SlideShare a Scribd company logo
1 of 19
Download to read offline
How is UCS developing?
Ingo Steuwer
Univention GmbH
steuwer@univention.de
One year of UCS 5.0
●
UCS 5.0 has been released 2022/05/21
●
Main features
●
UI: Look & Feel and framework
●
New Portal
●
Debian upgrade
●
Python3 migration
●
App Center
●
>300 Errata and various App updates
Progress on UI, Portal & Self Service
●
Light theme
●
Full edit mode in the portal
●
Self Service frontend rewrite based on
new Framework
●
Portal & Self Service Accessibility
dedicated slot later today
→
Service specific password for WLAN / RADIUS
●
WLAN passwords are stored on end user
devices in a decryptable way
●
If devices are lost passwords have to be
considered as „leaked“
●
To reduce the risk, WLAN/RADIUS passwords
differ from standard password
●
End users can manage the WLAN password
in the self service
Documentation
●
New backend:
reStructuredText instead of XML
●
New Look & Feel
●
Full review of Handbook &
Quickstart Guide
●
Index of UCR variable
●
New:
Architecture documentation
Apps for UCS 5.0
●
Many Apps have been available with the release:
●
Univention Apps: AD DC (Samba4), Fileservice, Printservice, AD Connector, ...
●
3rd party Apps: Nextcloud, ownCloud, Collabora and more
●
In the past year most Apps followed:
●
Univention Apps: UCS@school, MS 365 Connector,
Apple School Manager Connector, UCS Dashboard
●
3rd party Apps: Open Xchange, OPSI, Agorum, itslearning Connector
●
New Apps like OX Connector, XWiki, Brainyoo, Odoo/ITISeasy
●
Apps expected in the next weeks for UCS 5.0:
●
Univention Apps: UCS Dashboard based Nagios replacement, Google GSuite Connector
●
3rd party Apps: Kopano, OpenVPN4UCS, Zimbra Connector, Audriga, Openproject, ...
One year UCS 5.0 – User Feedback
Positive
●
New UI, features & options
●
General improvements,
stability & speed
→ To reduce the pressure we extended the maintenance for UCS 4.4
Improvable
●
Adoption rate of apps and
integrations
UCS 4.4 maintenance
●
Focus of new features is on UCS 5.0
●
Apps blocking upgrades to UCS 5.0 are expected in the next weeks
●
UCS 4.4 maintenance:
planned to allow upgrades in the next holiday seasons
●
End of Core Edition Maintenance: End of September 2022
●
End of Enterprise Maintenance: End of January 2023
(customers with subscription)
What else happend since last summit?
What else happened?
KOLIBRI
●
Univention
participated in a
PoC for the
Federated Login &
Portal for the
„National
Educational Portal“
of the german
government (BMBF)
●
Portal based on the
Univention Portal
●
Federated SSO
based on Keycloak
POSSIBLE
●
Project funded by the BMWi
●
Objective:
Federated collaboration
based on Phönix Weboffice
●
Federated catalogue: Connect Phönix deployments
among each other with standardized federation
●
Federated Dataspaces: Give organizations the
possibility to process data stored in Phönix in SaaS
offerings („smart services“)
What else happened?
Phoenix
●
Weboffice for the public sector
under direction of Dataport
●
IAM for
●
Federated Login with existing IDPs
●
Service integration for Phönix components
●
Portal with service & UI integration
●
Standardized look & feel of all modules
●
Functional integration like menues and file access
●
In collaboration with OpenXchange, Nextcloud, Collabora,
Matrix, Jitsi and others
Federated IDP scaled big – Univention ID Broker
●
Simplify SSO & Integration for
educational SaaS offerings:
●
Only one configuration for each offering
●
Only one configuration for each authority
●
Data protection and privacy
●
Full controll for authorities
●
Data transfer only for active users
●
Pseudonymization
School
Authorities /
Federal States
Educational
offerings
SSO APIs
Login
Access
Learning
context
What’s next?
Further short term Roadmap – upgrades in the next weeks
●
Keycloak as federated Identity Provider
●
Details in the next talk by Arvid Requate
●
UCS@school:
●
Improvements in classroom management & Veyon
●
MS 365 Connector: Migrate all functions to latest MS365 APIs
●
Samba Upgrade 4.13 4.16 in UCS 5.0-2
→
●
Radius: VLAN-assignment (released last week)
Further short term Roadmap – UCS Dashboard
●
UCS Dashboard:
KPI Dashboard based on Grafana &
Prometheus
●
First release for UCS 5.0 (last week)
●
Upgrade to current versions of Grafana &
Prometheus
●
Updates in the next weeks: Extended
functionality with monitoring & alerting
●
Replaces Nagios
What’s ahead? - Roles & Rights
●
Objective: Flexible Roles & Rights, configurable by administrators
●
Definition on API data model, not at the database level
●
→ in UDM REST API & KELVIN API, not OpenLDAP ACLs
●
„API First“ approach
●
Assignment of Rules to Roles can be done in UDM/UMC
●
Will be combined with rewrite of UI in new Framework
●
New UI already used for Portal and Self Service
●
UI behaviour based on rights
●
First implementation will be done for UCS@school
●
Base integration of „Open Policy Agent“ in Kelvin API already in production
What’s ahead? - Core upgrades
●
Functional upgrades – examples:
●
Generic improvements: speed, support-tools
●
Feature-Upgrades of core components (like Samba upgrade)
●
„Driverless Printing“ based on IPP
●
Further integration & extension of Keycloak IDP
●
Improve App integration & ISV workflows
●
Extend functionality of the portal
●
UCS 5.1
●
Will be based on new Debian release
●
Will discontinue Python 2 support
What’s ahead? - next speeches
modularization &
containerization
user interface
accessibility
Thank you!
Ingo Steuwer
Univention GmbH
steuwer@univention.de

More Related Content

Similar to Wohin entwickelt sich UCS? Ingo Steuwer - Univention Summit 2022

CloudStack Release 4.1 Retrospective
CloudStack Release 4.1 RetrospectiveCloudStack Release 4.1 Retrospective
CloudStack Release 4.1 Retrospective
Chip Childers
 

Similar to Wohin entwickelt sich UCS? Ingo Steuwer - Univention Summit 2022 (20)

Pivotal Cloud Foundry 2.6: A First Look
Pivotal Cloud Foundry 2.6: A First LookPivotal Cloud Foundry 2.6: A First Look
Pivotal Cloud Foundry 2.6: A First Look
 
03-03-2023 - APIForce (1).pdf
03-03-2023 - APIForce (1).pdf03-03-2023 - APIForce (1).pdf
03-03-2023 - APIForce (1).pdf
 
UCS Product Roundtrip – Highlights 2016 and Look-Out 2017
UCS Product Roundtrip – Highlights 2016 and Look-Out 2017UCS Product Roundtrip – Highlights 2016 and Look-Out 2017
UCS Product Roundtrip – Highlights 2016 and Look-Out 2017
 
Seminar Modernizing Your Development Using Microservices, Container & Kubernetes
Seminar Modernizing Your Development Using Microservices, Container & KubernetesSeminar Modernizing Your Development Using Microservices, Container & Kubernetes
Seminar Modernizing Your Development Using Microservices, Container & Kubernetes
 
Pivotal Cloud Foundry 2.1: Making Transformation Real Webinar
Pivotal Cloud Foundry 2.1: Making Transformation Real WebinarPivotal Cloud Foundry 2.1: Making Transformation Real Webinar
Pivotal Cloud Foundry 2.1: Making Transformation Real Webinar
 
WSO2 Cloud Platform: Vision and Roadmap
WSO2 Cloud Platform: Vision and RoadmapWSO2 Cloud Platform: Vision and Roadmap
WSO2 Cloud Platform: Vision and Roadmap
 
Webinar- Tea for the Tillerman
Webinar- Tea for the TillermanWebinar- Tea for the Tillerman
Webinar- Tea for the Tillerman
 
Berlin AWS meetup: here.com on AWS
Berlin AWS meetup: here.com on AWSBerlin AWS meetup: here.com on AWS
Berlin AWS meetup: here.com on AWS
 
Pivotal Cloud Foundry 2.5: A First Look
Pivotal Cloud Foundry 2.5: A First LookPivotal Cloud Foundry 2.5: A First Look
Pivotal Cloud Foundry 2.5: A First Look
 
[Cloud OnAir] Talks by DevRel Vol.4 データ管理とデータ ベース 2020年8月27日 放送
[Cloud OnAir] Talks by DevRel Vol.4 データ管理とデータ ベース 2020年8月27日 放送[Cloud OnAir] Talks by DevRel Vol.4 データ管理とデータ ベース 2020年8月27日 放送
[Cloud OnAir] Talks by DevRel Vol.4 データ管理とデータ ベース 2020年8月27日 放送
 
Modularisierung und Containerisierung von UCS
Modularisierung und Containerisierung von UCSModularisierung und Containerisierung von UCS
Modularisierung und Containerisierung von UCS
 
CENGN - OpenStack MeetUp - March 2017
CENGN - OpenStack MeetUp - March 2017CENGN - OpenStack MeetUp - March 2017
CENGN - OpenStack MeetUp - March 2017
 
Eclipse Hara, Updating Embedded Devices with hawkBit Made Easy
Eclipse Hara, Updating Embedded Devices with hawkBit Made EasyEclipse Hara, Updating Embedded Devices with hawkBit Made Easy
Eclipse Hara, Updating Embedded Devices with hawkBit Made Easy
 
Application Modernisation through Event-Driven Microservices
Application Modernisation through Event-Driven Microservices Application Modernisation through Event-Driven Microservices
Application Modernisation through Event-Driven Microservices
 
Open shift and docker - october,2014
Open shift and docker - october,2014Open shift and docker - october,2014
Open shift and docker - october,2014
 
CloudStack Release 4.1 Retrospective
CloudStack Release 4.1 RetrospectiveCloudStack Release 4.1 Retrospective
CloudStack Release 4.1 Retrospective
 
WebSDK - Switching between service providers
WebSDK - Switching between service providersWebSDK - Switching between service providers
WebSDK - Switching between service providers
 
Building a fully managed stream processing platform on Flink at scale for Lin...
Building a fully managed stream processing platform on Flink at scale for Lin...Building a fully managed stream processing platform on Flink at scale for Lin...
Building a fully managed stream processing platform on Flink at scale for Lin...
 
AD101: IBM Domino Application Development Futures
AD101: IBM Domino Application Development FuturesAD101: IBM Domino Application Development Futures
AD101: IBM Domino Application Development Futures
 
FlexPod_Feb2015-slideshare
FlexPod_Feb2015-slideshareFlexPod_Feb2015-slideshare
FlexPod_Feb2015-slideshare
 

More from Univention GmbH

Schule digital neu denken - Schulstiftung der Ev.-Luth. Landeskriche Sachsens...
Schule digital neu denken - Schulstiftung der Ev.-Luth. Landeskriche Sachsens...Schule digital neu denken - Schulstiftung der Ev.-Luth. Landeskriche Sachsens...
Schule digital neu denken - Schulstiftung der Ev.-Luth. Landeskriche Sachsens...
Univention GmbH
 

More from Univention GmbH (20)

Status des Rollen- und Rechtemodells in UCS und UCS@school - Daniel Tröder - ...
Status des Rollen- und Rechtemodells in UCS und UCS@school - Daniel Tröder - ...Status des Rollen- und Rechtemodells in UCS und UCS@school - Daniel Tröder - ...
Status des Rollen- und Rechtemodells in UCS und UCS@school - Daniel Tröder - ...
 
Technical Deep Dive - OpenID-Connect and OAuth 2.0 in UCS IAM - Florian Best ...
Technical Deep Dive - OpenID-Connect and OAuth 2.0 in UCS IAM - Florian Best ...Technical Deep Dive - OpenID-Connect and OAuth 2.0 in UCS IAM - Florian Best ...
Technical Deep Dive - OpenID-Connect and OAuth 2.0 in UCS IAM - Florian Best ...
 
Univention IAM and Portal for Kubernetes - Ingo Steuwer - Univention Summit 2024
Univention IAM and Portal for Kubernetes - Ingo Steuwer - Univention Summit 2024Univention IAM and Portal for Kubernetes - Ingo Steuwer - Univention Summit 2024
Univention IAM and Portal for Kubernetes - Ingo Steuwer - Univention Summit 2024
 
Keycloak as the New Identity Provider for UCS - Felix Botner & Erik Damrose -...
Keycloak as the New Identity Provider for UCS - Felix Botner & Erik Damrose -...Keycloak as the New Identity Provider for UCS - Felix Botner & Erik Damrose -...
Keycloak as the New Identity Provider for UCS - Felix Botner & Erik Damrose -...
 
Outlook on UCS 5.2 - Ingo Steuwer - Univention Summit 2024
Outlook on UCS 5.2 - Ingo Steuwer - Univention Summit 2024Outlook on UCS 5.2 - Ingo Steuwer - Univention Summit 2024
Outlook on UCS 5.2 - Ingo Steuwer - Univention Summit 2024
 
Barrierefreiheit in UCS - Univention GmbH - Univention Summit 2022
Barrierefreiheit in UCS - Univention GmbH - Univention Summit 2022Barrierefreiheit in UCS - Univention GmbH - Univention Summit 2022
Barrierefreiheit in UCS - Univention GmbH - Univention Summit 2022
 
Digitale Souveränität für die zivile Seenotrettung von Sea-Watch - Sea-Watch ...
Digitale Souveränität für die zivile Seenotrettung von Sea-Watch - Sea-Watch ...Digitale Souveränität für die zivile Seenotrettung von Sea-Watch - Sea-Watch ...
Digitale Souveränität für die zivile Seenotrettung von Sea-Watch - Sea-Watch ...
 
Schulische Lernplattformen in Deutschland - Institut für Informationsmanageme...
Schulische Lernplattformen in Deutschland - Institut für Informationsmanageme...Schulische Lernplattformen in Deutschland - Institut für Informationsmanageme...
Schulische Lernplattformen in Deutschland - Institut für Informationsmanageme...
 
Technologie in der Schule: Ein Projektüberblick & Beratungsansatz der Bechtle...
Technologie in der Schule: Ein Projektüberblick & Beratungsansatz der Bechtle...Technologie in der Schule: Ein Projektüberblick & Beratungsansatz der Bechtle...
Technologie in der Schule: Ein Projektüberblick & Beratungsansatz der Bechtle...
 
UCS@school Roadmap 2022 - Univention GmbH - Univention Summit 2022
UCS@school Roadmap 2022 - Univention GmbH - Univention Summit 2022UCS@school Roadmap 2022 - Univention GmbH - Univention Summit 2022
UCS@school Roadmap 2022 - Univention GmbH - Univention Summit 2022
 
BILDUNGSLOGIN: Mit zwei Klicks die ganze Bandbreite digitaler Bildungsmedien ...
BILDUNGSLOGIN: Mit zwei Klicks die ganze Bandbreite digitaler Bildungsmedien ...BILDUNGSLOGIN: Mit zwei Klicks die ganze Bandbreite digitaler Bildungsmedien ...
BILDUNGSLOGIN: Mit zwei Klicks die ganze Bandbreite digitaler Bildungsmedien ...
 
Schule digital neu denken - Schulstiftung der Ev.-Luth. Landeskriche Sachsens...
Schule digital neu denken - Schulstiftung der Ev.-Luth. Landeskriche Sachsens...Schule digital neu denken - Schulstiftung der Ev.-Luth. Landeskriche Sachsens...
Schule digital neu denken - Schulstiftung der Ev.-Luth. Landeskriche Sachsens...
 
UCS Roadmap 2022 - Univention GmbH - Univention Summit 2022
UCS Roadmap 2022 - Univention GmbH - Univention Summit 2022UCS Roadmap 2022 - Univention GmbH - Univention Summit 2022
UCS Roadmap 2022 - Univention GmbH - Univention Summit 2022
 
Shift happens! Let's create a better IT now! - UNivention GmbH - Univention S...
Shift happens! Let's create a better IT now! - UNivention GmbH - Univention S...Shift happens! Let's create a better IT now! - UNivention GmbH - Univention S...
Shift happens! Let's create a better IT now! - UNivention GmbH - Univention S...
 
Einführung eines zentralen IDM auf Basis der hessischen Landesdatenbank LUSD ...
Einführung eines zentralen IDM auf Basis der hessischen Landesdatenbank LUSD ...Einführung eines zentralen IDM auf Basis der hessischen Landesdatenbank LUSD ...
Einführung eines zentralen IDM auf Basis der hessischen Landesdatenbank LUSD ...
 
Sie serverlose Schule - Stadt Norderstedt - Univention Summit 2022
Sie serverlose Schule - Stadt Norderstedt - Univention Summit 2022Sie serverlose Schule - Stadt Norderstedt - Univention Summit 2022
Sie serverlose Schule - Stadt Norderstedt - Univention Summit 2022
 
Digital Souveräne Collaboration mit Nextcloud - Nextcloud-Univention-Summit-2...
Digital Souveräne Collaboration mit Nextcloud - Nextcloud-Univention-Summit-2...Digital Souveräne Collaboration mit Nextcloud - Nextcloud-Univention-Summit-2...
Digital Souveräne Collaboration mit Nextcloud - Nextcloud-Univention-Summit-2...
 
Enough about Gaia-X theory – Let’s shift towards real use cases! - Plusserver...
Enough about Gaia-X theory – Let’s shift towards real use cases! - Plusserver...Enough about Gaia-X theory – Let’s shift towards real use cases! - Plusserver...
Enough about Gaia-X theory – Let’s shift towards real use cases! - Plusserver...
 
Get your shift together now! - agorum Software - Univention Summit 2022
Get your shift together now! - agorum Software - Univention Summit 2022Get your shift together now! - agorum Software - Univention Summit 2022
Get your shift together now! - agorum Software - Univention Summit 2022
 
Alles schon da? IT-Architektur für die digital souveräne Verwaltung
Alles schon da? IT-Architektur für die digital souveräne VerwaltungAlles schon da? IT-Architektur für die digital souveräne Verwaltung
Alles schon da? IT-Architektur für die digital souveräne Verwaltung
 

Recently uploaded

Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Medical / Health Care (+971588192166) Mifepristone and Misoprostol tablets 200mg
 

Recently uploaded (20)

Evolving Data Governance for the Real-time Streaming and AI Era
Evolving Data Governance for the Real-time Streaming and AI EraEvolving Data Governance for the Real-time Streaming and AI Era
Evolving Data Governance for the Real-time Streaming and AI Era
 
WSO2Con2024 - Navigating the Digital Landscape: Transforming Healthcare with ...
WSO2Con2024 - Navigating the Digital Landscape: Transforming Healthcare with ...WSO2Con2024 - Navigating the Digital Landscape: Transforming Healthcare with ...
WSO2Con2024 - Navigating the Digital Landscape: Transforming Healthcare with ...
 
Architecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the pastArchitecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the past
 
WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?
 
WSO2CON 2024 - OSU & WSO2: A Decade Journey in Integration & Innovation
WSO2CON 2024 - OSU & WSO2: A Decade Journey in Integration & InnovationWSO2CON 2024 - OSU & WSO2: A Decade Journey in Integration & Innovation
WSO2CON 2024 - OSU & WSO2: A Decade Journey in Integration & Innovation
 
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
 
WSO2Con2024 - Software Delivery in Hybrid Environments
WSO2Con2024 - Software Delivery in Hybrid EnvironmentsWSO2Con2024 - Software Delivery in Hybrid Environments
WSO2Con2024 - Software Delivery in Hybrid Environments
 
WSO2CON2024 - Why Should You Consider Ballerina for Your Next Integration
WSO2CON2024 - Why Should You Consider Ballerina for Your Next IntegrationWSO2CON2024 - Why Should You Consider Ballerina for Your Next Integration
WSO2CON2024 - Why Should You Consider Ballerina for Your Next Integration
 
WSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaSWSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaS
 
WSO2CON 2024 - Lessons from the Field: Legacy Platforms – It's Time to Let Go...
WSO2CON 2024 - Lessons from the Field: Legacy Platforms – It's Time to Let Go...WSO2CON 2024 - Lessons from the Field: Legacy Platforms – It's Time to Let Go...
WSO2CON 2024 - Lessons from the Field: Legacy Platforms – It's Time to Let Go...
 
WSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security ProgramWSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security Program
 
WSO2CON 2024 - Software Engineering for Digital Businesses
WSO2CON 2024 - Software Engineering for Digital BusinessesWSO2CON 2024 - Software Engineering for Digital Businesses
WSO2CON 2024 - Software Engineering for Digital Businesses
 
WSO2CON 2024 - Designing Event-Driven Enterprises: Stories of Transformation
WSO2CON 2024 - Designing Event-Driven Enterprises: Stories of TransformationWSO2CON 2024 - Designing Event-Driven Enterprises: Stories of Transformation
WSO2CON 2024 - Designing Event-Driven Enterprises: Stories of Transformation
 
WSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With SimplicityWSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
 
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
 
WSO2Con2024 - Hello Choreo Presentation - Kanchana
WSO2Con2024 - Hello Choreo Presentation - KanchanaWSO2Con2024 - Hello Choreo Presentation - Kanchana
WSO2Con2024 - Hello Choreo Presentation - Kanchana
 
WSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - KeynoteWSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - Keynote
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
 
WSO2CON 2024 - IoT Needs CIAM: The Importance of Centralized IAM in a Growing...
WSO2CON 2024 - IoT Needs CIAM: The Importance of Centralized IAM in a Growing...WSO2CON 2024 - IoT Needs CIAM: The Importance of Centralized IAM in a Growing...
WSO2CON 2024 - IoT Needs CIAM: The Importance of Centralized IAM in a Growing...
 

Wohin entwickelt sich UCS? Ingo Steuwer - Univention Summit 2022

  • 1. How is UCS developing? Ingo Steuwer Univention GmbH steuwer@univention.de
  • 2. One year of UCS 5.0 ● UCS 5.0 has been released 2022/05/21 ● Main features ● UI: Look & Feel and framework ● New Portal ● Debian upgrade ● Python3 migration ● App Center ● >300 Errata and various App updates
  • 3. Progress on UI, Portal & Self Service ● Light theme ● Full edit mode in the portal ● Self Service frontend rewrite based on new Framework ● Portal & Self Service Accessibility dedicated slot later today →
  • 4. Service specific password for WLAN / RADIUS ● WLAN passwords are stored on end user devices in a decryptable way ● If devices are lost passwords have to be considered as „leaked“ ● To reduce the risk, WLAN/RADIUS passwords differ from standard password ● End users can manage the WLAN password in the self service
  • 5. Documentation ● New backend: reStructuredText instead of XML ● New Look & Feel ● Full review of Handbook & Quickstart Guide ● Index of UCR variable ● New: Architecture documentation
  • 6. Apps for UCS 5.0 ● Many Apps have been available with the release: ● Univention Apps: AD DC (Samba4), Fileservice, Printservice, AD Connector, ... ● 3rd party Apps: Nextcloud, ownCloud, Collabora and more ● In the past year most Apps followed: ● Univention Apps: UCS@school, MS 365 Connector, Apple School Manager Connector, UCS Dashboard ● 3rd party Apps: Open Xchange, OPSI, Agorum, itslearning Connector ● New Apps like OX Connector, XWiki, Brainyoo, Odoo/ITISeasy ● Apps expected in the next weeks for UCS 5.0: ● Univention Apps: UCS Dashboard based Nagios replacement, Google GSuite Connector ● 3rd party Apps: Kopano, OpenVPN4UCS, Zimbra Connector, Audriga, Openproject, ...
  • 7. One year UCS 5.0 – User Feedback Positive ● New UI, features & options ● General improvements, stability & speed → To reduce the pressure we extended the maintenance for UCS 4.4 Improvable ● Adoption rate of apps and integrations
  • 8. UCS 4.4 maintenance ● Focus of new features is on UCS 5.0 ● Apps blocking upgrades to UCS 5.0 are expected in the next weeks ● UCS 4.4 maintenance: planned to allow upgrades in the next holiday seasons ● End of Core Edition Maintenance: End of September 2022 ● End of Enterprise Maintenance: End of January 2023 (customers with subscription)
  • 9. What else happend since last summit?
  • 10. What else happened? KOLIBRI ● Univention participated in a PoC for the Federated Login & Portal for the „National Educational Portal“ of the german government (BMBF) ● Portal based on the Univention Portal ● Federated SSO based on Keycloak POSSIBLE ● Project funded by the BMWi ● Objective: Federated collaboration based on Phönix Weboffice ● Federated catalogue: Connect Phönix deployments among each other with standardized federation ● Federated Dataspaces: Give organizations the possibility to process data stored in Phönix in SaaS offerings („smart services“)
  • 11. What else happened? Phoenix ● Weboffice for the public sector under direction of Dataport ● IAM for ● Federated Login with existing IDPs ● Service integration for Phönix components ● Portal with service & UI integration ● Standardized look & feel of all modules ● Functional integration like menues and file access ● In collaboration with OpenXchange, Nextcloud, Collabora, Matrix, Jitsi and others
  • 12. Federated IDP scaled big – Univention ID Broker ● Simplify SSO & Integration for educational SaaS offerings: ● Only one configuration for each offering ● Only one configuration for each authority ● Data protection and privacy ● Full controll for authorities ● Data transfer only for active users ● Pseudonymization School Authorities / Federal States Educational offerings SSO APIs Login Access Learning context
  • 14. Further short term Roadmap – upgrades in the next weeks ● Keycloak as federated Identity Provider ● Details in the next talk by Arvid Requate ● UCS@school: ● Improvements in classroom management & Veyon ● MS 365 Connector: Migrate all functions to latest MS365 APIs ● Samba Upgrade 4.13 4.16 in UCS 5.0-2 → ● Radius: VLAN-assignment (released last week)
  • 15. Further short term Roadmap – UCS Dashboard ● UCS Dashboard: KPI Dashboard based on Grafana & Prometheus ● First release for UCS 5.0 (last week) ● Upgrade to current versions of Grafana & Prometheus ● Updates in the next weeks: Extended functionality with monitoring & alerting ● Replaces Nagios
  • 16. What’s ahead? - Roles & Rights ● Objective: Flexible Roles & Rights, configurable by administrators ● Definition on API data model, not at the database level ● → in UDM REST API & KELVIN API, not OpenLDAP ACLs ● „API First“ approach ● Assignment of Rules to Roles can be done in UDM/UMC ● Will be combined with rewrite of UI in new Framework ● New UI already used for Portal and Self Service ● UI behaviour based on rights ● First implementation will be done for UCS@school ● Base integration of „Open Policy Agent“ in Kelvin API already in production
  • 17. What’s ahead? - Core upgrades ● Functional upgrades – examples: ● Generic improvements: speed, support-tools ● Feature-Upgrades of core components (like Samba upgrade) ● „Driverless Printing“ based on IPP ● Further integration & extension of Keycloak IDP ● Improve App integration & ISV workflows ● Extend functionality of the portal ● UCS 5.1 ● Will be based on new Debian release ● Will discontinue Python 2 support
  • 18. What’s ahead? - next speeches modularization & containerization user interface accessibility
  • 19. Thank you! Ingo Steuwer Univention GmbH steuwer@univention.de