Home Knowledge Base Administrator Integrations Univention UCS@school – Dataduck Connector (Sysadmin)

Univention UCS@school – Dataduck Connector (Sysadmin)

TABLE OF CONTENTS


Introduction

This article describes the Univention UCS@school integration with itslearning through the Dataduck connector. It covers how the connector synchronises users, groups and hierarchies, what the customer needs to prepare, and what happens to data during a school year change.

Important: This article covers the Dataduck-based Univention connector only. If your school uses the Itswizard connector or the ID Broker connector for UCS@school, see the relevant article for that integration instead.


1 Overview

The connector retrieves data from UCS@school through the Univention Provisioning API and converts it into IMS Enterprise XML, a format itslearning can natively import. The connector also stores the data in a local database, so that a full synchronisation of the data is always possible.

This synchronisation runs on a nightly basis. Both the connector (Dataduck) and itslearning are itslearning services, hosted within the itslearning infrastructure.

This integration supports importing parent users and parent-child relationships.


2 Prerequisites

Prerequisite: The following must be in place before the connector can be set up:

  1. The customer must be running UCS version 5.2 or newer. The Univention Provisioning API is only available from this version onwards.
  2. The customer installs the Provisioning API in the UCS App Center.
  3. The customer publishes the Provisioning API endpoint and provides the URL to itslearning. Typical UCS installations are not exposed to the internet, so changes to the firewall or proxy may be required. itslearning can provide the IP addresses that will contact the API.
  4. The customer creates a subscription for itslearning, covering the users/user and groups/group topics.

3 How synchronisation works

3.1 Initial synchronisation

The first time the subscription runs, it provides a so-called prefill: all data available in UCS@school at the time of the request.

3.2 Ongoing synchronisation

After the prefill, the subscription provides updates to directory objects that have changed since the previous request. itslearning stores the prefill together with all subsequent changes in an intermediate database, which at any given time contains a full, current snapshot of the data. It is this snapshot that is synchronised with itslearning on a nightly basis.

3.3 Data synchronised

The connector uses a subset of the properties available from the Provisioning API and maps them to the corresponding IMS Enterprise elements used by itslearning:

Source (UCS@school)itslearning fieldNotes
univentionObjectIdentifierSync keyUsed as the itslearning synckey
username (LDAP uid)UsernameCommonly used as the SSO attribute
firstname / lastnameFirst name / last name
E-mail / telephoneEmail / phone
ucsschoolRoleUser roleStudent, Teacher or Admin
ucsschoolLegalGuardianParent-child relationshipUsed to link a parent account to the student
Groups (first cn)Hierarchy sync key and title

Group memberships are based on the user's ucsschoolRole: students become student members and teachers become teacher members in their respective groups.


4 Back to school (school year change)

According to Univention, the school year change ("Schuljahreswechsel") is not a single event with a defined end, but a process that can run over the whole summer period and looks different for every customer. The recommendation is therefore to keep the regular nightly synchronisation running throughout the summer.

A new prefill should only be requested from the customer's UCS vendor if a complete refresh of the data is needed.


5 Security

5.1 In transit

From the Univention API to Dataduck: access to the Univention API is protected with API credentials and IP blocking. Data is transmitted over HTTPS.

From Dataduck to itslearning: data is sent over the Secure FTP protocol.

5.2 At rest

Both Dataduck and the itslearning platform are hosted in alignment with itslearning's security policies and processes.


6 Known limitations

Important: Groups are derived from user properties rather than read directly from UCS@school. This means empty groups, with no members, are not synchronised to itslearning.


More Help Resources

Have more questions? Reach out to your itslearning or support contact depending on the issue. 

Product Release notes

Stay updated with itslearning latest releases: https://itslearning.com/product-updates 

Service Status

Check the current status of itslearning services: https://status.itslearning.com/ 

Ideas Portal

Share your ideas and help shape the future of itslearning: https://ideas.itslearning.com/ 

Roadmap

Check out our roadmap: https://itslearning.com/global/roadmap/