|
|
Metadirectory Technical Status Meeting
https://fsuid.fsu.edu/admin
10/5/2004
- Project
Status
- Redirected non-FSUID logins directly to FSUID
password reset; added “last login” timestamp (shows last LDAP
authentication from any app) on personal & helpdesk pages. The FSUID home page is now leaner and
meaner (hopefully easier to navigate).
New buzz phrase: “What’s my FSUID?”.
- Added FSUSN view page (only if FSUSN is
populated). FSUSNs to be
populated “any day now”. FSUSNs
will have to use upper case letters, due to mainframe restrictions..we
could just allow case-insensitive letters in any FSUID pages.
- 8/15/2004: Getting ready to migrate IS Secure
Login to use “native” FSUID and eDir, rather than ldap2 (http://admin-c6140-10.uc.fsu.edu:8080/SecureLogin/login
or devo3.ais.fsu.edu/SecureLogin/login).
Note the FSUID advertisements on the IS pages.
- Working out procedure for the ability of Secure
Login to create CARS usernames (and thus FSUIDs) directly at time person
registers account, rather than waiting for the backends to catch up.
- Last details of how to reset College of
Medicine WinAD passwords via LDAP: waiting on OTI Windows group to set up
AD-wide cert (at the ad.fsu.edu level) so the COM can just use it (at the
med.ad.fsu.edu level).
- Met with School of Music folks about their
enterprise identity needs (mostly Windows-based services); still working
with figuring out dynamic groups for “sub-root” access to tech-savvy
departments (FilmSchool, for example).
- Action
Items
- Vote on horizontal *vs* vertical layout of
Outlook/host name authentication, where ever it occurs within FSUID web
pages
- Vote on “minimzing” the non-FSUID
authentication methods…make them only allow reset of FSUID password and
not full access to all FSUID pages?
- [IS]
Re-design CARS pages to match look & feel of FSUID pages. This has been transformed to now read:
design FSUID pages to match the look & feel of FSUID pages but to do
the functionality required for the existing CARS pages.
- Fran has agreed to modify UCS/CARS password
change algorithm to match modified FSUID password change algorithm – this
means one could use special characters in the first character
position. A proposal has been
floated to relax the special character, given the strong “obvious value”
algorithm.
- [UCS,
IS] Integrate FSUID management closer to CARS (e.g., when person
changes CARS password or user name, immediately
change it in the eDir!)
- [IS]
Write web-based documentation explaining how to use eDir for
authentication (pure LDAP, UNIX passwd file, RADIUS, Apache auth_ldap,
etc.)
- [IS] Write Perl “LDAP failover”
module; get mod_perl working on fsuid.fsu.edu.
- [IS, ODDL] Connect C.A.S. to
Secure Login, Blackboard & FSUID, all pointing to eDir.
- [Group – longer term] Continue
working SSN à FSNSN replacement discussions with campus .
- Populate/associate Novell account information
into eDir (still need a Novell
proxy admin account))
|