Copyright Dave Steiner and Jeremy Rosenberg 2010. This work is the intellectual property of the authors. Permission is granted for this material to be.

Slides:



Advertisements
Similar presentations
Pennsylvania Banner Users Group 2008 Fall Conference Campus Identity Management in a Banner World.
Advertisements

Web Application Management Moving Beyond CMS Douglas Clark Director, Web Applications Copyright Douglas Clark 2003 This work is the intellectual property.
Copyright Tom Parker, Ron DiNapoli, Andrea Beesing, Joy Veronneau This work is the intellectual property of the authors. Permission is granted for.
On Beyond Z Building a Directory Service educause presentation #074 University of Colorado at Boulder Deborah Keyek-Franssen Marin Stanek Paula J. Vaughan.
1 Collaborators at the Gates of Troy: Extending eServices at USC.
1 Extending Authenticated Online Services with "Friend Accounts" at Washington State University Brian Foley Technology Architect/Application Developer.
Provisioning 101: Cutting Costs, Enhancing Security, and Improving Service David Lavenda VP Marketing & Product Strategy June 19, 2003 © Business Layers.
Selecting a Business Intelligence Standard for Higher Education Mid Atlantic Educause Conference Baltimore, Maryland Baltimore, Maryland January 10, 2006.
Copyright Jill M. Forrester This work is the intellectual property of the author. Permission is granted for this material to be shared for non- commercial,
Choosing Open Source and Partnering as an IT Strategy Brad Wheeler Associate Vice President & Dean Office of the VP & CIO Indiana University
Peter Deutsch Director, I&IT Systems July 12, 2005
The Homegrown Single Sign On (SSO) Project at UM – St. Louis.
JA-SIG CAS Enterprise Single Sign-On Scott Battaglia Application Developer Enterprise Systems & Services Rutgers, the State University of New Jersey Copyright.
Identity Management: The Legacy and Real Solutions Project Overview.
Copyright 2008, Elizabeth A. Evans. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
Procurement From the 20 th to the 21 st Century Copyright Byron Honoré This work is the intellectual property of the author. Permission is granted.
Providing and Managing Technology Training Providing & Managing Technology Training Susan McKibben The University of Akron.
Copyright Anthony K. Holden, This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
Web Portal Development with uPortal or.Net Midwest Educause: March 24-26, 2003 David B. Williams Mark Troester
Western Illinois University - Electronic Student Services Copyright Statement Copyright Western Illinois University – Electronic Student Services 2001.
Moving Your Paperwork Online Western Washington University E-Sign Web Forms Copyright Western Washington University, This work is the intellectual.
GatorAid: Identity Management at the University of Florida Mike Conlon Director of Data Infrastructure
Darrel S. Huish Katherine J. Ranes Arizona State University Lessons Learned During the First Year of myASU, a Large Institution Portal Copyright Darrel.
Shibboleth and InCommon Copyright Texas A&M University This work is the intellectual property of the author. Permission is granted for this material.
CAMP - June 4-6, Copyright Statement Copyright Robert J. Brentrup and Mark J. Franklin This work is the intellectual property of the authors.
Learning Management Systems Camp June 2004 Barry R Ribbeck UT HSC Houston Copyright, Barry Ribbeck, This work is the intellectual property of the.
Copyright Gordy Pace, This work is the intellectual property of the author. Permission is granted for this material to be shared for non- commercial,
Steven Hazzard – Dir Application Systems Karin West Mormando – Assoc Dir Admissions Charles Musgrove – Assoc Dir Admissions Extreme Makeover: Rebuilding.
Identity Management – Why and How Experiences at CU-Boulder Copyright Linda Drake, Director of Development and Integration, University of Colorado, Boulder,
EDUCAUSE April 25, 2006Enforcing Compliance with Security Policies … Enforcing Compliance of Campus Security Policies Through a Secure Identity Management.
#CONVERGE2014 Session 1304 Managing Telecom Directories in a Distributed or Multi-Vendor Environment David Raanan Starfish Associates.
Baylor University and Xythos EduCause Southwest 2007 Dr. Sandra Bennett Program Manager Online Teaching and Learning System Copyright Sandra Bennett 2007.
Sharing MU's SharePoint Experience 2005 Midwest Regional Conference Innovative Use of Technology: Getting IT Done Wednesday, March 23, 2005.
1 No More Paper, No More Stamps: Targeted myWSU Communications Lavon R. Frazier April 27, 2005 Copyright Lavon R. Frazier, This work is the intellectual.
Moving Your Paperwork Online University of California, Irvine presents PayQuest Copyright UC,Irvine This work is the.
NERCOMP Managing Campus Affiliates Managing Campus Affiliates Faculty? Student? Faculty? Student? Staff? Criss Laidlaw Director of Administrative.
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University.
University of Michigan MCommunity Project Liz Salley Product Manager, Michigan Administrative Information Services Luke Tracy
1 Simon: What, How and Why Jon Finke Communication and Middleware Technology.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 Shibboleth Pilot Local Authentication.
Group Management at Brown James Cramton Brown University April 24, 2007.
Uniting Cultures, Technology & Applications A Case Study University of New Hampshire.
University of Michigan MCommunity Project Liz Salley Product Manager, Michigan Administrative Information Services Luke Tracy
UWM CIO Office Where Did These Customizations Come From? Do We Need Them? March 14, 2007 Jill Unglaub, Senior Application Analyst Information and Media.
GatorLink Password Management Policy March 31, 2004.
KUALI IDENTITY MANAGEMENT Provides services for Identity and Access Management in Kuali Integrated Reference Implementations User Interfaces An “integration.
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University.
1 Copyright Carl Berger This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University.
Imagining a Community Source Student Services System Leo Fernig Richard Spencer SOA Workshop Vancouver March 24, 2006.
1 Presenters: Lucretia Parham Sara Connor Armstrong Atlantic State University October 30, :45 – 12:35 Copyright Sara Connor and Lucretia Parham,
Copyright Statement Copyright Robert J. Brentrup This work is the intellectual property of the author. Permission is granted for this material to.
Moving Forward in Stages Tom Barton, University of Chicago.
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UC Davis Eric Westfall, Indiana University.
Bringing it All Together: Charting Your Roadmap CAMP: Charting Your Authentication Roadmap February 8, 2007 Paul Caskey Copyright Paul Caskey This.
NMI-EDIT and Rice University Federated Identity Management: Managing Access to Resources in Texas Barry Ribbeck Director System Architecture and Infrastructure.
Introduction to Terra Dotta Applications Integration with Campus Data Systems for institutions beginning their software implementation.
OpenRegistry MACE-Dir 5/18/09 1 OpenRegistry Initiative Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University May 2009.
OpenRegistry Jasig Dallas OpenRegistry Initiative Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University March 2009.
OpenRegistry LSM 10/7/09 1 OpenRegistry Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University July 2009.
OpenRegistry: What’s New Jasig San Diego 3/10 1 What’s New With OpenRegistry Scott Battaglia Benjamin Oshrin March 2010.
University of Southern California Identity and Access Management (IAM)
New Developments in Central Directory Service and Account Provisioning Dan Menicucci Enterprise Architect - University of Pittsburgh.
OpenRegistry Initiative
Federated Identity Management at Virginia Tech
John O’Keefe Director of Academic Technology & Network Services
University of Southern California Identity and Access Management (IAM)
myIS.neu.edu – presentation screen shots accompany:
Technical Topics in Privilege Management
Managing Enterprise Directories: Operational Issues
Presentation transcript:

Copyright Dave Steiner and Jeremy Rosenberg This work is the intellectual property of the authors. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the authors.

From In-House to Open Source: Creating a Sense of Identity (Management) Dave Steiner – Rutgers University Jeremy Rosenberg – Simon Fraser University October 13, 2010

ABOUT US Dave Steiner Rutgers University – New Jersey Identity Management Architect Numerous IDM/Middleware Projects since 1984 Joined newly created IDM Team in 2006 Jeremy Rosenberg Simon Fraser University – Vancouver, BC Identity Management Architect Java Developer since 2004 MBA in Management of Technology

ABOUT THIS PRESENTATION Campus Perspectives Legacy IdM Architectures Strengths and limitations Future requirements OpenRegistry Project How did it start? What is OpenRegistry? Why open source? State of the project OpenRegistry workflow walkthough

ABOUT SFU Simon Fraser One University - Three campuses Burnaby Surrey Vancouver 32,000 students 900 faculty 1600 staff 100,000 alumni

SFU’S IDAM LAYOUT Amaint Account Provisioning Mail Lists Mail Lists Web Server UDD LDAP WebCT CAS AD PeopleSoft Shibboleth Eduroam Shibboleth Eduroam Zimbra

SFU STRENGTHS AND LIMITATIONS Centralized Single computing IDs CAS SSO Self Serve Maillists/ACLS Account Activation Auto Provisioning / Filespace WebCT Scalability Support for new SoRs No distributed admin Sustainability Only two developers (one is a rock climber) Granularity General role support No distributed data entry

SFU FUTURE NEEDS Capture more of the University Population More accurate and complete directory Greater auditing capabilities Built on sustainable industry standards

ABOUT RUTGERS UNIVERSITY One University – Three campuses New Brunswick Newark Camden Founded in 1766 Over 56,000 students 4150 faculty 6500 staff Over 380,000 alumni

RUTGERS LEGACY People Database (PDB) Student Records Database (SRDB) Payroll Guest Account Creation Kerberos/ Safeword CAS Oracle Account Creation SecurID LDAP Radius APPLICATIONS&SYSTEMSAPPLICATIONS&SYSTEMS Data Flow Query

RUTGERS STRENGTHS AND LIMITATIONS Central Identities for Students, Faculty and Staff Central Authentication via CAS and LDAP Self-service credential creation Self-service accounts Not all populations supported Joint institutions not supported Guests not well supported Support is too centralized Needs to be more real-time De-provisioning manual, once a year Roles don’t match needs Not an integrated system but grew up over time

RUTGERS FUTURE NEEDS A long term, core identity management solution Single identity throughout person’s lifetime Extend – e.g. for students, from Prospect through Alumni Add population types Continuing Education, joint institutions, conference attendees Faster propagation of data, real time where possible Data for better provisioning and de-provisioning both electronically and physically

HOW DID OPENREGISTRY START? Apr 2006 – creation of IDM group at Rutgers Production services (e.g. CAS, LDAP, Kerberos) New development Aug 2006 – IDM as part of a new IT Strategic Plan Nov 2006 – Rutgers IDM Assessment Feb 2007 – Rutgers IDM Potential Initiatives Mar 2008 – OpenRegistry design work started Jan 2009 – Became a Jasig Incubator project Late 2009 – SFU joined the project

WHAT IS OPEN REGISTRY? An open source Identity Management system A place for data about people affiliated with your institution Combines distributed identity information into single identity records Identity store, but generally NOT authoritative Identity reconciliation for multiple SoRs Identifier assignment Input: web, batch and REST interfaces from SoRs Output: queues, REST, batch, report server, Directory Builder, provisioning and de-provisioning

WHAT IS OPEN REGISTRY?

OPENREGISTRY ARCHITECTURE

WHY AN OPEN SOURCE PROJECT? “Off the shelf” solutions require significant customizations and integration work and may only solve a portion of an institutions needs Open source collaboration > in-house building Leverage scant resources Decades of combined experience Learn from others' experiences Sakai, uPortal, CAS, Shibboleth, Kuali Not all knowledge with a few in-house people Tailored to the needs of higher education

STATE OF THE PROJECT Generic data model designed and reasonably stable Domain objects and base service layer code written for addPerson, addRole, updatePerson, updateRole, etc. Currently being tested with real-life data Input methods well defined and being implemented, Output needs further requirements/design Production deployment at Rutgers in first half of 2011 dependant on new PeopleSoft payroll deployment

HOW DID SFU GET INVOLVED? Jan 2005 – Sponsored Account Management App April 2007 –Single Computing ID Project No more multiple accounts for employees and students One login for HR and Registrar with Roles Mar 2008 – Distance Ed becomes third SoR Aug 2008 – Lightweight Accounts Introduced No or Unix file space provisioned Aug 2009 – Contact with Rutgers IdM team Sept 2009 – Jasig Un-conference Late 2009 – First commits to OpenRegistry June 2010 – Additional Developers added

HR SIS Kipling, Rudyard Undergrad Staff Former Undergrad OpenRegistry CODE Bronte, Emily CODE WebCT Bookstore Bookstore Clerk Faculty Expired

THANK YOU Visit the Jasig Wiki at: Join the OpenRegistry Dev mail list: Attend a Jasig event Jeremy Rosenberg Dave Steiner