Registration: Difference between revisions

From bwCloud-OS
Jump to navigation Jump to search
No edit summary
No edit summary
Line 11: Line 11:
== What are "Entitlements" or "bwIDM Entitlements"? ==
== What are "Entitlements" or "bwIDM Entitlements"? ==


Every member of an institution (university, college, PH, HAW, etc.) in Baden-Württemberg has a personal account to log in to and use the IT services provided by the institution. If the institution is a member of the [https://www.bwidm.de/  federated identity management of Baden-Württemberg universities bwIDM], then associates of this institution can apply for further use of IT services offered by other locations.
Every member of an institution (university, college, PH, HAW, etc.) in Baden-Württemberg has a personal account to log in to and use the IT services provided by the institution. If the institution is a member of the [https://www.bwidm.de/  federated identity management of Baden-Württemberg universities bwIDM], then associates of this institution can apply for further IT services offered by other institutions.


In order that these "external" IT services "know" who the user is, the following information is provided during registration and/or usage of the external IT service and some data of the user(s) is transmitted to the IT service. The federated Identity management also ensures through the mutual trust model that the external IT service knows that the user really exists at the respective institution (validation of the account).
To enable these external IT services to identify the user, certain personal data is transmitted during registration and/or use of the service. The federated Identity management also ensures through the mutual trust model that the external IT service knows that the user really exists at the respective institution (validation of the account).


Within the context of the bwIDM Federation, the participating institutions have agreed on a minimum data set, which is transmitted to the external IT service. This data record includes, for example Attribute like eduPersonalPrincipalName, mail or givenName. These are so-called "standard attributes".
Within the context of the bwIDM Federation, the participating institutions have agreed on a minimum data set, which is transmitted to the external IT service. This data record includes, for example Attribute like eduPersonalPrincipalName, mail or givenName. These are so-called "standard attributes".
Line 23: Line 23:
== Which Entitlements do I need to use bwCloud-OS? ==
== Which Entitlements do I need to use bwCloud-OS? ==
To use the bwCloud-OS you need a bwCloud entitlement. A detailed overview of the current regulations on entitlements can be found [[Entitlements|here]].
To use the bwCloud-OS you need a bwCloud entitlement. A detailed overview of the current regulations on entitlements can be found [[Entitlements|here]].
<nowiki>'''</nowiki>Note:<nowiki>'''</nowiki> The specific bwCloud-OS entitlements are currently under review and may be subject to change.


== How can I find out which entitlements my account contains?==
== How can I find out which entitlements my account contains?==

Revision as of 15:06, 17 October 2025

In a Nutshell
  • Access to bwCloud-OS requires an active account from a bwIDM-participating institution.
  • Your account must include a valid bwCloud entitlement, assigned by your home institution. This is usually automatic. If missing, contact your institution’s IT support. The bwCloud-OS team cannot assign entitlements.
  • Log in once to the Dashboard to activate your profile. Setup is automated via bwIDM.
  • After login, select your home region as described here to begin using bwCloud-OS.


Entitlements

This page explains the bwIDM entitlements required to use bwCloud-OS and their impact on access, resources, and operating rules. Entitlements are currently under revision and might change soon.

What are "Entitlements" or "bwIDM Entitlements"?

Every member of an institution (university, college, PH, HAW, etc.) in Baden-Württemberg has a personal account to log in to and use the IT services provided by the institution. If the institution is a member of the federated identity management of Baden-Württemberg universities bwIDM, then associates of this institution can apply for further IT services offered by other institutions.

To enable these external IT services to identify the user, certain personal data is transmitted during registration and/or use of the service. The federated Identity management also ensures through the mutual trust model that the external IT service knows that the user really exists at the respective institution (validation of the account).

Within the context of the bwIDM Federation, the participating institutions have agreed on a minimum data set, which is transmitted to the external IT service. This data record includes, for example Attribute like eduPersonalPrincipalName, mail or givenName. These are so-called "standard attributes".

However, some IT services require specific information, such as whether a home institution is permitted to use a foreign IT service at all. This specific information can be added to the personal account of the user(s) through the assignment of an additional special attribute (eduPersonEntitlement).

Which Entitlements do I need to use bwCloud-OS?

To use the bwCloud-OS you need a bwCloud entitlement. A detailed overview of the current regulations on entitlements can be found here.

'''Note:''' The specific bwCloud-OS entitlements are currently under review and may be subject to change.

How can I find out which entitlements my account contains?

To find out which Entitlements are linked to an account, you can for example log into the "RegApp". When logging into a RegApp, an overview of the data to be transmitted is displayed. This overview also includes the supplied Entitlements (see screenshot).

File:Screenshot login bwSupportPortal.png


What do I do if my account has no bwCloud entitlement assigned to it?

The assignment of the entitlement is the sole responsibility of the respective home institiution. The bwCloud-OS team cannot add or remove entitlements to user accounts! In this case, please contact the central IT service department (computer center, IT service center, service center, ...) and request the assignment of the desired entitlement.


Regions

What does "region" mean in bwCloud-OS?

bwCloud-OS currently consists of four different operating sites = regions, which can be selected and administered via a common interface (dashboard). Each of the four operating sites acts as an independent region. This means: running instances in the Mannheim region receive an IP address according to the configuration of the Mannheim region. The IP address is specific to Mannheim and cannot move to another region. The region selection can be changed as described here.

What is a "home region"?

Each user in the bwCloud-OS is initially assigned a home region during the setup. For users from the four operating locations this assignment is of course trivial. For users from other locations we have oriented ourselves to the network topology of the BelWü. The goal of the current assignment is the shortest possible connection of the respective location to one of our operating sites.

For users, the assignment is usually not relevant. A table with the assignment can be found here.

Where do I select the region in the dashboard?

In the left half of the top navigation bar in the dashboard you can click on a drop-down menu to display the regions. The currently selected region is marked with a tick. A click on the respective region switches there.

File:Select region dashboard.png