|
|
Metadirectory Technical Status Meeting
https://fsuid.fsu.edu/admin
4/19/2005
- Project
Status
- “ndsd” core dump on mdsoti update: Still waiting (sent “bug email” this
AM).
- “directory.fsu.edu” is now “ldap.fsu.edu. Jan Townsend pointed out a difference
between attributes displayed using anon bind between Eudora and Outlook
(perhaps more Outlook-style attribs still need to be populated?)
- CARS <= => FSUID bridge components:
- cars_dba.cars_utils.get_uuid(:ssn): returns a CARS UUID
- cars_dba.cars_session.session_new('fsuid','IPADDRESS',:session_id); needed for
future “write” operations, such as newaccount
-
cars_dba.cars_utils.newaccount(:session_id,:uuid,:req_type,NULL,NULL,:cleartext,:crypt,
:login,:hoststr,:out_notice);
- session_id
- req_type == ‘STAFF’ or ‘STUDENT’
- ‘T’ == “id only” (no garnet/mailer acct); ‘F”
or NULL == “create accounts”
- NickName, if desired (used by username
creation algorithm)
- Cleartext password
- Crypt() password
- :login == returned value (username; limited
to 8 or full?)
- :hoststr == returned value of allowed hosts
- :out_notice == status text message (various
fields)
- Still need:
- FSUID account management pages to replace
account creation & management functions at http://cars.acns.fsu.edu; hook
into “Activate my FSUID” already existing page with “auto
determination” of STAFF or STUDENT?
Use hourly CROSOVR2 table, DATA_SHARE, PS_EMPLOYEE to get most
current “facts” on a person (CARS lag problem?)
- Mechanism for creating UUIDs?
- Mechanism for setting free dialup access?
- Mechanism for vacation notification?
- Mechanism for setting email forwarding?
- Mechanism for setting email privacy flag?
- “test” CARS instance
- Secure channel for all PL/SQL traffic
- Tweaks to load-mods-mds.pl (disable FSUID
creation of CARS accounts)
- FSUID ßà Win AD identity management work for UCS TEC,
US WSG & College of Medicine.
Wolfgang Adolph is also interested. TEC is almost done.
- “Bb as
Portal”: Have http://staging.campus.fsu.edu
almost ready to go with authentication against the test eDir MDSDEV.
- Action
Items
- Set up “account disable-izer” script to clean
up Windows AD accounts on a per-domain basis (former students, employees,
etc.).
- Set up an “account disable-izer” script for
former employees (compare daily PeopleSoft HR extracts).
- [Group – longer term] Continue
working SSN à FSUSN replacement discussions with campus. Pushing in IS out to customers to
start using FSUSN which is now populated in USER_ACCOUNT. Latest:
New on-line grade submission now uses FSUSN!
|