Federation At Fermilab. Al Lilianstrom National Laboratories Information Technology Summit May 2015



Similar documents
Getting Started with AD/LDAP SSO

Authentication Methods

SAML-Based SSO Solution

HP Software as a Service. Federated SSO Guide

About Me. Software Architect with ShapeBlue Specialise in. 3 rd party integrations and features in CloudStack

Flexible Identity Federation

The increasing popularity of mobile devices is rapidly changing how and where we

Identity. Provide. ...to Office 365 & Beyond

Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department

SAML-Based SSO Solution

The Top 5 Federated Single Sign-On Scenarios

HP Software as a Service

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

PROVIDING SINGLE SIGN-ON TO AMAZON EC2 APPLICATIONS FROM AN ON-PREMISES WINDOWS DOMAIN

Pick Your Identity Bridge

Identity Federation: Bridging the Identity Gap. Michael Koyfman, Senior Global Security Solutions Architect

SAML SSO Configuration

The Primer: Nuts and Bolts of Federated Identity Management

Microsoft Office365 with Active Directory Federated Services (ADFS) Authenticating Users Using SecurAccess Server by SecurEnvoy

Using Shibboleth for Single Sign- On

Federated Identity for Cloud Computing and Cross-organization Collaboration

Extend and Enhance AD FS

Authentication Integration

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

The Primer: Nuts and Bolts of Federated Identity Management

managing SSO with shared credentials

TRANSITIONING ENTERPRISE CUSTOMERS TO THE CLOUD WITH PULSE SECURE

Increase the Security of Your Box Account With Single Sign-On

NCSU SSO. Case Study

Google Identity Services for work

Security Assertion Markup Language (SAML) Site Manager Setup

Leveraging SAML for Federated Single Sign-on:

Symantec Enterprise Vault.cloud Overview

Sage Nonprofit Online and Sage Virtual Services. Frequently Asked Questions

How To Use Saml 2.0 Single Sign On With Qualysguard

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

Single Sign-On: Reviewing the Field

Easy as 1-2-3: The Steps to XE. Mark Hoye Services Portfolio Consultant

Security Overview Enterprise-Class Secure Mobile File Sharing

Federated Identity Management and Shibboleth. Noreen Hogan Asst. Director Enterprise Admin. Applications

nexus Hybrid Access Gateway

Getting Started with Single Sign-On

MIGRATING SHAREPOINT TO THE CLOUD

Symplified I: Windows User Identity. Matthew McNew and Lex Hubbard

Perceptive Experience Single Sign-On Solutions

New Single Sign-on Options for IBM Lotus Notes & Domino IBM Corporation

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

Swivel Secure and the Cloud

IDENTITY INFORMATION MANAGMENT ARCHITECTURE SUMMARY Architecture and Standards Branch Office of the CIO Province of BC People Collaboration Innovation

OVERVIEW. DIGIPASS Authentication for Office 365

Azure Active Directory

Authentication and Single Sign On

Copyright

SAML Security Option White Paper

CLAIMS-BASED IDENTITY FOR WINDOWS

Single Sign On. SSO & ID Management for Web and Mobile Applications

How to Provide Secure Single Sign-On and Identity-Based Access Control for Cloud Applications

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

Cisco ASA Adaptive Security Appliance Single Sign-On: Solution Brief

SAML Authentication Quick Start Guide

APPLICATION ACCESS MANAGEMENT (AAM) Augment, Offload and Consolidate Access Control

SAM Context-Based Authentication Using Juniper SA Integration Guide

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

Speeding Office 365 Implementation Using Identity-as-a-Service

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

Improving Security and Productivity through Federation and Single Sign-on

Getting Started with Single Sign-On

owncloud Architecture Overview

USER GUIDE. Lightweight Directory Access Protocol (LDAP) Schoolwires Centricity

QLIKVIEW MOBILE SECURITY

CA Federation Manager

ADFS Integration Guidelines

Single Sign On for ShareFile with NetScaler. Deployment Guide

How Single-Sign-On Improves The Usability Of Protected Services For Geospatial Data

Q&A Session for Understanding Atrium SSO Date: Thursday, February 14, 2013, 8:00am Pacific

User Identity and Authentication

JumpCloud is your Directory-as-a-Service. A fully managed directory to rule your infrastructure whether on-premise or in the cloud.

CONFIGURATION GUIDE WITH MICROSOFT ACTIVE DIRECTORY FEDERATION SERVER

White Paper. What is an Identity Provider, and Why Should My Organization Become One?

Flexible Identity Federation

SAML 2.0 SSO Deployment with Okta

INUVIKA OPEN VIRTUAL DESKTOP FOUNDATION SERVER

Symantec Enterprise Vault.cloud Overview

Mobile Security. Policies, Standards, Frameworks, Guidelines

DualShield SAML & SSO. Integration Guide. Copyright 2011 Deepnet Security Limited. Copyright 2011, Deepnet Security. All Rights Reserved.

Single Sign-on. Overview. Using SSO with the Cisco WebEx and Cisco WebEx Meeting. Overview, page 1

Agenda. How to configure

Ensuring Enterprise Data Security with Secure Mobile File Sharing.

CERN Single Sign On. Emmanuel Ormancey CERN IT/IS. CERN IT Department CH-1211 Genève 23 Switzerland

Accessing the Media General SSL VPN

owncloud Architecture Overview

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

Active Directory Integration twitter.com/onelogin ONELOGIN WHITEPAPER

Evaluation of different Open Source Identity management Systems

Junos Pulse Secure Access Service Enables Service Providers to Deliver Scalable and On-Demand, Cloud-Based Deployments with Simplicity and Agility

Fairsail. Implementer. Single Sign-On with Fairsail and Microsoft Active Directory Federation Services 2.0. Version 1.92 FS-SSO-XXX-IG R001.

Transcription:

Federation At Fermilab Al Lilianstrom National Laboratories Information Technology Summit May 2015

About Fermilab Since 1967, Fermilab has worked to answer fundamental questions and enhance our understanding of everything we see around us. As the United States' premier particle physics laboratory, we work on the world's most advanced particle accelerators and dig down to the smallest building blocks of matter. Fermilab collaborates with more than 20 countries on physics experiments based in the United States and elsewhere. Fermilab's 6,800-acre site is located in Batavia, Illinois, and is managed by the Fermi Research Alliance LLC for the U.S. Department of Energy Office of Science. FRA is a partnership of the University of Chicago and Universities Research Association Inc., a consortium of 86 research universities. 2

Bison 3

Terms ADFS Active Directory Federation Services https://technet.microsoft.com/en-us/windowsserver/dd448613.aspx COTS - Commercial Off The Shelf IdP Identity Provider InCommon https://www.incommon.org/ LDAP Lightweight Directory Access Protocol http://en.wikipedia.org/wiki/lightweight_directory_access_protocol SP Service Provider SAML Security Assertion Markup Language http://saml.xml.org/about-saml Shibboleth https://shibboleth.net/ SSL Security Sockets Layer http://en.wikipedia.org/wiki/transport_layer_security SSO Single Sign On 4

Abstract Fermilab is working to provide a seamless web for science and business applications by using federated identities from internal identity providers such as Active Directory Federation Services and Shibboleth and external identity providers such as InCommon Federation members and social identities such as Google. This talk will focus on the complexities of internal and external identities, open source and COTS identity providers, and open source and COTS applications and how we are working to make the user experience for authentication as simple and secure as possible. 5

History 2003 Shibboleth 1.0 released 2008 Centrally managed LDAP service for web application authentication was brought online Computer Security initiated push for web application owners to move from.htaccess files to LDAP over SSL Not federation just a single password A big step in the right direction 2010 Fermilab hosted Shibboleth Installfest 20+ attendees from Fermilab and several other institutions Significant interest from all attendees 6

Crickets 7

History 2013 ADFS IdP in Production 2014 ADFS SP SharePoint 2013 Office 365 Shibboleth IdP in Production Managed Service On Premise Connected to InCommon Federation 2015 CiLogon SP Shibboleth Service 8

Why Federate? Passwords Authorization External identities Platform Independent Security Boundaries 9

Why Federate? Passwords Same password as LDAP Service Single Logon Authorization Application Compatibility Username Email Address 10

Why Federate? Identities Internal Centrally Managed External Business Partners Federation Members Social Media Identity Proofing How do you know who the user really is? Authoritative source Termination Control of Information Authentication Source 11

Why Federate? Platform Independent Operating System Application SAML Support SP IdP Client Web Browser 12

Security Boundaries Two types of logons at Fermilab Interactive and Web Password strength requirements are the same Interactive Logon to Linux or Windows Remote Desktop SSH Web SharePoint Email Interactive logons are not used to access web services Web logons are not used for interactive access to computers 13

Security Boundaries 14

Security Boundaries Why? Goal was to prevent compromised web credentials from gaining access to interactive systems As more services move to the web is this a valid concern? Some applications are designed around logon accounts being used to gain access to web services SharePoint Exchange Can Federation provide a true SSO environment? 15

Federation and SSO ADFS Windows Integrated Authentication ADFS in the Windows Logon Domain IdP as a RP to primary ADFS IdP Logon credentials used to access web applications Logon credentials are never presented to the web application No passwords on the wire Ever Non-Windows clients can kinit against the Windows Domain and use the applications in the same manner* 16

Federation and SSO ADFS to ADFS 17

Federation Service Today 18

Federation Service Today Hybrid Solution ADFS Microsoft stack SharePoint Office 365 Shibboleth Everything else InCommon CiLogon Central Web Services Service Now Apache Based Applications Social Connections 19

Hybrid Solution Issues Usability Two IdPs IdP to IdP Trust Support Managed Service Issues Compatibility Claims Formats 20

Hybrid Solution Why not just use one? ADFS Microsoft Documentation Microsoft Applications Open Source Applications Evil Empire PowerShell Internal Support System Configuration Hardware Software Quirks ADFS is an excellent choice for a Windows shop 21

Hybrid Solution Shibboleth Microsoft Applications Supported but Open Source Applications Documentation Product Support Paid https://shibboleth.net/community/consultants.html Free Your mileage may vary Internal Support System Configuration Hardware Software 22

Changing the Solution Federation is starting to gain acceptance at Fermilab Multiple SPs testing Central web services Content Management Cloud SaaS Issues with current solution Support Reliability Need a robust supported solution Internal Support Vendor Third-party 23

Federation The Next Generation Shibboleth out, Ping Federate in Standards Compliant Industry leader Excellent support In use in the DOE complex Mobile device integration Not without issues Configuration Metadata Import Export IdP Trust 24

Federation The Next Generation 25

Federation The Next Generation Simplify ADFS As part of upgrade to ADFS v3 Move from SQL Server to Windows Integrated Database More redundancy Data Centers Ping Federate ADFS Domain Controllers Cloud 26

Federation Service Goals True SSO for Windows Users Domain Members True SSO for Linux and OSX Users Kerberos Login Required Forms Based SSO All other Mobile Device Support Improve ease of use 27

Lessons Learned COTS Features Support Open Source Support Issues Managed Service Vendor Response Standards Support 28

Lessons Learned Evaluate the market Products are constantly evolving Don t be afraid to change Results can be worth the pain 29

Questions? Contact Information Al Lilianstrom lilstrom@fnal.gov FERMILAB-CONF-15-154-CD 30