Presentation is loading. Please wait.

Presentation is loading. Please wait.

Enabling Cloud Services & Federated Authentication UPN & Email Infrastructure Changes Chris Pruess ITS AIS Directory & Authentication Services.

Similar presentations


Presentation on theme: "Enabling Cloud Services & Federated Authentication UPN & Email Infrastructure Changes Chris Pruess ITS AIS Directory & Authentication Services."— Presentation transcript:

1 Enabling Cloud Services & Federated Authentication UPN & Email Infrastructure Changes Chris Pruess ITS AIS Directory & Authentication Services

2 Strategic Plan Goal 3: Support evolving identity management and information security requirements. Strategy 3: Strengthen HawkID identity verification to meet evolving campus authentication and external federation service requirements. – Roadmap: Federated Authentication and Provisioning for Cloud Service Investigations and Deployments 5/10/2012 2

3 UPN Background What is the User Principal Name? – Internet-style login name for a user name@domain ( RFC 822 ) HawkID@ui ( HawkIDs in UI AD Forest ) – Enforces uniqueness of IDs across the forest – Historically supported multiple-domain model – Now sets scope for “active” HawkID searches 5/10/2012 3

4 Cloud Requirements 1.UPN must match domain name for federated services. – eduPersonPrincipalName (eppn) is the username attribute for use in the federation User IDs must be scoped to the institution – hawkid@uiowa.edu 2.UPN should match user’s email address. – hawkid@uiowa.edu 5/10/2012 4

5 1. UPN must match domain name for federated services Change the UPN suffix on the HawkID from “ui” to “uiowa.edu” – Domain Scope: Iowa domain is our federation domain “ui” UPN suffix is only in the Iowa domain – ID Scope: HawkIDs; no automatic change to Service IDs Change is mostly a back-office change 5/10/2012 5

6 UPN Change: Impact Identify Potential Local Impact Points – Domain/Workstation/OWA Login Style Iowa\hawkid (will continue to work) hawkid@ui (will break) Adopt Consistent Login: hawkid@uiowa.edu – Locally-developed application authentication Kerberos, NTLM V2, LDAP Authentication Shibboleth, HawkID Login Tools will manage the change 5/10/2012 6

7 2. UPN should match user’s email address Support mail delivery to hawkid@uiowa.edu – Common address format in higher education – Common experience with consumer services Users sign up & login with email address – Extend our mail routing with hawkid@uiowa.edu delivery addresses – Mail alias (firstname-lastname@uiowa.edu) will continue to be supported – Initially, multiple aliases will be delivered to same (single) mailbox – Still evaluating Exchange options 5/10/2012 7

8 Projected Timeline UPN Change – 6/9/2012 (Infrastructure Day) – Dependent on Tool and Application Updates Mail Routing Change – August 2012 – Dependent on Mail Routing Upgrade Project Replaces Ph with LDAP 5/10/2012 8

9 Communication Plan CITL AD Infrastructure Support Groups ITS Spotlight, Help Desk Communities – Application Developers – ITADmins – Webmasters Researchers 5/10/2012 9

10 In the Cloud Thinking 5/10/2012 10 What do you think?


Download ppt "Enabling Cloud Services & Federated Authentication UPN & Email Infrastructure Changes Chris Pruess ITS AIS Directory & Authentication Services."

Similar presentations


Ads by Google