The New Grouper: Its New User Interface and More



Similar documents
Business and Process Requirements Business Requirements mapped to downstream Process Requirements. IAM UC Davis

Multi-Factor Authentication, Assurance, and the Multi-Context Broker

Three Campus Case Studies: Managing Access with Grouper

Three Case Studies in Access Management

Create, Link, or Edit a GPO with Active Directory Users and Computers

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Enterprise Portal Built by and for Higher Education

How to Create a Delegated Administrator User Role / To create a Delegated Administrator user role Page 1

TIBCO Spotfire Server Deployment and Administration

Using Management Shell Reports and Tracking User Access in the NetVanta UC Server

Cloudfinder for Office 365 User Guide. November 2013

Elgg 1.8 Social Networking

Office 365 SharePoint Online

Getting started with 2c8 plugin for Microsoft Sharepoint Server 2010

DETAILED BOOT CAMP AGENDA

TIBCO Spotfire Server Migration. Migration Manual

Secure Messaging Server Console... 2

Using Grouper: Newcastle University case studies. Richard James Caleb Racey

Microsoft SharePoint Server 2010: What s New and What s Changed?

TECHNICAL DOCUMENTATION SPECOPS DEPLOY / APP 4.7 DOCUMENTATION

DeviceLock Management via Group Policy

Microsoft SharePoint 2010 End User Quick Reference Card

isupport 15 Release Notes

Kaltura Extension for IBM Connections Deployment Guide. Version: 1.0

Moving the Web Security Log Database

MS MCITP: Windows 7 Enterprise Desktop Support Technician Boot Camp

Administrator s Guide

Identity and Access Management Integration with PowerBroker. Providing Complete Visibility and Auditing of Identities

How to Prepare for the Upgrade to Microsoft Dynamics CRM 2013 (On-premises)

Avatier Identity Management Suite

SageCRM 6.1. What s New Guide

How To Manage Inventory On Q Global On A Pcode (Q)

Remote Media Encryption Log Management

Exercise Safe Commands and Audit Trail

Altiris Asset Management Suite 7.1 from Symantec User Guide

DigitalPersona Pro Server for Active Directory v4.x Quick Start Installation Guide

DeviceLock Management via Group Policy

Backup and Restore with 3 rd Party Applications

HOUR 3. Installing Windows Server 2003

EMC Documentum Webtop

Automate Your BI Administration to Save Millions with Command Manager and System Manager

Alfresco Online Collaboration Tool

Affiliation Security

NYS Office 365 Administration Guide for Agencies

PROMODAG REPORTS 10 FOR MICROSOFT EXCHANGE SERVER. Reporting on Exchange made simple! Getting started

AWS Directory Service. Simple AD Administration Guide Version 1.0

Help File. Version February, MetaDigger for PC

FileMaker Server 14. FileMaker Server Help

User Management Tool 1.6

SharePoint 2013 Permissions Guide

Introduction to Directory Services

HOW TO SILENTLY INSTALL CLOUD LINK REMOTELY WITHOUT SUPERVISION

RSA Event Source Configuration Guide. Microsoft Exchange Server

Apache Sentry. Prasad Mujumdar

ContentWatch Auto Deployment Tool

WebSpy Vantage Ultimate 2.2 Web Module Administrators Guide

Wakanda Studio Features

Business 360 Online - Product concepts and features

Protected Trust Directory Sync Guide

Content Management Implementation Guide 5.3 SP1

Pcounter Web Report 3.x Installation Guide - v Pcounter Web Report Installation Guide Version 3.4

Owner of the content within this article is Written by Marc Grote

RSA Security Analytics

6.7. Quick Start Guide

SonicWALL CDP 5.0 Microsoft Exchange InfoStore Backup and Restore

Administrator s Guide

Setting up the Oracle Warehouse Builder Project. Topics. Overview. Purpose

Javelina Software, LLC 3524 South River Terrace Edgewater, MD USA

SMART Directory Sync Known Limitations

K7 Business Lite User Manual

Active Directory Manager Pro New Features

Identity Management with midpoint. Radovan Semančík FOSDEM, January 2016

Lesson One Creating the Website and the WordPress Process

Active Directory Management. Agent Deployment Guide

Installation and Configuration Guide

Tips and tricks for using SAP BusinessObjects Web Intelligence with SAP BW

Microsoft Outlook Reference Guide for Lotus Notes Users

Intel Internet of Things (IoT) Developer Kit

Tutorial: Building a Dojo Application using IBM Rational Application Developer Loan Payment Calculator

BusinessObjects XI R2 Product Documentation Roadmap

Why Upgrade to RightFax 10.5?

User Guide. Version R91. English

Creating Home Directories for Windows and Macintosh Computers

HP ALM. Software Version: Tutorial

NetWrix SQL Server Change Reporter

SonicWALL CDP 5.0 Microsoft Exchange User Mailbox Backup and Restore

Crystal Enterprise 9 Getting Started Guide

Upgrading a Single Node Cisco UCS Director Express, page 2. Supported Upgrade Paths to Cisco UCS Director Express for Big Data, Release 2.

EnterpriseLink Benefits

Wimba Pronto. Version 3.1. Administrator Guide

Top 10 Oracle SQL Developer Tips and Tricks

Course Delivery Educational Program Development Onsite Blackboard Training

Exclaimer Mail Archiver User Manual

CA SiteMinder. Policy Server Management Guide. r6.0 SP6. Second Edition

Websense Support Webinar: Questions and Answers

Transcription:

The New Grouper: Its New User Interface and More IAM Online September 10, 2014 Grouper Project Team Chris Hyzer, University of Pennsylvania Shilen Patel, Duke University Dave Langenberg, University of Chicago Emily Eisbruch, Internet2

Thank you to InCommon Affiliates for helping to make IAM Online possible Brought to you by Internet2 s InCommon in cooperation with the Higher Education Information Security Council 2

Open source, community-driven access management project enabled by Internet2, National Science Foundation, Universities, and Commercial Affiliates Let people & business processes manage access Designed for delegation and distributed management Groups and more express all kinds of access policies Dynamic, ad hoc, nested, Boolean Roles, permissions, attributes, rules Integratable with most any technology Connectors, APIs, loaders, shell, hooks, changelog,

Today s Agenda New User Interface Chris Other New Features Shilen Upgrading and Gotchas Shilen Provisioning Dave Q&A all along the way You guys 4

Today s Agenda New User Interface Chris Other New Features Shilen Upgrading and Gotchas Shilen Provisioning Dave Q&A all along the way You guys 5

Grouper new UI agenda Overview Screen design Dashboard Groups Entities Memberships Privileges 6

Grouper new UI overview Designed by Michael Girgis, experienced designer at University of Chicago Includes user experience testing Ajaxy (but bookmarkable and backbutton friendly) No struts CSRF protection Rich controls (DOJO) work better and are accessible (e.g. can be controlled with keyboard) Tree control Combobox (can use modal dialog instead) New libraries: e.g. bootstrap, less, font-awesome 7

Grouper new UI screen design Tree control Search Create objects Quick links Tabbed screens Filter and page results Hide buttons in menus 8

Grouper new UI dashboard Recent activity Widgets Recently used Favorites Services 9

Grouper new UI groups Show commonly needed attributes, hide the rest Show memberships by default (like lite UI) Easy to edit memberships Composites are easier Privileges much easier Can see where group is used 10

Grouper new UI memberships Can trace a membership to see what paths an entity has in a group Works for privileges too On the entities screen there are tabs for quick views into a subject s memberships or privileges Can quickly deprovision 11

Grouper new UI bulk assign Can add memberships / privileges from multiple entities to multiple groups at once Similar import to Lite UI 12

Today s Agenda New User Interface Chris Other New Features Shilen Upgrading and Gotchas Shilen Provisioning Dave Q&A all along the way You guys 13

Contents Other new features Configuration Overlays Services in Grouper UNIX GID Management Subject Security Realms Upgrade and Install Highlights and Gotchas Performance 14

Configuration Overlays Before v2.2, each configuration file would contain all properties including the default ones and your customized ones. Upgrades become challenging because you have to merge your configuration files with the new version to get new properties but also keep your custom ones. Many (but not all) of the configuration files in v2.2 use a new method to solve this problem. There is a base file that contains the default properties and then you have one or more override files. 15

Configuration Overlays (continued) For example: grouper.base.properties contains all the default properties. grouper.properties your custom properties go here. Another example: grouper.base.properties contains all the default properties. grouper.properties your custom properties that apply to all environments. grouper.local.properties your custom properties that apply to the current environment (test vs prod). 16

Services in Grouper The folder structure in Grouper can be difficult for end users to navigate especially in institutions that have a large number of groups and folders. An end user may just be interested in a particular folder somewhere in the hierarchy that contains objects that they can manage for a service. Or the objects related to the service may be in multiple folders. V2.2 allows tagging folders as a service to make them easier to find and manage. 17

Services in Grouper (continued) Services can be created using the lite UI. Services can be assigned to folders also using the lite UI. A services widget exists in the new UI that shows on the main page. 18

UNIX GID Management Groups, folders, attribute definitions, and attribute names are now assigned unique integers. Those integers can be used for UNIX GIDs. 19

Subject Security Realms Different users might have different privacy requirements for the Subject API. For instance admin users can see more data than regular users. (e.g. FERPA protected attributes) When calling search methods in the Subject API, callers can specify a realm that is used to adjust how the search takes place and what the results look like. The GrouperJdbcSourceAdapter2 source adapter in Grouper supports this feature. 20

Today s Agenda New User Interface Chris Other New Features Shilen Upgrading and Gotchas Shilen Provisioning Dave Q&A all along the way You guys 21

Upgrade and Install Highlights and Gotchas Before you upgrade: Be aware of legacy attribute migration. Be aware of new attribute privileges. Make sure you have enough tablespace. Check to make sure new unique indexes would be added without issue. Analyze your tables. Upgrading software and configuration Keep in mind that in Grouper 2.2 many configuration files use configuration overlay. Download Grouper 2.2 software and merge configuration. 22

Upgrade and Install Highlights and Gotchas (continued) Upgrading database Run command to produce SQL script. Execute SQL script Creates stem set table. Adds integer values for groups, folders, attribute definitions, and attribute names. Adds unique indexes for point in time audit tables. Adds new privileges. Backs up legacy attribute tables. Run a post install script (postgrouper2_2upgrade.gsh) Adds group sets for new privileges Migrates legacy attributes Populates stem set table. Fixes point in time audit due to new privileges 23

Performance Performance testing between v2.2 and v2.1.5. Environments loaded with 126K groups, 105K folders, 1 million memberships/privileges, and 585K permissions. Tests were run against several of the API methods. The numbers for both versions were largely similar. 24

25

26 26

Today s Agenda New User Interface Chris Other New Features Shilen Upgrading and Gotchas Shilen Provisioning Dave Q&A all along the way You guys 27

Provisioning Grouper à Downstream Grouper PSP for Active Directory / LDAP Voot (https://spaces.internet2.edu/x/ua35aq) Experimental Support for SCIM 28

Future Directions Junction for Provisioning Strategy Discussion on the grouper-dev list Post-PSP Provisioning wiki: https://spaces.internet2.edu/x/habkag 29

Today s Agenda New User Interface Chris Other New Features Shilen Upgrading and Gotchas Shilen Provisioning Dave Q&A all along the way You guys 30

Contributing to the Community Share info about your deployment on the Community Contributions page. Participate on the Grouper-Users List Starting point is the Grouper wiki: https://spaces.internet2.edu/ display/grouper/grouper+wiki +Home 31

Evaluation Please complete the evaluation of today s webinar https://www.surveymonkey.com/s/iam_online_september_2014 32

Register today for the Technology Exchange REFEDS, Advance CAMP, CAMP See the CAMP 101 and CAMP 201 schedules here: http://www.incommon.org/techex2014.html October 26-30, 2014 - Indianapolis, Indiana Complete Technology Exchange information here: http://events.internet2.edu/2014/technology-exchange/ 33

InCommon Shibboleth Installation Workshops Single Sign-on and Federating Software September 29-30 New Jersey Institute of Technology Newark NJ November 10-11 University of Utah Salt Lake City Details and registration at www.incommon.org/shibtraining 34

Thank you to InCommon Affiliates for helping to make IAM Online possible Brought to you by Internet2 s InCommon in cooperation with the Higher Education Information Security Council 35