The following uhReleasedGrouping values are made available by ITS as an added convenience. Developers may find it useful to check for these values as part of their application authorization step.
Curated Groupings
Our UH Group Store has a wealth of groups that would be useful to UH applications. ITS will work with the Data Governance Program to curate a collection of groups from the UH Group Store and make them available via uhReleasedGrouping.
Having a curated collection of groupings in uhReleasedGrouping means your application can check against a lot of official data without having to create a grouping. Of course, if you expect to manage exceptions, you should create your own grouping (usually with some of the groups in our curated collection) and release it.
Remember that uhReleasedGrouping data is only for official use within the UH community and not for release to external parties, except under the terms of a written memorandum of agreement or contract.
Value of uhReleasedGrouping | Description | Available Since |
---|---|---|
hawaii.edu:store:uhims:general:mfa-enabled | Person has registered for multi-factor authentication (MFA) and is not in Duo bypass mode. If CAS returns this value after a successful authentication, it can be surmised that the person has passed the Duo prompts in the UH Login screen. If you require MFA and it didn't happen, your application can redirect the user to our generic MFA-required URL (after making user the user is logged out of your application) Departmental usernames are currently not supported! Non-personal usernames who are registered and enabled for Duo will not have this uhReleasedGrouping value. This might change in the future, but as of this writing, UH Groupings was designed with people as grouping members (as opposed to usernames or email addresses). Departmental usernames are often used by multiple individuals, so their ambiguity seems counter-productive to authentication, authorization and MFA. | 9/19/2018 |
hawaii.edu:store:uhims:general:gcn-compliant | Person has a current acknowledgement of the University of Hawaii General Confidentiality Notice (GCN). See https://www.hawaii.edu/its/acer/ GCN compliance period:
For example,
Updated on a nightly basis only. | 1/29/2019 |
hawaii.edu:store:uhims:general:isat-compliant | Person has a current certification for the UH Information Security Awareness Training Certification (ISAT). See https://www.hawaii.edu/its/acer/ ISAT compliance period:
For example,
Updated on a nightly basis only. | 1/29/2019 |
(use above hawaii.edu:store:uhims:general:mfa-enabled value instead) | Person has registered for multi-factor authentication (MFA). Does not account for Duo bypass mode. This will be removed on February 5, 2019, after everyone has transitioned to hawaii.edu:store:uhims:general:mfa-enabled. | 1/22/2018 |
No longer available for general use. Will be removed on February 5, 2019. Contact its-iam-help@lists.hawaii.edu if you need to build a grouping with this information. | 1/31/2018 | |
Tentative Provides more granularity than the generic roles of faculty, staff and student. |