110 likes | 269 Views
Enabling Cloud Services & Federated Authentication UPN & Email Infrastructure Changes. Chris Pruess ITS AIS Directory & Authentication Services. Strategic Plan. Goal 3: Support evolving identity management and information security requirements .
E N D
Enabling Cloud Services &Federated AuthenticationUPN & Email Infrastructure Changes Chris Pruess ITS AIS Directory & Authentication Services
Strategic Plan Goal 3: Support evolving identity management and information security requirements. • Strategy 3: Strengthen HawkID identity verification to meet evolving campus authentication and external federation service requirements. • Roadmap: Federated Authentication and Provisioning for Cloud Service Investigations and Deployments
UPN Background • What is the User Principal Name? • Internet-style login name for a user • name@domain (RFC 822) • HawkID@ui (HawkIDs in UI AD Forest) • Enforces uniqueness of IDs across the forest • Historically supported multiple-domain model • Now sets scope for “active” HawkID searches
Cloud Requirements • UPN must match domain name for federated services. • eduPersonPrincipalName (eppn) is the username attribute for use in the federation • User IDs must be scoped to the institution • hawkid@uiowa.edu • UPN should match user’s email address. • hawkid@uiowa.edu
1. UPN must match domain name for federated services • Change the UPN suffix on the HawkIDfrom “ui” to “uiowa.edu” • Domain Scope: • Iowa domain is our federation domain • “ui” UPN suffix is only in the Iowa domain • ID Scope: HawkIDs; no automatic change to Service IDs • Change is mostly a back-office change
UPN Change: Impact • Identify Potential Local Impact Points • Domain/Workstation/OWA Login Style • Iowa\hawkid (will continue to work) • hawkid@ui (will break) • Adopt Consistent Login: hawkid@uiowa.edu • Locally-developed application authentication • Kerberos, NTLM V2, LDAP Authentication • Shibboleth, HawkID Login Tools will manage the change
2. UPN should match user’s email address • Support mail delivery to hawkid@uiowa.edu • Common address format in higher education • Common experience with consumer services • Users sign up & login with email address • Extend our mail routing with hawkid@uiowa.edu delivery addresses • Mail alias (firstname-lastname@uiowa.edu) will continue to be supported • Initially, multiple aliases will be delivered to same (single) mailbox • Still evaluating Exchange options
Projected Timeline • UPN Change • 6/9/2012 (Infrastructure Day) • Dependent on Tool and Application Updates • Mail Routing Change • August 2012 • Dependent on Mail Routing Upgrade Project • Replaces Ph with LDAP
Communication Plan • CITL • AD Infrastructure Support Groups • ITS Spotlight, Help Desk • Communities • Application Developers • ITADmins • Webmasters • Researchers
In the Cloud Thinking What do you think?