160 likes | 241 Views
User-administration system (BAS) at the University of Oslo. Creating of a single user-administration system for University of Oslo By Bård Henry Moum Jakobsen. University of Oslo (UoO), Norway. 32 000 students 6 000 fac. & staff 4 000 other!
E N D
User-administration system (BAS) at the University of Oslo Creating of a single user-administration system for University of Oslo By Bård Henry Moum Jakobsen
University of Oslo (UoO), Norway • 32 000 students • 6 000 fac. & staff • 4 000 other! • 35 431 users in one user-management system UREG2000 • Ca 1 600 computers for students • Win*, MacOS, Linux, mm • almost 9 000 computers…
What is an User administration system (BAS) Student registry BAS Persons Users Personal registery
BAS BAS AT (LDAP) SR (FS/MSTAS) Other HR
User administration system (BAS) • Person • unique ID • Name • Address • Affiliation • User • Username (UID) • Password • Mail address • Home dir • Group • Group ID (GID) • Comment • Members • - users • - other Groups
UoOs BAS, UREG2000 • A SQL (Oracle) database • API in Perl5 • A collection of programs (mostly Perl5) for managing users and attributes • Procedures for extracting information from LT (UoOs HR-system) and FS (UoOs Student registry) • Printer accounting!
More… • Creates: • NIS (2 domains) • AD (win2k) • LDIF • IMS Enterprise • Domino Directory • Tivoli • Remedy ARS • Exim (mail) • Mailman (mail-lists) • etc
LT – HR-system (i) • Gives UREG: • Organizational units • SKO – unit number • Made national by our national Student registry system • 4 parts • Institution (‘\d{4}’) • Faculty (‘\d{2}’) • Department (‘\d{2}’) • Group (‘\d{2}’) • Organization unit Name • Phone, fax, URL, email (for the unit) • Addresses (Snail-mail and physical address)
LT – HR-system (ii) • Gives UREG • Person • National id-number (Social security number) • Name • Org.unit • Type (Faculty, Staff, other) • Problem: It takes time to register a person, to much time… • Gets from UREG • Email-addresses
FS – Student registry • Gives UREG: • Persons • National id-number (Social security number) • Name • addresses • Curriculum • Gets from UREG • Email-addresses
LT FS BOFH Ureg2000 LDAP UA (Adgangskontroll) Notes Exim/Mailman NT LMS (CF) Tivoli PRISS NIS (UiO) ARS NIS (IfI) AD (W2K) Radius
UREG (or BAS) creates • Userid/shortname ’baardj’ (unix-username) • Username in NIS • Loginname in AD • UID in LDAP (for MacOS X) • Groups, general group basic • Creating Filegroups • Creating netgroups • Creating AD groups • Creating Notes groups • Creating mailinglists
Is this a PKI? No! • But it is a requirement for a functional PKI. • We are not a CA (to much work) • But we need certificates for persons, roles, organizations, units and servers. • External CA for persons, internal for all others. • We need a map from ID in persons certificates to an uniq id at the University, which CA is secondary
More? Contact us! • Bard.Jakobsen@usit.uio.no • +47 22852778 • Foils: http://folk.uio.no/baardj/pres/GNOMIS-eng.ppt