Univention UCS@school – Dataduck Connector (Sysadmin)
TABLE OF CONTENTS
- 1 Overview
- 2 Prerequisites
- 3 How synchronisation works
- 4 Back to school (school year change)
- 5 Security
- 6 Known limitations
Introduction
This article describes the Univention UCS@school integration with itslearning through the Dataduck connector. It covers how the connector synchronises users, groups and hierarchies, what the customer needs to prepare, and what happens to data during a school year change.
Important: This article covers the Dataduck-based Univention connector only. If your school uses the Itswizard connector or the ID Broker connector for UCS@school, see the relevant article for that integration instead.
1 Overview
The connector retrieves data from UCS@school through the Univention Provisioning API and converts it into IMS Enterprise XML, a format itslearning can natively import. The connector also stores the data in a local database, so that a full synchronisation of the data is always possible.
This synchronisation runs on a nightly basis. Both the connector (Dataduck) and itslearning are itslearning services, hosted within the itslearning infrastructure.
This integration supports importing parent users and parent-child relationships.
2 Prerequisites
Prerequisite: The following must be in place before the connector can be set up:
- The customer must be running UCS version 5.2 or newer. The Univention Provisioning API is only available from this version onwards.
- The customer installs the Provisioning API in the UCS App Center.
- The customer publishes the Provisioning API endpoint and provides the URL to itslearning. Typical UCS installations are not exposed to the internet, so changes to the firewall or proxy may be required. itslearning can provide the IP addresses that will contact the API.
- The customer creates a subscription for itslearning, covering the users/user and groups/group topics.
3 How synchronisation works
3.1 Initial synchronisation
The first time the subscription runs, it provides a so-called prefill: all data available in UCS@school at the time of the request.
3.2 Ongoing synchronisation
After the prefill, the subscription provides updates to directory objects that have changed since the previous request. itslearning stores the prefill together with all subsequent changes in an intermediate database, which at any given time contains a full, current snapshot of the data. It is this snapshot that is synchronised with itslearning on a nightly basis.
3.3 Data synchronised
The connector uses a subset of the properties available from the Provisioning API and maps them to the corresponding IMS Enterprise elements used by itslearning:
| Source (UCS@school) | itslearning field | Notes |
|---|---|---|
univentionObjectIdentifier | Sync key | Used as the itslearning synckey |
username (LDAP uid) | Username | Commonly used as the SSO attribute |
firstname / lastname | First name / last name | – |
| E-mail / telephone | Email / phone | – |
ucsschoolRole | User role | Student, Teacher or Admin |
ucsschoolLegalGuardian | Parent-child relationship | Used to link a parent account to the student |
Groups (first cn) | Hierarchy sync key and title | – |
Group memberships are based on the user's ucsschoolRole: students become student members and teachers become teacher members in their respective groups.
4 Back to school (school year change)
According to Univention, the school year change ("Schuljahreswechsel") is not a single event with a defined end, but a process that can run over the whole summer period and looks different for every customer. The recommendation is therefore to keep the regular nightly synchronisation running throughout the summer.
A new prefill should only be requested from the customer's UCS vendor if a complete refresh of the data is needed.
5 Security
5.1 In transit
From the Univention API to Dataduck: access to the Univention API is protected with API credentials and IP blocking. Data is transmitted over HTTPS.
From Dataduck to itslearning: data is sent over the Secure FTP protocol.
5.2 At rest
Both Dataduck and the itslearning platform are hosted in alignment with itslearning's security policies and processes.
6 Known limitations
Important: Groups are derived from user properties rather than read directly from UCS@school. This means empty groups, with no members, are not synchronised to itslearning.
More Help Resources
Have more questions? Reach out to your itslearning or support contact depending on the issue.
Product Release notes
Stay updated with itslearning latest releases: https://itslearning.com/product-updates
Service Status
Check the current status of itslearning services: https://status.itslearning.com/
Ideas Portal
Share your ideas and help shape the future of itslearning: https://ideas.itslearning.com/
Roadmap
Check out our roadmap: https://itslearning.com/global/roadmap/