Decommissioning IP-Based Authentication for Licensed E-Resources
Project Charter: Decommissioning IP-Based Authentication for Licensed E-Resources
Project Name
Decommissioning IP-Based Authentication for Licensed E-Resources
Project Goals
Transition all Harvard Library e-resource authentication from IP-based to credential-based authentication. User Impact: All users irrespective of location, including those on-campus from their wired connection, will now need to authenticate via Harvard Key prior to authorization via OpenAthen or EZproxy (HarvardKey + OpenAthens/cloud EZproxy).
Strengthen security, compliance, and operational efficiency across digital content systems.
Provide equitable and consistent access for all authorized users, regardless of location.
Problem and Value Statements
Problem Statement
Harvard Library currently maintains IP-based authentication for on-campus access to licensed e-resources. This model—introduced in 2011 to simplify faculty research workflows—has become increasingly risky and unsustainable:
Harvard can no longer reliably trace usage by IP, breaching vendor compliance requirements.
IP spoofing and misuse of on-campus ranges have created significant security vulnerabilities.
Maintaining complex IP whitelists imposes high operational burden and fragility.
Solution and Business Value
Replacing IP-based authentication with credential-based access through HarvardKey and OpenAthens:
Enables vendor-compliant traceability and auditability.
Aligns with Harvard’s Zero Trust and modern identity management principles.
Reduces technical debt and administrative overhead.
Enhances user equity and experience across all campuses and affiliations.
Alignment with Harvard Library Multi-Year Goals and Objectives
Digital Access Strategy: Supports secure, seamless, and equitable digital access.
Operational Resilience: Simplifies infrastructure, reducing fragility and maintenance costs.
Compliance and Stewardship: Meets vendor and institutional security expectations.
Alignment with HUIT Objectives
Advances Harvard’s transition to passwordless, identity-driven security.
Supports the enterprise IAM modernization roadmap.
Reduces network-based authentication dependencies.
Vision
Decommissioning IP-Based Authentication for Licensed E-Resources | ||
All Harvard Library e-resources are accessed through authenticated, user-based credentials, whether on campus or off campus—eliminating IP-based dependencies while ensuring secure, auditable, and equitable access for all authorized patrons. | ||
Strategic Objectives | Guiding Principles | Key Performance Indicators |
|
|
|
In Scope/Out of Scope
In Scope
Retirement of IP-based access for Harvard-wide licensed resources across all Harvard-managed networks.
Improved guest access implementation via time/location-based OpenAthens credentials.
Faculty, staff, and user communication and training.
Out of Scope
Changes to locally digitized, open-access, or public-domain materials.
Network redesign beyond authentication dependencies.
Authentication/authorization for school-only electronic resources.
Vendor platform redesigns beyond authentication configuration.
Deliverables and Work Products
Task | Outcome | Responsible Parties |
Vendor migration to OpenAthens (in process) | 95% vendor coverage by Fall 2025 | LTS / ITS |
Guest access rollout | Improved OpenAthens guest credentials active in all libraries. Work, training, documention - Fall 2026. Rollout to libraries - January 2027. | LTS / Public Services |
Communication campaign | Staff and faculty informed by Winter 2026 | HL Communications / LTS / ITS |
IP decommissioning | All campus IPs removed from vendor lists by Fall 2026 | ITS with LTS support |
Monitoring & stabilization | Verified post-cutover access integrity by Dec 2026 | ITS / LTS |
Definition of Done
All vendors transitioned to OpenAthens or cloud EZProxy.
All legacy campus IP-based access deactivated.
Guest access fully functional and documented.
Communications, signage, and training delivered.
Vendor confirmations obtained for IP list removal.
Stakeholders
Stakeholder | Title/Role | Participation |
VPDR | Project Sponsor | Approval and oversight |
LTS | Lead implementer | Project management, system migration, authentication, network, and IAM integration |
ITS:ERS | Co-lead | Vendor Coordination; testing |
IAM | Technical partner | HarvardKey and federation integration |
HL Communications | Support | Communication and messaging development |
Public Services Staff | Operational partner | Guest support and user guidance |
Project Team
Portfolio | Key Member & Role | Affiliation |
Library Technology Services | Project Manager, Laura Morse | LTS |
Information Technology Services | Technical Lead, Amanda Schmidt | LTS |
Information & Technical Services | Project team, Amy Dittman, Lauren Syer, Kasia Maciak | ITS |
IAM Program | Integration Support | HUIT |
Communications | Consultant, Clare O’Keefe | HL Communications |
Cost and Estimated Schedule
Phase | Phase Start | Phase End | Completion Milestone |
Planning & Vendor Coordination | Fall 2025 | Jan 2026 | 75% vendor readiness |
Communication & Training | Fall 2025 | Winter 2026 | Community awareness campaign complete |
Decommissioning & Monitoring | Spring 2026 | Summer 2026 | IP-based access retired and verified stable |
Assumptions, Constraints, Dependencies, and Risks
Assumptions
Vendors will complete IP access updates as requested.
HarvardKey and IAM infrastructure remain stable and scalable.
Constraints
Resource availability across ITS and LTS teams.
Coordination across multiple vendor platforms.
Dependencies
Completion of OpenAthens project.
Vendor responsiveness to IP removal requests.
Risks
Delays in migration to OpenAthens for long tail of vendors.
Temporary user confusion or increased support load during transition.
Compliance risk if IP access persists during cutover.