Uploaded image for project: 'Grouper'
  1. Grouper
  2. GRP-2469

New Content - Grouper Security Model

    XMLWordPrintable

Details

    • Documentation
    • Resolution: Unresolved
    • Minor
    • None
    • None
    • grouperDeploymentGuide
    • None

    Description

      1. Grouper Security Model - Bill Thompson
        1. Priv management is quite complex
          1. 8 priv on groups
          2. 8 on groups
          3. 6 on folders?
          4. Lots of combinations
        2. Grouper team made some decisions around how defaults should work
        3. Grouper Team should be more aware to explain how the default privileges work, perhaps in a separate table
        4. Guide to get someone up and running would be helpful
        5. Tutorial doc for initial deployers or adopters
        6. There is currently lots of Grouper documentation but not enough simple doc for beginning deployers, showing step 1, then step 2
        7. The info is there but there is not organized from mindset of how to get up and running
      2. Related to priv management within Grouper
      3. Call out admin and security groups in GDG
      4. But not much guidance on how to manage
      5. Some work on how to understand what the privileges are  and what is required.
      6. There may be a gap in the reference docs , We may want to add  more in the admin guides
      7. The draft has info that belongs in various buckets,  how to doc, reference doc, conceptual best practice
      8. Table lists all the priv and admin actions, this is good ref doc for the Grouper project
      9. Some Grouper features works only on Groups not on privileges
      10. Oregon  State: this Grouper Security Model draft has good value, would be helpful,  though hard to keep up to date,  
      11. BillT: Survey of the Grouper deployments could help 
      1. Chris: Looking at modules in the future, Grouper team should try to err on side of simplicity
      2. Matt: Good to have advanced features behind an “advanced” button
      3. Chris: we do have a lot in the UI behind the “More” menu
      4. For Grouper 2.6 we may want to simplify the menus in the Grouper UI
      5. Improve Info architecture around menus and tabs
      6. Grouper team should work more on documenting the privileges, folding in Bill’s Security Model draft.
      7. Matt: people learn this material organically
      8. Look from a code level backwards? Share the unit tests?
      9. Bubble up to a user doc set
      10. Jason Rappaport: took training at Madison, but still working to get up a Proof of Concept.
      11. Chris: GDG should help with how to get Grouper up and running and how to get an app up and running w  Grouper
      12. Chris: about to announce configuration in database, which will lead to more Wizards in the UI
      13. Configuration might be an “I want to…” button
      14. “I want to connect to AD”
      15. Matt: in future, perhaps  cross linking the Grouper UI back to the wiki
      16. Link the actual doing to the HOW TO docs
      17. Could have a search box in Grouper UI to search the Grouper wiki
      18. Shilen: the wiki doc assumes an admin is using it, would need to be dumbed down if there is a link to it from the Grouper UI
      19. Could create a more curated wiki area , for in-page help text
      20. Or have better in-page help
      21. Summary: in the future, provide better documentation on how Grouper privileges work:
        Can use as a starting point the  Grouper Security Model GDG V2  https://docs.google.com/document/d/1Zgb708hFJjk49kw6SGCfP1ZrcHYEka5i5GRni0z7iyA/edit#
        1. Could be another guide, or an appendix

      Attachments

        Issue Links

          Activity

            People

              bill.thompson.3@at.internet2.edu Bill Thompson
              bill.thompson.3@at.internet2.edu Bill Thompson
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated: