20
LDAP for Authentication LDAP for Authentication and Authorization @ UH and Authorization @ UH Info. Tech. Svcs. University of Hawaii Russell Tokuyama 10/03/00 University of Hawaii © 2000

LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Embed Size (px)

Citation preview

Page 1: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

LDAP for AuthenticationLDAP for Authenticationand Authorization @ UHand Authorization @ UH

Info. Tech. Svcs.

University of Hawaii

Russell Tokuyama 10/03/00University of Hawaii © 2000

Page 2: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

What is LDAP?What is LDAP?

lLightweight directory accessprotocol

lClient-server protocol fordirectory service (e.g., X.500)

lSchema and transport

lStandards based

Page 3: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

What is a directory What is a directory svcsvc??

lCentral information source, likewhite pages phone book

lPrimarily lookup, read often

l Infrequent writes

lNot a relational database

Page 4: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Why a central Why a central dirdir??

lM inimize duplication ofinformation

lReduce errors due to copyingand multiple sources

lSingle identifier (ID) for user

Page 5: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Why not central Why not central dirdir??

lFERPA (confidentiality ofstudent’s information)

l Don’t trust others with the datal Fear of big brother

l Fear of fall ing into wrong hands

l But managable with planning

Page 6: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Why central LDAP?Why central LDAP?

lMany roles at several campuses

lCommon source of informationfor users and applications

lEnables Web-based servicestailored to users’ needs

lStd protocol for client access

Page 7: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Why central LDAP? Why central LDAP? ((contcont))

lUser authentication

lAccess control (authorization)

lConfigurability

lCore services

lSingle, well-managed passwordimproves security (universal ID)

Page 8: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

ITS UsernameITS Username

lStudents in credit classes

lOutreach students

lFaculty

lStaff

lClinical staff

Page 9: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

ITS Username ITS Username ((contcont ))

lRCUH

lE W C

lVisiting faculty

lProfessor Emeritus

lSpecial programs with approval

Page 10: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

UNISON UNISON (previous)(previous)

UNISON

A/R

OHR

R C U H

E W C

UHF

UHUNIX

ModemPool

PA`E

NIS

FTP

ID + passw

ord

Page 11: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Got LDAP?Got LDAP?

lStudent Employment andCooperative Education

lOHR’s Historical LeaveInformation

lmore to come...

Page 12: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

What’s in LDAP?What’s in LDAP?

luid (ITS username)

lpassword (UNIX encrypted)

lname (last, first, middle)

l alternateID (SSN)

l affiliation (faculty, staff, student)

lhomeCampus

Page 13: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Central LDAP Central LDAP (current)(current)

UNISON

LDAP

Central

LDAP

WebMai l

UHUNIX

OHR Leave

SECE

Modem

Pool

ID + passw

ord

Page 14: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Central LDAP Central LDAP (future)(future)

UNISON Central

LDAP

WebMai l

UHUNIX

OHR Leave

SECE

Portals

Web Apps

Modem

Pool

Page 15: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

What/who will use it?What/who will use it?

lWireless LAN access

lNew Web applications

lPortals

lRoaming profiles

Page 16: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

What’s next?What’s next?

l Improve data collection andprocessing for UNISON

lUH Portal

lWeb registration for the CCs

lDigital signatures

lElectronic approvals

Page 17: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

What’s I2 got do w/ it?What’s I2 got do w/ it?

lM iddleware infrastructure

lEarly Adopters program

lEduPerson

lDirectory of directories

lUniversal identifiers

Page 18: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Those other guys?Those other guys?

lLDAP allows any other backend

lActive Directory Service (ADS)

– tight Win2K integration

lNovell Directory Service (NDS)

– tight Novell integration

Page 19: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

LinksLinks

lLDAP: Use as Directed– http://www.data.com/990207/ldap .html

l An LDAP Roadmap & FAQ– http:/ /www.kingsmountain .com/ldapRoadmap .

shtml

l Mark W ahl's LDAP FAQ– http:/ /www3.innosoft .com/ldapworld /ldapfaq .ht

m l

Page 20: LDAP for Authentication and Authorization @ UH · LDAP for Authentication and Authorization @ UH Info. Tech. Svcs. University of Hawaii ... lStd protocol for client access. Why central

Links Links ((contcont))

l ITS Username– http:/ /www.hawaii.edu/infotech/yourusername.

h tml

lLDAP v2 (RFC 1777, 1778, 1779)

lLDAP v3 (RFC 2251, 2252, 2253)

l ITS LDAP Team– russ@ hawaii.edu