Skip to Content.
Sympa Menu

grouper-study - Re: U-M's TIER CSP Grouper Project Plan

Subject: grouper-study

List archive

Re: U-M's TIER CSP Grouper Project Plan


Chronological Thread 
  • From: Aimee Lahann <>
  • To: Keith Hazelton <>
  • Cc: thompsow <>, "" <>, "Waldbieser, Carl" <>
  • Subject: Re: U-M's TIER CSP Grouper Project Plan
  • Date: Tue, 19 Dec 2017 14:49:08 -0500
  • Ironport-phdr: 9a23:EtjiIh8jsdk8df9uRHKM819IXTAuvvDOBiVQ1KB20ewcTK2v8tzYMVDF4r011RmVBdyds6oMotGVmpioYXYH75eFvSJKW713fDhBt/8rmRc9CtWOE0zxIa2iRSU7GMNfSA0tpCnjYgBaF8nkelLdvGC54yIMFRXjLwp1Ifn+FpLPg8it2O2+54Dfbx9UiDahfLh/MAi4oQLNu8cMnIBsMLwxyhzHontJf+RZ22ZlLk+Nkhj/+8m94odt/zxftPw9+cFAV776f7kjQrxDEDsmKWE169b1uhTFUACC+2ETUmQSkhpPHgjF8BT3VYr/vyfmquZw3jSRMNboRr4oRzut86ZrSAfpiCgZMT457HrXgdF0gK5CvR6tuwBzz4vSbY6SKfR+Y7jdfcsESmVdQsZfWStBAoamYIsOCeoKIOJUoob5qlcLqxa1GAuiC/71yjJQhHD206003eoiHw/bwgIvA8kDv27IoNjvLqoeTfy5wavOwD7eb/1WwzD96I3Qfx09oPGMWKx/ftTMwkcpDQzFjk+fqYrjPziI0ekCqWmb7+9+Wu2xj24otQRxryOyxscpi4nGmoIVxkra+ipk3YY4PNu1Q1N1b96jFZtfrSCaN41uT8MtRGFovyk6yrkYtpKhYCcKz5EnywbQa/yGb4iI4g/jW/2LLThkg3Jlfaqzhhiz8Ui71uLwTNe730tXridDj9LCtWgN2gTN5sWGVvdw/EKs2TiM2g/I9u1JJE85mbbHJ5Mvx7M/ioYfvEXGEyLzhkn6kqGWe0M58eay8evneK/pppqEOo90lA7+NqMul9S6AesiMwgOW3GX+eO91LH/5EH4T6tGguM4kqXDv5DaIsMbpqG9AwBLyIos9xG/DzK+3NQZm3kIMk5FdQqZg4XoJ13DIvX1Dfm8jlu3jDtmwv/LMqH9DpjDK3XMjKvtcLd45kNZ1gY/095f64pRCr4bIfLzXkHxtMbfDh88KwG72efnCNBj2YwAXWKAHKqZPbjPsV+N5+IgP+mMaJULtzngNvgp/+TugmMhmV8BYamp2oMaaH+iHvRhPkWZeWTjgs0YHWcRogo+UfHliV2ZXD5XZnayRL485iolBI68DIfDQJytj6Kb3Ce9AJJWen5KBkqSHnj1aoXXE8sLPQGfI9Nh2hwNR7WlV4gnnUWtuQ7my/xnJ/jZ/jEfs7r81cN+oeDfiEdh2yZzCpG00mSAQilQl2MBQTl+iKl+pEFwzlqG+bV9gvdYU9Ff+qUaAU8BKZfAwrkiWJjJUQXbc4LMFQ+r

Great!

We will mention we are pulling something together to the larger TIER group on the call today.
I will send out a doodle poll to the grouper-study group for dates in January.

I'll take you up on the scribe help as well. thx!


On Tue, Dec 19, 2017 at 2:41 PM, Keith Hazelton <> wrote:

If possible, I’d like to sit in on this call. I can offer to help with scribing meeting notes.   --Keith

___________________________________

email & jabber:

calendar: http://go.wisc.edu/i6zxx0

 

From: <> on behalf of Aimee Lahann <>
Date: Tuesday, December 19, 2017 at 13:29
To: Bill Thompson <>
Cc: "" <>, "Waldbieser, Carl" <>
Subject: Re: U-M's TIER CSP Grouper Project Plan

 

Okay - will do!

 

Have fun!!

 

On Tue, Dec 19, 2017 at 2:20 PM, thompsow <> wrote:

Sounds good. We can’t be all the call today (holiday parties!), but if you want to propose and host, we will definitely particpate.

 

Best,

Bill

 



On Dec 19, 2017, at 2:12 PM, Aimee Lahann <> wrote:

 

Thanks again, Bill.

 

Super helpful.  

 

We would welcome hearing about your reference groups and current approach to grouper security.  How about a breakout session call targeted to all those interested in the topic instead of using the time with the whole TIER group?  I would be happy to organize the call and provide any notes back to the larger TIER Group if you would present on the topic. :)

 

Aimee

 

On Tue, Dec 19, 2017 at 10:00 AM, thompsow <> wrote:

Great questions! :)

 

I don’t have any docs handy to share with you, but we’d be happy to review our reference groups and current approach to grouper security, perhaps on a tier call sometime soon. Access to our implementation is fairly limited at the moment, and mostly consists of the IAM team and small cohort in central IT. Though we do have some users, who are not in IT, maintaining reference groups and exceptions via the Grouper UI. 

 

Generally we let the access policy requirements drive what reference groups we have. I should also point out that broadly we have two types of reference groups based on scope (institutional and application specific). So far there has been ample need/requests from central IT to make this mostly an IAM team driven process.

 

Carl maintains a set of python scripts we use to help maintain our security model, folder structures, etc. He’s published those to GitHub here: https://github.com/cwaldbieser/grouper_jython_scripts.  These only work if you install the Shell Wrappers for Grouper. Perhaps if there’s enough demand we could get the project to include support for jython scripts and possibly include these in the base install.

 

We’ve also started to sketch out a TIER security model chapter for the next revision of the development guide. Feel free to comment on that doc and add your questions/thoughts.

 

Best,

Bill

 



On Dec 7, 2017, at 3:52 PM, Aimee Lahann <> wrote:

 

Thanks, Bill. Your feedback is helpful.  

 

Do you have any documentation about your approach to Grouper security?  We are interested in learning about security in the context of limiting who can see which group members - especially in the case of course groups due to FERPA regulations. Security concerns are one of the reasons we are first exploring only departmental groups with staff members. We would be interested in helping to refine the security piece of the Deployment Guide.

 

How are you receiving your use cases/ policy requirements?  Are administrators in departments and/or application owners contacting you/your staff directly with requests?  Do you create the reference groups, build groups from them according to end-user requirements and then provide end-users an interface to include or exclude members to the group?  What are some of your use cases?  How did you begin? Could we talk to you more about this?

 

We would like to provide data-driven groups that are useful to users to create access control groups. Somehow we are a little stuck analyzing what reference groups are useful and how to offer groups to whom.  

 

Now you have opened the floodgates...

 

Thanks for your help!

Aimee

 

 

 

On Wed, Dec 6, 2017 at 4:32 PM, thompsow <> wrote:

HI Aimee,

 

The workstreams look reasonable. Our original implementation took about 3 months calendar time to implement a very specific use case (VPN access).  Since then, we have let our use cases/policy requirements drive any additional basis/ref groups that we have added.

 

I wouldn’t worry too much about getting all the basis/ref groups right at the start. These are fairly easily to refactor in Grouper. Recommend focusing on a specific access policy and start with that.

 

One thing you'll want to give some thought to is the security model for Grouper itself. This isn’t discussed much in the Grouper Deployment Guide. Might be an opportunity for us to refine that and include something in the next revision.

 

Best,

Bill

 



On Dec 6, 2017, at 3:19 PM, Aimee Lahann <> wrote:

 

Hi.

 

We would like to share U-M's plan for our CSP Grouper project with the Grouper cohort for feedback.  The Google document, TIER CSP Grouper Project Plan -DRAFT is currently a list of workstreams with milestones/tasks. Our original intent was to focus on identifying the work involved. Dependencies and order of operation are not yet noted. However, we have made time estimates for each workstream.

 

We would love to see others' Grouper project plans so we can learn how to improve our own.

 

(I apologize if you already received this email already.  I realized I originally sent it to the umich grouper study email group instead of the more recent Internet2 group email.)

 

Thanks!

 

Aimee Lahann

ERP Business Systems Analyst Senior

Identity and Access Management Team

University of Michigan



 



 

--

Aimee Lahann

ERP Business Systems Analyst Senior

Identity and Access Management Team

University of Michigan



 



 

--

Aimee Lahann

ERP Business Systems Analyst Senior

Identity and Access Management Team

University of Michigan



 



 

--

Aimee Lahann

ERP Business Systems Analyst Senior

Identity and Access Management Team

University of Michigan

(734) 764-5641






--

Aimee Lahann

ERP Business Systems Analyst Senior

Identity and Access Management Team

University of Michigan

(734) 764-5641





Archive powered by MHonArc 2.6.19.

Top of Page