security Challenge Wayne Donald, Virginia Tech Cathy Hubbs, George Mason University Darlene Quackenbush, James Madison.
Middleware Business Case and Stakeholders: The why and who of enterprise. Mark Crase, Ed.D. Sr. Director, Technology Infrastructure Initiatives The California.
Copyright - L. Thanasides, 2002 Using the Right FACTS Can Be Informative: Florida’s Statewide Student Information System Linda Thanasides Marsha Stickel.
Intellectual Property Protocol and Assessment for Distance Learning Liz Johnson Project Manager Advanced Learning Technologies Board of Regents of the.
CAMP Med Mapping HIPAA to the Middleware Layer Sandra Senti Biological Sciences Division University of Chicago C opyright Sandra Senti,
1 Fighting Back With An Alliance For Secure Computing And Networking Wayne Donald, Virginia Tech Cathy Hubbs, George Mason University Darlene Quackenbush,
1 A Change Model for Building and Maintaining a Successful Campus DE Strategy A. Darryl Davis  January 28, 2003 This work is the intellectual property.
Next Generation Strategic Planning for Educational Technology and IT: A Study of Process and Engagement Deborah Keyek-Franssen and Marin Stanek IT Initiatives.
EDUCAUSE April 25, 2006Enforcing Compliance with Security Policies … Enforcing Compliance of Campus Security Policies Through a Secure Identity Management.
A Balanced Scorecard is a Process Not Numbers MID ATLANTIC EDUCAUSE 2005 Saint Michael’s College Bill Anderson – Chief Information Officer Billie Miles.
Common Management Systems in the California State University “An ERP to Remember” EDUCAUSE 2001 Indianapolis, IN.
Lynette Olson, Assessment & Effectiveness Director & Gary Langer, Associate Vice Chancellor, Office of the Chancellor, Minnesota State Colleges and Universities.
Herding CATS: the Community of Academic Technology Staff Lou Zweier, Director CSU Center for Distributed Learning The California State University NLII,
NERCOMP Managing Campus Affiliates Managing Campus Affiliates Faculty? Student? Faculty? Student? Staff? Criss Laidlaw Director of Administrative.
CougarNet Dennis Fouty, Ph.D. Associate Vice Chancellor, University of Houston System Associate Vice President, University of Houston Mary Dickerson, MCSE.
1/17/07 1SCC-SSM Supporting Academic Needs: A Strategic Customer Care Sustainable Support Model Educause Mid-Atlantic Regional Conference 2007 Paul Halpine.
Enterprise IT Decision Making
Managing Intellectual Property for Distance Learning Liz Johnson Project Manager Advanced Learning Technologies Board of Regents of the University System.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 Shibboleth Pilot Local Authentication.
Directory Services at UMass  Directory Services Overview  Some common definitions  What can a directory do or not do?  User Needs Assessment  What.
Value & Excitement University Technology Services Oakland University Information Technology Strategic Planning Theresa Rowe October 2004 Copyright Theresa.
16 September 2015 The Silver Ring: Inter-institutional Middleware Collaboration Michael Berman Mark Crase April 9, 2003 Michael Berman Mark Crase April.
Center for Planning and Information Technology T HE C ATHOLIC U NIVERSITY of A MERICA ERP Systems: Ongoing Support Challenges and Opportunities Copyright.
NERCOMP 2002 Networks, Town and Gown: Collaborating with the Community Pat Cronin & Bill Davis Bridgewater State College Bridgewater, Massachusetts Copyright.
DATAD WORKSHOP In collaboration With Kenyatta University Nairobi 11 – 12 July 2007 The Database of African Theses and Dissertations (DATAD) Pascal Hoba.
March 21, 2006 NERCOMP 2006 Worcester, Massachusetts 1 Copyright Sunny Donenfeld, This work is the intellectual property of the author. Permission.
Safeguarding Research Data Policy and Implementation Challenges Miguel Soldi February 24, 2006 THE UNIVERSITY OF TEXAS SYSTEM.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 NMI R3 Enterprise Directory Components.
Copyright [Dr. Michael Hoadley, Chat Chatterji, and John Henderson ] [2004]. This work is the intellectual property of the authors. Permission is granted.
Cdigix at Yale Chuck Powell Director, Academic Media & Technology, ITS Yale University September 15, 2004 Copyright Charles Powell.
National Information Communication Technologies Strategy Vasif Khalafov “National strategy” working group - Web -
What’s Happening at Internet2 Renee Woodten Frost Associate Director Middleware and Security 8 March 2005.
Welcome to Base CAMP: Enterprise Directory Deployment Ken Klingenstein, Director, Internet2 Middleware Initiative Copyright Ken Klingenstein This.
2007 Carnegie Mellon University 1 Copyright Kelley Anderson and Mary L. Pretz- Lawson, This work is the intellectual property of the authors. Permission.
Quickly Establishing A Workable IT Security Program EDUCAUSE Mid-Atlantic Regional Conference January 10-12, 2006 Copyright Robert E. Neale This.
Bringing it All Together: Charting Your Roadmap CAMP: Charting Your Authentication Roadmap February 8, 2007 Paul Caskey Copyright Paul Caskey This.
NSF Middleware Initiative and Enterprise Middleware: What Can It Do for My Campus? Mark Luker, EDUCAUSE Copyright Mark Luker, This work is the intellectual.
University of Southern California Identity and Access Management (IAM)
Tom Barton, Senior Director for Integration, University of Chicago
California State University CSUconnect Federation
John O’Keefe Director of Academic Technology & Network Services
Decentralization in a Centralized IT Environment
EDUCAUSE Southwest 2009 "Copyright Mario Berry and Shah Ardalan This work is the intellectual property of the author. Permission is granted for.
University of Southern California Identity and Access Management (IAM)
Presentation transcript:

Multi-Campus Middleware: Technical and Organizational Dimensions A. Michael Berman, Cal Poly Pomona Mark Crase, CSU Office of the Chancellor Kent McKinney, CSU Hayward Copyright A. Michael Berman, Mark Crase, and Kent McKinney, This work is the intellectual property of the authors. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the authors. To disseminate otherwise or to republish requires written permission from the authors

Overview of Presentation California State University: background, strategy, drivers A grass roots experiment: the Directories Working Group Developing an Institutional Response

First, some background… The California State University 23 Campuses 1 R2 Research 21 4-year Comprehensive California Maritime Academy 350,000 Students 80,000 Faculty and Staff

Integrated Technology Strategy In 1993, the CSU Presidents came together to ensure that each campus in the system would have the technology infrastructure required to support each institution’s academic and administrative programs. The result was the creation of the CSU Integrated Technology Strategy

Integrated Technology Strategy Outcomes-based strategy Built on Integrated Academic and Administrative Initiatives Supported by a Robust Infrastructure Access (Hardware, Software, Network) Training Support Services

Technology Prerequisites Outcomes Initiatives SupportTraining Access Network Hardware Software Initiatives / Projects Distributed Learn. & Teach. Multimedia Repository Library Resources Student Friendly Services Common. Mgt. Systems Streamline I/T Delivery Procurement Process Improvement One Card Access Infrastructure Initiative Centers for Inst. Tech. Develop. Optimal Personal Productivity Excellence in Learning and Teaching Quality of Student Experience Administrative Productivity and Quality Baseline Training & User Support Infrastructure   ITS FRAMEWORK FULL BASELINE CURRENT

Institutional Leadership Information Technology Advisory Committee Campus CIO’s Chancellor’s Office Staff Middleware Steering Committee CIO’s, Campus Technical Staff, CO flywheels Directories Working Group Campus Technical Staff

Drivers for a Multi-campus Approach to Middleware Financial While a one-size-fits-all approach may not work for all components, some economies of scale can be achieved. Political Being a State-subsidized institution, proper stewardship of public resources is always important, but it is especially important when budgets are tight.

Drivers for a Multi-campus Approach to Middleware Coordination Success even at the campus level will depend on a well coordinated approach. A Systemic effort will help reinforce the importance of coordination and cooperation. Help communicate the value of middleware and the benefits of the effort. Consistent with CSU Integrated IT Strategy

SupportTraining Network Hardware Software Access Infrastructure InitiativeBaseline Training & User Support Infrastructure Middleware Service Outcomes Initiative Applications The position of Middleware in the ITS Pyramid when viewed through the technology.

Drivers for a Multi-campus Approach to Middleware Maximize Value of Technology Investments Infrastructure Terminal Resources Project Common Management Systems PHAROS Library Project Help balance requirements for Strategic and Tactical planning Improve integration with other education institutions (e.g. EDUCAUSE, Internet2, etc.)

California State University Directories Working Group Technical Working Group charged by CSU system wide CIO’s to develop an Enterprise Directories strategy and test bed implementation

Group Dynamics Directories as the starting point for more comprehensive middleware effort Ad hoc effort to work collaboratively Volunteers/interested parties persons representing most campuses Smaller detailed architecture sub-group

Principles Collaborative effort among all CSU campuses Maintain appearance of unified directory architecture Adopt a system wide unique identifier Common view (eduPerson, etc.) Standard software (LDAP now, others later) Security at least as good as source data/applications/business processes

Key Recommendations Federated directory approach Common view incorporating eduPerson LDAP architecture Unique ID (unique vs. Linking) Internet2 involvement

Detailed Architecture Proposal Distributed directory model (campus directories, LDAP v3 referrals to all others) Domain component naming Adoption of eduPerson 1.0 (now 1.5) Extension to calstateEduPerson (affiliation, major, SecurityFlag, VOIP address) Provision for campusEduPerson attributes Global unique ID based on “uniqueness” algorithm Secure directory servers (SSL)

Test Bed Implementation Five campuses (SLO, Hayward, Northridge, Pomona, Fresno) Mixed directory software (iPlanet, OpenLDAP, Oracle) Various levels of compliance with system wide schema (mandatory-optional attributes) Various population subsets (student, staff, real/sample) Various client access methods (specialized search engines, Microsoft ‘address book’, Netscape ‘address book’, LDAP command line clients)

Some Results So Far Response times are long (local server capacity, client referrals) Client handling of referrals varies (some do – some don’t) Coordination of referral trees at multiple sites is difficult

Final Recommendations Central directory servers (redundant and diverse) Submit campus data to system wide directory registry service (like DoDHE CDS) Common view with extensions, unique ID, security, Minimum central attributes option Expanded central attributes option Will depend on projected system wide uses

Future of Group Larger scale central directory performance testing Automation of campus-to-central data feeds Design central registry reconciliation processes Lessons learned: need to commit resources, not just volunteer System wide direction: to be determined by Steering Committee

From Experiment to Institutional Response First Step: Middleware presented to the CSU Executive Council Executive Council is 23 Presidents + Chancellor 2/3 receive Middleware briefing in February Consensus: “We’re not sure what it is, but if this is what we need, let’s do it.”

“Citizen of the CSU” Scenarios Alice Chu is a junior biology major at Cal State Hayward, and a Citizen of the CSU. As a “traditional” student, most of Alice’s coursework is in classrooms at the Hayward campus, but last semester she was an intern at a biotechnology company in Anaheim. Using the 4Cnet, she was able to access all her usual Hayward resources, even though she was connected to her company’s intranet. Since she was in the area, she also registered to receive about lectures in biology at Cal Poly Pomona and Cal State Fullerton, and attended one in-person and another via video streaming etc…

Result: Middleware Steering Committee Formed Charged by CSU CIO, David Ernst CIO’s from multiple campus, CSU auditor Asked to “come up with a plan” for Middleware for CSU Formed in May 2002, report due in October 2002

Highlights of Draft Recommendations Organized into three phases January 2003 – June 2003 July 2003 – December 2003 January 2004 – December 2004

Phase One: Jan 2003 – June 2003 Establish CSU Middleware Policy Board, reporting to TSC of Presidents Create initial policies Establish CSU-wide LDAP definition < EduPerson Establish a single, state-wide LDAP directory service replicate external-facing portion of individual directories one-third of campuses providing data to this directory. Pilot Shibboleth authorization.

Phase One: Jan 2003 – June 2003 Register the CSU as a certificate authority Establish a model and whitepaper to define best practices for identity reconciliation. Prepare a “good practices” whitepaper on developing campus registry and directories recipe for campus development statewide workshop

Phase One: Jan 2003 – June 2003 Work with CalVIP to integrate of the directory structure into Video initiatives. Working group to evaluate business case for CSU-wide permanent identifier for individuals Get commitment from CMS Executive Committee to assure integration into CMS baseline (ERP Project)

Phase Two: July 2003 – December 2003 Complete external directories for all entities. Move Shibboleth from pilot into full production. Develop a plan to integrate campus-wide directories into CMS and CSU Mentor (Admissions) Develop a plan to integrate campus-wide directories into Pharos (Library system). Pilot secure messaging/digital signature system, possibly based on PKI-Lite specification CSU-wide identifier - consider initial development of technology and procedures for implementation

Phase Three: January 2004 – December 2004 Complete Integration with CMS and CSU Mentor Complete integration with Pharos Extend secure messaging/digital signatures to all campuses Assignment of permanent identifiers in full operation. Pilot extension of Middleware infrastructure to Community College and K12 community.

Reaction within CSU CIO’s – very supportive – “we need to do this” Initial response from Library, ERP initiative has been positive Challenge to find resources in tight budget environment