1 access control and the student career mark norman, systems development and support team, oucs

9
1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

Upload: esther-blair

Post on 11-Jan-2016

213 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: 1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

1

Access Control and the student career

Mark Norman,Systems Development and

Support Team, OUCS

Page 2: 1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

2

Sysdev @ OUCS

• What do we do?

• Apart from authentication/authorisation services…• Email (Herald)

• Mailing lists system administration

• Web hosting sysadmin

• Linux shell service

• Version control (support for web sites and coding projects)

• Software mirror downloads

• News services

• Virtual learning environment (VLE – Weblearn) sysadmin

• Wikis sysadmin (for OUCS)

• Alumni e-mail forwarding service sysadmin

• Lots of dull back-end stuff for resilience and backup etc.

Page 3: 1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

3

Students and access control

• How many usernames and passwords do students need?

• Student Information Systems – self service

• Email

• Webmail

• College services

• Departmental services

• Athens (for external library resources)

• Desktop management systems

• HFS Backup password (graduates)

• Help centre username/password

• Weblearn

• Library resources/OXAM (VPN for)

• Personal web space

• Accounts for downloading software (e.g. Sophos, VPN clients)

• And Facebook, itunes, myspace etc. etc….

Page 4: 1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

4

Kerberos is the answer

• (Yes, the 3 headed dog!)• Kerberos (and Webauth) has meant that the following all

work from one username/password pair

• Student Information Systems – self service

• Email

• Webmail

• College services

• Departmental services

• Athens (for external library resources)

• Desktop management systems

• HFS Backup password (graduates)

• Help centre username/password

• Weblearn

• Library resources/OXAM (VPN for)

• Personal web space

• Accounts for downloading software (e.g. Sophos, VPN clients)

• And Facebook, itunes, myspace etc. etc….

Page 5: 1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

5

Kerberos is the answer

○ Not the complete answer (still need some other accounts)

• Student Information Systems – self service

• Email

• Webmail

• College services

• Departmental services

• Athens (for external library resources)

• Desktop management systems

• HFS Backup password (graduates)

• Help centre username/password

• Weblearn

• Library resources/OXAM (VPN for)

• Personal web space

• Accounts for downloading software (e.g. Sophos, VPN clients)

• And Facebook, itunes, myspace etc. etc….

◦ The following are all managed using the SSO system

◦ Password management is done via Webauth

Page 6: 1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

6

Kerberos is the answer

○ Athens is being superseded by Shibboleth (uses Kerberos/Webauth)

• Student Information Systems – self service

• Email

• Webmail

• College services

• Departmental services

• Athens (for external library resources)

• Desktop management systems

• HFS Backup password (graduates)

• Help centre username/password

• Weblearn

• Library resources/OXAM (VPN for)

• Personal web space

• Accounts for downloading software (e.g. Sophos, VPN clients)

• And Facebook, itunes, myspace etc. etc….

• Student Information Systems – self service

• Email

• Webmail

• College services

• Departmental services

• Athens (for external library resources)

• Desktop management systems

Page 7: 1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

7

• Student Information Systems – self service

• Email

• Webmail

• College services

• Departmental services

• Athens (for external library resources)

• Desktop management systems

Kerberos is the answer

○ A lot more web based services are now using Webauth

• HFS Backup password (graduates)

• Help centre username/password

• Weblearn

• Library resources/OXAM (VPN for)

• Personal web space

• Accounts for downloading software (e.g. Sophos, VPN clients)

• And Facebook, itunes, myspace etc. etc….

Page 8: 1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

8

• Student Information Systems – self service

• Email

• Webmail

• College services

• Departmental services

• Athens (for external library resources)

• Desktop management systems

Kerberos is the answer

○ Some desktop systems can use kerberos cross-realm trust (e.g. Active Directory)

• HFS Backup password (graduates)

• Help centre username/password

• Weblearn

• Library resources/OXAM (VPN for)

• Personal web space

• Accounts for downloading software (e.g. Sophos, VPN clients)

• And Facebook, itunes, myspace etc. etc….

Page 9: 1 Access Control and the student career Mark Norman, Systems Development and Support Team, OUCS

9

• Student Information Systems – self service

• Email

• Webmail

• College services

• Departmental services

• Athens (for external library resources)

• Desktop management systems

Kerberos is the answer

○ And we have high hopes for Oracle too!

• HFS Backup password (graduates)

• Help centre username/password

• Weblearn

• Library resources/OXAM (VPN for)

• Personal web space

• Accounts for downloading software (e.g. Sophos, VPN clients)

• And Facebook, itunes, myspace etc. etc….