GlobalSign Enterprise Solutions Google Apps Authentication User Guide
|
|
|
- Russell Lester Sutton
- 10 years ago
- Views:
Transcription
1 GlobalSign Enterprise Solutions Google Apps Authentication User Guide Using EPKI for Google Apps for Business Single Sign-on and Secure Document Sharing v.1.1 1
2 Table of Contents Table of Contents... 2 Introduction... 3 Solution Requirements... 3 Step 1 Authentication Server Setup... 3 Step 2 Apache CSR Generation... 4 Step 3 Obtaining a Certificate... 5 Step 4 Installation of the Certificate to the Server Step 5 Apache SSL Settings Step 6 Creating a Key Pair for Google Apps Step 7 Google Apps Settings Step 8 LDAP Settings (Via LDIF) Step 9 Accessing Google Apps for Business Appendix A Password Synchronization Advanced Design GlobalSign Contact Information
3 Introduction As more and more organizations experience the business benefits of cloud-based applications, such as Google Apps, organizations should consider implementing strong two-factor authentication for users accessing sensitive data stored outside the trusted network. Google Apps for Business by default allows users to login via username/password. This can be a security issue for companies where users passwords can be attacked. Google offers alternative methods for accessing their services to enhance security as well as improving the user experience. Here we will explain setting up and using the SAML Single Sign-on (SSO) Service for Google Apps web based applications. Security Assertion Mark-up Language (SAML) is an XML standard that allows secure web domains to exchange user authentication and authorization data. Using SAML, an online service provider can contact a separate online identity provider to authenticate users who are trying to access secure content. Google Apps SSO service is based on SAML v2; there are a number of clients available for communicating with Google using this specification. Here we will focus on using the GHeimdall open source solution together with an LDAP server for providing access rights. GHeimdall enables you to authenticate Google Apps users by your own authenticate back end. Overview of the Setup for Google SSO Login Solution Requirements The following components will be required for this solution: Google Apps for Business Account LDAP Directory Server (e.g. Apache Directory Server) SAML Authentication Server o GHeimdall2-repos o Gdata (Google Apps Provisioning API) o GHeimdall2 ( o Apache o Python Step 1 Authentication Server Setup To configure the Authentication Server you will need to adjust your LDAP directory server settings as well as adjust the GHeimdall configuration file and Apache configuration file. LDAP Directory Server Settings Define the settings for the directory server within the SAML authentication system as well as the filter to apply for user authentication. LDAP URI ldap://localhost/ 3
4 LDAP basedn LDAP filter dc=globalsign,dc=com GHeimdall Location and Configuration File After installing GHeimdall, the configuration tree will be as follows: Location /etc/gheimdall2/ /etc/gheimdall2/gheimdall2.conf Description Authentication key pair location GHeimdall Config File GHeimdall2 Preferences (gheimdall2.conf): Parameters Value Remarks apps_domain orgname.com Google Apps Domain Name always_remember_me False "Remember me the next time" to enable / disable check box privkey_filename /etc/gheimdall2/privkeynopass.pem service Secret key to use Google Apps SSO auth_engine ldapauth Authentication modules use_header_auth True Set whether to perform authentication using HTTP headers auth_header_key If the header name to HTTP_SSL_CLIENT_S_DN_E authenticate with the HTTP MAIL header use_change_passwd True Enable / disable the Change Password feature use_reset_passwd False Enable / disable the password reset feature passwd_regex ^[ -~]{8,}$ Change the password restrictions domain_admin adminname Google Apps administrator User admin_passwd ****** Google Apps administrator password hash_function_name SHA-1 Google Apps password hash format Apache Used Folders and Configuration File Configuration file, directory /etc/httpd/conf/httpd.conf /etc/pki/tls/certs /etc/http/conf.d/ssl.conf Description Apache Configuration File SSL certificate store directory SSL Configuration File Step 2 Apache CSR Generation If you use HTTPS to access the SAML authentication system from the client, the server will require an SSL certificate authentication system. If you already have a certificate to use for the application, please proceed to Step 4 Installation of the Certificate to the Server. 4
5 1. Follow the CSR generation procedure in the next step to get the SSL server certificate. 2. Set the following items for the certificate Distinguished Name (DN). Note, you should replace the following details with the details specific to your organization. Item Country Name (2 letter code) [GB]: Organization Name (eg, company) [My Company Ltd]: Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []: Address []: Value GB OrgName Domain Control Validated server.orgname.com Step 3 Obtaining a Certificate The next step is to obtain a GlobalSign Organizational Vetted (OV) certificate from the CSR you created in the previous steps. 1. Go to and click Buy Now under the Organizational High Assurance SSL option. 2. Select your region and click Select and Continue to go to the next step. 5
6 3. Your order will then be processed and the Certificate Application will appear. Complete all required information of the application and click Next. Note, this is not the vetted certificate information. Click Continue once you have completed the application. 4. Next you will enter in your account details. These details will be vetted and included as the certified identity within your issued certificate. Important make sure the details entered are correct as GlobalSign will vet the details you include. 6
7 You will also need to choose a username and password. An account number (PAR####) will be appended to the username you choose. Optional add an additional point of contact (this is commonly used when you are applying on behalf of someone else). 7
8 Click Continue. 5. Enter in your Certificate Signing Request (CSR). The next step varies depending on whether you will provide a self-generated CSR or not. If you choose the AutoCSR option, it is recommended to write down the private key password that you create. For security purposes, this password is not kept on file. If this password is lost, you must reissue your certificate in order to create a new one. Click Continue. 6. You will be presented with the option to obtain a Site Seal. You will be able to display the Secure Site Seal on your webpages. When clicked, your visitor will be presented with your company profile. This will give enhanced confidence in your identity. This is optional. Once you have completed the form or decided not to obtain a Site Seal click Continue. 8
9 7. Complete the payment details. Click Continue. 8. Confirm the details you entered and agree to the Terms of Service and Subscriber Agreement. Click Complete. Once you have successfully ordered your Organizational Vetted (OV) Certificate, your application will be sent to our vetting team. Vetting your application details can take up to 2-3 business days. Once the vetting process is complete, your certificate will be ed to you and available for download from your account. Once the vetting process is complete please proceed to Step 4 Installation of the Certificate to the Server. 9
10 Step 4 Installation of the Certificate to the Server The SSL server certificate, key and intermediary certificates are each stored on the server, in a location referenced from the Apache SSL Configuration file. Location /etc/httpd/conf/ssl.crt/server.orgname.com.crt /etc/httpd/conf/ssl.key/server.orgname.com.key /etc/httpd/conf/ssl.crt/ int.crt Description SSL Certificate Private Key (without password) Intermediate Certificates File Note, if you use a private key with a pass phrase, starting/restarting Apache requires the private key password to be entered each time. Step 5 Apache SSL Settings Setting up SSL on Apache requires adding the location of the certificate, key and intermediary certificates to the Apache configuration file. Note, that this may be located in its own file or in some cases will be in the httpd.conf file. Apache SSL Configuration File Location /etc/http/conf.d/ssl.conf Description SSL Configuration File Apache SSL Settings Parameters SSLCertificateFile SSLCertificateKeyFile SSLCertificateChainFile Values /etc/httpd/conf/ssl.crt/server.orgname.com.crt /etc/httpd/conf/ssl.key/server.orgname.com.key /etc/httpd/conf/ssl.crt/int.crt Step 6 Creating a Key Pair for Google Apps In order to use Google Apps, you will require a key pair for authenticating your system to Google Apps SSO service. We will create the key pair using OpenSSL. Complete the key pair generation. The private key should be stored on your server and the public key should be uploaded to the Google Apps control panel. Step 7 Google Apps Settings It is now time to configure your Google Apps Settings to allow the single sign-on: 1. Go to the Google Apps web control panel. 10
11 2. Select Advanced Tools and Single Sign-on to set all settings to enable SSO. Overview of the Google Apps SSO Settings: Parameters SSO Valid Login URL Logout URL Password URL Values ON
12 Certificates Browse to file location of publickey.der (created at step 1 above) Step 8 LDAP Settings (Via LDIF) Next, the EPKI Administrator uploads the public certificates associated with authorized users to a directory that the SAML server with query for authorization decisions. EPKI provides a method to generate a LDIF (Lightweight Directory Access Protocol) report for upload to an LDAP directory. This LDAP directory will be used to authorize users to log on to the corporate Google Apps account using their certificate for authentication. If you are looking for more information about using your EPKI account please refer to the instructions found in the EPKI Administrator Guide: 1. Extracting LDIF From EPKI Console LDIF reports can be formatted by the EPKI administrator via the Configure LDIF link found under Other Functions in the EPKI management console. Please note that the initial LDIF default format has been established by GlobalSign. The EPKI Administrator must modify the LDIF Template based on the Profile the LDIF query will run against. The LDIF message format can be modified by clicking on a variety of substitution variables available in the far right pane. To save changes click Next and then Complete. 12
13 You can reset the format back to the default values anytime by clicking Reset Message as illustrated below. 2. Generating a LDIF Report LDIF reports are generated from the Search Certificates link found under My Certificates. Select the appropriate date range, profile ID (if you have more than one) and set the Certificate Status as Issue Completed via the drop down menu. Note, if a certificate has been reissued the replacement certificate will have a status of issued and will be included in the LDIF report. The original, replaced certificate will not be included in the query since its status will change to reissued. Only non-revoked and unexpired certificates will be included. Then click on the LDIF button to download the report. Open the file with your preferred application. 13
14 Below is an example entry: Upload this to your LDAP directory according to your product specific instructions. For example, for OpenLDAP the LDIF would be added using a command as such: ldapadd H ldap://ldap.orgname.com x D cn=orgname,dc=example,dc=com f ldif.txt w secret Step 9 Accessing Google Apps for Business Users should now have access to Google Apps via their usual link ( On first access, the user will be asked to present a certificate together with their password, and will be asked whether they wish to link this certificate to their account. As long as the certificate and password are linked in the LDAP, they will be allowed access and future logins will be via their certificate. If allowed by the administrator, users will also be able to update their password. From here users can share docs with others in the usual way. 14
15 Appendix A Password Synchronization Advanced Design There is an optional password sync/manage process which is also controlled by GHeimdall. GHeimdall will update the Google s user s password from the local directory server. The Google user password and the GHeimdall user password can be set to remain in sync. GHeimdall Configuration Defining the necessary configuration information in GHeimdall is carried out in two locations. 1. GHeimdall Template modify the template GHeimdall2. For modifications please refer to the relevant screen configuration of GHeimdall2. Below is the templates directory: Location /etc/gheimdall2/static/ /etc/gheimdall2/templates/ Description css, image file storage directory Web page template file 2. Authentication Related modify the settings file to configure GHeimdall for your Organizational needs. Required settings include your domain name, your private key location, authentication type, password settings, certificate authentication field, LDAP information and template path. GHeimdall2 Settings (/etc/gheimdall2/gheimdall2.conf) (additions to default): --- gheimdall2.conf.dist ,6 # Domain name for Google apps -apps_domain = 'example.com' +apps_domain = 'orgname.com' 15
16 # private key -privkey_filename = '/some/where/privkey-nopass.pem' +privkey_filename = -22,3 # auth_engine to use -auth_engine = 'sample' +auth_engine = -54,4 # passwd policy -passwd_regex = '^.{8,}$' +# passwd_regex = '^.{8,}$' # passwd_regex = '^.*(?=.{8,})(?=.*\d)(?=.*[a-z])(?=.*[A-Z])(?=.*[@#$%^&+=]).*$' +# passwd_regex = '(?=.*\d)(?=.*[a-z])(?=.*[a-z])^[ -~]{8,}$' +passwd_regex = '^[ -61,3 # Set to True if you use auth with specific header value -use_header_auth = False +use_header_auth = -72,8 # The header name for header authentication. -auth_header_key = 'SSL-CLIENT-S-DN-CN' +#auth_header_key = 'SSL-CLIENT-S-DN-CN' #auth_header_key = 'REMOTE_USER' +auth_header_key = 'HTTP_SSL_CLIENT_S_DN_ ' # Google Apps admin user name and password. (If you want to sync passwords.) -domain_admin = 'admin' -admin_passwd = 'password' 16
17 +domain_admin = 'admin' +admin_passwd = -83,7 # ldap stuff -ldap_uri = 'ldap://ldap.example.com/' -ldap_basedn = 'dc=example,dc=com' -ldap_filter = 'uid=%s' -ldap_rootdn = 'cn=admin,dc=example,dc=com' -ldap_rootpw = 'password' +ldap_uri = 'ldap:// /' +ldap_basedn = 'dc=globalsign,dc=com' +ldap_filter = '(mail=%s@orgname.*)' +ldap_rootdn = 'cn=admin,dc=orgname,dc=com' +ldap_rootpw = '*******' ldap_passwd_hash_style = -100,3 # Corresponds with an error on SSL Client Auth -use_subproccess_for_signing = False +use_subproccess_for_signing = -111,3 [[response_creators]] -google.com = "default" +google.com = "uselocalpart" GHeimdall2 Settings (/usr/lib/python2.4/site-packages/gheimdall2/settings.py) Additions to default here you will change the settings from warnings only to info and add the correct link to the template location: file_logger = logging.filehandler("/var/log/gheimdall2/error.log") -file_logger.setlevel(logging.warn) +file_logger.setlevel(logging.info) formatter = logging.formatter('%(asctime)s: %(pathname)s: %(lineno)d: %(name)s: %(levelname)s: %(message)s') 17
18 -45,3 +45,3 logging.getlogger('').addhandler(file_logger) -logging.getlogger().setlevel(logging.warn) +logging.getlogger().setlevel(logging.info) -123,3 +123,7 # Don't forget to use absolute paths, not relative paths. - os.path.join(os.path.dirname(os.path.abspath( file )), 'templates'), + '/etc/gheimdall2/templates', +) + +LOCALE_PATHS = ( + '/etc/gheimdall2/locale', ) Apache & GHeimdall Related Settings (additions to default) For your Apache server you will add the webserver, certificate and encryption details for our local server. At this stage you will also add the client certificate details which Google will use to connect to the service. +Listen 443 +<VirtualHost _default_:443> +ServerName server.orgname.com:443 +ErrorLog logs/ssl_error_log +TransferLog logs/ssl_access_log +LogLevel warn +SSLEngine on +SSLProtocol all -SSLv2 +SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM:+LOW +SSLCertificateFile /etc/httpd/conf/ssl.crt/server.orgname.com.crt +SSLCertificateKeyFile /etc/httpd/conf/ssl.key/server.orgname.com.key +SSLCertificateChainFile /etc/httpd/conf/ssl.crt/int.crt +SetEnvIf User-Agent ".*MSIE.*" \ + nokeepalive ssl-unclean-shutdown \ + downgrade-1.0 force-response-1.0 +CustomLog logs/ssl_request_log \ + "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b" +</VirtualHost> + <Location -8,5 PythonDebug On + SSLCACertificatePath /etc/pki/tls/certs + SSLVerifyClient require + SSLVerifyDepth 3 +# SSLRequire (%{SSL_CLIENT_S_DN_O} in {"OrgName"} ) + SSLRequire (%{SSL_CLIENT_S_DN_O} in {"OrgName"} ) or (%{SSL_CLIENT_S_DN_ } in {"[email protected]"}) + RequestHeader set SSL_CLIENT_S_DN_ %{SSL_CLIENT_S_DN_ }s </Location> -Alias /gheimdall2/static/ "/usr/lib/python2.4/site-packages/gheimdall2/static/" -<Directory "/usr/lib/python2.4/site-packages/gheimdall2/static/"> +Alias /gheimdall2/static/ "/etc/gheimdall2/static/" +<Directory "/etc/gheimdall2/static/"> Options Indexes MultiViews 18
19 GHeimdall2Rotating Logging Setting (/etc/logrotate.d/gheimdall2) /var/log/gheimdall2/*log { weekly create 0755 apache apache missingok notifempty sharedscripts } GlobalSign Contact Information GlobalSign Americas Tel: [email protected] GlobalSign EU Tel: [email protected] GlobalSign UK Tel: [email protected] GlobalSign FR Tel: [email protected] GlobalSign DE Tel: [email protected] GlobalSign NL Tel: [email protected] 19
GlobalSign Enterprise PKI Support. GlobalSign Enterprise Solution EPKI Administrator Guide v2.4
GlobalSignEnterprisePKISupport GlobalSignEnterpriseSolutionEPKIAdministratorGuidev2.4 1 TABLE OF CONTENTS GETTING STARTED... 3 ESTABLISHING EPKI SERVICE... 3 EPKI ADMINISTRATOR/USER CERTIFICATE... 4 ESTABLISHING
How to: Install an SSL certificate
How to: Install an SSL certificate Introduction This document will talk you through the process of installing an SSL certificate on your server. Once you have approved the request for your certificate
esync - Receiving data over HTTPS
esync - Receiving data over HTTPS 1 Introduction Natively, the data transfer between ewon and esync is done over an HTTP link. However when esync is hosted on Internet, security must be taken in account
This section describes how to use SSL Certificates with SOA Gateway running on Linux.
This section describes how to use with SOA Gateway running on Linux. Setup Introduction Step 1: Set up your own CA Step 2: SOA Gateway Server key and certificate Server Configuration Setup To enable the
To enable https for appliance
To enable https for appliance We have used openssl command to generate a key pair. The below image shows on how to generate key using the openssl command. SSH into appliance and login as root. Copy all
Installing an SSL certificate on the InfoVaultz Cloud Appliance
Installing an SSL certificate on the InfoVaultz Cloud Appliance This document reviews the prerequisites and installation of an SSL certificate for the InfoVaultz Cloud Appliance. Please note that the installation
GlobalSign Solutions
GlobalSign Solutions SNI + CloudSSL Implementation Guide Hosting Multiple SSL on a Single IP Address Contents Introduction... 3 Why do hosting companies want SNI/CloudSSL?... 3 Configuration instructions...
Implementing HTTPS in CONTENTdm 6 September 5, 2012
Implementing HTTPS in CONTENTdm 6 This is an overview for CONTENTdm server administrators who want to configure their CONTENTdm Server and Website to make use of HTTPS. While the CONTENTdm Server has supported
HP Cloud Service Automation Deployment Architectures
Technical white paper HP Cloud Service Automation Deployment Architectures Details of the content Table of contents Purpose... 2 Enterprise Deployment... 2 All-in-One CSA... 3 All-in-One CSA with remote
User s guide. APACHE 2.0 + SSL Linux. Using non-qualified certificates with APACHE 2.0 + SSL Linux. version 1.3 UNIZETO TECHNOLOGIES S.A.
User s guide APACHE 2.0 + SSL Linux Using non-qualified certificates with APACHE 2.0 + SSL Linux version 1.3 Table of contents 1. PREFACE... 3 2. GENERATING CERTIFICATE... 3 2.1. GENERATING REQUEST FOR
Administrator Guide. v 11
Administrator Guide JustSSO is a Single Sign On (SSO) solution specially developed to integrate Google Apps suite to your Directory Service. Product developed by Just Digital v 11 Index Overview... 3 Main
Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.
This chapter provides information about the Security Assertion Markup Language (SAML) Single Sign-On feature, which allows administrative users to access certain Cisco Unified Communications Manager and
GlobalSign Customers. Enterprise PKI Client Authentication User Guide. Employing authentication as an additional security layer to the EPKI platform
GlobalSign Customers Enterprise PKI Client Authentication User Guide Employing authentication as an additional security layer to the EPKI platform I. Background information... 3 II. EPKI administrator
CA Nimsoft Service Desk
CA Nimsoft Service Desk Single Sign-On Configuration Guide 6.2.6 This Documentation, which includes embedded help systems and electronically distributed materials, (hereinafter referred to as the Documentation
Cloudwork Dashboard User Manual
STUDENTNET Cloudwork Dashboard User Manual Make the Cloud Yours! Studentnet Technical Support 10/28/2015 User manual for the Cloudwork Dashboard introduced in January 2015 and updated in October 2015 with
ADFS Integration Guidelines
ADFS Integration Guidelines Version 1.6 updated March 13 th 2014 Table of contents About This Guide 3 Requirements 3 Part 1 Configure Marcombox in the ADFS Environment 4 Part 2 Add Relying Party in ADFS
Creating X.509 Certificates With OpenSSL
Creating X.509 Certificates With OpenSSL Overview This procedure describes one of the ways to use OpenSSL to create an X.509 Certificate file and an associated RSA Key file to use for ssl/tls certificates.
Managing users. Account sources. Chapter 1
Chapter 1 Managing users The Users page in Cloud Manager lists all of the user accounts in the Centrify identity platform. This includes all of the users you create in the Centrify for Mobile user service
Active Directory Requirements and Setup
Active Directory Requirements and Setup The information contained in this document has been written for use by Soutron staff, clients, and prospective clients. Soutron reserves the right to change the
Authentication Methods
Authentication Methods Overview In addition to the OU Campus-managed authentication system, OU Campus supports LDAP, CAS, and Shibboleth authentication methods. LDAP users can be configured through the
1 of 24 7/26/2011 2:48 PM
1 of 24 7/26/2011 2:48 PM Home Community Articles Product Documentation Learning Center Community Articles Advanced Search Home > Deployments > Scenario 3: Setting up SiteMinder Single Sign-On (SSO) with
Security Assertion Markup Language (SAML) Site Manager Setup
Security Assertion Markup Language (SAML) Site Manager Setup Trademark Notice Blackboard, the Blackboard logos, and the unique trade dress of Blackboard are the trademarks, service marks, trade dress and
F-Secure Messaging Security Gateway. Deployment Guide
F-Secure Messaging Security Gateway Deployment Guide TOC F-Secure Messaging Security Gateway Contents Chapter 1: Deploying F-Secure Messaging Security Gateway...3 1.1 The typical product deployment model...4
WebSpy Vantage Ultimate 2.2 Web Module Administrators Guide
WebSpy Vantage Ultimate 2.2 Web Module Administrators Guide This document is intended to help you get started using WebSpy Vantage Ultimate and the Web Module. For more detailed information, please see
Tenrox. Single Sign-On (SSO) Setup Guide. January, 2012. 2012 Tenrox. All rights reserved.
Tenrox Single Sign-On (SSO) Setup Guide January, 2012 2012 Tenrox. All rights reserved. About this Guide This guide provides a high-level technical overview of the Tenrox Single Sign-On (SSO) architecture,
Adobe Connect LMS Integration for Blackboard Learn 9
Adobe Connect LMS Integration for Blackboard Learn 9 Install Guide Introduction The Adobe Connect LMS Integration for Blackboard Learn 9 gives Instructors, Teaching Assistants and Course Builders the ability
Configuring Sponsor Authentication
CHAPTER 4 Sponsors are the people who use Cisco NAC Guest Server to create guest accounts. Sponsor authentication authenticates sponsor users to the Sponsor interface of the Guest Server. There are five
T his feature is add-on service available to Enterprise accounts.
SAML Single Sign-On T his feature is add-on service available to Enterprise accounts. Are you already using an Identity Provider (IdP) to manage logins and access to the various systems your users need
1. PREREQUISITES 2. NETWORK ADMINISTRATORS INFO
1. PREREQUISITES Software on Database server: - Microsoft SQL Server 2012 or 2012 Express - Minimum 1 CPU (more depending on number of users) - Minimum 4 GB (more depending on number of users) Software
Configuring ADFS 3.0 to Communicate with WhosOnLocation SAML
Configuring ADFS 3.0 to Communicate with WhosOnLocation SAML --------------------------------------------------------------------------------------------------------------------------- Contents Overview...
10gAS SSL / Certificate Based Authentication Configuration
I. Overview This document covers the processes required to create a self-signed certificate or to import a 3 rd party certificate using the Oracle Certificate Authority. In addition, the steps to configure
WWPass External Authentication Solution for IBM Security Access Manager 8.0
WWPass External Authentication Solution for IBM Security Access Manager 8.0 Setup guide Enhance your IBM Security Access Manager for Web with the WWPass hardware authentication IBM Security Access Manager
GlobalSign Enterprise Solutions
GlobalSign Enterprise Solutions Two Factor Authentication for SharePoint User Guide GlobalSign Enterprise PKI for Strong Two Factor Client Authentication using Windows SharePoint INTRODUCTION Microsoft
Getting Started with Clearlogin A Guide for Administrators V1.01
Getting Started with Clearlogin A Guide for Administrators V1.01 Clearlogin makes secure access to the cloud easy for users, administrators, and developers. The following guide explains the functionality
CA Performance Center
CA Performance Center Single Sign-On User Guide 2.4 This Documentation, which includes embedded help systems and electronically distributed materials, (hereinafter referred to as the Documentation ) is
Configuration Guide BES12. Version 12.3
Configuration Guide BES12 Version 12.3 Published: 2016-01-19 SWD-20160119132230232 Contents About this guide... 7 Getting started... 8 Configuring BES12 for the first time...8 Configuration tasks for managing
SAML-Based SSO Solution
About SAML SSO Solution, page 1 SAML-Based SSO Features, page 2 Basic Elements of a SAML SSO Solution, page 2 SAML SSO Web Browsers, page 3 Cisco Unified Communications Applications that Support SAML SSO,
Adeptia Suite LDAP Integration Guide
Adeptia Suite LDAP Integration Guide Version 6.2 Release Date February 24, 2015 343 West Erie, Suite 440 Chicago, IL 60654, USA Phone: (312) 229-1727 x111 Fax: (312) 229-1736 DOCUMENT INFORMATION Adeptia
GlobalSign Integration Guide
GlobalSign Integration Guide GlobalSign Enterprise PKI (EPKI) and AirWatch Enterprise MDM 1 v.1.1 Table of Contents Table of Contents... 2 Introduction... 3 GlobalSign Enterprise PKI (EPKI)... 3 Partner
SSL Installing your new Certificate
SSL Installing your new Certificate Contents Introduction... 3 Preparing your Certificate... 3 Installing your Certificate... 3 IIS 7.0... 3 IIS6... 5 Apache... 7 Plesk... 8 Other operating systems...
Agenda. How to configure
[email protected] Agenda Strongly Recommend: Knowledge of ArcGIS Server and Portal for ArcGIS Security in the context of ArcGIS Server/Portal for ArcGIS Access Authentication Authorization: securing web services
Configuration Guide. BES12 Cloud
Configuration Guide BES12 Cloud Published: 2016-04-08 SWD-20160408113328879 Contents About this guide... 6 Getting started... 7 Configuring BES12 for the first time...7 Administrator permissions you need
NSi Mobile Installation Guide. Version 6.2
NSi Mobile Installation Guide Version 6.2 Revision History Version Date 1.0 October 2, 2012 2.0 September 18, 2013 2 CONTENTS TABLE OF CONTENTS PREFACE... 5 Purpose of this Document... 5 Version Compatibility...
User Guide. Time Warner Cable Business Class Cloud Solutions Control Panel. Hosted Microsoft Exchange 2007 Hosted Microsoft SharePoint 2007
Chapter Title Time Warner Cable Business Class Cloud Solutions Control Panel User Guide Hosted Microsoft Exchange 2007 Hosted Microsoft SharePoint 2007 Version 1.1 Table of Contents Table of Contents...
Clearswift Information Governance
Clearswift Information Governance Implementing the CLEARSWIFT SECURE Encryption Portal on the CLEARSWIFT SECURE Email Gateway Version 1.10 02/09/13 Contents 1 Introduction... 3 2 How it Works... 4 3 Configuration
Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)
w w w. e g n y t e. c o m Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS) To set up ADFS so that your employees can access Egnyte using their ADFS credentials,
SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy
SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy Contact information SecurEnvoy www.securenvoy.com 0845 2600010 Merlin House
Embedded Web Server Security
Embedded Web Server Security Administrator's Guide September 2014 www.lexmark.com Model(s): C54x, C73x, C746, C748, C792, C925, C950, E260, E360, E46x, T65x, W850, X264, X36x, X46x, X543, X544, X546, X548,
Sophos UTM Web Application Firewall for Microsoft Exchange connectivity
How to configure Sophos UTM Web Application Firewall for Microsoft Exchange connectivity This article explains how to configure your Sophos UTM 9.2 to allow access to the relevant Microsoft Exchange services
This chapter describes how to use the Junos Pulse Secure Access Service in a SAML single sign-on deployment. It includes the following sections:
CHAPTER 1 SAML Single Sign-On This chapter describes how to use the Junos Pulse Secure Access Service in a SAML single sign-on deployment. It includes the following sections: Junos Pulse Secure Access
Microsoft Office 365 Using SAML Integration Guide
Microsoft Office 365 Using SAML Integration Guide Revision A Copyright 2013 SafeNet, Inc. All rights reserved. All attempts have been made to make the information in this document complete and accurate.
Integrating EJBCA and OpenSSO
Integrating EJBCA and OpenSSO EJBCA is an Enterprise PKI Certificate Authority issuing certificates to users, servers and devices. In an organization certificate can be used for strong authentication.
Single Sign On for ShareFile with NetScaler. Deployment Guide
Single Sign On for ShareFile with NetScaler Deployment Guide This deployment guide focuses on defining the process for enabling Single Sign On into Citrix ShareFile with Citrix NetScaler. Table of Contents
Protected Trust Directory Sync Guide
Protected Trust Directory Sync Guide Protected Trust Directory Sync Guide 2 Overview Protected Trust Directory Sync enables your organization to synchronize the users and distribution lists in Active Directory
Active Directory Sync (AD) How it Works in WhosOnLocation
Active Directory Sync (AD) How it Works in WhosOnLocation 1 P a g e Contents Overview... 3 About AD in WhosOnLocation... 3 The Way It Works... 3 Requirements... 3 How to Setup Active Directory Sync...
Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER
Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER Table of Contents Introduction.... 3 Requirements.... 3 Horizon Workspace Components.... 3 SAML 2.0 Standard.... 3 Authentication
CERTIFICATE-BASED SINGLE SIGN-ON FOR EMC MY DOCUMENTUM FOR MICROSOFT OUTLOOK USING CA SITEMINDER
White Paper CERTIFICATE-BASED SINGLE SIGN-ON FOR EMC MY DOCUMENTUM FOR MICROSOFT OUTLOOK USING CA SITEMINDER Abstract This white paper explains the process of integrating CA SiteMinder with My Documentum
Content Filtering Client Policy & Reporting Administrator s Guide
Content Filtering Client Policy & Reporting Administrator s Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your system. CAUTION: A CAUTION
Architecture and Data Flow Overview. BlackBerry Enterprise Service 10 721-08877-123 Version: 10.2. Quick Reference
Architecture and Data Flow Overview BlackBerry Enterprise Service 10 721-08877-123 Version: Quick Reference Published: 2013-11-28 SWD-20131128130321045 Contents Key components of BlackBerry Enterprise
BlackBerry Enterprise Service 10. Version: 10.2. Configuration Guide
BlackBerry Enterprise Service 10 Version: 10.2 Configuration Guide Published: 2015-02-27 SWD-20150227164548686 Contents 1 Introduction...7 About this guide...8 What is BlackBerry Enterprise Service 10?...9
Configuration Guide BES12. Version 12.2
Configuration Guide BES12 Version 12.2 Published: 2015-07-07 SWD-20150630131852557 Contents About this guide... 8 Getting started... 9 Administrator permissions you need to configure BES12... 9 Obtaining
Apache SSL Certificate Deployment Guide
Apache SSL Certificate Deployment Guide 沃 通 电 子 认 证 服 务 有 限 公 司 WoSignCA Limited All Rights Reserved Content 1.The environment for installing the SSL certificate... 3 1.1 Brief introduction of SSL certificate
NETASQ ACTIVE DIRECTORY INTEGRATION
NETASQ ACTIVE DIRECTORY INTEGRATION NETASQ ACTIVE DIRECTORY INTEGRATION RUNNING THE DIRECTORY CONFIGURATION WIZARD 2 VALIDATING LDAP CONNECTION 5 AUTHENTICATION SETTINGS 6 User authentication 6 Kerberos
SecuritySpy Setting Up SecuritySpy Over SSL
SecuritySpy Setting Up SecuritySpy Over SSL Secure Sockets Layer (SSL) is a cryptographic protocol that provides secure communications on the internet. It uses two keys to encrypt data: a public key and
How to setup HTTP & HTTPS Load balancer for Mediator
How to setup HTTP & HTTPS Load balancer for Mediator Setting up the Apache HTTP Load Balancer for Mediator This guide would help you to setup mediator product to run via the Apache Load Balancer in HTTP
Acronis Backup Cloud APS 2.0 Deployment Guide
Acronis Backup Cloud APS 2.0 Deployment Guide Table of contents 1 About this guide...3 2 Audience...3 3 Terms and abbreviations...3 4 General architecture and services...3 5 Deployment procedure...4 5.1
e-cert (Server) User Guide For Apache Web Server
e-cert (Server) User Guide For Apache Web Server Revision Date: Sep 2015 Table of Content A. Guidelines for e-cert (Server) Applicant... 2 B. Generating Certificate Signing Request (CSR)... 3 C. Submitting
Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication
Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication Authentication is about security and user experience and balancing the two goals. This document describes the authentication
Active Directory Service. Integration Parameters and Implementation
Active Directory Service Integration s and Implementation Revised January, 2014 Table of Contents Overview... 3 Getting Started... 3 Migrating Your Users... 7 Manually Adding or Editing Users with the
LDAP User Guide PowerSchool Premier 5.1 Student Information System
PowerSchool Premier 5.1 Student Information System Document Properties Copyright Owner Copyright 2007 Pearson Education, Inc. or its affiliates. All rights reserved. This document is the property of Pearson
Configuring the BIG-IP APM as a SAML 2.0 Identity Provider for Microsoft Office 365
Configuring the BIG-IP APM as a SAML 2.0 Identity Provider for Microsoft Office 365 Welcome to the F5 deployment guide for configuring the BIG-IP Access Policy Manager (APM) to act as a SAML Identity Provider
Administration Guide. BlackBerry Enterprise Service 12. Version 12.0
Administration Guide BlackBerry Enterprise Service 12 Version 12.0 Published: 2015-01-16 SWD-20150116150104141 Contents Introduction... 9 About this guide...10 What is BES12?...11 Key features of BES12...
Introduction to the EIS Guide
Introduction to the EIS Guide The AirWatch Enterprise Integration Service (EIS) provides organizations the ability to securely integrate with back-end enterprise systems from either the AirWatch SaaS environment
Deploying RSA ClearTrust with the FirePass controller
Deployment Guide Deploying RSA ClearTrust with the FirePass Controller Deploying RSA ClearTrust with the FirePass controller Welcome to the FirePass RSA ClearTrust Deployment Guide. This guide shows you
Configuring EPM System 11.1.2.1 for SAML2-based Federation Services SSO
Configuring EPM System 11.1.2.1 for SAML2-based Federation Services SSO Scope... 2 Prerequisites Tasks... 2 Procedure... 2 Step 1: Configure EPM s WebLogic domain for SP Federation Services... 2 Step 2:
HOTPin Integration Guide: Google Apps with Active Directory Federated Services
HOTPin Integration Guide: Google Apps with Active Directory Federated Services Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document is provided 'as
CHAPTER 7 SSL CONFIGURATION AND TESTING
CHAPTER 7 SSL CONFIGURATION AND TESTING 7.1 Configuration and Testing of SSL Nowadays, it s very big challenge to handle the enterprise applications as they are much complex and it is a very sensitive
escan SBS 2008 Installation Guide
escan SBS 2008 Installation Guide Following things are required before starting the installation 1. On SBS 2008 server make sure you deinstall One Care before proceeding with installation of escan. 2.
Connection Broker Managing User Connections to Workstations, Blades, VDI, and More. Quick Start with Microsoft Hyper-V
Connection Broker Managing User Connections to Workstations, Blades, VDI, and More Quick Start with Microsoft Hyper-V Version 8.1 October 21, 2015 Contacting Leostream Leostream Corporation http://www.leostream.com
Running Multiple Shibboleth IdP Instances on a Single Host
CESNET Technical Report 6/2013 Running Multiple Shibboleth IdP Instances on a Single Host IVAN NOVAKOV Received 10.12.2013 Abstract The article describes a way how multiple Shibboleth IdP instances may
SAP Cloud Identity Service Document Version: 1.0 2014-09-01. SAP Cloud Identity Service
Document Version: 1.0 2014-09-01 Content 1....4 1.1 Release s....4 1.2 Product Overview....8 Product Details.... 9 Supported Browser Versions....10 Supported Languages....12 1.3 Getting Started....13 1.4
Configuration Guide - OneDesk to SalesForce Connector
Configuration Guide - OneDesk to SalesForce Connector Introduction The OneDesk to SalesForce Connector allows users to capture customer feedback and issues in OneDesk without leaving their familiar SalesForce
Configuring Single Sign-On from the VMware Identity Manager Service to Office 365
Configuring Single Sign-On from the VMware Identity Manager Service to Office 365 VMware Identity Manager JULY 2015 V1 Table of Contents Overview... 2 Passive and Active Authentication Profiles... 2 Adding
Egnyte Single Sign-On (SSO) Installation for OneLogin
Egnyte Single Sign-On (SSO) Installation for OneLogin To set up Egnyte so employees can log in using SSO, follow the steps below to configure OneLogin and Egnyte to work with each other. 1. Set up OneLogin
INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN
INTEGRATION GUIDE IDENTIKEY Federation Server for Juniper SSL-VPN Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document is provided 'as is'; VASCO
SecureAware on IIS8 on Windows Server 2008/- 12 R2-64bit
SecureAware on IIS8 on Windows Server 2008/- 12 R2-64bit Note: SecureAware version 3.7 and above contains all files and setup configuration needed to use Microsoft IIS as a front end web server. Installing
FileCloud Security FAQ
is currently used by many large organizations including banks, health care organizations, educational institutions and government agencies. Thousands of organizations rely on File- Cloud for their file
Google Integration Instructions
SAFARI Montage Google Integration Instructions SAFARI Montage now offers Interoperability Support Services subscribers a powerful new integration option that links SAFARI Montage directly with Google,
Using LDAP Authentication in a PowerCenter Domain
Using LDAP Authentication in a PowerCenter Domain 2008 Informatica Corporation Overview LDAP user accounts can access PowerCenter applications. To provide LDAP user accounts access to the PowerCenter applications,
Configuration Guide BES12. Version 12.1
Configuration Guide BES12 Version 12.1 Published: 2015-04-22 SWD-20150422113638568 Contents Introduction... 7 About this guide...7 What is BES12?...7 Key features of BES12... 8 Product documentation...
Embedded Web Server Security
Embedded Web Server Security Administrator's Guide September 2014 www.lexmark.com Model(s): MS911de, MX910de, MX911, MX912, XM9145, XM9155, XM9165, CS310, CS410, CS510, CX310, CX410, CX510, M1140, M1145,
INTEGRATION GUIDE. DIGIPASS Authentication for Google Apps using IDENTIKEY Federation Server
INTEGRATION GUIDE DIGIPASS Authentication for Google Apps using IDENTIKEY Federation Server Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document
Copyright: WhosOnLocation Limited
How SSO Works in WhosOnLocation About Single Sign-on By default, your administrators and users are authenticated and logged in using WhosOnLocation s user authentication. You can however bypass this and
Configuring Salesforce
Chapter 94 Configuring Salesforce The following is an overview of how to configure the Salesforce.com application for singlesign on: 1 Prepare Salesforce for single sign-on: This involves the following:
Building Secure Applications. James Tedrick
Building Secure Applications James Tedrick What We re Covering Today: Accessing ArcGIS Resources ArcGIS Web App Topics covered: Using Token endpoints Using OAuth/SAML User login App login Portal ArcGIS
Single Sign-On Implementation Guide
Single Sign-On Implementation Guide Salesforce, Winter 16 @salesforcedocs Last updated: November 4, 2015 Copyright 2000 2015 salesforce.com, inc. All rights reserved. Salesforce is a registered trademark
Quick Start Guide. Hosting Your Domain
Quick Start Guide Hosting Your Domain http://www.names.co.uk/support/ Table of Contents Web Hosting... 3 FTP (File Transfer Protocol)... 3 File Manager... 6 SiteMaker... 7 2 Please keep these documents
The increasing popularity of mobile devices is rapidly changing how and where we
Mobile Security BACKGROUND The increasing popularity of mobile devices is rapidly changing how and where we consume business related content. Mobile workforce expectations are forcing organizations to
Single Sign-On Implementation Guide
Salesforce.com: Salesforce Winter '09 Single Sign-On Implementation Guide Copyright 2000-2008 salesforce.com, inc. All rights reserved. Salesforce.com and the no software logo are registered trademarks,
