Please enable JavaScript.
Coggle requires JavaScript to display documents.
BEIS (Key Concepts (Access management (Trusted based authentication…
BEIS
Key Concepts
-
Access management
-
-
-
-
Does not control what the users is authorized to do after system access is granted. This is done by the application.
-
-
-
Common Architecture
-
Roles
Authoritative
Banner feeds the central idenity vault. Identity Events in Banner cause a central SPML Request Authority (RA), the Banner Identity Proxy, to make provisioning requests to one or more Provisioning Service Providers (PSPs)
Non-Authoritative
Data changes in the central identity vault are sent to Banner. Banner is a Provisioning Service Target (PST) that receives provisioning requests from its PSP, the Banner Identity Gateway.
-
Central Identity Vault
-
Authoritative Apps (Banner, ERP) feed the central vault
Changes stimulate the provisioning and processioning of accounts in other enterprise applications based on established rules.
-
-
Components (Middleware)
-
-
Banner Identity Proxy
-
-
Update defined Provisioning Service Targets via web services communication with their associated Provisioning Service Providers (PSP)
SSO Manager
-
-
Provides services for other Ellucian products to facilitate claims based auth based on UDCIdentifier
-
-
-
Configurations
-
-
Single Sign On (SSO)
-
-
-
CAS-based authentication
-
Service validates the CAS session and provides the identity of the user to the SSO Manager in an XML format.
SAML 2.0 authentication
SSO Manager supports the Security Assertion Markup Lanaguage 2.0. Standard for the exchange of authentication and authorization data.
-