UWA Directory Services David Glance Strategic Projects.

Slides:



Advertisements
Similar presentations
Omni eControl: Unified management console for multiple applications
Advertisements

ADManager Plus Simplify Your Active Directory Management.
UTILIZING WITH ITA. offers an entire suite of benefits for you and your students. You can also set up s for the purpose.
Agenda 2 factor authentication Smart cards Virtual smart cards FIM CM
Sentry Isis. Temporary Card Kiosk The system consists of a PC based kiosk running a windows application and a web application. Both applications interact.
Introduction to Physics IT Support. To learn about IT Support available with the Department of Physics, and across the University. To find out a little.
A walk through the world of Help Desk. When you realize you need help with your computer, phone, or printer, and your supervisor can not help, please.
People Database project John Byrne. Project aims Improve current Computing Service resource management processes Provide a reference 'People Database'
FSU Directory Project The Issue of Identity Management Jeff Bauer Florida State University
Simple and Secure Approach to Discovery at the Desktop.
John R. Kasich, Governor Tracy J. Plouck, Director.
University of Bedfordshire Workplace Induction. Organising the workspace Items to remember:  Security (keys)  Login/Passwords  Arrange Workspace/ equipment.
UCB Enterprise Directory Services. Directory Services – Project History  Requirements defined  Project commission & goals articulated  Project teams.
Your personal files go into the Private folder. Files you wish to share with others go into the Public folder. Everyone on campus can see the files in.
Technology Update TSAG Meeting 3/13/03. Announcements: Disaster Recovery Test:[Bill]  (2/18-19) Networking Infrastructure: DNS, DHCP, Authentication.
UCB Enterprise Directory Services. Directory Services – Project History  Requirements defined  Project commission & goals articulated  Project teams.
21 June 2006Copyright 2006 University of Kent1 Delegation of Authority (DyVOSE project) David Chadwick University of Kent.
Wireless Guest Access Allows short-term visitors to have temporary access to the wireless network without going through the temporary affiliate process.
© 2014, Florida Department of Education. All Rights Reserved. © 2014, Florida Department of Education. All Rights Reserved.
Account Management, The Next Generation Unified Directories at the Rochester Institute of Technology Dan Tobin Matt Campbell.
© 2008 Cisco Systems, Inc. All rights reserved. Cisco Unity Connection 7.0 Directory Integration TOI Manoj Agrawal
Page 1 CITS Active Directory Implementation UMass Dartmouth.
Enterprise SharePoint Service (ESPS) 17 August 2011 A Combat Support Agency Defense Information Systems Agency.
Penn State University College Of Education Understanding College of Education Resources.
Sierra Systems itSMF Development Days Presentation March 4 th, 2014 Colin James Assyst Implementation Specialist.
Unified Student-Centric Authentication and Authorization Nathan Wilder Special Assistant - Technology Office of the CIO.
1 Secure Internet browsing and Support for staff in schools.
NAMS Account Activation Training. 2 What is NAMS? The NASA Account Management System is NASA’s centralized process for requesting and maintaining accounts.
1 Simon: What, How and Why Jon Finke Communication and Middleware Technology.
what is contacts? In-contacts is an online contacts database designed from the ground up to be compatible with modern business needs.
Directory Services at UMass  Directory Services Overview  Some common definitions  What can a directory do or not do?  User Needs Assessment  What.
© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Access Control Personal.
PostalOne! / FAST Data Exchange - Vision 02/15/05.
SSL, Single Sign On, and External Authentication Presented By Jeff Kelley April 12, 2005.
GatorLink Password Management Policy March 31, 2004.
Using AS 10g with EBS What are the Benefits of Integrating AS 10g with Oracle Applications?
TWSd - Security Workshop Part I of III T302 Tuesday, 4/20/2010 TWS Distributed & Mainframe User Education April 18-21, 2010  Carefree Resort  Carefree,
Building Secure, Flexible and Scalable Environments using LDAP - SANS Orlando Sacha Faust PricewaterhouseCoopers
Riva Managed Identity Integration for Active Directory and Novell ® GroupWise ® Aldo Zanoni CEO, Managing Director Omni Technology Solutions
FSUID & AD Integration Partnering with the College of Human Sciences Jeff Bauer, AIS
MobileMAN Internal meetingHelsinki, June 8 th 2004 NETikos activity in MobileMAN project Veronica Vanni NETikos S.p.A.
Office 365 Bob McCoy
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Using the Supplier Portal Updated September 12, 2011 Using the Supplier Portal.
VirtuaGrades A Web-Based Gradebook Application Don Tinsley CS 470 Project.
Campus Experience: Pubcookie University of Alabama at Birmingham Academic Computing Zach Garner.
Compliance Assist Refresher Instruction Guide Adding or Editing Student Learning Outcomes.
1 SCO MeInc. and EdgeClick – How does it work Martin Batz - SCO Senior System Engineer.
A very Quick Guide to Finding E-Books, Journal Articles & Other E-Resources Leanne Young University Library Services Updated February 2013.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Copyright © 2006, Infinite Campus, Inc. All rights reserved. User Security Administration.
May 12, 1999Common Solutions Group, DS Workshop1 Directory Design & Operations at Princeton University Michael R. Gettes Collaboration Services Group (CSG)
The overview How the open market works. Players and Bodies  The main players are –The component supplier  Document  Binary –The authorized supplier.
Expense Tracking System Developed by: Ardhita Maharindra Muskan Regmi Nir Gurung Sudeep Karki Tikaprem Gurung Date: December 05 th, 2008.
IS 4506 Windows NTFS and IIS Security Features.  Overview Windows NTFS Server security Internet Information Server security features Securing communication.
Getting Started at Walsall Learning Centre. General Information Key Facts Card Opening hours, contact details, loan information, fines, renewals, useful.
CERN IT Department CH-1211 Genève 23 Switzerland t Single Sign On, Identity and Access management at CERN Alex Lossent Emmanuel Ormancey,
Unified Address Book Security Implications. Unified Address Book Overview –What are we talking about –What is the Risk –What are we doing to minimize.
EZAccess User Guide. EZAccess is a web proxy server that allows authorized users to access IP-restricted electronic resources subscribed by UiTM library.
#SummitNow Alfresco Authentication and Synchronization Nov 2013 Mark Rogers.
Authentication Interact Cloud.
AIM/education directory (Ed dir)
Step 1 Login on UHCP Site
no unique identification
Managing Digital Identity
Welcome to FOCUS FOCUS website:
Web File Sharing.
Guidance for New IRBNet Users
Designing IIS Security (IIS – Internet Information Service)
Password Reset and Access Management
Presentation transcript:

UWA Directory Services David Glance Strategic Projects

Agenda Requirements Architecture Client Requirements Timeline

Requirements System provides user information for: Authorisation/Authentication Users Students Staff Groups UnitOfferings CourseOfferings Roles BusinessUnits Data comes from defined sources SRS/Callista HR Visitor Information (Library) UCS

Requirements (cont…) User accounts created Password management controlled centrally through Account Management System (AMS) Initial password generated

Requirements (cont…) Data passed to designated client systems SSL and/or IPSec Client needs to be authorised to receive data Permission to access data from data custodians: Student Services Library Campus Card UCS

Architecture (data import) SRS HR SRSDownload HRDownload Active Directory UserManager Contacts Visitors Campus Card VisitorDownload CCDownload Exported ldif Imported ldif MSM Q

Architecture (data export) Active Directory UserManager Exported ldif Imported ldif MSM Q Q Processor FNAS Q CSSE Q ARTS Q LDAP Client SOAP Client File Client Client Active Directory Synch Manager AMSLDAP Directory SOAP Server LDAP Directory NIS+ Scripts/Programs SOAP Client

Architecture (schema) AD.UWA.EDU.AU BusinessUnitsgroup uwaOrganisationalUnit Users Students Staff InactiveStudents InactiveStaff Teaching UnitOfferings CourseOfferingsgroup uwaCourseOffering group uwaUnitOffering inetOrgPerson uwaPerson Rolesgroup uwaRole

Architecture (AMS) Account Management System Prime requirement for web based interaction No PIN? May allow PIN as initial password Use student number or username as account name. User component Initial password, change password, Help desk Reset password, disable, lock account

Architecture (AMS) User Create initial password Provide details (Birth date, Student/Staff Number) Provide challenge question and answer Change password Supply the challenge/response Change details

Architecture (AMS) Helpdesk Search for users Reset password User provides answer to challenge Disable/Lock account

Client Systems Can choose: Ignore system altogether Just get files (ldif changes or unprocessed atrribute/value files) Elect to get static data but ignore password changes Use SOAP server (C# or Python) Use file changes LDAP update Setup Active Directory to synchronize off of central AD

Client Systems Critical Clients SIMS Validating using LDAP authentication UCS Obtaining user names and password information.

Client Systems Requirements Choose method of access Get permission for data being used Allocate a server for communication Use SSL or IPSec All local mechanisms for password changing needs to be disabled Update all user documentation, web pages, etc. for the new system

Timeframe Equipment purchase and provisioningMon 11/10/04 Test system for clientsMon 25/10/04 Production systemsMon 25/10/04 Help desk operationalMon 17/01/05 UCS operationalWed 1/12/04 Callista operationalWed 8/12/04* Callista/SRS changeoverFri 8/4/05 First Round Student OffersWed 19/01/05 Documentation for Client SystemsMon 7/02/05

Information directory services mailing list directory_services public project page directory_services