Murdoch Authentication & Identification SystemMAIS Help Topics
MAIS, What Is It?The Murdoch Authentication & Identification System (MAIS) is used to:-
Availability of the MAISThe MAIS database is available at all times. Should there be a problem with the MAIS database, the MAIS login screen will carry a WARNING message, such as the database is offline, or a browser will display an error message, eg. Failed to connect (via RPC) with Oracle listener (check_idval) MAIS DatabaseThe MAIS is a corporate database containing information about people, organisational units or areas, and location information for buildings and facilities on the Murdoch campuses. The MAIS database is populated primarily by data extracted from other University databases, including the Human Resources System and the Student Management System. There is a facility for authorised persons to add entries to the database for 'others'. MAIS 'Others' are:
An entry in the MAIS database is a pre-requisite for:
Staff & Student Database EntriesEach night, the MAIS database is updated using data downloaded from the Human Resources System and the Student Management System. This means that when staff leave, or their contracts expire, or when students cease to be enrolled, their entries in the MAIS database will expire and they can no longer access services and systems that use the MAIS for authentication or for access restriction. However, there may be services that use a MAIS database entry to identify students who are no longer enrolled, and following login using a Murdoch Username and Murdoch Password, allow them access to restricted information. Staff who are waiting for a renewed contract to be processed may find that they cannot use their Murdoch Password until their details in the MAIS database have been updated. Students should note that if they are not enrolled in the active Semester, eg. Semester 1, but have completed enrolment procedures for the next Semester, eg. Semester 2, they may not be included in the MAIS database. The MAIS records a student as 'active' only when their enrolment period is within 50 days of the current date. Data Held in the MAIS DatabaseData currently held in the MAIS database includes:
Preferred Email AddressThe MAIS database holds details of the preferred email addresses of both staff and students.
Preferred Email Address (Staff)The preferred email addresses of staff are stored in the MAIS database and then used by Murdoch's Campus Directory to display details of people associated with Murdoch University. The preferred email address is extracted from the MAIS for use by other systems and services at Murdoch (eg. WebCT and the Library System). This means that if staff do not maintain their current preferred email address in the MAIS database, then problems will occur with email being misdirected when sent using these other systems. To update their email address details in the MAIS database, staff need to access the update facility, ie. the Personal Details Editor, via the Campus Directory. Access to the Personal Details Editor is restricted. Staff need to enter their Murdoch Username (ie. Staff Number) and Murdoch Password. The Personal Details Editor will only update email address details held in the MAIS. Using the editor will not ensure that email sent to a previously used address, such as an account on a Divisional Server, is redirected to the preferred address. Staff will still need to ensure email redirection from one mail server to another is in place if needed. Preferred Email Address (Students)The preferred email addresses of students are stored in the MAIS database. These addresses are not made available via the Campus Directory. All students are allocated an email address as part of their automatically generated account on the Student Network. Those students who choose to use an alternative address may make use of a facility to re-direct email from the Student Network address to their preferred email address. The email redirection facility for students to use is offered within MyInfo, the Web interface for students to the Student Management System (Callista). The preferred email address details are extracted from the Student Management System and stored in the MAIS database as well as in other systems such as WebCT and the Library System. To access MyInfo, students are prompted at a MyInfo login screen to enter their Murdoch Username (ie. Student Number) and Murdoch Password. Students should ensure that they use MyInfo to update their email address details to their preferred email address so that other systems such as WebCT and the Library System make use of the current preferred email address.
Where is the MAIS Used?
In most cases, if you are a current member of staff or an enrolled student, then you will be able to access MAIS restricted Web pages, forms, programs and application systems. However, in some cases you will find that you have insufficient authority to access these services (ie. you don't have the appropriate MAIS Authority Type against your MAIS database entry). If this is the case, when you attempt to login at a MAIS login screen, the MAIS will return an error message or warning, stating that you have insufficient authority. If you think you should have the required authority against your MAIS database entry, then please contact the IT Service Desk on 9360 2000, or e-mail, itservicedesk@murdoch.edu.au), who will determine who is the custodian of the associated MAIS Authority Type and refer you to them. Systems & Services Using the MAIS Login ScreenThe following list includes some of the systems and services that use the MAIS login screen. Some of these services are hosted externally. Most of the systems have associated authorisation requirements (eg. MAIS Group, MAIS Authority Type). This means that login to the MAIS with a valid username and password may be insufficient authority. A user may need to be a member of a MAIS Group, such as 'staff', or have the appropriate MAIS Authority Type, such as 'Maintain News Items (Positions Vacant)' added against their MAIS database entry.
Individual HTML pages, files in other formats (eg. Word, PDF, PPT), forms and programs may also use the MAIS as the method to restrict access. Metadata is used to assign the level of access and to narrow the access restriction, eg. to 'staff'. When a link is selected to one of these pages, forms, or programs, the MAIS login screen displays, prompting the user to enter their Murdoch Username and Murdoch Password. Other Systems Using MAIS to Authenticate, With Own Login ScreenThe following application systems authenticate users against the MAIS database, but use their own login screen, rather than the MAIS login screen.
The Online Response System also interacts with the MAIS database. If you have any queries about using the MAIS as the method to restrict access to information resources, please contact the Web Coordinator.
Who Can Use the MAIS?Use of the MAIS for authentication and authentication purposes is restricted to members of the Murdoch University community. This includes staff, students and 'MAIS others'.
MAIS AuthoritiesThe Murdoch Authentication & Identification System (MAIS) includes a facility for creating "Authorities" which are then associated with a person or position to grant specific permissions to perform restricted functions (eg. view agenda attachments for a Committee meeting). Where a MAIS Authority is in use, at the time a person uses the MAIS login screen to access a restricted information resource or an application system, the MAIS database is checked to determine if the person has the appropriate MAIS Authority Type associated with their entry in the MAIS database. The University's Data Administrator is responsible for creating MAIS Authorities. Each MAIS Authority Type has a numeric value or code and associated with it three roles, 'Custodian', 'Grantor' and 'User'.
For any MAIS Authority Type, there may be more than one person (or position) who has been assigned the "Custodian" and/or "Grantor" and/or "User" role. MAIS Authorities Maintenance & InquiryA facilty to maintain MAIS Authority Types is used by authorised persons. If you are either a 'Custodian' or a 'Grantor' for a MAIS Authority Type, use the following link to login to the MAIS. The system will display a list of all MAIS Authority Types that your MAIS database entry is associated with. Select the appropriate code from the list. If you have problems using this facility, contact the Web Coordinator, De Stanton (d.stanton@murdoch.edu.au). MAIS Authority Types ListingMAIS Authority Types have been created for activities like maintaining items in the News & Events system, updating personal details in the ACV System and viewing documents associated with various University committees. At present no listing is made available of the MAIS Authority Types in use. Nor is there any listing of the people or positions assigned the role of Custodian for the MAIS Authority Types. For those staff members who have been assigned the role of Custodian or Grantor or a MAIS Authority, a listing of these MAIS Authorities, will be included on the Administration theme page in the Staff Portal. Requesting a New MAIS Authority TypeIf you have an application or an information resource that you wish to restrict access to and you would like to know if you can use a MAIS Authority Type, contact the Web Coordinator, De Stanton (d.stanton@murdoch.edu.au).
MAIS GroupsAny person with an entry in the Murdoch Authentication & Identification System (MAIS) database is a member of at least one MAIS Group. Most people are members of more than one MAIS Group. MAIS Groups include:
Membership of a MAIS Group is defined as:
If a MAIS Group is used to restrict access to Content, then the Content Provider, in conjunction with the Content Custodian, needs to use the appropriate metadata tagging with the files to be restricted. The MAIS Groups 'course' and 'unit' are always qualified by a alphanumeric code. The University's Handbook needs to be referred to for details of Course Codes and Unit Codes. The MAIS Groups 'orgunit' and 'orgset' are also always qualified by a code. The University's Organisational Chart needs to be referred to for a organisational unit code and for the code of an organisational unit that because of its place the hierarchy may be used as an 'orgset' for the purposes of restricting access.
MAIS Login and LogoutMAIS LoginWhen using Murdoch's Web sites you may wish to access information resources, services and systems that have been restricted using the MAIS. Usually when links to restricted resources are included on Web pages the links have an associated hand icon indicating some form of access restriction. If you select a MAIS restricted item, then the MAIS login screen displays and you are prompted to enter a Murdoch Username (ie. Staff Number, Student Number, Person Number) and a Murdoch Password. The MAIS login screen displays 2 buttons, [ Enter ] and [ Help ]. If you have recently logged into the MAIS it may also display the link (More Help). You need to click on the [Enter] button for the Murdoch Username and Murdoch Password you have typed in to be encrypted and validated via a Secure Web Server. After validation of your Murdoch Username and Murdoch Password against data stored in the MAIS database, the resource or service you wish to access will be displayed. In many cases a simple check is made to confirm you have a valid entry in the MAIS database. However, in some cases a MAIS Authority Type is associated with an individual or a position, and this can influence what is displayed on the screen (eg. a full menu rather than an abbreviated menu). If you try to access a system or service for which you do not have the requisite MAIS Authority Type associated in the MAIS database with your name or position number, you will see a MAIS 'error' message indicating that you have insufficient authority. In most cases when you see the MAIS login screen displayed, if you check the URL in the address bar you will notice that it includes an 's' with the 'http', ie. 'https', as well as a padlock either in the address bar or somewhere else on your screen. This means that the Web Server being used is a Secure Server and when you retrieve information from that Server it will be encrypted. eg. https://www.murdoch.edu.au/itservicedesk/login.edo eg. https://www.murdoch.edu.au/apps/req_file?form=mais_pdm_student&env=prod Occasionally you will find that the URL for a MAIS login screen does not include the 's'. Although the login screen is being displayed on an 'insecure' Web Server, when you select [ Enter ] the login form submits your details to the Secure Server at https://www.murdoch.edu.au/apps/mais/login. However, where an 'insecure' Server is used to display a MAIS login screen, although the login details are encrypted the Content hosted on the Server and retrieved by your Web browser is not encrypted. MAIS Login PersistenceOnce you have accessed a MAIS restricted information resource you will, in most cases, NOT be prompted again to enter your Murdoch Username and Murdoch Password when you select another MAIS restricted resource within the MAIS login timeout period. This persistence of login occurs for many, but not all Web-based applications, and for programs and pages hosted on the MurdochNet Host where the domain name includes murdoch.edu.au. NOTE: Once you have logged into the MAIS, when you jump to another information resource, service, or system that is not MAIS restricted, be aware that you have NOT logged out of the MAIS. You can, within the timeout period, jump back to a MAIS restricted resource and not have have to login again. If you are using a Web browser in a public area, or leaving your Web browser unattended, please remember to use the MAIS Logout link displayed adjacent to your name, or the MAIS [Exit] button if it is displayed on the bottom right hand corner of the page you are viewing. Alternatively, use the Manual Logout link provided below. MAIS Login ProblemsMAIS login problems may be due to
Web Browser ProblemsThe MAIS Help Topics include MAIS Web browser requirements, and a link to information on upgrading browsers. Commonly Occurring Problems
MAIS Login ScreenAs a number of different services and systems now make use of the login combination of Murdoch Username and Murdoch Password, if you are experiencing login problems and you do ask for help from the IT Service Desk, please clarify whether or not you are trying to login to a MAIS login screen. If it is a MAIS login screen, it will display the heading Murdoch Authentication & Identification System, and the [ Help ] button will lead to this set of MAIS Help Topics. MAIS Login Error MessagesWhen you have a problem logging in, the MAIS login screen will display with a Warning message above the box for entering your Murdoch Username. In addition to the short message you can select the link for (More Help) and a small window will open that includes a longer explanation for the problem you are experiencing. A listing of commonly occurring MAIS login error messages is available. MAIS LogoutFor a forced logout from the MAIS, select this link https://wwwdev.murdoch.edu.au/images/buttons/navigate/login.gif
MAIS [Exit] ButtonIf you access MAIS restricted applications or Web pages located on some of the centrally-managed Web Servers (eg. https://www.murdoch.edu.au/ or https://wwwlib.murdoch.edu.au/), then you should see either a Logout link adjacent to your name, or a MAIS [Exit] button displayed on the bottom of a Web page.
'MAIS Others''MAIS Others' are persons who are neither staff of Murdoch University, nor students of Murdoch University, but who have some formal asssociation with Murdoch University that requires them to have an entry in the MAIS database (eg. contract staff, consultants). For such a person to obtain an entry in the MAIS database they need to complete a Request for Murdoch Username and Password Form (PDF). The form must be authorised with the signature of an appropriate person. The list of MAIS Authorised Agents should be used to determine who should sign the form. If it is unclear who should act as a MAIS Authorised Agent, then the IT Service Desk should be contacted by phone on 9360 2000. The applicant (personally) should take the completed form (together with some personal identification with an identifiable photo, such as a Driver's Licence) to the IT Service Counter (Level 2, North Wing, Library, Murdoch Campus). If the applicant is unable to attend the IT Service Counter in person, then they may send a completed application form via internal mail to the IT Service Counter, or arrange for their Authorised Agent to deliver the form to the IT Service Counter for them. For more detail, refer to Requesting a Murdoch Password (New Person) 'MAIS Other' Please Note: A MAIS 'Other' entry in the MAIS database is valid for 12 months, unless an earlier expiry date is specified by the MAIS Authorised Agent.
After entering your Murdoch Username (ie. Staff Number, Student Number, Person Number) and Murdoch Password at a MAIS login screen, your Web browser may return one of the following error messages. Please take the recommended action.
MAIS Web Browser RequirementsTo use the MAIS login screen, a recent version of a Web browser is recommended. Your Web browser needs to be: CookiesThe MAIS login screen allows members of the Murdoch community to enter their Murdoch Username (ie. Staff Number, Student Number or Person Number) and Murdoch Password. These details are validated in the MAIS database and a MAIS session is established for the user using that Web browser. Information about the user's session is retained by the Web browser by means of a "cookie". In order for the MAIS to obtain information about your session, please do not modify your Web browser set up to disable support for "cookies". NOTE: If "cookies" have been disabled, you will find that tbe MAIS login screen displays over and over. If you are unable to login to the MAIS due to a 'cookie' problem, and your browser does have cookies enabled, please contact the IT Service Desk for assistance. Security and Secure ServersThe security of data transmitted by your Web browser whilst you are using the MAIS depends on your Web browser supporting the security feature and the information resource or service you wish to use being offered via a Secure Server. When your Web browser sends a request to a Secure Server, the data sent is encrypted and the data returned is encrypted. The University has paid for Digital certificates or IDs. A Digital ID is used on the central Web Server (https://www.murdoch.edu.au), that handles your requests to login to the MAIS and on the Oracle Web Server used for access to systems such as the ACV System, Web Self Service, the News & Events System and for changing your Murdoch Password. Digital IDs have also been purchased for the other Servers including the one used to provide MyInfo, the Web interface to the Student Management System. You will notice that the URLs for these services include https:// Each year the subscriptions for the Digital IDs must be renewed. Sometimes the renewal process is not trouble free and there are delays which can affect you as a user. Some browsers have problems connecting to a Secure Server when the digital ID has expired. Usually there is a warning message and an option to [Continue]. Older browser versions, eg Netscape 4.0 to 4.03 do not allow you to successfully select the [Continue] button and move on. Problems have been noted with early versions of Netscape browsers, even when the Digital ID on the Web Server has NOT expired. This is because the Digital IDs used by the browsers expired on January 1st 2000. If you are using an early version, eg. Netscape earlier than 4.7 as your browser, you are advised to upgrade to a more recent version. Users of the MAIS should be aware that Web browsers have an option to store usernames and passwords for future use. Be careful of this feature if it is likely other people may have access to the computer you are using to login to the MAIS.
Proxy Cache ServersMurdoch University Network UsersYou are advised to check the instructions for setting up your browser to use Murdoch University's Proxy Cache Server. NOTE: If you are using Microsoft Internet Explorer as your Web browser, and the version is 'old', you will need to follow the instructions for bypassing the Proxy Cache Server at Murdoch. It is recommended that you upgrade to a more recent version. Users on Domains Other Than murdoch.edu.auIf your computer is not on the Murdoch University Network (eg. you are using modem access via an ISP or using a computer at your place of employment), you will most likely be using a Proxy Cache Server other than Murdoch's Proxy Cache Server. When you use the MAIS login screen to login to the MAIS, this process is handled by a Secure Web Server. In this situation the Proxy Server used by your ISP or your employer has no effect, as the data being transferred between the University's Secure Web Server and your browser is fully encrypted. The MAIS login routine notes your browser's IP address as being the REAL address. Insecure Web ServersIf the resources being restricted via the MAIS are NOT hosted on or accessed via a Secure Server (ie. they are hosted on or accessed via a Web Server without a Digital ID), then problems may occur with the MAIS login process. Even though the initial part of the process ensures that a valid MAIS session is established, the Proxy Cache Server used by your ISP or employer DOES take effect when, as the next part of the process your browser tries to retrieve a resource hosted on or accessed via an insecure Web Server. The Proxy Cache Server used by your ISP or employer acts as a buffer, and so the "client IP" (ie your browser's IP address) as seen by the University's Secure Web Server is NOT the browser's IP address, but is the Proxy Server's IP address. This conflict in IP addresses causes a MAIS security alert, as a change in IP address is considered a security breach. In this is the case, the login via the MAIS will fail and return an error message to the browser screen, eg. "client address conflict'. NOTE: Some types of Proxy Servers pass on the browser's real IP address as well, and so don't cause this problem. Action You May Take
|
