IDENTITY MANAGEMENT ROLLOUT: IN A HURRY. Jason Blackader, UNIX Systems Administrator



Similar documents
Using Shibboleth for Single Sign- On

Outsource the hosting of Luminis and have it hosted elsewhere

SharePoint AD Information Sync Installation Instruction

1. Please login to the Own Web Now Support Portal ( with your address and a password.

Administering Google Apps & Chromebooks for Education

Architecture and Data Flow Overview. BlackBerry Enterprise Service Version: Quick Reference

Device Log Export ENGLISH

Provisioning and Deprovisioning 1 Provisioning/De-provisiong replacement 1

Configuration Guide. BES12 Cloud

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

Entrust IdentityGuard Comprehensive

Troubleshooting BlackBerry Enterprise Service 10 version Instructor Manual

Getting Started with Clearlogin A Guide for Administrators V1.01

Oracle Business Intelligence Enterprise Edition LDAP-Security Administration. White Paper by Shivaji Sekaramantri November 2008

Easy as 1-2-3: The Steps to XE. Mark Hoye Services Portfolio Consultant

Talk Internet User Guides Controlgate Administrative User Guide

Insight Video Net. LLC. CMS 2.0. Quick Installation Guide

Configuration Guide BES12. Version 12.1

Introduction. Connection security

Configuration Guide. BlackBerry Enterprise Service 12. Version 12.0

Configuring EPM System for SAML2-based Federation Services SSO

Configuration Guide BES12. Version 12.3

Use of UniDesk Code of Practice

How To Set Up A Macintosh With A Cds And Cds On A Pc Or Macbook With A Domain Name On A Macbook (For A Pc) For A Domain Account (For An Ipad) For Free

Agenda. How to configure

Configure Single Sign on Between Domino and WPS

Introduction to Google Apps for Business Integration

User Guide. Version R91. English

Preparing for GO!Enterprise MDM On-Demand Service

Configuration Guide BES12. Version 12.2

Xopero Backup Build your private cloud backup environment. Getting started

Active Directory Requirements and Setup

Encore Software Solutions (V3) Identity Lifecycle Management and Federated Security Suite (ILM/FSS) Overview and Technical Requirements

Quick Start Guide Migration Planner

Administration Guide. BlackBerry Enterprise Service 12. Version 12.0

Configuring Sponsor Authentication

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

BlackBerry Enterprise Service 10. Version: Configuration Guide

How To - Implement Single Sign On Authentication with Active Directory

Single Sign On. SSO & ID Management for Web and Mobile Applications

Authentication Methods

GlobalSign Customers. Enterprise PKI Client Authentication User Guide. Employing authentication as an additional security layer to the EPKI platform

Defender Token Deployment System Quick Start Guide

IRMACS Setup. Your IRMACS is available internally by the IMAP protocol. The server settings used are:

Active Directory Authentication Integration

Centrify Cloud Connector Deployment Guide

Quick Start Guide Sendio Hosted

Administration: Users and Roles

Outlook Web App (Online)... 3 Outlook 2013 (Desktop) Apple Mail Mobile Devices Android iphone... 40

Enterprise Directory Project Pre-Feasibility Study Information and Educational Technology

managing SSO with shared credentials

qliqdirect Active Directory Guide

SchoolBooking SSO Integration Guide

AskCody Connect Connect your Outlook or AD to AskCody s solutions seamlessly. Everything included!

Wazza s QuickStart 1. Leopard Server - Install & Configure DNS

TIBCO Spotfire Platform IT Brief

Current Environment Assessment Specification. Single Sign On Customer Relation Management Workstation Support

Active Directory Integration

Google Apps & Chromebooks for Education Deployment Best Practices

Active Directory Sync (AD) How it Works in WhosOnLocation

Using LDAP Authentication in a PowerCenter Domain

Fus - Exchange ControlPanel Admin Guide Feb V1.0. Exchange ControlPanel Administration Guide

Initial Setup of Microsoft Outlook 2011 with IMAP for OS X Lion

Introduction to the AirWatch Cloud Connector (ACC) Guide

Integration of Office 365 with existing faculty SSO

Employee Active Directory Self-Service Quick Setup Guide

iphone in Business How-To Setup Guide for Users

A SECURITY MODEL THAT WORKS FOR YOU!

Kerio Connect. Kerio 4D Migration. Kerio Technologies

Zendesk SSO with Cloud Secure using MobileIron MDM Server and Okta

Integrating OID with Active Directory and WNA

Configuring Parature Self-Service Portal

Single Sign On for ShareFile with NetScaler. Deployment Guide

TG Web. Technical FAQ

Identity and Access Management (IAM) Roadmap DRAFT v2. North Carolina State University

Bill Fiddes Learning and Development Specialist Rob Latino Program Manager in Office 365 Support

Skyward LDAP Launch Kit Table of Contents

For details for obtaining this later version; see the Known issues & Limitations, section at the end of this document.

Identity Management in Quercus. CampusIT_QUERCUS

Active Directory Sync (AD) How to Setup

Migration guide. Business

ManageEngine Desktop Central. Mobile Device Management User Guide

Authentication: Password Madness

Cloudwork Dashboard User Manual

SchoolBooking LDAP Integration Guide

How to Scale out SharePoint Server 2007 from a single server farm to a 3 server farm with Microsoft Network Load Balancing on the Web servers.

IIS, FTP Server and Windows

WiNG5 CAPTIVE PORTAL DESIGN GUIDE

Advanced Administration

Linux VPS with cpanel. Getting Started Guide

Transcription:

IDENTITY MANAGEMENT ROLLOUT: IN A HURRY Jason Blackader, UNIX Systems Administrator

Undergraduate, Graduate, Continuing Ed Industrial Design, Communication Design, Design Sciences, Arts & Media Two Campuses 1500 Degree Students, 3000 Continuing Ed 450 Faculty, 250 Staff

2007 CENTRALIZED WEB DELIVERY Challenge: Integrate new offerings January New student ERP rollout April Degree student online enrollment May Continuing Ed instant enrollment June itunesu launch August Degree Student web mail launch August Portal launch inside.artcenter

EXISTING IDENTITY RESOURCES What did we have to work with? Independent systems of record Two active directory domains Local logins on different servers (i.e. ftp / www) 17,000 sendmail records (accounts + aliases) Conflicting student ERP generated usernames Mixed Numeric and alphanumeric login names Different login names in different systems Many users with multiple passwords

IDENTITY MANAGEMENT What did we want from this effort? Create a common method for authentication Plan as open an architecture as possible to grow service for future requirements Applications have access to common person data that is useful from app to app Users passwords can be Self Service Front line support can provision accounts

WHERE DO WE START?

2007 STARTING OBJECTIVES What do we need for software and hardware? Directory (LDAP/AD) / WWW / App Serv Preferably >= two servers per service Who will we get the software from? Purchase from Oracle, Microsoft, Sun Write it ourselves What systems need to be tied to IDMS first? Student ERP (Datatel) / Active Directory WWW Services not yet built Find the right consultant to help

SOFTWARE ANALYSIS Oracle Microsoft Sun Layered products based on (LDAP/Oracle) Professional Services Required Layered products based on (AD LDAP (ADAM)/MSSQL) Professional Services Required Layered products based on Sun JES (LDAP/Java) Professional Services Suggested Comfort Level: Moderate Comfort Level: Low Comfort Level: Moderate Cost: $$ Cost: $$ Cost: $ (Academic Discount)

2007 INTEGRATION OBJECTIVES Portal Username Password Role (All Constituents) Primarily for student use at first Student ERP Username Password Student ID (All Constituents) Student /Faculty +Staff online use itunesu Webmail Username Password Role (Student/Faculty) New services offered with the portal LDAP LDAP LDAP

PHASED GAME PLAN

PHASED GAME PLAN 1. Active Directory changes in advance of IDM integration 2. LDAP needs in advance of IDM integration 3. IDM resource integration Initial deployment 4. Single sign-on integration 5. Maintenance and future integration policy

PHASE 1 ACTIVE DIRECTORY 1. Student username migration from studentid_num to match email username 2. Password policy changes 3. Communication to reduce impact to users 4. File and folder regeneration 5. Testing and support

USERNAME CREATION DURING MIGRATION AD ACCOUNT PROVISIONING FEEDS COLLEAGUE USER STATE USER KNOWN USER UNKNOWN NORMAL FEED (ALL/ADD/DROP) FOUND POSITIVE USER MATCH UMRA PICKUP CANNOT ASSERT ABSOLUTE USER MATCH ACTIVE DIRECTORY and STORAGE SETUP Admin Arbitration

PHASE 2 LDAP 1. Build LDAP server farm 2. Build LDAP OU structure 3. Decide uid method for LDAP usernames: uid=username cn= first last 4. Create attribute model based on eduperson (register PEN at pen.iana.org) 5. Assess needs of individual applications

PHASE 3 IDMS INTEGRATION 1. Attach active directory domains to Sun IDM 2. Establish LDAP link with Sun IDM: LDAP has no user accounts yet 3. Compare test exports between active directory and lists of sendmail accounts 4. Import active directory accounts into Sun IDM, pushing AD accounts into LDAP 5. Load text files of sendmail accounts into SUN IDM, pushing accounts into LDAP

PASSWORD CAPTURE MECHANISM LDAP PASS AUTH Sun IDM LDAP ACTIVE SYNC

PHASE 4 SINGLE SIGN ON 1. Set up Shibboleth server 2. Integrate portal applications Based on time restraints, we cheated and used basic PHP trust scripts for SSO. We do have plans for Shibboleth in the future.

PHASE 5 MAINTENANCE AND THE FUTURE 1. Define IDMS support roles 2. Cross train support leads as project progresses 3. Constant review of practices 4. Management priority set on future application integration 5. Completion of Faculty and Staff issues created by migration based on Students

PROJECT PROGRESS Milestones reached June-August 2007 New student usernames introduced between terms Attribute structure still in development LDAP password capture mechanism for existing logins worked extremely well Custom script based solution written: ERP query LDAP before account creation Portal launched for fall online registration

IMPLEMENTATION TO MAINTENANCE Delivery mode change in project New processes are required to replace old forgotten processes Data flow issues are not all equal Required: Documentation of attribute flow Determine exception handling methods

ATTRIBUTE TOPOLOGY DOCUMENTATION CUSTOM USERS USERNAME FEED Colleague Registry ColleagueID Username PrimaryRole IDM RECONCILE IDM ACTIVESYNC Password + NewAccount Whoami table WA username AD username CampusID ColleagueID Default Password PrimaryRole Department

LESSONS LEARNED Start small Decide authority of historical user naming Learn from old problems IDMS is replacing Determine minimum attributes needed Build with intent to rebuild and reorganize Good design will resolve unrecognized details Redundancy is vital for centralized resources

2008 What are we delivering this year? Attribute flow topology migration to Oracle New blogs server implementation New course management system implementation Alumni access to online campus resources Instructor and Alumni maintenance of email forwarding LDAP based email routing

FUTURE OBJECTIVES Requests for more, more, more! IDMS will provision OS accounts IDMS will manage AD and Exchange Library integration (Millennium) Equipment rentals integration (Webcheckout) Dynamic email lists via LDAP

THANK YOU Jason Blackader jblackader@artcenter.edu 626.396.2459 www.artcenter.edu