50 likes | 133 Views
David Walker Information and Educational Technology University of California, Davis DHWalker @ ucdavis.edu. Authorization in UCTrust. The Problem. How do we authorize people to use applications via UCTrust? Two possible scenarios
E N D
David Walker Information and Educational Technology University of California, Davis DHWalker @ ucdavis.edu Authorization in UCTrust
The Problem • How do we authorize people to use applications via UCTrust? • Two possible scenarios • Campuses make authorization decisions and transmit them to applications • Application management makes authorization decisions, based on identities provided by campuses
Some Definitions • Affiliation / group – A person's relationship to the organization • Student, employee, PS201 class member, ... • Role – A person's purpose for the organization • Low-value purchaser, IdM administrator, parent, ... • Entitlement / permission – Something a person is allowed to do • Access library materials, view general ledger, ...
The Big Picture (I Think) App IdM App App Signet Grouper App KIM Shib App IdM App AuthN App IdM Signet Grouper Auth Srcs Signet Grouper
CO-Manage Demo • http://middleware.internet2.edu/co/tour/index.html