1 Internet2 EduPerson 2nd TF-LSD meeting, Amsterdam, 2. February 2001 Peter Gietz

Slides:



Advertisements
Similar presentations
Whos who in the IETF Zoo? Geoff Huston Executive Director, Internet Architecture Board.
Advertisements

04 June 2002, TERENA, Limerick MACE: Directories at Work Keith Hazelton, Senior IT Architect, Univ. of Wisconsin-Madison Chair, MACE-Dir Working Group.
All About Attributes (in federated identity) Nate Klingenstein 30 January 2007 OGF 19 Chapel Hill.
Edu-Person Working Group PKI Working Group, Tempe, Arizona, 8-Feb-2000 Keith Hazelton, Univ. of Wisconsin
The International Security Standard
Credentialing, Levels of Assurance and Risk: What’s Good Enough Dr. Michael Conlon Director of Data Infrastructure University of Florida.
Indications in green = Live content Indications in white = Edit in master Indications in blue = Locked elements Indications in black = Optional elements.
Directory of Directories for Higher Education (DoDHE) October 5, 2001 Michael R. Gettes Principal Technologist Georgetown University Project Leader, DoDHE.
EduPerson and Federated K-12 Activities InCommon/Quilts Pilot Group February 27, 2014 Keith Hazelton UW-Madison, InCommon/I2.
LDAP Lightweight Directory Access Protocol LDAP.
Schema: eduPerson views Michael R Gettes Duke University EuroCAMP, November 2005.
TechSec WG: Related activities overview Information and discussion TechSec WG, RIPE-45 May 14, 2003 Yuri Demchenko.
LDAP crawlers use cases, dangers and how to cope with them 2 nd OpenLDAP Developers Day, Vienna, July 18, 2003 Peter Gietz
GGF2 -GIS WG \ GOS Grid Object Specification Presented by Gregor von Laszewski Developed under discussion by the whole working group and more July, 2001.
CS603 Active Directory February 1, 2001.
1 Directory related work in the Global Grid Forum 3rd TF-LSD Meeting in Antalya Peter Gietz
UCB Enterprise Directory February 7, History Refresher – Commissioning Statement Establish a framework for deploying and maintaining general purpose.
CMS Advanced Electronic Signatures (CAdES) Target Category: Informational Intended to update and replace : RFC 3126 IETF Meeting Paris - August 2005 Denis.
Management of the Internet
07 May 2002, I2 Member Meeting MACE: Directories at Work Keith Hazelton, Senior IT Architect, Univ. of Wisconsin-Madison Chair, MACE-Dir Working Group.
Shibboleth-intro-dec051 Shibboleth A Technical Overview Tom Scavo NCSA.
Middleware Activities Update Internet2 Membership, with coordination provided by Internet2 et al presentation by Renee Woodten Frost Internet2 and the.
1 International Directory Initiatives TERENA Networking Conference 2001 in Antalya Peter Gietz (CEO of DAASI International, chair of TF-LSD)
23/4/2001LDAP Overview - HEPix - LAL 2001 LDAP Overview HEPix – LAL Apr Michel Jouvin
LDAP Search Criteria Fall 2004 Rev. 2. LDAP Searches Can be performed on Single directory entry Contents of a single container Entire subtree Required.
01 February 2002 Directories are Fundamental Keith Hazelton, Senior IT Architect University of Wisconsin-Madison Keith Hazelton, Senior IT Architect University.
GRID Centralized management of the Globus grid-mapfile Carlo Rocca INFN, Catania.
Introduction To OpenLDAP Directory Services. What is a Directory Service? A specialized database optimized for reading, browsing, and searching. No complicated.
Information Technologies Jeremy Mortis 1 hi LDAP The Online Directory.
Privacy provision in e-learning standardized systems: status and improvements 指導教授:溫嘉榮教授 暑資碩三:吳清淵 M
LDAP: LDIF & DSML Fall 2004 Rev. 2. LDIF Light-weight Data Interchange Format RFC 2849 Common format to exchange data entry schema.
HPD Overview Carl Leitner IntraHealth OpenHIE Provider Registry Community Call March 6,
Directories Keith Hazelton, University of Wisconsin Brendan Bellina, University of Notre Dame Tom Barton, University of Chicago.
Implementing LDAP Client/Server System for Directory Service By Maochun Sun Project Advisor: Dr. Chung-E Wang Department of Computer Science California.
LDAP Items
Schema: eduPerson views Michael R Gettes Duke University EuroCAMP, March 2005.
Sonoma State White Pages Implementation Barry Blackburn Andru Luvisi Brian Biggs.
The LDAP Schema Registry and its requirements on Slapd development OpenLDAP Developers' Day San Francisco 21 March 2003 Peter Gietz, DAASI International.
LDAP (Lightweight Directory Access Protocol ) Speaker: Chang-Yu Wu Adviser: Quincy Wu Date:2007/08/22.
19 May 2003, TERENA, Zagreb Civilizing eduPerson Keith Hazelton, Senior IT Architect, Univ. of Wisconsin-Madison Chair, MACE-Dir Working Group Keith Hazelton,
1 COP 4343 Unix System Administration Unit 13: LDAP.
LDAP: Accessing Operational Information CNS 4650 Fall 2004 Rev. 2.
The HEP White Pages Project Ray Jackson CERN / IT - Internet Services Group 23rd April HEPiX/HEPNT Conference, LAL-Orsay, France.
AuEduPerson Schema Schema Derived from: - eduPerson - person [RFC 4517, RFC 4519] - organizationalPerson [RFC 4517, RFC 4519] - inetOrgPerson [RFC 2798]
29 October 2001Terena TF-LSD1 Certificate Retrieval With OpenLDAP David Chadwick.
AACLS Documentation LDAP and releasing information issue ACL and ACI AACLS Model Physical Architecture Logical Architecture Example : a French university.
GRID Centralized Management of the Globus grid-mapfile Carlo Rocca, INFN Catania.
Welcome to Base CAMP: Enterprise Directory Deployment Ken Klingenstein, Director, Internet2 Middleware Initiative Copyright Ken Klingenstein This.
1 Internet2 Middleware update Main source Based on I2 Member meeting, Oct 2000 (trip report.
1 Internet2 Virtual Briefing Multi-Campus Middleware Issues University of Colorado.
November 20, 2002IETF 55 - Atlanta1 VPIM Voice Profile for Internet Mail Mailing list: To subscribe: send.
Campus Community Growing Pains at the Univ. of Wisconsin Common Solutions Group Duke University, 11-Jan-2001 Keith Hazelton, Univ. of Wisconsin
Authorization: Just when you thought middleware was no fun anymore Keith Hazelton, Senior IT Architect, Univ. of Wisconsin-Madison Member, Internet2 Middleware.
5 Point Check List  The 5 Point Check List or the CRAAP Test is a good way to identify if a website is:  worthy of using with students  or with any.
May I introduce you to eduPerson? Keith Hazelton Sr. IT Architect, UW-Madison TNC 2001, Antalya, Turkey, 15-May-2001.
Portable Symmetric Key Container (PSKC) Mingliang Pei Philip Hoyer Dec. 3, th IETF, Vancouver.
LDAP Lightweight Directory Access Protocol LDAP.
Middleware: Directories LDAP-Recipe Michael R Gettes Georgetown University.
Finding Information in an LDAP Directory Info. Tech. Svcs. University of Hawaii Russell Tokuyama 05/02/01 University of Hawaii © 2001.
1 Name of Meeting Location Date - Change in Slide Master Authentication & Authorization Technologies for LSST Data Access Jim Basney
Chief Regulatory Adviser, JANET(UK)
Introduction to LDAP Frank A. Kuse.
Data Type Registries Breakout
LDAP
Index Object Schema and Replication Infrastructure
CEG 2400 Fall 2012 Directory Services - LDAP
LDAP – Light Weight Directory Access Protocol
2nd TF-LSD meeting, Amsterdam, 2. February 2001
Identity Management: Shibboleth Activity Update
Project Proposal: Definition of an European Educational Person (DEEP)
Presentation transcript:

1 Internet2 EduPerson 2nd TF-LSD meeting, Amsterdam, 2. February 2001 Peter Gietz

2 Agenda  EduPerson Working Group  EduPerson Objectclass  New developments  What shall we do about it?

3 EduPerson WG bodies  Internet2 ( Consortium led by > 180 Universities in cooperation with industry and government 20 WGs, 3 of Middleware Architecture Commitee for Education (MACE), 1: MACE-DIR  EDUCAUSE ( International nonprofit association Transforming education through information technology 1800 people from > 190 corporations (edu and a few coms) world wide

4 EduPerson WG bodies contd.  ( Part of EDUCAUSE Merger of: Networking and Telecommunications Task Force (NTTF) Federation of American Research Networks (FARNET) EduPerson WG part of PKI  EduPerson WG Members from Univ. of Wisconsin, Georgetown Univ., Univ. of Washington, MIT Chair: Keith Hazelton (Univ. of Wisconsin)

5 Edu-Person WG Charter  Deliverables: Proposed definition of an edu-Person object class, version 0.9 Explanatory documents Schema registration / IETF standardization Proposal for maintanance and update od edu-Person definition

6 Edu-Person WG Charter  inetOrgPerson (RFC 2798)  plus additional attributes  Needed to support: Role-based access to services and resources Anonymous access to licensed resources PKI-enabled functions X.509 certificate standard and extensions for educational environment

7 EduPerson OC definition  Structure: Name OID Syntax Semantics Controlled vocabulary Advice on Usage, management and application context Group and certificate-based access control Indexing and update procedures

8 InetOrgPerson Attributes displayName, givenName, initials, uid, cn, sn telephoneNumber, facsimileTelephoneNumber, mobile, pager, homePhone homePostalAddress, postalAddress, postalCode, postOfficeBox, street ou, o, st, l Mail, labeledURI, description, jpegPhoto userCertificate, userSMIMECertificate preferredLanguage, seeAlso

9 New attributes  eduPersonAffiliation ( ) Relationship(s) to institution in broad categories: Faculty, student, staff, alum, member, affiliate, employee For „none of the above“: empty attribute Only „member“ and „affiliate“ described „a reasonable person should find the listed relationships commonsensical“ Usage: Dir of Dirs, WP, access control Syntax: CIS, multivalue Indexing pres, eq, sub

10 New attributes contd.  eduPersonPrimaryAffiliation ( ) Primary relationship to institution in broad categories (same as eduPersonAffiliation) Usage: Dir of Dirs, WP, access control Syntax: CIS, singlevalue Indexing pres, eq, sub

11 New attributes contd.  eduPersonAlternateName ( ) Persons nickname Self-maintained attribute hence not additional cn But: „editorial oversight advisable“ Usage: Dir. Of Dirs., WP Syntax: CIS, multivalue Indexing: pres, eq, sub

12 New attributes contd.  eduPersonPrincipalName ( ) „NetID“ of the person for inter-institutional authentication Shoud be stored in the form: Authentication ID for local services Local authentication systems should be able to affirm (to local and remote applications) this ID Uid use is not prescribed sufficiantly precise and consistent for cross domain authorization Usage: controlling access to resources Syntax: CES, singlevalue Indexing: pres, eq, sub

13 New attributes contd.  eduPersonOrgDN ( ) „DN of the directory entry representing the institution with which the person is associated“ For efficient lookup in the institutions directory „We recommend using the attribute searchGuide“ since Org doesn‘t include labeledURI Usage, DoD, WP Syntax: CIS [SIC!], singlevalue Indexing: none

14 New attributes contd.  eduPersonOrgUnitDN ( ) „DN of the directory entry representing the person‘s Organizational Unit(s)“ For efficient lookup for information on OUs „We recommend using the attribute searchGuide“ since OU doesn‘t include labeledURI Usage, DoD, WP Syntax: CIS [SIC!], multivalue Indexing: pres, eq, sub

15 searchGuide  X.521, information of suggested search criteria For entries that are convenient base-objects for the search operation (e.g.: C or O) Includes: Optional objectclass id for type of object sought Search criteria for constructing filters: attribute types logical operators matching level enhancedSearchGuide adds search depth (base, one, sub)

16 searchGuide  LDAP RFC , 5.48, 6.2, 6.3 For use by X.500 clients in constructing search filters enhancedSearchGuide obsoletes searchGuide

17 searchGuide contd.  EduPerson WG proposal (axle.doit.wisc.edu/ ~haz/mware/eduPerson/eduPerson%20OrgRelated.pdf) replace syntax by labeledURI Use not only as ldap filter (e.g., ldap://host:389/basedn?attrs?depth?(filter) But also for web URLs (e.g.,  Newest development: We have opted not to redefine searchGuide Going with the labeledURIobject

18 EduPerson FAQ  Basic Questions  Technical Issues Only a pointer to The LDAP Recipe document  Policy Issues Technical details Data management issues  Process Issues „Characteristics of eduPerson will be dynamic“

19 General remarks  V 1.0 Dec 3, 2000 still looks very incomplete Flaws (CIS instead of DN), Typos Some wordings unspecific „commonsensical“ as argument No formal definitions (ASN.1 or BNF) No Objectclass definition  V 0.9 was sent out to the world for comments, but not to Europe  V 1.0. Jan 22, 2001 not yet published

20 What shall we do about it?  Give comments to V1.0 Dec. 3, 2000  Wait for V 1.0 Jan 22, 2001 to comment  Specify own EUEduPerson (project?) Look at other specs, e.g.: NIH nihInetOrgPerson ( ) IBM ePerson (  Try to co-work on V 2.0