Jill Gemmill 2004 H.350 (ITU-T Recommendation H.350 Directory Services Architecture for Multimedia) What and Why? Egon Verharen, SURFnet Jill Gemmill,

Slides:



Advertisements
Similar presentations
Unified Communications Bill Palmer ADNET Technologies, Inc.
Advertisements

SIP, Presence and Instant Messaging
SIP and Instant Messaging. SIP Summit SIP and Instant Messaging What Does Presence Have to Do With SIP? How to Deliver.
VON Europe /19/00 SIP and the Future of VON Protocols SIP and the Future of VON Protocols: Presence and IM Jonathan Rosenberg.
Fall VoN 2000 SIP for IP Communications Jonathan Rosenberg Chief Scientist.
Vidmid-vc: Middleware for Video Conferencing Services
SURA/ViDe 4th Annual Workshop SIP, Security & Threat Models Dr. Samir Chatterjee School of Information Science Claremont Graduate University Claremont,
SURA / ViDe 5 th Annual Digital Video Workshop GCATT Atlanta, GA March 24-26, 2003.
Secure Videoconferencing Jill Gemmill, UAB. Room for Improvement… Videoconferencing applications today No resource discovery – need to already know address.
CGUsipClientv1.1: Architecture and Demonstration Tarun Abhichandani Research Associate Network Convergence Lab Claremont Graduate University Claremont,
19 July 2005UAB-IBM Life Sciences Mtg, Hawthorne Center UAB IT Academic Computing David L Shealy, Director Jill Gemmill, Asst. Director John-Paul Robinson,
The Internet2 NET+ Services Program Jerry Grochow Interim Vice President CSG January, 2012.
Vodacom Microsoft Hosted Lync
A Presentation on H.323 Deepak Bote. , IM, blog…
Real Time Communications Protocols and Applications Tyler Johnson Acting Director Telecommunications R&D.
IP Communications Services Redefining Communications Teresa Hastings Director WorldCom SIP Services Conference – April 18-20, 2001.
Prepared by Dept. of Information Technology & Telecommunication, May 1, 2015 DoITT Identity Management Security, Provisioning, Authentication.
ECS and LDAP Karen Krivaa Product Marketing Manager.
IBM Software Group ® Accessing Domino via Outlook iNotes Access for Microsoft Outlook - Notes Domino 5.5 – Domino Access for MS Outlook - Notes Domino.
CGU SIP VC Client: Design, Architecture & Demo Dr. Samir Chatterjee Network Convergence Laboratory School of Information Science Claremont Graduate University.
K. Stoeckigt, E. Verharen, Secure real-time audio/video communication – H.350,
Charles James Director Microsoft Alliance EMEA Polycom Microsoft UC Innovation Partner of the Year.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
SIP vs H323 Over Wireless networks Presented by Srikar Reddy Yeruva Instructor Chin Chin Chang.
Unified. Simplified. Unified Communications Launch 2007.
A centralized system.  Active Directory is Microsoft's trademarked directory service, an integral part of the Windows architecture. Like other directory.
Copyright © 2002 ACNielsen a VNU company Key Features and Benefits of the 3CX PBX for Windows Server.
#CONVERGE2014 Session 1304 Managing Telecom Directories in a Distributed or Multi-Vendor Environment David Raanan Starfish Associates.
Hosted Exchange The purpose of this Startup Guide is to familiarize you with ExchangeDefender's Exchange and SharePoint Hosting. ExchangeDefender.
OU Passwords What they all mean. What is a password Webster’s Online Dictionary describes a password as “a sequence of characters required for access.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
H.350 Case Study: University of Alabama at Birmingham Jason L. W. Lynn IT Academic Computing University of Alabama at Birmingham.
Larry Amiot Northwestern University Internet2 Commons Site Coordinator Training September 27, 2004 Austin, Texas Introduction to.
Simplify and Strengthen Security with Oracle Application Server Allan L Haensgen Senior Principal Instructor Oracle Corporation Session id:
Vidmid VC working group: Scenarios & workplan Egon Verharen, SURFnet.
USERS Implementers Target Communities NMI Integration Testbed The NMI Integration Testbed NMI Participation Developed and managed by SURA Evaluate NMI.
Module 11: Implementing ISA Server 2004 Enterprise Edition.
Building Secure, Flexible and Scalable Environments using LDAP - SANS Orlando Sacha Faust PricewaterhouseCoopers
ViDeNet and the Global Dialing Scheme Tim Poe University of North Carolina Internet2 Commons Site Coordinator Training December 3, 2003 National University.
Appendix A UM in Microsoft® Exchange Server 2010.
ViDeNet and the Global Dialing Scheme Larry Amiot Northwestern University Internet2 Commons Site Coordinator Training March 23,
ViDeNet and the Global Dialing Scheme Larry Amiot Northwestern University Internet2 Commons Site Coordinator Training September.
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
Implementing LDAP Client/Server System for Directory Service By Maochun Sun Project Advisor: Dr. Chung-E Wang Department of Computer Science California.
Introduction to SIP Larry Amiot Northwestern University Internet2 Commons Site Coordinator Training March 22, 2004 Indianapolis,
Overview of H.350 Directory Services For Multimedia Conferencing Larry Amiot Northwestern University Internet2 Commons Site Coordinator.
Requirement for Enterprise Directory Services A Customer Influenced Perspective TOG DCE Program Group ® Brian Breton Gradient Technologies, Inc.
Copyright © 2003 Open Mobile Alliance Ltd. All Rights Reserved. Open Mobile Alliance Presence Enabled Messaging Specifications Presence, Mobile Instant.
LDAP (Lightweight Directory Access Protocol ) Speaker: Chang-Yu Wu Adviser: Quincy Wu Date:2007/08/22.
5/7/2002 Vidmid-vc: Middleware for Video Conferencing Services Egon Verharen, SURFnet Vidmid-vc chair Middleware Vidmid VC History, Scope, Status, Authentication.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
INTERNET. Objectives Explain the origin of the Internet and describe how the Internet works. Explain the difference between the World Wide Web and the.
Mario D’Silva National Technology Specialists Unified Communications UNC307.
The HEP White Pages Project Ray Jackson CERN / IT - Internet Services Group 23rd April HEPiX/HEPNT Conference, LAL-Orsay, France.
4 October 2001 Tuning in to H.323 / LDAP security What this presentation is about - RADvision ECS registration control via LDAP - information and configs.
Jill Gemmill 2004 NMI Component: commObject ITU-T H.350 Directory Services for Multimedia Jill Gemmill University of Alabama at Birmingham
5/7/2002 Vidmid-vc: Middleware for Video Conferencing Services Egon Verharen, SURFnet Vidmid-vc chair.
H.350 Deployment Case Studies IETF Leveraging Middleware for Unified Campus Services: ITU-T H.350 and IETF RFC 3944 Jason Lynn (UAB) Frank Reinemer (Danet)
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Larry Amiot Northwestern University Internet2 Commons Site Coordinator Training September 27, 2004 Austin, Texas Overview of H.350.
Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, H.350: Everything OpenSource and solving the H.323 problem.
S Postgraduate Course in Radio Communications. Application Layer Mobility in WLAN Antti Keurulainen,
Overview of H.350 Directory Services For Multimedia Conferencing Tim Poe University of North Carolina Internet2 Commons Site Coordinator Training December.
Vidmid Session Overview
SIX MONTHS INDUSTRIAL TRAINING REPORT
Principles of Network Applications
Architecture Competency Group
Egon Verharen, SURFnet Vidmid-vc chair
Tyler Technologies presents: What you need to know about upcoming changes to your New World ERP technical environment in Scott Alan Miller MCP,
Presentation transcript:

Jill Gemmill 2004 H.350 (ITU-T Recommendation H.350 Directory Services Architecture for Multimedia) What and Why? Egon Verharen, SURFnet Jill Gemmill, University of Alabama at Birmingham

Jill Gemmill

Jill Gemmill CH National Gatekeeper (0041) CY National Gatekeeper (00357) CZ National Gatekeeper (00420) DE National Gatekeeper (0049) DK National Gatekeeper (0045) ES National Gatekeeper (0034) GR National Gatekeeper (0030) HR National Gatekeeper (00385) HU National Gatekeeper (0036) IT National Gatekeeper (0039) Ireland National Gatekeeper (00353) LT National Gatekeeper (00370) NL National Gatekeeper (0031) NO National Gatekeeper (0047) PL National Gatekeeper (0048) PT National Gatekeeper (00351) RU National Gatekeeper (007) SE National Gatekeeper (0046) SI National Gatekeeper (00386) UK National Gatekeeper (0044)

Jill Gemmill The Hardest and Most Expensive Part of Video / VoIP Managing Users and Workflow becomes the biggest issue once deployment scales up. –Requesting gatekeeper/proxy server entry –Requesting white pages listing for dialing info –How to do reliable billing –How to implement classes of service –Getting configuration information right in endpoints

Jill Gemmill LDAP Lightweight Directory Access Protocol A protocol describes messages used to access certain types of data LDAP provides a data model (schema) that standardizes data naming and organization for global unique naming Derived from OSI X.500 LDAP V3 (IETF RFC 3377) includes important security enhancements (SSL…)IETF RFC 3377

Jill Gemmill Origins Of H.350 ViDe and Internet2 exploring ‘video and voice over IP to every person on Earth.’ ViDeNet testbed providing ‘video and voice Internet’ for several hundred universities and research networks worldwide ( ViDeNet scalability issues –Interoperability –Call signaling –Security –Network Management Operational need for directory-enabled video/voice led to Video Middleware working group Architecture proposed to ITU-T, accepted and ratified as H.350 in August 2003

Jill Gemmill H.350 Design Goals Associate endpoints with people Enable online searchable "white pages" Store all data in central directory (not call server); draw from authoritative source & avoid duplication Support global white pages “portals” Multiple endpoints/user; multiple protocols/endpoint Provide or auto-load per-user configuration Extensible “Lightweight” impact on enterprise directory

Jill Gemmill Technology Silos Redundant Processes and Confusion

Jill Gemmill What Is H.350 ? H.350 is –An LDAP schema –Standardized way to store information –Simple, basic elements are defined –Extensible – can include proprietary elements –Multi - protocol H.350 is not –A protocol –Just for H series protocols

Jill Gemmill The Enterprise Directory Central stores of information about people associated with an institution Authoritative (eg: Human Resources, Registrar; Telecommunications) ONE consolidated list – duplicate identities resolved Benefits: –Correct and current –Single location to disable account –Single location to reset password Video/VoIP manager – reinvent this wheel? Enterprise Directory

Jill Gemmill What Operational Needs? Universities are building central, authoritative user directories – Use this identity management system, don’t require vendor’s (often proprietary) directory Standardize storage of protocol-specific data to ease updates and migrations; one central data store for multiple protocols Leverage identity management for reliable USER (not device) authentication

Jill Gemmill Directory-Enabled Video / VoIP Enterprise Directory H.350 Directory SIP IP-PBX H.323 Video Call Server Unified Messaging White Pages Workflow Management Enterprise Tools HR, , Billing, Parking, SSO, Web, Data Storage, VPN… Directory Managers USERS Service Managers “Sanity”

Jill Gemmill Benefits From Standardized Identity Management for Video / VoIP Without re-working business process, you can –Change vendor platforms –Have multi-vendor services –Integrate more than just video/voice (e.g. , web) Leverage existing identity management tools –Most call server manufacturers not expert at identity management –LDAP tools are mature, secure, flexible, open

Jill Gemmill H.350 Series Recommendations H Directory services architecture for multimedia conferencing –Base architecture H Directory services architecture for H.323 H Directory services architecture for H.235 H Directory services architecture for H.320 H Directory services architecture for SIP H Directory services architecture for non- standard protocols H – Directory services architecture for call forwarding and preferences H.350 Implementers Guide

Jill Gemmill H.350 Directory commobject commUniqueId commOwner commPrivate h323Identity h323IdentityGKDomain h323IdentitydialedDigits h323Identity -ID …… h323IdentityEndPointTyper h323IdentityServiceLevel h235Identity h235IdentityUid h323IdentityPassword userCertificate Enterprise Directory inetOrgPerson name (dn) address telephone organization organizational unit commURI RFC 1274 userPassword A Peek Inside H.350

Jill Gemmill Flexible Architecture One person can be associated with more than one commURI (ie, device) One person can be associated with multiple protocols, eg. both H.323 and SIP

Jill Gemmill Flexible Deployment Enterprise and H.350 directories can be two branches of a single DIT, or May be implemented as two separately administered directories Enterprise entry needs only commURI ViDeNet ou=people,dc=vide, dc=net ou=h323identity, dc=vide,dc=net UAB Enterprise Directory ou=people,dc=uab,dc=edu UAB H.350 Directory ou=commobjects,dc=ac,dc=uab,dc=edu

Jill Gemmill H Call Forwarding and Preferences URI + Label –URI points to location where call forwarding address can be found –Label specifies type of forwarding and wait time Potential Targets –Another number –Unified messaging number –CPL script –mailto: –Web form ‘Sorry we missed your call. Please fill out this form and we’ll have someone call you back’ –whack_a_mole.jsp video game

Jill Gemmill

Jill Gemmill What about Rooms? Depends on objects available in enterprise directory Open question: if authentication is used, who should authenticate? –The device –The conference moderator –Everyone in the conference –All of the above

Jill Gemmill Global Directory How do you arrange for your servers to be indexed by it? –Contact Egon Verharen Service is built using –TIO = "Tagged Index Object ", RFC 2654 –CIP = “Common Indexing Protocol”, RFC 2653 –LIMS = “LDAP Index Metadata Server” (Catalogix)

Jill Gemmill Global Directory Services Client / browser crawler commObject & Enterprise dir. LDAP v3 server TIO Pool commObject (video dir.) Enterprise dir. Ldif file Ldif file TAGS (TIO Indexer) … Combined video/ Enterprise dir. TAGS (TIO Indexer) export Ldif file Config. file Config. file LDAP v3 client LIMS

Jill Gemmill Security Credential Storage (H.235 and SIP)

Jill Gemmill Endpoints Implementing H.350 can… Lookup correct configuration information and load it. Solves big user support issue! No matter what protocol or brand, necessary data can be managed in an organized way. Do white pages search via LDAP protocol – receive answers; ‘click to dial’ if supported. Endpoints Implementing H.235 can… Lookup correct configuration information and load it. Solves big user support issue! No matter what protocol or brand, necessary data can be managed in an organized way. Do white pages search via LDAP protocol – receive answers; ‘click to dial’ if supported.

Jill Gemmill Call Servers Implementing H.350 can… Pull information from canonical store –Solves manual data entry problems –Can convert canonical to proprietary if needed on the fly Use XIdentityServiceLevel attribute to provide levels of authorization Scale up video/voip operations

Jill Gemmill So, does any of this stuff work and exist in the real world?

Jill Gemmill Prototypes Developed ViDeNet and “early adopter” directory entries H.350-aware H.323 endpoint H.350-aware gatekeeper H.350-aware SIP user agent H.350-aware SIP Proxy server Automated configuration for endpoints Enterprise authentication used to obtain protocol-specific password White pages and “Directory of directories”

Jill Gemmill Industry Uptake? Yes! RADVISION ECS VCON MXM (Q2 2004) Tandberg TMS 8.0 HCL SIP Proxy Aethra

Jill Gemmill What About Presence? Call forwarding and Call preference is not presence sip.edu (an Internet2 project) uses presence and didn’t think much of H.350………until they scaled up their service and decided configuration storage and autoconfiguration were “good things”.

Jill Gemmill ViDe H.350 Cookbook 60+ pages of text and 200 pages with step by step instructions and examples –Detailed description and example use of each attribute in all H.350 objects –LDIF files ready to use for iPlanet, OpenLDAP, and Active Directory –H.350 installation and server configuration instructions Included in National Science Foundation Middleware Initiative (NMI) Releases 4 & 5National Science Foundation Middleware Initiative (NMI)

Jill Gemmill ViDe H.350 Cookbook

Jill Gemmill Conclusions Videoconferencing Services are growing Managing these services well provides scalability and ease of use H.350 plus cookbook are valuable tools

Jill Gemmill Acknowledgments Colleagues: Tyler Miller Johnson, Samir Chatterjee, Egon Verharen, Jason Lynn Internet2 Middleware Architects (MACE) and Video Middleware (VidMid) Working Groups SURA Southeastern Universities Research Association RADVISION, Cisco NSF ANI “ViDe.Net: Middleware for Scalable Video Services for Research and Higher Education” (Gemmill (PI), Chatterjee, Johnson) NSF ANI “NSF Middleware Initiative” via SURA “UAB Middleware Testbed Program: Integrated Directory Services, PKI, Video, and Parallel Computing”, Subcontract (Shealy, Gemmill (Technical Lead)) NSF EPS via UA “Alabama Internet2 Middleware Initiative”, NSF EPSCoR (Shealy, Gemmill (co-PI) ) Any opinions, findings or recommendations expressed in this material are those of the authors and do not necessarily reflect the views of the National Science Foundation.