Educause Security Discussion
mailing list archives
Re: Guest wireless access at University Conference Centers
From: Cal Frye <cjf () CALFRYE COM>
Date: Tue, 18 Sep 2007 16:26:37 -0400
Brinkman, Kathleen B. Ms. wrote:
Tagging onto this thread (I checked the archives and see 12/2006
threads on "open access to student labs" and "public access library
ports", but don't see other threads on specific vendor solutions in
support of guest access in a 'private network' sense).
Does anyone have information on a vendor-provided solution to manage
guest accounts? We plan to implement across campus, as Virginia Tech
seems to have done. I like the VA Tech system's ability for a guest
to create their own account and request departmental approval ---
that off-loads some of the setup to the person requesting access.
We use Cisco Clean Access and can feed the accounts to CCA, once
created. I had planned to manage them elsewhere, in a system
designed for that.
Kathie Brinkman Director, Support Services IT Services Miami
University Oxford, Ohio
We wrote a little web utility that someone with OC credentials (student,
staff, faculty) can use to create a "sponsored account" for a guest,
with limited lifetime. Those accounts have a flag attribute set in our
SunOne LDAP directory indicating their status, expiration, and person
responsible for creation. We use Clean Access to authenticate against
LDAP, and if the sponsored attribute is set, the user is sent into our
sponsored role, which times out in 24 hours, has only limited access to
on-campus resources, etc. etc.
Ping me offline if you want to talk to the development team about this.
-- Cal Frye, Network Administrator, Oberlin College
"When one party is shameless, the other can't afford to be spineless."
-- Julian Bond.