Presentation is loading. Please wait.

Presentation is loading. Please wait.

Managing Enterprise Directories: Operational Issues

Similar presentations


Presentation on theme: "Managing Enterprise Directories: Operational Issues"— Presentation transcript:

1 Managing Enterprise Directories: Operational Issues
Dr. Tom Barton, University of Memphis Copyright Tom Barton, This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.

2 Stateful Provisioning
Base CAMP - February 5-7, 2003 2

3 The Problem Unclear process for lifecycle management of accounts & other IT resources Seat of pants policy determination Inconsistent operational practices Done differently by different people at different times Common business logic forced to reside in applications to determine eligibility Eg. Is this user “currently a member of community”? Inconsistent service levels for users results. Base CAMP - February 5-7, 2003 3

4 Automated stateful provisioning
Basic account provisioning is guided by a finite state machine. Managed resources include shell accounts IMAP/POP/HTTP mailbox service campus-wide computing cluster access variety of directory enabled application and web services that use an LDAP directory for access control, or that use the LDAP directory to determine eligibility for service. Base CAMP - February 5-7, 2003 4

5 States embody levels of service
Provisioning profiles Full access to basic services Faculty, staff, enrolled student & identity management, including PIN maintenance for access to administrative web applications Accepted student, registered student Identifiers maintained for continued support for outsourced services Alum, id retained Steps between these and oblivion Notification of impending doom Access denied Resources deleted Base CAMP - February 5-7, 2003 5

6 Independent variables for state transitions
substate date the present state was reached date by which the present state might end (expiration date) major affiliation (faculty, staff, enrolled student, accepted student, registered student, alum, id retained) multivalued attribute holding the identifiers of resources being managed for this account. Base CAMP - February 5-7, 2003 6

7 Not shown: transitions to prospective state from grace, limbo, slide, IDonly.
Base CAMP - February 5-7, 2003 7

8 Benefits Smooth over issues with feeds from source systems (grace state). Provide continuity of service to persons who temporarily drop out of source systems. Absence from a source system need not imply absence from University community. Avoid deletion of resources for persons not in fact departed (limbo state). Organizing principle for business logic that determines provisioning. Base CAMP - February 5-7, 2003 8

9 Benefits Authorization policy in applications can leverage knowledge of user’s “state”. Details of how to determine “standing” of a person from data in source systems is only instantiated once. Administrative exceptions need only be represented once, in the metadirectory. Source of IT resource management policy. Increases value of integrated architecture (cf. “Middleware Business Case” – middleware value proposition) Base CAMP - February 5-7, 2003 9

10 Issues Expression of former affiliation Guest account management
Exposed during graceful removal? “accidental” nature of residual affiliation Guest account management manageGuest – thumbs up Sponsored account management Managed by humans – well, supposed to be.. Base CAMP - February 5-7, 2003 10


Download ppt "Managing Enterprise Directories: Operational Issues"

Similar presentations


Ads by Google