One thing that bothers students and teachers most about the school is too many accounts. The teaching system, a library, a mailbox, now even WiFi has to register an Internet account separately. Repeating numbers are not just trouble but also security risks: the same student may use five different passwords in five systems, three of which are weak orders. Connecting the school's WiFi nitshell_AUTH_BILLING system and campus-uniform identity certification to allow teachers and students to go through the school with a set of account numbers, which is no longer a sub-class, but rather a basic building requirement.
What exactly does a U.S.I. identify?
National universities and a number of primary and secondary schools have built a single identity certification platform, most of which is based on standard protocols such as LDAP, CAS, OAuth2 or closer ODS. The interface should be followed by an understanding of what the school platform supports, which interfaces are exposed to, and whether there are existing developers ' files. Some schools have consolidated identifications that were bought many years ago for commercial products, and interface documents are not available, so then contact the factory or IPO to extract the interface parameters from the configuration.
Steaking with standard protocols is steady compared to private interfaces
We strongly recommend standard protocols, not to quickly connect the company with a private synchronous interface. The private interface is that once the UID has been upgraded, the docking breaks up and often leaves no false hints, except that students may not go on. Based on OIDC or CAS interfaces, the authentication platform issues the token to the school WiFi online Authentication & Billing system, which uses a sign to verify user identification, and has a mature library that can be reused and easily located. If the school ' s uniform identity is only available for LDAP queries, then the LDAP binding certification is done on the side of the system, at least to ensure that account numbers and passwords are consistent.
The account properties need to be clearly mapped
It's not just the hook."Accessible"The roles of students, teachers, visitors are completely different from the calculation strategy. Students may go on a basket for months, teachers will be free and visitors limited in time. The unified identification usually includes user types, faculties, school names, and the billing system is able to read and map the characters properly inside. The wrong mapping can make jokes, such as identifying principals as visitors, and limiting access to the Internet to two hours. It is suggested that each role be checked with a series of test accounts before the line, confirming properties in synchronizing.
The account life cycle needs to be synchronized
Schools are mobile, with new students enrolled in school, graduates from old age and transfers of teaching staff changing their status in the context of a unified identity certificate. If the billing system is not synchronized, the student account number for three years of graduation can continue to be connected to the Internet, both as a security risk and as a result, and it must be checked whether a change of status can be obtained or the deactivated account number is banned at the expense of the billing rate. Many schools have ignored this, adding tens of thousands of zombie accounts to the fee system over several years, and annual renewal authorization is paid on a peak basis for nothing.
The fault isolation is more important than the perfect docking.
Finally, the UIS itself is also a failure. If the billing system relies entirely on it for real-time authentication, WiFi will be collectively disjointed once it has been released. A sure way to do this is to create a local cache or downgrade strategy: if the CRS is not available, the last valid certificate retained locally by the system will be allowed to be temporarily released and sent to alert security. So single-point malfunctions will not turn into full school breakout networks. The school WiFi online Authentication & Billing system and the HUILING interface are essentially entangled to allow the UIS accreditation system to operate."An identity."It runs through the school, but it is necessary to leave a way back on the project and not place all the eggs in a certification service.
Test environment first runs to produce.
The right approach is to set up a separate testing environment, using a batch of analogies to get all login, attribute mapping, state synchronization, and failure downgrades through a series of login, feature mapping, and confirmation of the correct re-cuting. We have seen schools directly retool the certification profile online, resulting in one wrong call address, which will be out of the Internet for half an afternoon. The time spent on testing the environment is far less than the cost of processing a production accident, and this is how we do it first.
The matching documents and keys are kept separately.
The sensitive information that will be generated during the connection, such as interface addresses, application keys, certificates, is just as important as the teacher-student account, and once leaked, the attackers can fake a school WiFi web-based NATSHEL_AUTH_BILLING system to defraud the token. These documents are stored in the key management facility of the school, not in the official text of the implementing document, nor in personal mailboxes.