June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University
An agile, best-of-breed, community governed, comprehensive IAM solution for higher education 2012 Jasig Sakai Conference2
Build upon existing open source IAM projects Create a comprehensive, modular IAM stack Implement open, standards-based architecture Reduce ops costs (TCO) through improved integration, automation, QA Focus on needs, challenges distinctive to HE Avoid vendor lock-in Do so by pooling community resources 2012 Jasig Sakai Conference3
4
TODO… 2012 Jasig Sakai Conference5
6
TODO… 2012 Jasig Sakai Conference7
Why are we involved and what do we need 2012 Jasig Sakai Conference8
UC Berkeley and UCSF have merged IAM oversight and strategy Both have IAM systems which need significant re-vamping and both need a person registry UCB currently uses LDAP as primary person data store UCSF has mainframe based person registry The UC system is moving to a common SOR for HR data Great opportunity for exploring common person registry solutions 2012 Jasig Sakai Conference9
10
2012 Jasig Sakai Conference11
2012 Jasig Sakai Conference12
2012 Jasig Sakai Conference13
Kuali Identity Management ◦ Shared identity and access management Used by many Kuali projects ◦ Finance, research, student, library, HR “Identity registry-like” functionality ◦ but wasn’t originally designed for this purpose Serves as an “integration platform” for IAM within Kuali This has worked well for Kuali for a long time…but things are changing Jasig Sakai Conference14
Kuali People Management for the Enterprise (KPME) Kuali Student (KS) These are traditionally Systems of Record for identity ID Match is critical for both of these systems TODO… 2012 Jasig Sakai Conference15
TODO… 2012 Jasig Sakai Conference16
What are we talking about, what have we done, and what are we going to do? 2012 Jasig Sakai Conference17
Objective of the Group ◦ Develop a plan to identify current gaps in identity registries ◦ Evaluate options for developing a single person registry ◦ Move forward to close the gaps by developing a registry Involved Partners ◦ UC Berkeley, UCSF, Brown, U. Washington, Internet2, Indiana, Kuali, SFU, PSU, Open Registry, Rutgers, others What are we looking at? ◦ A central, single authority Registry ◦ Identity Match functionality ◦ Working closely with the Provisioning side of CIFER 2012 Jasig Sakai Conference18
2012 Jasig Sakai Conference19
Identity Registry Functional Model Core Requirements Evaluation ID Match ◦ Strawman design for ID match system ◦ Evaluation of OpenEMPI Evaluations of three different Open Source Identity Registry solutions ◦ OpenRegistry ◦ Penn State’s Central Person Registry (CPR) ◦ Kuali Identity Management (KIM) 2012 Jasig Sakai Conference20
For identity match ◦ Evaluated OpenEMPI and will decide w/in a month to use or explore other options (integrations, self- written) For Registry ◦ Evaluated OpenRegistry and CPR ◦ Both fairly well-developed, team feels both are viable candidates Likes/Dislikes of each What about KIM? 2012 Jasig Sakai Conference21
Next Steps ◦ Potential ID Match “task force” ◦ Work on shared APIs from SOR’s into a registry ◦ Provisioning of the registry to downstream systems Other Potential Goals ◦ Try and get OR out of incubation status ◦ Work with PSU to full “open-source” CPR ◦ Get involvement from other, interested parties Other Initiatives ◦ Kuali is doing an evaluation of CPR mapping to KIM ◦ UC is doing architectural evaluations ◦ Both of these groups are eager to move things forward! 2012 Jasig Sakai Conference22
Your Input! ◦ We need your input on the integration points How to get particular SOR information into CPR or OR? Development of shared APIs Your Experiences ◦ If you’ve been or are going through the process, if available, what would you need to make this work Your Help! ◦ If your campus has registry needs, consider getting involved by investing into this effort! 2012 Jasig Sakai Conference23
Summary statement here 2012 Jasig Sakai Conference24
Possible future IAM Online Registries team wiki: ◦ Future Home Page (work-in-progress!): ◦ Jasig Sakai Conference25
For more information contact: 2012 Jasig Sakai Conference26