{"id":3506,"date":"2024-07-09T08:56:33","date_gmt":"2024-07-09T06:56:33","guid":{"rendered":"https:\/\/wpethzprd.ethz.ch\/its\/?p=3506"},"modified":"2024-07-09T08:56:35","modified_gmt":"2024-07-09T06:56:35","slug":"target-systems-active-directory-ldaps-radius","status":"publish","type":"post","link":"https:\/\/blogs.ethz.ch\/its\/2024\/07\/09\/target-systems-active-directory-ldaps-radius\/","title":{"rendered":"Target systems: Active Directory, LDAPS, Radius"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Good to know: Active Directory, LDAPS and Radius are authentication infrastructures that are used for the utilisation of identities (persons) and for the assignment of access rights in a network. They ensure that only authenticated users (persons) can access information and systems.<\/p>\n\n\n\n<!--more-->\n\n\n\n<h2 class=\"wp-block-heading\">Identity and Access Management<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">ETH Zurich operates an <a href=\"https:\/\/ethz.ch\/staffnet\/en\/it-services\/catalogue\/identity-access\/identity-access-management.html\" target=\"_blank\" rel=\"noreferrer noopener\">Identity and Access Management<\/a> (IAM) system, known to us as the <a href=\"https:\/\/www.password.ethz.ch\/authentication\/login_en.html\" target=\"_blank\" rel=\"noreferrer noopener\">ETH Web Center<\/a>. The system enables the control and supply of data to the directory services (Active Directory, LDAP and Radius). This makes it possible to create user accounts, and it standardises the management of groups and distributors.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Image ETH Web Center<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><a href=\"https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Accounts_Zielsysteme_EN.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"205\" src=\"https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Accounts_Zielsysteme_EN-1024x205.jpg\" alt=\"ETH Web Center Tab Self Service\" class=\"wp-image-3511\" srcset=\"https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Accounts_Zielsysteme_EN-1024x205.jpg 1024w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Accounts_Zielsysteme_EN-300x60.jpg 300w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Accounts_Zielsysteme_EN-768x154.jpg 768w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Accounts_Zielsysteme_EN-1536x307.jpg 1536w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Accounts_Zielsysteme_EN-600x120.jpg 600w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Accounts_Zielsysteme_EN.jpg 1599w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>ETH Web Center Tab Self Service &gt; User overview &gt; Section Accounts<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Target systems<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The term &#171;target systems&#187; refers to the specific platforms or services within an IT infrastructure. At ETH, the target systems are used for authentication and, in some cases, also for authorisation. They ensure that the people who log in are genuine. In a practical context, a target system can be anything from a server to a database to an application programme.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Active Directory<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Active Directory (AD) is a directory service developed by Microsoft that is used in application resources. It enables the management of user accounts and computer objects (IT devices). Administrators can use it to control resources, manage user rights and enforce policies. The most common applications that are offered as an <a href=\"https:\/\/ethz.ch\/staffnet\/en\/it-services\/catalogue\/identity-access\/active-directory.html\" target=\"_blank\" rel=\"noreferrer noopener\">Active Directory service<\/a> by IT Services (<a href=\"https:\/\/ethz.ch\/content\/dam\/ethz\/associates\/services\/Service\/IT-Services\/files\/sla\/sla-ads-de.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">SLA<\/a>) for ETH members are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>When logging in on your personal computer (desktop\/laptop)<\/li>\n\n\n\n<li>Exchange (Outlook, email)<\/li>\n\n\n\n<li>SharePoint<\/li>\n\n\n\n<li>Confluence<\/li>\n\n\n\n<li>Teams<\/li>\n\n\n\n<li>OneDrive<\/li>\n\n\n\n<li>Zoom<\/li>\n\n\n\n<li>Almost all cloud services<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">LDAPS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">LDAPS stands for &#171;Lightweight Directory Access Protocol Secure&#187; and is a protocol that is used to retrieve and change information from directory services (such as user names and passwords). Like AD, the <a href=\"https:\/\/ethz.ch\/staffnet\/en\/it-services\/catalogue\/identity-access\/ldap.html\" target=\"_blank\" rel=\"noreferrer noopener\">LDAPS service<\/a> is an ETH-wide authentication, authorisation and information service. LDAPS service is based on the OpenLDAP software. It serves as a central source of information for applications and systems and enables the exchange of information about users, groups, systems and services <a href=\"https:\/\/ethz.ch\/content\/dam\/ethz\/associates\/services\/Service\/IT-Services\/files\/sla\/sla-ldap-de.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">(SLA<\/a>).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Radius<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Radius (Remote Authentication Dial-In User Service) is a network protocol that is used for the authentication, authorisation and accounting (AAA) of users. It is used to manage access control to networks, especially wireless networks and Internet access services. RADIUS is used for the <a href=\"https:\/\/ethz.ch\/staffnet\/en\/it-services\/catalogue\/networks-connections\/remote.html\" target=\"_blank\" rel=\"noreferrer noopener\">VPN<\/a> network access service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AD, LDAPS and Radius have an SSL layer (Secure Sockets Layer) to encrypt communication between the client and the servers and thus increase data security.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Image of Web Center<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><a href=\"https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Passworte_aendern_EN.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"753\" src=\"https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Passworte_aendern_EN-1024x753.jpg\" alt=\"ETH Web Center Tab Self Service &gt; Change password\" class=\"wp-image-3513\" srcset=\"https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Passworte_aendern_EN-1024x753.jpg 1024w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Passworte_aendern_EN-300x221.jpg 300w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Passworte_aendern_EN-768x565.jpg 768w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Passworte_aendern_EN-1536x1130.jpg 1536w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Passworte_aendern_EN-600x441.jpg 600w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/06\/Passworte_aendern_EN.jpg 1697w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>ETH Web Center Tab Self Service &gt; Change password &gt; Change passwords for user &#171;XXX&#187; &gt; Selection of the target systems for the password change<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Identity &amp; Access<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An &#171;ETH user account&#187; <a href=\"https:\/\/unlimited.ethz.ch\/display\/itkb\/ETH+user+account\" target=\"_blank\" rel=\"noreferrer noopener\">(IT Knowledge Base<\/a>) is created for each ETH member when they join the university. This account contains a variety of service roles (services such as mailbox, VPN, etc.) as well as identities in various target systems (Active Directory, LDAP, Radius). In the Web Center you can see in which target systems an account exists and manage your passwords.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">There are three different ETH passwords<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ETH password for web applications, AAI (LDAP)<\/li>\n\n\n\n<li>ETH password for email (Active Directory)<\/li>\n\n\n\n<li>ETH network password (Radius)<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">And two password groups<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Group = The ETH password for web applications, AAI (LDAP) and the ETH password for email (Active Directory)<\/li>\n\n\n\n<li>Group = ETH network password (Radius)<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The password for the Radius target system must be different from the password for web applications, AAI (LDAPS) or email (Active Directory).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Active Directory, LDAPS and Radius are authentication infrastructures that are used for the utilisation of identities (persons) and for the assignment of access rights in a network. <\/p>\n","protected":false},"author":838,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[257891,25],"tags":[301842,301840,301835,301838,261285,261286,254136,301839,301841,290449,301836,301837,301834,2851],"class_list":["post-3506","post","type-post","status-publish","format-standard","hentry","category-it-sec","category-news","tag-access","tag-access-rights","tag-active-directory","tag-authentication-infrastructures","tag-eth-passwords","tag-eth-web-center","tag-iam","tag-identities","tag-identity","tag-identity-and-access-management","tag-ldaps","tag-radius","tag-target-systems","tag-vpn"],"_links":{"self":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/3506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/users\/838"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/comments?post=3506"}],"version-history":[{"count":0,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/3506\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/media?parent=3506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/categories?post=3506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/tags?post=3506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}