Download presentation
Presentation is loading. Please wait.
1
Introducing Access Management
IAMUCLA Mini-Conference November 18, 2008
2
IAMUCLA “Simplified and Streamlined User Identity & Access Management”
3
IAMUCLA Access Management (Authorization) Authentication
Enterprise User Identity Store
4
IAMUCLA Authentication Access Management (Authorization)
UCLA Logon ID Standard Web SSO (Shibboleth) Groups and Roles Access Management (Authorization) Privilege Management Enterprise User Identity Store Enterprise User Identity Store
5
Authorization Re-cap <subject> can <perform action> on <resource> given <constraint>. Joe Bruin can edit pages on the IAMUCLA site. Students enrolled in Math 33A can view contents of the Math 33A Course Web Site.
6
“I manage access using roles
“I manage access using roles. Just tell me what groups the logged in person is in.” Most applications want group membership data. Applications use group member data to make authorization decisions
7
“Groups based on PPS/SRS/other university data are great, except that I need to add this one exception…”
8
Grouper Internet2 developed group management software Open source
Flexible group management capabilities Ongoing work to integrate with other I2 initiatives
9
Grouper in IAMUCLA PPS SRS Enterprise Directory Shibboleth Grouper
4 1 3 SRS Group Membership/Role Attribute Storage and Delivery 2 Grouper generates university groups/roles automatically using known data sources Administrators create custom groups Group data provisioned into Enterprise Directory Group data delivered to applications via Shibboleth Others Administrators University Data Sources Group Management
10
Demonstration
11
Grouper for Naga Gamers
PPS Enterprise Directory Shibboleth Grouper 4 1 3 SRS Group Membership/Role Attribute Storage and Delivery 2 Grouper generates university groups/roles automatically using known data sources Administrators create custom groups Group data provisioned into Enterprise Directory Group data delivered to applications via Shibboleth Others Administrators University Data Sources Group Management
12
Using Grouper Data to Manage Access
Group data delivered through Shibboleth attribute response Protect static content using Shibboleth SP Map attributes to groups in applications
13
https://spaces.ais.ucla.edu/iamucla
14
EVERYBODY PANIC!!! OMG! O NOES!
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.