50 likes | 139 Views
Learn about authorizing application use via UCTrust, understanding affiliations, roles, and entitlements. Explore scenarios and make informed decisions. Enhance application management efficiency.
E N D
David Walker Information and Educational Technology University of California, Davis DHWalker @ ucdavis.edu Authorization in UCTrust
The Problem • How do we authorize people to use applications via UCTrust? • Two possible scenarios • Campuses make authorization decisions and transmit them to applications • Application management makes authorization decisions, based on identities provided by campuses
Some Definitions • Affiliation / group – A person's relationship to the organization • Student, employee, PS201 class member, ... • Role – A person's purpose for the organization • Low-value purchaser, IdM administrator, parent, ... • Entitlement / permission – Something a person is allowed to do • Access library materials, view general ledger, ...
The Big Picture (I Think) App IdM App App Signet Grouper App KIM Shib App IdM App AuthN App IdM Signet Grouper Auth Srcs Signet Grouper
CO-Manage Demo • http://middleware.internet2.edu/co/tour/index.html