© GT/SAPP/USIT University of Oslo, Norway User-administration system (BAS) at the University of Oslo Creating of a single user-administration system for.

Slides:



Advertisements
Similar presentations
AD User Import From SIMS.NET
Advertisements

Omni eControl. New Features in Version 2.x - Manage Mixed Networks: eDirectory, Active Directory, GroupWise, Exchange eControl Version 2.0 New Features.
© GT/SAPP/USIT University of Oslo, Norway Cerebrum, UoO new UAS Developing a 2 nd generatione of a single user- administration system for University of.
Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
Quick Start Guide. To setup another account (aside from the school ) 1) Tap “Settings”
People Database project John Byrne. Project aims Improve current Computing Service resource management processes Provide a reference 'People Database'
By Rashid Khan Lesson 5-Directory Assistance: Administration Using Active Directory Users and Computers.
Extern name server - translates addresses of s messages - enables users to use aliases - … ID cards system - controls entrance to buildings,
ELAG Trondheim Distributed Access Control - BIBSYS and the FEIDE solution Sigbjørn Holmslet, BIBSYS, Norway Ingrid Melve, UNINET, Norway.
Our z/OS Security Introducing z/OS Security 1 hour PowerPointOur z/OS Security PowerPoint Our z/OS Security Administration and Auditing Webinar Understanding.
1 Collaborators at the Gates of Troy: Extending eServices at USC.
Active Directory: Final Solution to Enterprise System Integration
UCB Enterprise Directory Services. Directory Services – Project History  Requirements defined  Project commission & goals articulated  Project teams.
Understanding Active Directory
June 1, 2001 Enterprise Directory Service at College Park David Henry Office of Information Technology University of Maryland College Park
Design Aspects. User Type the URL address on the cell phone or web browser Not required to login.
UCB Enterprise Directory Services. Directory Services – Project History  Requirements defined  Project commission & goals articulated  Project teams.
System Architecture University of Maryland David Henry Office of Information Technology December 6, 2002.
Microsoft Windows Domains Structure and Services Chatziioannidis Christos Computer & Informatics Engineer Computer & Networking Services Computer Technology.
© N. Ganesan, Ph.D., All rights reserved. Active Directory Nanda Ganesan, Ph.D.
TWSd Configuring Tivoli Workload Scheduler Security 1of3
Identity Lifecycle Management Jonny Chambers Senior Technical Specialist Microsoft Ireland
Lesson 17. Domains and Active Directory. Objectives At the end of this Presentation, you will be able to:
Configuring CIFS Upon completion of this module, you should be able to: Configure the Data Mover for a Windows environment Create and Join a CIFS Server.
Digital Identity Management Strategy, Policies and Architecture Kent Percival A presentation to the Information Services Committee.
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
Feide is a identity management system on a national level for the educational sector in Norway. Federated Electronic Identity for Norwegian Education Tromsø,
Database Security and Auditing: Protecting Data Integrity and Accessibility Chapter 3 Administration of Users.
Uniting Cultures, Technology & Applications A Case Study University of New Hampshire.
Information Technologies Jeremy Mortis 1 hi LDAP The Online Directory.
NMI-EDIT CAMP Synopsis, ISCSI Storage Solution, Linux Blade Cluster, And Current State Of NetID By Jonathan Higgins Presentation Template available from.
Questions? Ext Instructions 1. Login: 2. Click on Register Here.
HAKA project HAKA User administration inside Finnish Higher Education Institutes results from the KATO project Barbro Sjöblom EDS 2003 Uppsala.
ACTIVE DIRECTORY : AN INTRODUCTION The Network Team Knox County Schools.
CIT 470: Advanced Network and System AdministrationSlide #1 CIT 470: Advanced Network and System Administration Accounts and Namespaces.
1 Federating applications at NTNU EuroCAMP Bjørn Ove Grøtan – Software Developer Federating applications at NTNU.
Questions? Ext Instructions 1. Login: 2. Click on Register Here.
Implementing LDAP Client/Server System for Directory Service By Maochun Sun Project Advisor: Dr. Chung-E Wang Department of Computer Science California.
10/25/20151 Single Sign-On Web Service Supervisors: Viktor Kulikov Alexander Sherman Liana Lipstov Pavel Bilenko.
Module 7 : Configuration I Jong S. Bok
Baltic IT&T, Riga 2007 Identity Management within the educational sector in Norway Senior Adviser Jan Peter Strømsheim, Norwegian ministry of Education.
Chapter 10: Rights, User, and Group Administration.
Identity Management Practical Issues Associated with Sharing Federated Services William A. Weems The University of Texas Health Science Center at Houston.
Office of Information Technology Help Desk: ECS 020 Phone: Web UMBC Uploading your personal.
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Microsoft Identity Integration Server & Role Base Access Theo Kostelijk Consultant Microsoft BV
1 Connecting to a Database Server. 2 We all have accounts, with a single database each, on a Microsoft SQL Server on the USF network: allman.forest.usf.edu.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
Directory Services CS5493/7493. Directory Services Directory services represent a technological breakthrough by integrating into a single management tool:
Module 1: Introduction to Windows 2000 and Networking.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Windows Active Directory – What is it? Definition - Active Directory is a centralized and standardized system that automates network management of user.
Virtual Directory Services and Directory Synchronization May 13 th, 2008 Bill Claycomb Computer Systems Analyst Infrastructure Computing Systems Department.
LDAP: Synchronizing LDAP Information CNS 4650 Fall 2004 Rev. 2.
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
BUILDING A NEW ACTIVE DIRECTORY Smita Carneiro, GCWN Active Directory Systems engineer Purdue University.
Using Your Own Authentication System with ArcGIS Online
CollegeSource Security Application &
Punching data to the authentication server
Welcome to DCISD Technology
Student: Salman Shtayeh
Adding account to iOS Device (11.3.1)
Dartmouth College Status Report
Management of users at UNIL
INFORMATION TECHNOLOGY NEW USER ORIENTATION
Matthew Levy Azure AD B2B vs B2C Matthew Levy
Identity Management at the University of Florida
Active Directory Overview
INFORMATION TECHNOLOGY NEW USER ORIENTATION
Presentation transcript:

© GT/SAPP/USIT University of Oslo, Norway User-administration system (BAS) at the University of Oslo Creating of a single user-administration system for University of Oslo By Bård Henry Moum Jakobsen

© GT/SAPP/USIT University of Oslo, Norway University of Oslo (UoO), Norway students fac. & staff other! users in one user-management system UREG2000 Ca computers for students –Win*, MacOS, Linux, mm almost computers…

© GT/SAPP/USIT University of Oslo, Norway What is an User administration system (BAS) Student registry Student registry Personal registery BAS Persons Users

© GT/SAPP/USIT University of Oslo, Norway FEIDE

© GT/SAPP/USIT University of Oslo, Norway BAS SR (FS/MSTAS) OtherHR AT (LDAP)

© GT/SAPP/USIT University of Oslo, Norway User administration system (BAS) Person - unique ID - Name - Address - Affiliation Group - Group ID (GID) - Comment - Members - users - other Groups User - Username (UID) - Password - Mail address - Home dir

© GT/SAPP/USIT University of Oslo, Norway UoOs BAS, UREG2000 A SQL (Oracle) database API in Perl5 A collection of programs (mostly Perl5) for managing users and attributes Procedures for extracting information from LT (UoOs HR-system) and FS (UoOs Student registry) Printer accounting!

© GT/SAPP/USIT University of Oslo, Norway More… Creates: –NIS (2 domains) –AD (win2k) –LDIF –IMS Enterprise –Domino Directory –Tivoli –Remedy ARS –Exim (mail) –Mailman (mail-lists) –etc

© GT/SAPP/USIT University of Oslo, Norway LT – HR-system (i) Gives UREG: –Organizational units »SKO – unit number Made national by our national Student registry system 4 parts Institution (‘\d{4}’) Faculty (‘\d{2}’) Department (‘\d{2}’) Group (‘\d{2}’) »Organization unit Name »Phone, fax, URL, (for the unit) »Addresses (Snail-mail and physical address)

© GT/SAPP/USIT University of Oslo, Norway LT – HR-system (ii) Gives UREG –Person »National id-number (Social security number) »Name »Org.unit »Type (Faculty, Staff, other) »Problem: It takes time to register a person, to much time… Gets from UREG – -addresses

© GT/SAPP/USIT University of Oslo, Norway FS – Student registry Gives UREG: –Persons »National id-number (Social security number) »Name »addresses »Curriculum Gets from UREG – -addresses

© GT/SAPP/USIT University of Oslo, Norway Ureg2000 FSLT NIS (UiO) NT AD (W2K) Notes ARS Tivoli BOFH Radius UA (Adgangskontroll) PRISS Exim/Mailman NIS (IfI) LDAP LMS (CF)

© GT/SAPP/USIT University of Oslo, Norway UREG (or BAS) creates Userid/shortname ’baardj’ (unix-username) –Username in NIS –Loginname in AD –UID in LDAP (for MacOS X) Groups, general group basic –Creating Filegroups –Creating netgroups –Creating AD groups –Creating Notes groups –Creating mailinglists

© GT/SAPP/USIT University of Oslo, Norway Is this a PKI? No! But it is a requirement for a functional PKI. We are not a CA (to much work) But we need certificates for persons, roles, organizations, units and servers. External CA for persons, internal for all others. We need a map from ID in persons certificates to an uniq id at the University, which CA is secondary

© GT/SAPP/USIT University of Oslo, Norway More? Contact us! Foils: eng.ppt

© GT/SAPP/USIT University of Oslo, Norway Coming Structure of LDAP at UoO