Service Requirements for ED-ID Usage

Release 1.0
Date 07/26/2004
  1. All services using the Enterprise Directory's person credentials, currently known as the UUPID and password, MUST collect and transmit these credentials over a secured communication channel that ensures end-to-end information integrity and confidentiality, such as SSL or TLS.
  2. Services MUST connect to ED-ID using only LDAPS (SSL version 3) or LDAP over TLS (TLS version 1) and employ the SASL External authentication mechanism with a client certificate issued from the VT Middleware CA.
  3. Any service wishing to connect to ED-ID MUST have at least one current technical contact person and one active full-time salaried employee designated as the responsible party for the service.
  4. Services MUST NOT allow other applications access to ED-ID data or functionality.
  5. Services MUST use a person's UID, not their UUPID, as the principal identifier for that person, though the UUPID may be used to authenticate a person and retrieve their UID.
  6. Services MUST NOT store a user's password for longer than that user's application session.
  7. Services SHOULD NOT store any information retrieved from ED-ID about a person for longer than a user's application session unless provisions are made to keep this data timely.
  8. Services MUST respect a person's privacy flags such that:
    1. Services of type “personal” MAY only display a person's suppressed information to that person.
    2. Services of type “private” or “public” MUST NOT display a person's suppressed information.
    3. Services used by administrative staff MAY display any of the above information if it is required to perform their job.
  9. Middleware and IRM staff MAY periodically audit, either passively or actively, services to ensure they comply with all rules stated above, or appoint a third party to do so.
  10. IRM MAY update these rules as necessary.

Approved for release



IAD Director __________________________________________________ Date _______________


IRM Representative ____________________________________________ Date _______________
 
middleware/ed/edid/services/requirements.txt · Last modified: 2009/10/07 17:17 (external edit)
 
Except where otherwise noted, content on this wiki is licensed under the following license:CC Attribution-Noncommercial-Share Alike 3.0 Unported
Recent changes RSS feed Donate Powered by PHP Valid XHTML 1.0 Valid CSS Driven by DokuWiki