Go to Main Contents

:: Industry developments

How does campus network certification system fit into the school's uniform identity?

When the school gets to a single identification platform, it's almost an answer to the question whether or not the web certification system is connected. Ideally, teachers and students use an account to access teaching services, email boxes, and Internet.

Your position:Home > Content Centre > Industry News > > Text

When schools have access to the UIS, it is almost a question-and-answer system. Ideally, teachers and students use an account number to enter teaching services, email boxes, and Internet, without having to keep several passwords in mind. But when they arrive, many schools find that these two systems are time-specific, different manufacturers, data models are not consistent, interface standards are inconsistent, and there are more holes than expected.

Let's just get to the point."Account"Or..."Authentication"

A lot of people talk about the hooking."Synchronize the account numbers."But the bottom line is two layers: one is a reconciliation of account numbers, allowing the network-certified account to be identified as a single source; the other is a matching of authentication capabilities, enabling students and teachers to access the Internet directly using the same identity platform ' s support, without having to do the same again. These levels are very complex. Just do the account synchronization, and change the script to it; for certification, you have to get a standard single point log-in protocol, with the volume and acceptance criteria completely different. Before you need to know which floor you want, so that the manufacturer makes a subprime claim, you think you've got the full set.

Most common is the sync of a time account.

For most schools, the highest value-for-money option is timed synchronization. The HID platform regularly passes to the web certification system for both students and teachers, which only recognizes these accounts, and the password strategy is managed upstreamly. This way it is less costly to adapt, so that problems are checked because the two-side account numbers are"Copies of individual tubes"The disadvantage is that the password has been changed to wait for the synchronous cycle to work, and the urgent students and teachers may have to wait a few minutes. But in school scenes, these minutes are usually accepted, so we generally recommend that small and medium schools prioritize this path.

If you want to experience it, you have to get a standard single-point login.

If the school really wants to have students and teachers..."One access point."The usual practice is to use standard id protocols to jump online authentication pages to the UID platform for verification of documents and verification of release. This path is best, but only if the UID itself supports external issuance of certificates and the network certification system is properly consumed. We have seen two months of project cards, and the problem is that there are no user type identifiers needed on the side of the web in the field returned by the UID, which leads students and teachers to be assigned to a wrong access strategy.

Field alignment is more grinding than interfaces

The connection is often not unconnected, but in the field."School number"And the side of the network."Internet account"Is it the same thing, whether or not to keep an Internet access number for ex-service employees, how do temporary staff like outsourcing cleaning handle these rules without predefined business rules, and only technical experts can guess? We suggest that schools start with a field map of what signs each party uses, which state is synchronized and which are exceptions, by article. This watch is twitching, but it blocks most of the back half of the dirt.

We'll have to go in two steps.

The correct approach is to run a parallel period of time: the new account has been synchronized by a single identity, the old account has been kept together for a while, and the same two sets have been stored, and it has been observed whether the synchronization is on time or not. Once the old passages are stabilized, we gradually phase out. We've seen schools that cut down. The UID interface is over-connected one day, and all teachers and students get off the net, so no one gets down from the accident retray. So just do what you need to do when the switch goes down.

Don't let the Internet account go completely out of touch.

Finally, a reminder: even if the same identity is connected, the network certification system itself must maintain a copy of the account number available and emergency access to the code. If the unified identity platform fails, teachers and students cannot even access the Internet if there is no independent documentation on the side of the network."Gate", which is a secure design when the network side is in crisis. The docking is for convenience and not for the delivery of lifelines.

How to merge historical accounts in separate columns

The hardest thing to do with the same identity is that the old system does not match the numbers, such as those built in hand and from different sources. They are treated separately when they dock, either into a single identity or explicitly deactivated, and cannot be kept together as ghost accounts and new ones. We suggest pulling one before matching."List of unusual accounts"And, you know, go around and start full sync. This part of the job looks like a little bit of a scratch, but it just decides to get back online and dry.

Run through the test account and do it all.

The right thing to do is take a small batch of test accounts, get through the full process of synchronisation, login, decryption and write-off, confirm that each link is correct and then scale it up to the full amount. The field error, time series problems that are detected during the testing phase are very inexpensive; the whole number only becomes known as an accident across the school. We call this ""Try your own people first."Slower, but steady.

Access Program I'll be right back. Telephone counselling