live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax:
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: B ANNER I NTEGRATIONS F AIRFIELD U NIVERSITY Michael Graham-Cornell Director, Computing & Network Services
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: A GENDA The user experience with CAS, BEIS, and Shibboleth CAS Overview BEIS Overview Shibboleth Overview What we had What we did What we have Benefits and Gotchas
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: U SER E XPERIENCE N UMBER 1 – MY.F AIRFIELD Staff requests my.Fairfield Active my.Fairfield Session? Active CAS Session? User logs into CAS No Yes User granted access CAS
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: U SER E XPERIENCE N UMBER 2 – B ANNER Staff requests Banner Forms or Self-Service Active Forms Session? Active SSOManager session? Active CAS Session? SSOManager: Lookup login ID or PIDM via UDCID User logs into CAS No Yes User granted access SSOManager UDC_Identifier
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: U SER E XPERIENCE N UMBER 3 – S TUDENT G MAIL Student accesses mail.student.fairfield.edu Active Gmail Session? Active Shibboleth Session? Active CAS Session? Gmail access granted User logs into CAS No Yes Shibboleth eduPersonPrincipalName
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: O VERVIEW OF CAS
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: O VERVIEW OF BEIS Provides Inbound Account Provisioning Outbound Account Provisioning Single Sign-On (only part we’re using today) Uses UDCIdentifier The UDCIdentifier is an unchanging, system-generated, 32- character, alphanumeric value. Like: 36BE6D6D18560C44E BA33B440 Banner tables map UDCID to PIDM and Oracle logins
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: B ANNER S INGLE S IGN - ON TO S ELF -S ERVICE
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: B ANNER S INGLE S IGN -O N TO F ORMS S ERVER
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: O VERVIEW OF S HIBBOLETH
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: W HAT W E H AD Banner (“Person” System of Record) – LOCAL NETWORK Sun Identity Manager (NetID and Password System of Record) – LOCAL NETWORK Sun Directory Server (LDAP) – LOCAL NETWORK Shibboleth Identity Provider (IdP) – LOCAL NETWORK Gmail Service Provider (SP) – IN CLOUD Library Database Provider (SP) – IN CLOUD
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: W HAT WE DID – A LL ON F AIRFIELD N ETWORK Install CAS in Test Install CAS Service Manager CASify Shibboleth Install BEIS, including SSOManager Populate Banner with UDCID’s (BEIS utility) Propagate UDCID’s to our LDAP Directory Install BEIS add-ons to CAS Configure CAS Service Manager to accept Banner services
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: W HAT WE NOW HAVE All of above, plus: Shibboleth now proxies to CAS CAS Authentication for all SSO applications, including: Banner (Forms, Self-Service, WorkFlow, BDMS), Gmail, myCampus, in-house applications, Blackboard (9.1 SP8 this summer), EZProxy (summer)
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: B ENEFITS CAS is a very secure and robust SSO environment CAS easily integrated into PHP and.NET applications (preferred for in-house authentication) We now support CAS and Shibboleth Service Providers – very flexible and easy to configure Only authorized service providers can authenticate Legacy applications can still authenticate through LDAP, but are rapidly being “CASified” Banner Forms, Self-Service, Workflow and BDMS use CAS authentication
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: C AVEATS /G OTCHAS Lots of moving parts require lots of testing Verify multiple logins in same browser session Verify timeouts Verify all browsers Time – took us about six months Ellucian documentation for reconfiguring CAS to support BEIS assumed no Service Manager Watch out for CAS version. Ellucian recommended CAS (also support and 3.3.1) Forms and Self-Service support multiple authentication methods simultaneously, but WorkFlow and BDMS do not Because our CAS server is local, and portal is in the cloud, we have been dealing with time-sync issues
live. learn. work. play Superior Ave E Suite 310 Cleveland Ohio Tel: Fax: