Notes from 2012-08-03 Meeting

UH Applications Developers Meeting

August 3, 2012

Security Policy Updates

  • Sensitive info saved/used only when required for business purposes, not for convenience.
  • E2.214 requires inclusion of contract language with 3rd party vendors to protect UH sensitive info. What about current contracts?
    • Amend if possible, otherwise include in the next contract cycle.

Holiday Web Service

  • Request: Would be great to be able to subscribe to an ics calendar pertaining to holidays.
  • Does this contain sensitive info?
    • No.
  • Request: Make data publicly available on the web.
  • Has this been used by a production app yet?
    • No.

UHIMS Events

  • Already used by KFS.
  • Peoplesoft users use UHIMC to retrieve UH Numbers.
  • Most apps should listen for deleteAffiliation instead of deleteUsername, since the latter follows ITS-specific life cycle.
  • Remaining affiliation count
    • Message will return all affiliations remaining, after resolving issue with KFS.
  • Retrofit will not completely replace need for initial load of data.

CAS3

  • Production ready in 4 to 8 weeks.
  • Attribute release format differs between CAS2 and CAS3.
    • CAS3 uses SAML.
  • Issues registering apps in development environments that use a hostname of "localhost"on a laptop.
  • Request: Is it possible to have app-specific error screens to address repeated login failures?

Other Updates

  • Does ACER address FERPA issues?
    • No.