Introducing Access Management IAMUCLA Mini-Conference November 18, 2008
IAMUCLA “Simplified and Streamlined User Identity & Access Management”
IAMUCLA Access Management (Authorization) Authentication Enterprise User Identity Store
IAMUCLA Authentication Access Management (Authorization) UCLA Logon ID Standard Web SSO (Shibboleth) Groups and Roles Access Management (Authorization) Privilege Management Enterprise User Identity Store Enterprise User Identity Store
Authorization Re-cap <subject> can <perform action> on <resource> given <constraint>. Joe Bruin can edit pages on the IAMUCLA site. Students enrolled in Math 33A can view contents of the Math 33A Course Web Site.
“I manage access using roles “I manage access using roles. Just tell me what groups the logged in person is in.” Most applications want group membership data. Applications use group member data to make authorization decisions
“Groups based on PPS/SRS/other university data are great, except that I need to add this one exception…”
Grouper Internet2 developed group management software Open source Flexible group management capabilities Ongoing work to integrate with other I2 initiatives
Grouper in IAMUCLA PPS SRS Enterprise Directory Shibboleth Grouper 4 1 3 SRS Group Membership/Role Attribute Storage and Delivery 2 Grouper generates university groups/roles automatically using known data sources Administrators create custom groups Group data provisioned into Enterprise Directory Group data delivered to applications via Shibboleth Others Administrators University Data Sources Group Management
Demonstration
Grouper for Naga Gamers PPS Enterprise Directory Shibboleth Grouper 4 1 3 SRS Group Membership/Role Attribute Storage and Delivery 2 Grouper generates university groups/roles automatically using known data sources Administrators create custom groups Group data provisioned into Enterprise Directory Group data delivered to applications via Shibboleth Others Administrators University Data Sources Group Management
Using Grouper Data to Manage Access Group data delivered through Shibboleth attribute response Protect static content using Shibboleth SP Map attributes to groups in applications
https://spaces.ais.ucla.edu/iamucla
EVERYBODY PANIC!!! OMG! O NOES!