Attachment_6_-_March_2019_Current_State_Report.pdf
PDF 927 KB Posted
- Attached to
- Enterprise Middleware Architecture and Services Federal contract opportunity
- Solicitation number
- 910031-19-R-0003
About this file
This is an award notice for an indefinite delivery, indefinite quantity contract solicitation for middleware architecture and services. The Department of Education's Office of Federal Student Aid seeks proposals to award an ID/IQ contract for a term of ten years to provide middleware support for its modernization efforts through multiple task order iterations of approximately two and a half years each. Along with the ID/IQ contract, FSA intends to award two initial task orders. The solicitation is set aside for small businesses under NAICS code 541519 for other computer related services.
Attachment 6 - March 2019 Current State Report
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNITED STATES
DEPARTMENT OF EDUCATION
EITA Current State Report
March 2019
Integrated Technical Architecture (ITA), Enterprise Service Bus (ESB), and Access and Identity Management System (AIMS)
Maintenance Support
Contract No. ED-FSA-14-O-0006
April 15, 2019
Attachment 6 - March 2019 Current State Report
Operations & Maintenance Support
EITA Current State Report, March 2019 i Version 1.0
Document Control
Document history:
Version Date Author Pages Changed
1.0 April 15, 2019 Initial version.
Release authorization:
Version Date Name Title Signature
1.0 4/15/19
Requesting changes:
To request a change to this document, contact the .
Document source:
The latest version of this document is available on the EITA Repository (located on FSA
SharePoint) at:
https://fsa.share.ed.gov/teams/to/EITA/EITALibrary/EITA/Forms/AllItems.aspx?RootFolder=%2 fteams%2fto%2fEITA%2fEITALibrary%2fEITA%2fContract%20Deliverables%2fCurrent%20St ate%20Report&FolderCTID=0x012000BB548D64BD70834983BF31CD81EF9826 ii Version 1.0
TABLE OF CONTENTS
1 INTRODUCTION
1.1 EITA OVERVIEW
1.2 EXECUTIVE SUMMARY
1.3 CONTENTS
2 INFORMATION SYSTEMS
2.1 EITA SUPPORTED INFORMATION SYSTEM
2.1.1 Active Directory (AD)
2.1.2 Borrower Defense (BD)
2.1.3 Central Processing System (CPS)
2.1.4 CPS / Business Services
2.1.5 CPS / Financial Aid Administrators (FAA) Access
2.1.6 CPS / FAFSA On the Web (FOTW)
2.1.7 CPS / FAFSA Debug
2.1.8 CPS / FAFSA Demonstration (FAFSA Demo)
2.1.9 CPS / FAFSA Web Service
2.1.10 CPS / FSADownload
2.1.11 CPS / Student Aid Internet Gateway (SAIG) Customer Service Site (PMCS)
2.1.12 CPS / Student Aid Internet Gateway (SAIG) and PM Enrollment
2.1.13 Citrix (EDUCATE / FSA)
2.1.14 Common Origination and Disbursement (COD)
2.1.15 CyberArk
2.1.16 Digital Communication Tool (DCT)
2.1.17 Electronic Cohort Default Rate (eCDR) Appeals System
2.1.18 EDConnect
2.1.19 Employee Enterprise Business Collaboration (EEBC) (SBM Applications - PATS, HSP, FIMS)
2.1.20 Experimental Sites (XSITES)
2.1.21 eZ-Audit and eZ-Audit DataMart
2.1.22 Feedback and Dispute Management System (FDMS)
2.1.23 Financial Aid Toolkit (formerly FSA4Counselors)
2.1.24 Financial Management System (FMS)
2.1.25 Financial Partners Portal (FPP)
2.1.26 FSAIC Oracle RightNow Cloud Solution (ORCS)
2.1.27 FSA Conferences Web Site
2.1.28 HEAL Online Processing System (HOPS)
2.1.29 Information for Financial Aid Professionals (IFAP)
2.1.30 Integrated Student Experience (ISE)
2.1.31 Microsoft Dynamic 365
2.1.32 Message Status Inquiry Tool (MSIT)
2.1.33 National Student Loan Data System (NSLDS)
2.1.34 NSLDS for Financial Aid Professionals (NSLDSFAP)
2.1.35 NSLDS For Students (NSLDSSA)
2.1.36 NSLDS Training Site (NSLDSTrain)
2.1.37 Netscaler VPN Appliance
2.1.38 Ombudsman Case Tracking System (OCTS and GE Users)
2.1.39 Partner Enterprise Business Collaboration (PEBC)
2.1.40 Person Authentication Service (PAS) (Admin Tool)
2.1.41 Postsecondary Education Participant System (PEPS)
iii Version 1.0
2.1.42 SAIG Mailbox
3 ITA COTS PRODUCTS & SERVERS
3.1 SERVER CONFIGURATION
3.1.1 Non-Production & Production Servers
3.2 ITA PRODUCTS
3.2.1 Apache Web Server
3.2.2 DigiGov Search
3.2.3 OpenText Open Deploy
3.2.4 OpenText TeamSite
3.2.5 Drupal
3.2.6 ER Studio
3.2.7 Jenkins
3.2.8 IBM HTTP Server (IHS)
3.2.9 IBM WebSphere Application Server (WAS)
3.2.10 IBM InfoSphere Information Server (InfoServer)
3.2.11 ISA Light
3.2.12 Logstash
3.2.13 MicroStrategy
3.2.14 Quadient Architect (Formerly Satori)
3.2.15 Oracle Database
3.2.16 SearchBlox
3.2.17 Wily Introscope
4 ACCESS AND IDENTITY MANAGEMENT SYSTEM (AIMS) COTS PRODUCTS &
SERVERS 22
4.1 SERVER CONFIGURATION
4.1.1 Non-Production & Production Servers
4.2 AIMS PRODUCTS AND INTERFACES
4.2.1 DB2
4.2.2 Lightweight Directory Access Protocol (LDAP)
4.2.3 Logstash
4.2.4 Oracle Database Server
4.2.5 Security Access Manager (SAM)
4.2.6 Security Identity Manager (SIM)
4.2.7 Symantec Validation and ID Protection Service (VIP) Enterprise Gateway
4.2.8 TAM Adapter
4.2.9 Tivoli Directory Integrator (TDI)
4.2.10 Tivoli Federated Identity Manager (TFIM)
4.2.11 WebSEAL
4.2.12 IBM WebSphere Application Server (WAS)
5 ENTERPRISE SERVICE BUS (ESB) INTERFACES, ENVIRONMENTS AND PRODUCTS
5.1 INTERFACE SUMMARY
5.1.1 Batch Interfaces
5.1.2 Real-Time Interfaces
5.1.3 ESB Web Service Interfaces
5.2 ESB ARCHITECTURE
5.2.1 Supported Environments
5.2.2 Server Tables
5.3 ESB PRODUCTS
iv Version 1.0
5.3.1 IBM WebSphere DataPower Gateway (IDG)
5.3.2 IBM Integration Bus (IIB)
5.3.3 IBM MQ (MQ) and IBM MQ Managed File Transfer (MFT)
5.3.4 Oracle Database
6 EITA CUSTOM DEVELOPMENT
6.1 ITA REUSABLE COMMON SERVICES (RCS) COMPONENTS
6.1.1 Component Factory
6.1.2 Email
6.1.3 Exception
6.1.4 JSP Tag Library
6.1.5 Logging
6.1.6 Audit Tracking Framework
6.1.7 Log Encryption
6.1.8 Persistence
6.1.9 PIN Web Service
6.1.10 Search
6.2 ACTIVE RCS COMPONENTS
6.3 RCS UTILITIES
6.3.1 RCS Logger
6.3.2 SMTP Mailing Appender
6.3.3 Portlets
6.4 ESB CUSTOM DEVELOPED CODE
6.5 AIMS CUSTOM DEVELOPED CODE
6.5.1 Change Password, Forgot Password, Forgot User Id
6.5.2 Edit Profile
6.5.3 Account Registration (Self Registration and FSA User ID Registration from PM)
6.5.4 SSO / DPA Approval
6.5.5 AIMS Web Services
6.5.6 Custom Authentication Service (CAS)
6.5.7 Two-Factor Authentication (TFA)
6.5.8 Custom Scripts
6.5.9 AIMS Tool for Application Customer Service Representation (CSR)
6.5.10 AIMS Help Desk Tool
7 APPENDICES
1 Version 1.0
1 INTRODUCTION
1.1 EITA Overview
The Enterprise Integrated Technical Architecture (EITA) provides a standardized, reusable infrastructure for enabling business capabilities within the Federal Student Aid (FSA) application community. The infrastructure comprises three main areas:
• Integrated Technical Architecture (ITA)
• Enterprise Service Bus (ESB)
• Access and Identity Management System (AIMS)
EITA provides a comprehensive set of technology to enable FSA’s application enterprise through common web architecture and services (ITA), a messaging infrastructure (ESB), and a common security infrastructure (AIMS).
1.2 Executive Summary
The March 2019 EITA Current State Report documents the current state of the products, servers, upgrades and services provided within the EITA for the period March 1, 2019 to March 31, 2019.
The intended audience is those who are familiar with the products and architecture used in the
EITA environment.
1.3 Contents
This report contains seven sections and eight appendices:
• Section 1 provides an overview and a summary of the contents of this report.
• Section 2 describes the FSA applications and products hosted in the EITA Production environment. Where applicable, a summary of activities affecting the applications has been added this month.
• Section 3 provides an overview of the ITA Commercial Off the Shelf (COTS) products and servers. Where applicable, a summary of activities affecting these products has been added this month.
• Section 4 provides an overview of the AIMS COTS products and servers. Where applicable, a summary of activities affecting these products has been added this month.
• Section 5 provides an overview of ESB interfaces, environments, and products. Where applicable, a summary of activities affecting these products has been added this month.
• Section 6 provides an overview of EITA custom development, including ITA Reusable
Common Services (RCS) components, ESB custom developed code and AIMS custom developed code.
• Section 7 provides an overview of the appendices associated with this document.
• Appendix A provides NGDC network diagrams of EITA Non-Production and Production environments.
• Appendix B provides a summary of EITA products, the servers on which they reside within NGDC, and the FSA information systems that use them.
2 Version 1.0
• Appendix C provides a mapping of FSA Applications to products used within the EITA environments in which they reside, ITA and AIMS RCS components the applications use them, and AIMS integration method.
• Appendix D provides a summary of Service Level Agreement (SLA) metrics and task order objectives related to requests that were received during the reporting period.
• Appendix E provides an inventory of EITA databases, the servers on which they reside within NGDC, and the FSA information systems that use them.
• Appendix F provides an inventory of ESB Message Classes with associated mailboxes, environment, and information system.
• Appendix G provides a summary of ESB source-to-target File and Real-Time interfaces as well as the ESB supported Web Service operations.
• Appendix H provides AIMS Two-Factor Authentication (TFA) Support Center metrics for the reporting period
3 Version 1.0
2 INFORMATION SYSTEMS
This section provides an overview of FSA Information Systems hosted in the EITA Production and Pre-Production environments or supported by EITA project teams. The EITA project teams provide the following services to these hosted applications:
• Expert COTS Product Support
• Architecture and Upgrade Support
• RCS Component Development and Support
• AIMS User Account Tier 2 Support
2.1 EITA Supported Information System
The EITA project teams provide subject matter expertise, best practices, and development advice for FSA development partners. EITA project teams also administer Non-Production environments that application teams can develop in. These Non-Production environments generally fall within one of the following two areas:
• Development - Used by application teams to test application code on a runtime environment that is similar to production. These environments use the same operating system, have the same directory structure, and use the same COTS product version.
• Test - Used by application teams for integrated testing and user acceptance testing.
Appendix A provides network diagrams of each EITA supported environment within NGDC.
The diagrams are updated as changes are made to the environments.
This section provides a brief description of the FSA Information Systems that are supported by
EITA project teams. In each Information System chart below, it is noted which EITA project team provides support. Current EITA updates for information systems can be found in EITA
Weekly Reports and monthly Project Management Reports.
2.1.1 Active Directory (AD)
AIMS synchronizes with EDUCATE Active Directory using Tivoli Directory Integrator (TDI) to populate user accounts into AIMS for FSA employees and contractors and to perform ongoing updates when AD has account changes. AIMS processes this information and creates or disables accounts in AIMS.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
AIMS AIMS synchronizes with EDUCATE Active Directory using Tivoli Directory
Integrator (TDI)
4 Version 1.0
2.1.2 Borrower Defense (BD)
The BD application allows loan servicers to process BD applications, consolidate, and discharge
Federal Student Loans.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
AIMS The BD application uses AIMS federation for authentication
2.1.3 Central Processing System (CPS)
The CPS system uses the federal methodology to calculate a student’s expected family contribution based on information provided on the Free Application for Federal Student Aid
(FAFSA) forms. The resulting Student Aid Report is mailed to the applicant and transmitted to any educational institution listed on the FAFSA form.
EITA Area Hosted/Supported
ITA N/A
ESB Interfaces using the ESB are listed in Appendix G.
AIMS N/A
2.1.4 CPS / Business Services
Business Services is a Web Service that is called by HP’s customer service User Interface so that
CSRs can assist FAFSA users who call for assistance.
EITA Area Hosted/Supported
ITA Hosted in the ITA environment
ESB Interfaces using the ESB are listed in Appendix G
AIMS N/A
5 Version 1.0
2.1.5 CPS / Financial Aid Administrators (FAA) Access
FAA Access to CPS Online consists of Student Inquiry, Return of title IV Funds (R2T4), and
Application/Correction Entry. These functions assist FAAs with administering the FSA programs.
EITA Area Hosted/Supported
ITA The FAA Access application is hosted in the ITA environment.
ESB N/A
AIMS The FAA Access application is protected by AIMS. User identity is communicated to FAA Access via http header. User identities are synchronized between the repositories via custom developed web services.
2.1.6 CPS / FAFSA On the Web (FOTW)
College students and schools use the FOTW application to submit financial aid applications to
FSA via the Internet. ITA provides a dedicated WebSphere environment for FAFSA because the site is utilized by millions of applicants. The peak periods occur in October and March and as many as 60k applications are processed each day.
EITA Area Hosted/Supported
ITA The FAFSA website is part of the ITA environment and fronted by Akamai.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS N/A
2.1.7 CPS / FAFSA Debug
FAFSA Debug is a utility available for FAFSA developers to recreate and test issues reported in production by customers, institutions, or FSA.
EITA Area Hosted/Supported
ITA FAFSA Debug is hosted in the ITA environment.
ESB Interfaces using the ESB are listed in Appendix G.
6 Version 1.0
2.1.8 CPS / FAFSA Demonstration (FAFSA Demo)
Schools and conferences use the FAFSA Demo application for training students and parents on how to fill out and submit FAFSA applications. FAFSA Demo uses Google for search functionality.
EITA Area Hosted/Supported
ITA FAFSA Demo is hosted in the ITA environment.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS N/A
2.1.9 CPS / FAFSA Web Service
The FAFSA Web Service enhances FSA’s EITA, AIMS and ESB systems in support of the
FAFSA External application programming interfaces (API) effort. The web service allows authorized Data Transmitters to transmit an applicant’s data to FAFSA. AIMS established a credential management portal to allow certificate management by authorized users. The external partner’s Data Transmitter utilizes web service requests to transmit data, and DataPower/ESB functions as the security gateway and communicates with AIMS, Participation Management
(PM), and FAFSA systems. Once the data is transmitted to and processed by FAFSA, DataPower/ESB sends a transmission response back to the Data Transmitter.
EITA Area Hosted/Supported
ITA FAFSA Web Service is hosted in the ITA environment.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS N/A
2.1.10 CPS / FSADownload
The FSADownload Web site provides links to downloadable technical references and guides, software and associated documentation. FSADownload uses Google for search functionality.
EITA Area Hosted/Supported
ITA FSADownload sits in the shared ITA environment.
ESB N/A
7 Version 1.0
2.1.11 CPS / Student Aid Internet Gateway (SAIG) Customer Service Site (PMCS)
Customer Service site to support PM Enrollment.
EITA Area Hosted/Supported
ITA Hosted within the shared ITA environment.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS The application is secured by AIMS. User identity is communicated via http header. User identities are synchronized between the repositories via custom developed web services.
2.1.12 CPS / Student Aid Internet Gateway (SAIG) and PM Enrollment
SAIG is a system for organizations to transfer information electronically to and from the
Department of Education. Many student financial aid services can be accessed via the SAIG.
EITA Area Hosted/Supported
ITA SAIG Enrollment is hosted within the shared ITA environment.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS The SAIG Enrollment Application (Participation Management) application is secured by AIMS. User identity is communicated to Participation
Management via http header. User identities are synchronized between the repositories via custom developed web services.
2.1.13 Citrix (EDUCATE / FSA)
Citrix is deployed to provide FSA/ED users with a virtual desktop environment. This common desktop environment provides FSA/ED users with a baseline set of applications that is applicable to all users. This solution provides a dedicated Citrix environment for FSA/ED users that can be securely accessed internally, as well as over the internet.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
AIMS Citrix uses TFA Radius Server (Symantec VIP Enterprise Gateway)
8 Version 1.0
2.1.14 Common Origination and Disbursement (COD)
The COD application is hosted outside of the ITA and the NGDC but does have interfaces that are maintained as part of the ESB. The COD application uses AIMS federation for authentication.
EITA Area Hosted/Supported
ITA N/A
ESB Interfaces using the ESB are listed in Appendix G.
AIMS The application uses AIMS federation for authentication.
2.1.15 CyberArk
CyberArk software technology manages passwords, keeps audit trails, and integrates with existing authentication mechanisms. CyberArk has the following features:
• Automation of password changes
• Brokering of passwords
• Auditing of user sessions via keystroke logging, screen capture and video
• Workflow and role-based access of servers and infrastructure resources
• Simplification of user accounts on hardware to role-based accounts
EITA Area Hosted/Supported
ITA N/A
ESB N/A
AIMS AIMS provisions CyberArk groups to CyberArk Active Directory for
CyberArk access.
2.1.16 Digital Communication Tool (DCT)
The DCT is an FSA system serving as a digital communications tool for the department.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
AIMS The application uses AIMS federation for authentication.
9 Version 1.0
2.1.17 Electronic Cohort Default Rate (eCDR) Appeals System
The eCDR Appeals application allows schools, servicers, GAs, and FSA to complete the Cohort
Default Rate appeals process electronically.
EITA Area Hosted/Supported
ITA eCDR Appeals is hosted within the ITA environment.
ESB N/A
AIMS The eCDR Appeals application is secured by AIMS. User identity and fine-grained authorization information is communicated via http header.
2.1.18 EDConnect
EDConnect is a custom client-side software product used to send and receive data transmissions securely over the Internet. This software presents a user interface for users to send and receive data. The EDConnect is coded in the C++ language and utilizes the TDClient Windows API. The software is installed on the client’s standalone PC or in a workstation/network server environment.
EITA Area Hosted/Supported
ITA N/A
ESB Interfaces using the ESB are listed in Appendix G.
AIMS The EDConnect user authentication is enabled by a custom developed web service.
2.1.19 Employee Enterprise Business Collaboration (EEBC) (SBM Applications - PATS, HSP, FIMS)
EEBC is an internal facing platform that is used by Employees and Contractors for collaboration and knowledge management. EEBC resides on the Enterprise Business Collaboration (EBC) platform which allows FSA project teams to effectively manage and share documents, instant messages, schedule virtual meetings, and create workflows that automate business processes.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
AIMS EEBC Serena components are secured by AIMS. User identity for Serena based components is communicated by http header.
10 Version 1.0
2.1.20 Experimental Sites (XSITES)
This application is used to facilitate the reporting of information between schools that are participating in the XSITES Initiative and FSA. The XSITES Initiative is ED/FSA’s field-test for changes to specific Title IV statutory/regulatory requirements. Participating schools are required to submit an annual report that captures performance-based data for the prior academic year. The
XSITES Annual Reporting Tool is used to collect this data. The site is secure and integrated behind AIMS.
EITA Area Hosted/Supported
ITA XSITES is part of the ITA environment.
ESB N/A
AIMS The XSITES application is secured by AIMS. User identity and fine-grained authorization information is communicated via http header.
2.1.21 eZ-Audit and eZ-Audit DataMart eZ-Audit provides schools with the ability to submit financial statements and compliance audits to FSA via the Web. eZ-Audit historical data is maintained in a separate data mart that is accessed via the MicroStrategy Web site. The eZ-Audit Data Mart has a dedicated Oracle database.
EITA Area Hosted/Supported
ITA eZ-Audit and eZ-Audit DM both are part of the ITA environment.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS The eZ-Audit DataMart application is secured by AIMS. User identity is communicated by http header. MicroStrategy then looks up authorization information in the SAM LDAP.
2.1.22 Feedback and Dispute Management System (FDMS)
FDMS (formerly Enterprise Complaints System) provides a complaints system to ensure quality, service, and accountability for the DoED, its contractors, colleges, and loan servicers. FDMS has two portals, one for ECS Service console application and the other for partner portal. The ECS
Service Console includes FSA business unit users, other authorized Department of Education employees, contact center agents, and system administrators and uses the same URL as OCTS.
The Partner Portal includes FSA loan servicers, private collection agencies, other FSA system contractors. These partner portal user accounts are provisioned from PM Enrollment.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
11 Version 1.0
EITA Area Hosted/Supported
AIMS The application uses AIMS federation for authentication
2.1.23 Financial Aid Toolkit (formerly FSA4Counselors)
The purpose of the Financial Aid Toolkit Web site is to provide financial aid counselors with various sources of information so that they can assist students and parents with planning and preparation for college, career and trade school. Financial Aid Toolkit uses DigiGov for search functionality.
EITA Area Hosted/Supported
ITA Financial Aid Toolkit is part of the ITA environment.
ESB N/A
AIMS TeamSite content for Financial Aid Toolkit is secured by AIMS, but the application is not. User identity is communicated to TeamSite via http header.
2.1.24 Financial Management System (FMS)
The FMS is a centralized system for all FSA financial transactions. It allows financial partners to collect, process, maintain, transmit, and report data about financial events online. It also provides functionality to support financial planning and budgeting activities, accumulate and report cost information, and prepare financial statements.
EITA Area Hosted/Supported
ITA N/A
ESB Interfaces using the ESB are listed in Appendix G.
AIMS FMS uses AIMS custom TFA registration to support their Two Factor service
2.1.25 Financial Partners Portal (FPP)
FPP work in partnership with Guaranty Agencies, Lenders, Servicers, Trade Associations, Trustees, Schools and Secondary Markets to ensure access for students to Federal Student Loans, particularly the Federal Family Education Loan (FFEL) program. In addition, Financial Partners work with Guaranty Agencies currently participating in Voluntary Flexible Agreements (VFA) and with State Grant Agencies on the LEAP/SLEAP grant program. The Web site uses Google for search functionality.
EITA Area Hosted/Supported
ITA FPP is hosted in the ITA environment.
ESB N/A
12 Version 1.0
EITA Area Hosted/Supported
AIMS Access to the TeamSite content for FPP is secured by AIMS, but the FPP application is not. User identity is communicated to TeamSite via http header.
2.1.26 FSAIC Oracle RightNow Cloud Solution (ORCS)
The ORCS system allows the FSAIC ISSO to approve FSAIC users that were granted/have an
AIMS ID to access the ORCS system.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
AIMS The application uses AIMS federation for authentication.
2.1.27 FSA Conferences Web Site
The FSA Conferences Web site provides information on FSA conferences and events. The site only contains static information so it does not use the WebSphere Application server or Oracle database server.
EITA Area Hosted/Supported
ITA FSA Conferences Website is part of ITA.
ESB N/A
AIMS FSA Conferences TeamSite branch is secured by AIMS, but the web application is not. User identity is communicated to TeamSite via http header.
2.1.28 HEAL Online Processing System (HOPS)
The Health Education Assistance Loan (HEAL) HOPS enables the HEAL program to project the government’s potential liability for future claim payments and to track payment, default and collections data on HEAL loans. The HOPS system maintains all necessary information regarding HEAL borrowers, schools, servicers, loans and loan holders, claims, and litigation.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
AIMS The application is protected by AIMS using forms based single-sign-on.
13 Version 1.0
2.1.29 Information for Financial Aid Professionals (IFAP)
The IFAP Web site is an electronic library for financial aid professionals containing publications, regulations, and guidance regarding the administration of Title IV Federal Student Aid Programs.
A beginning user learns the software functions and practices using the software in a simulated environment. IFAP uses Google for search functionality. TeamSite is used to deploy updates to the web site.
EITA Area Hosted/Supported
ITA IFAP resides in the shared ITA environment.
ESB N/A
AIMS TeamSite content for IFAP is secured by AIMS, but the application is not.
User identity is communicated to TeamSite via http header.
2.1.30 Integrated Student Experience (ISE)
The ISE (StudentAid.Gov) website, FSA’s first mobile optimized site, consolidates multiple websites such as College.gov, Ombudsman.gov, Federalstudentaid.ed.gov and Studentaid.ed.gov to support the following:
1 The Federal CIO’s Digital Government Strategy to “Enable the American people and an increasingly mobile workforce to access high-quality digital government information and services anywhere, anytime, on any device…”
2 The Presidential Memorandum to: Enhances Online and Mobile Resources for Loan
Repayment Options and Debt Management.
EITA Area Hosted/Supported
ITA The ISE website is part of the ITA environment and fronted by Akamai.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS ISE Admin site is protected by AIMS. User identity is communicated via http header.
2.1.31 Microsoft Dynamic 365
The customer relationship management (CRM) solution used by GDIT for CPS Help Desk.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
14 Version 1.0
2.1.32 Message Status Inquiry Tool (MSIT)
The MSIT is a tool developed by ESB to allow business owners and application partners to view
EAI interface statistics both historically and in real time.
EITA Area Hosted/Supported
ITA MSIT sits in the ITA WAS environment
ESB Interfaces using the ESB are listed in Appendix G.
AIMS The MSIT application is secured by AIMS. User identity is communicated to
MSIT via http header.
2.1.33 National Student Loan Data System (NSLDS)
The NSLDS is the central database for student aid. It receives data from schools, agencies that guaranty loans, the Direct Loan program, the Pell Grant program, and other ED programs.
NSLDS provides a centralized, integrated view of loans and Pell grants that are tracked through their entire cycle, from approval to closure.
EITA Area Hosted/Supported
ITA NSLDS web application is deployed in the shared ITA Environment
ESB Interfaces using the ESB are listed in Appendix G.
AIMS NSLDS is behind AIMS. User identity is communicated to NSLDS via http header.
2.1.34 NSLDS for Financial Aid Professionals (NSLDSFAP)
The NSLDSFAP site provides access to the NSLDS application to Financial Aid Professionals.
EITA Area Hosted/Supported
ITA NSLDS FAP is hosted within the shared ITA environment.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS NSLDS FAP is behind AIMS. User identity is communicated via http header.
15 Version 1.0
2.1.35 NSLDS For Students (NSLDSSA)
The NSLDS is the U.S. Department of Education's central database for student aid. NSLDS receives data from schools, Guaranty Agencies, the Direct Loan program, the Pell Grant program, and other Department of Education programs. NSLDS Student Access provides a centralized, integrated view of Title IV loans and Pell grants so that recipients of Title IV Aid can access and inquire about their Title IV loans and/or Pell grant data.
EITA Area Hosted/Supported
ITA NSLDS is hosted within the in the shared ITA environment.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS N/A
2.1.36 NSLDS Training Site (NSLDSTrain)
The NSLDSTrain site provides new users with a comprehensive view of the functions of
NSLDS.
EITA Area Hosted/Supported
ITA NSLDSTrain sits in the shared ITA environment.
ESB Interfaces using the ESB are listed in Appendix G.
AIMS NSLDSTrain is behind AIMS. User identity is communicated via http header.
2.1.37 Netscaler VPN Appliance
VPN allowing FSA users to access the NGDC network.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
AIMS The system uses AIMS federation for authentication.
2.1.38 Ombudsman Case Tracking System (OCTS and GE Users)
Ombudsman Case Tracking System using Salesforce.
EITA Area Hosted/Supported
ITA N/A
ESB N/A
16 Version 1.0
2.1.39 Partner Enterprise Business Collaboration (PEBC)
PEBC is an external facing platform that provides an end to end view of FSA’s operating partners, including Lenders, Servicers, Guaranty Agencies, Schools, and Software Providers.
PEBC resides on the EBC platform which allows partners to integrate and streamline core business processes through workflow automation and migration of services and data provided in current legacy systems.
EITA Area Hosted/Supported
ITA N/A
ESB Interfaces using the ESB are listed in Appendix G.
AIMS The PEBC application is integrated with AIMS. User identity for Serena based components is communicated by http header. The Serena internal user repository is managed by a custom developed ITIM adapter. SharePoint based components receive identity and authorization information via SAML tokens generated by the TFIM AIMS component.
2.1.40 Person Authentication Service (PAS) (Admin Tool)
PAS enables FSA’s non-privileged users (students, parents and borrowers) to securely access
FSA systems and data.
EITA Area Hosted/Supported
ITA N/A
ESB Interfaces using the ESB are listed in Appendix G.
AIMS PAS Admin Tool is secured by AIMS. User identity is communicated via http header.
2.1.41 Postsecondary Education Participant System (PEPS)
The PEPS system maintains school demographic, participation, and Title IV eligibility data.
EITA Area Hosted/Supported
ITA N/A
ESB Interfaces using the ESB are listed in Appendix G.
17 Version 1.0
2.1.42 SAIG Mailbox
Postsecondary schools, lenders, guarantors, and their servicers can sign up for a SAIG mailbox to send and receive application (FAFSA) and recipient data with the US Department of
Education.
EITA Area Hosted/Supported
ITA SAIG Mailbox is hosted within the shared ITA environment
ESB Interfaces using the ESB are listed in Appendix G.
AIMS The SAIG Enrollment Application (Participation Management) application is secured by AIMS. User identity is communicated to Participation
Management via http header. User identities are synchronized between the repositories via custom developed web services.
18 Version 1.0
3 ITA COTS PRODUCTS & SERVERS
3.1 Server Configuration
3.1.1 Non-Production & Production Servers
See attached server configuration diagram (Appendix A) or server matrix (Appendix B).
3.2 ITA Products
This section provides an overview of ITA products used by FSA applications hosted in the ITA production environment. The specific NGDC servers on which the products are installed are summarized in Appendix A and Appendix B. Please refer to Appendix B for all current version numbers. Current EITA product updates can be found in EITA Weekly Reports and monthly
Project Management Reports.
3.2.1 Apache Web Server
The Apache HTTP Server is web server software used by the ISE application.
3.2.2 DigiGov Search
Government search solution used by Financial Aid Toolkit and ISE.
3.2.3 OpenText Open Deploy
OpenText is a distribution engine which works in conjunction with OpenText TeamSite and allows for the deployment of content and code to application servers, web servers, and databases.
3.2.4 OpenText TeamSite
TeamSite enables content contribution, collaboration, and management across the enterprise.
The product provides the necessary components to streamline business processes, integrate currently used productivity tools, and accelerate all eBusiness initiatives, enhanced by the
WorkFlow Plus add-on. TeamSite is currently running in the ITA environment and is integrated with AIMS.
3.2.5 Drupal
Drupal is a free and open-source content management framework (CMF) written in PHP. It is used as a back-end system for the ISE application.
19 Version 1.0
3.2.6 ER Studio
ER Studio is an Embarcadero product. The tool is used for enterprise data and metadata modelling. The repository resides on a SQL Server environment and used for version control.
Users check in and checkout objects to the repository.
3.2.7 Jenkins
Jenkins is a continuous integration (CI) tool written in Java, which runs in a servlet container, such as Apache Tomcat. It supports SCM tools including CVS, and can execute Apache based projects, as well as arbitrary shell scripts and Windows batch commands. EITA utilizes Jenkins as a repository for WAS configurations and to facilitate auditing.
3.2.8 IBM HTTP Server (IHS)
IBM’s Web serving offering is based upon the Apache Web server. The implementation that
IBM has custom tailored allows for tight integration into the IBM WebSphere applications and other IBM products. IHS allows for the serving of multiple Web documents, while providing necessary application interaction.
3.2.9 IBM WebSphere Application Server (WAS)
The IBM WAS manages the deployment and runtime environment for Java based applications.
It makes use of Java technology compatibility for most Web application offerings. WAS is a highly configurable solution for a small offering or a large enterprise. It is the middleware between the HTTP servers and the databases. WAS stores session information in a session database which is hosted on the ITA Oracle Database servers.
3.2.10 IBM InfoSphere Information Server (InfoServer)
IBM InfoSphere InfoServer is an umbrella of products. At FSA those products consist of:
• Information Analyzer - Profiles and establishes an understanding of source systems and monitors data rules
• DataStage - Extracts, transforms, and loads data between multiple sources and targets
• QualityStage - Standardizes and matches information across heterogeneous sources
• Business Glossary - Creates, manages, shares an enterprise vocabulary and classification system and searches metadata definitions.
• Business Glossary Anywhere is an application independent search / pop-up box that can be called from any application (Excel, data modeling tools, reporting applications, Microsoft Word, etc.) that provides instant access to Business Glossary terms, taxonomies and stewards.
• FastTrack - Simplifies and streamlines communication between the business analyst and developer by capturing business requirements and automatically translating into
DataStage ETL jobs.
20 Version 1.0
• Metadata Workbench - Provides end-to-end metadata management, depicting the relationships between sources and consumers.
• Information Services Director - Allows information access and integration processes to be published as reusable services in a service-oriented architecture.
3.2.11 ISA Light
ISA Light provides automatic data collection, diagnostic testing, symptom analysis, and pre-requisite checking for IBM InfoSphere InfoServer installations.
• Provides diagnostic testing and health verifications of installations of any tiers of
InfoSphere Information Server and its components
• Providing automatic gathering and collection of diagnostic data and log files and FTP to
IBM Customer Support
• Graphically documents the installation topology and highlighting communication channels
• Performing symptom analysis and log analysis to help streamline the problem determination process
• Validating the prerequisites of the installation
3.2.12 Logstash
A dynamic data collection pipeline with an extensible plugin ecosystem. Logstash is the primary mechanism to transform and load data into Elasticsearch. FSA expanded the existing FSA Elastic
Stack implementation to route EITA product and application logs into the Elastic Log aggregation cluster for performing real-time indexing, parsing and searching.
3.2.13 MicroStrategy
MicroStrategy provides reporting, analysis, and information delivery capabilities. MicroStrategy is currently running in the ITA environment and it is integrated with AIMS. The FSA applications that use MicroStrategy is eZ-Audit.
3.2.14 Quadient Architect (Formerly Satori)
Satori Architect software is integrated with FAFSA and is used to provide address scrubbing and verification functionality.
3.2.15 Oracle Database
Most ITA applications require a database to hold business information. The database product used by ITA is Oracle.
21 Version 1.0
3.2.16 SearchBlox
FSA identified the SearchBlox COTS product as the replacement for the Google Search
Appliance (GSA), which reached end of life in October 2018. SearchBlox is integrated with ITA
Reusable Common Services (RCS) and serves search results for multiple ITA applications.
3.2.17 Wily Introscope
Wily Introscope is a tool which FSA uses for end-to-end monitoring of application transactions.
The tool gathers data from Production environments for analysis for fine tuning. Please note that this tool is not managed by EITA.
22 Version 1.0
4 ACCESS AND IDENTITY MANAGEMENT SYSTEM (AIMS) COTS
PRODUCTS & SERVERS
4.1 Server Configuration
4.1.1 Non-Production & Production Servers
See attached server configuration diagram (Appendix A) or server matrix (Appendix B).
4.2 AIMS Products and Interfaces
This section provides an overview of products used by AIMS in the production environment.
The specific NGDC servers on which the products are installed are summarized in Appendix A and Appendix B. The specific NGDC servers on which the products are installed are summarized in Appendix B. Please refer to Appendix B for all current version numbers.
4.2.1 DB2
DB2 is the backing store for the AIMS LDAP servers. All information stored by LDAP is kept in DB2 tables. The DB2 database schema is dictated by the LDAP software requirements. High availability is not needed for LDAP backing DB2 database because data replication is handled by the LDAP software. DB2 is also used by TIM to store historical transaction information. This database schema is dictated by the ITIM software requirements. The TIM transactional database is Test, EPT, and Production environments is configured in High Availability HADR configuration.
4.2.2 Lightweight Directory Access Protocol (LDAP)
Both Security Access Manager (SAM), formerly known as Tivoli Access Manager (TAM), and
Tivoli Identity Manager (TIM) use Lightweight Directory Access Protocol (LDAP) directories to store user credentials. In the AIMS production environment, there is an additional SAM LDAP registry that functions as a failover to the primary registry. In both the Development and
Production environments, the LDAP directories are installed on their corresponding TIM and
SAM servers.
4.2.3 Logstash
A dynamic data collection pipeline with an extensible plugin ecosystem. Logstash is the primary mechanism to transform and load data into Elasticsearch. FSA expanded the existing FSA Elastic
Stack implementation to route EITA product and application logs into the Elastic Log aggregation cluster for performing real-time indexing, parsing and searching. The Logstash client is installed on AIMS servers in NGDC.
23 Version 1.0
4.2.4 Oracle Database Server
AIMS consists of an Oracle Database used for staging, managing, and transforming data required for identity and access management. The architecture supports loading of the data into the database through IBM Directory Integrator as well as the FSA’s EAI bus. The AIMS database is used as a repository for all demographic and other information collected during the user provisioning process. The data in this Oracle instance is a superset of the data in the Directory server, which contains only the data needed for authentication and authorization.
4.2.5 Security Access Manager (SAM)
The IBM SAM, formerly known as Tivoli Access Manager (TAM), product is a policy-based access management solution that integrates with FSA applications to deliver a secure, unified and personalized user experience. SAM provides authentication and authorization Application
Programming Interfaces (APIs) thus enabling integration with application platforms such as
J2EE, the most commonly used application platform for the FSA Target State Vision Systems.
SAM secures access to business-critical applications and data spread across FSA systems and provides Web-based single sign-on for the various enterprise applications.
4.2.6 Security Identity Manager (SIM)
SIM helps FSA set up new accounts and passwords quickly for employees and customers, including the ability for users to reset and synchronize their own passwords. SIM enables FSA to improve visibility into security management operations and quickly produce centralized reports about security policy, access rights, and audit events for auditors. Helps increase user and IT efficiency by cutting elapsed turn-on time for new accounts and decrease errors by automating user submission and approval requests. Reduces IT administration costs by providing Web self-care interfaces.
4.2.7 Symantec Validation and ID Protection Service (VIP) Enterprise Gateway
The TFA authentication architecture consists of Symantec VIP Enterprise and Web Service modules. These modules utilize Symantec’s cloud based VIP authentication service to validate
TFA credentials. User ID and token serial number mapping are stored securely in-cloud at
Symantec’s datacenter for flexibility and reliability. FSA’s Enterprise TFA solution supports both RADIUS and web service protocols to meet various systems need for multi-factor authentication.
The Department of Education uses the Symantec VIP also known as the RADIUS server for Two
Factor Authentication.
24 Version 1.0
4.2.8 TAM Adapter
The TAM adapter is bundled with the TIM software. It allows TIM to manage SAM user and group information including user names, passwords, group memberships and any additional information needed by SAM for authorization decisions. The TAM adapter leverages the TDI runtime.
4.2.9 Tivoli Directory Integrator (TDI)
TDI enables consistent data throughout multiple identity or generic data resources. The TDI server and runtime provide connectors for an extremely diverse set of greatly simplifying migration or loading of data. AIMS uses TDI to batch load users when integrating new applications, to develop custom SIM adapters to allow management of internal user repositories of integrated applications, to synchronize user information with the Educate active directory, to load nightly files into the Oracle database, and as part of the TAM adapter. TDI leverages a java runtime and can be extended with custom Java extensions.
4.2.10 Tivoli Federated Identity Manager (TFIM)
TFIM provides web and federated single sign-on (SSO) to end users across multiple applications.
TFIM leverages support for the emerging OAuth open standard for authorization and other standards like SAML, OpenID, Liberty, WS-Federation, WS-Security, WS-Trust to provide employees SSO access to enterprise, SaaS, and cloud-based applications. TFIM also integrated with Tivoli Access Manager to seamlessly integrate with current SSO implementations. TFIM is not directly involved in user authentication or the creation of an application session. Instead, Tivoli Federated Identity Manager relies on a point of contact server. The point of contact server is a proxy or application server that interacts with a user, which in AIMS is WebSEAL. TFIM is used by the Department of Educate G5 application to provide a SAML assertion to authenticate internal users. TFIM is also used by FSA’s Netscaler appliance NGDC VPN solution, CPS SAIG
Helpdesk - Microsoft Dynamics CRM Online (Office 365), and FSAIC HP Oracle RightNow
Cloud Solution (ORCS) to provide a SAML assertion to authenticate AIMS users. In addition
SharePoint based components receive identity and authorization information from TFIM.
4.2.11 WebSEAL
The enforcement of the security policy is the job of the WebSEAL resource manager.
WebSEAL calls the SAM authorization service with the credentials of the user making the request, the type of access desired, and the object to be accessed. The authorization service, also known as the authorization engine, uses the security policy to determine whether the request should be allowed, denied, or conditionally allowed pending additional verification by the resource manager. The resource manager takes the recommendation of the authorization service, performs any additional verification actions, and ultimately either denies the request, or permits the request to be processed.
WebSEAL junctions serve as the TCP/IP connection between a front-end WebSEAL server and a back-end Web application server. Junctions logically combine the Web space of the back-end server with the Web space of the WebSEAL server, resulting in a unified view of the entire Web
25 Version 1.0 object space. A junction allows WebSEAL to provide protective services on behalf of the back-end server.
In the AIMS Production environment, there is a primary and a failover WebSEAL server. If the primary server experiences an application failure, hardware failure, or an operating system error, the failover server will automatically respond to user requests until the primary server is able.
This failover clustering provides hardware redundancy and ensures high availability.
4.2.12 IBM WebSphere Application Server (WAS)
The IBM WAS manages the deployment and runtime environment for AIMS custom Java based applications. It makes use of Java technology compatibility for most Web application offerings.
26 Version 1.0
5 ENTERPRISE SERVICE BUS (ESB) INTERFACES, ENVIRONMENTS
AND PRODUCTS
5.1 Interface Summary
The sections below describe the various system-to-system interfaces supported by the ESB team,
- previously known as the Enterprise Application Integration (EAI) team. These interfaces include batch file transfers, real-time MQ transfers, and web services that are available to various systems.
5.1.1 Batch Interfaces
Batch transactions are generally large, multi-record files transmitted on a defined or regular interval for which the submitting system is not typically expecting an immediate response or acknowledgement. This type of transaction comprises the majority of inter-system communication at FSA.
For a complete summary of source-to-target ESB Batch Interfaces, please refer to Appendix G.
5.1.2 Real-Time Interfaces
Unlike batch, real-time transactions occur immediately based on a user submission or action and typically require an immediate or real-time response or acknowledgement. This type of transaction is often associated with FSA’s web-based applications such as FAFSA.
For a complete summary of source-to-target ESB Real-Time Interfaces, please refer to Appendix
G.
5.1.3 ESB Web Service Interfaces
The ESB also supports a number of real-time web service operations. These transactions are similar to the real-time MQ transactions but are based on SOAP/XML. This type of interface is also often associated with FSA’s web-based applications such as AIMS and COD.
For a complete summary of ESB supported Web Service operations, please refer to Appendix G.
5.2 ESB Architecture
5.2.1 Supported Environments
The ESB team built and maintains environments to support internal and application interface development, enhancements, and production fixes as they progress through the development lifecycle. The following is a list of all the environments:
• Architecture Development
• Integration Development
• Integration Test (includes: UAT and IST)
• Performance Test
• Staging
• Production
27 Version 1.0
5.2.2 Server Tables
WebSphere MQ, and DataPower configurations are installed and configured on numerous servers and must be managed across each of the environments to ensure the integrity of the baseline. Please refer to Appendices A and C (NGDC) for the detailed architecture diagram and server matrix.
5.3 ESB Products
This section provides an overview of software components used in the ESB architecture. Details on the versions used for each application are provided in Appendix B.
5.3.1 IBM WebSphere DataPower Gateway (IDG)
IBM WebSphere DataPower Gateway is IBM’s hardware ESB, delivering common message transformation, integration, and routing functions in a network device, cutting operational costs, and improving performance. By making on-demand data integration part of the shared Service-
Oriented Architecture (SOA) infrastructure, the IDG is one of the few non-disruptive technologies for application integration.
5.3.2 IBM Integration Bus (IIB)
IIB provides function and transport capabilities that support and facilitate enterprise-level business integration. IIB provides for message/data transformation and database integration, content and table-driven routing capabilities and multi-protocol event switching that fully supports WebSphere MQ Series protocols. This product is a core component in the ESB infrastructure and has resulted in the reduction of our custom code-base by several thousand lines through the replacement of custom java-based components. IBM has rebranded the product from
WebSphere Message Broker (WMB).
5.3.3 IBM MQ (MQ) and IBM MQ Managed File Transfer (MFT)
Formerly known as MQSeries and IBM WebSphere MQ, IBM MQ provides the base-messaging infrastructure. SupportPac MA0F and SupportPac MQ Classes for Java and MQ Classes for Java
Message Service are both part of the IBM MQ package. These provide a simple application-programming interface, support for point-to-point publish/subscribe messaging, and a Java development and application programming interface.
IBM MQ MFT leverages the IBM MQ messaging platform to provide a high-speed transport mechanism for transferring large bulk files between systems for batch transactions. When sending a file, MFT automatically splits it up into MQ messages, sends it across a channel(s), and reassembles it at the destination machine.
28 Version 1.0
5.3.4 Oracle Database
Oracle provides the data repository for Data Integrator (DI) file transfer status information for the ESB Message Status Inquiry Tool (an internally used utility).
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .