Get Cloud Ready: Secure Access to Google Apps and Other SaaS Applications



Similar documents
NetIQ Aegis Adapter for Databases

The Who, What, When, Where and Why of IAM Bob Bentley

NetIQ Access Manager. Developer Kit 3.2. May 2012

Executing Large-Scale Data Center Transformation Projects with PlateSpin Migrate 12

Optimizing Business Continuity Management with NetIQ PlateSpin Protect and AppManager. Best Practices and Reference Architecture

Strong authentication. NetIQ - All Rights Reserved

DualShield SAML & SSO. Integration Guide. Copyright 2011 Deepnet Security Limited. Copyright 2011, Deepnet Security. All Rights Reserved.

The Challenges of Administering Active Directory

NetIQ Update October 31, 2013 Michel van der Laan

CAS8489 Delivering Security as a Service (SIEMaaS) November 2014

NetIQ Aegis Adapter for VMware vcenter Server

HP Software as a Service. Federated SSO Guide

Security Assertion Markup Language (SAML) Site Manager Setup

TUT8173 Best Practices for Security Monitoring in Distributed Environments November 2014

Configuring Single Sign-on from the VMware Identity Manager Service to WebEx

Security and HIPAA Compliance

Novell Access Manager

Real-Time Security Intelligence for Greater Visibility and Information-Asset Protection

NetIQ Identity Manager Setup Guide

Agenda. How to configure

Configuring Single Sign-on from the VMware Identity Manager Service to AirWatch Applications

Real-Time Security for Active Directory

NetIQ Präsentation. 9. Oktober Otto W. Schäfer. Account Manager

Installation and Configuration Guide. NetIQ Security and Compliance Dashboard

SAML Security Option White Paper

NetIQ AppManager for NetBackup UNIX

Flexible Identity Federation

A Practical Guide to Cost-Effective Disaster Recovery Planning

NetIQ AppManager ResponseTime for Microsoft Active Directory Management Guide

Virtualization Management Survey Analysis White Paper August 2008

Configuring Single Sign-On from the VMware Identity Manager Service to Office 365

HP Software as a Service

Reduce Your Breach Risk: File Integrity Monitoring for PCI Compliance and Data Security

SAML single sign-on configuration overview

CAS8491 Data Center Transformation as Service

Google Apps and Open Directory. Randy Saeks

User Management Tool 1.5

PingFederate. Windows Live Cloud Identity Connector. User Guide. Version 1.0

Samsung KNOX EMM Authentication Services. SDK Quick Start Guide

PingFederate. SSO Integration Overview

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

Single Sign-on to Salesforce.com with CA Federation Manager

Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER

Microsoft Office 365 Using SAML Integration Guide

Centrify Mobile Authentication Services

About Me. Software Architect with ShapeBlue Specialise in. 3 rd party integrations and features in CloudStack

Configuring. Moodle. Chapter 82

365 Services. 1.1 Configuring Access Manager Prerequisite Adding the Office 365 Metadata. docsys (en) 2 August 2012

McAfee Cloud Single Sign On

Setup Guide Access Manager 3.2 SP3

SAML SSO Configuration

SAML Authentication Quick Start Guide

Google Apps Deployment Guide

Centrify Mobile Authentication Services for Samsung KNOX

OneLogin Integration User Guide

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

Copyright: WhosOnLocation Limited

PingFederate. Salesforce Connector. Quick Connection Guide. Version 4.1

Perceptive Experience Single Sign-On Solutions

Configuring Single Sign-on from the VMware Identity Manager Service to Dropbox

Computer Services Documentation

SP-initiated SSO for Smartsheet is automatically enabled when the SAML feature is activated.

The Top 5 Federated Single Sign-On Scenarios

Single Sign On. SSO & ID Management for Web and Mobile Applications

Mod 2: User Management

HOTPin Integration Guide: Salesforce SSO with Active Directory Federated Services

Configuring Single Sign-on from the VMware Identity Manager Service to ServiceNow

How To Use Salesforce Identity Features

NetIQ AppManager for Cisco Interactive Voice Response. Management Guide

SAP NetWeaver AS Java

User Guide. Directory and Resource Administrator Exchange Administrator. Directory and Resource Administrator Exchange Administrator User Guide

OpenAM All-In-One solution to securely manage access to digital enterprise and customer services, anytime and anywhere.

Driver for NetIQ Privileged User Manager Implementation Guide. Identity Manager 4.0.2

McAfee Cloud Identity Manager

Connected Data. Connected Data requirements for SSO

Section 1, Configuring Access Manager, on page 1 Section 2, Configuring Office 365, on page 4 Section 3, Verifying Single Sign-On Access, on page 5

INTEGRATION GUIDE. DIGIPASS Authentication for SimpleSAMLphp using IDENTIKEY Federation Server

BlackBerry Enterprise Server for Microsoft Office 365 preinstallation checklist

HOTPin Integration Guide: Google Apps with Active Directory Federated Services

Identity Federation: Bridging the Identity Gap. Michael Koyfman, Senior Global Security Solutions Architect

User Guide. NetIQ VigilEnt Policy Center. August 2011

CA Nimsoft Service Desk

NetIQ AppManager for Cisco Unity Express. Management Guide

INTEGRATION GUIDE. DIGIPASS Authentication for Salesforce using IDENTIKEY Federation Server

NetIQ AppManager for IP Phone Quality. Management Guide

Egnyte Single Sign-On (SSO) Installation for OneLogin

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview)

Dell One Identity Cloud Access Manager How to Configure for SSO to SAP NetWeaver using SAML 2.0

Administrator Guide. v 11

The Role of Federation in Identity Management

Identity. Provide. ...to Office 365 & Beyond

VMware Identity Manager Administration

Setup Guide Access Manager Appliance 3.2 SP3

Transcription:

Get Cloud Ready: Secure Access to Google Apps and Other SaaS Applications Matt Weisberg Vice President & CIO, Weisberg Consulting, Inc. matt@weisberg.net Paul McKeith Technical Sales, Novell, Inc. pmckeith@novell.com Mike Weaver IDM Practice Lead, Concensus Consulting mike.weaver@concensus.com

Introduction Provisioning and Management of Accounts Single Sign-On using Secure Assertion Markup Language (SAML) 2

Provisioning via Identity Manager

NetIQ/Identity Manager (IDM) Event-Based Identity Provisioning and Management Near real-time data synchronization between connected systems User Password Management Password Self-Service Multiple hosting platform support Out of the box support for a wide array of connected systems 4

IDM Connector for Google Apps IDM Connector for Google Apps Enterprise Identity Data 5

IDM Connector for Google Apps IDM Integration Module for unidirectional synchronization into Google Apps Native Java code Utilizes several published Google APIs IDM 4.0.1 or later 6

Features Synchronize (provision): Users Groups Shared Contacts Containers (OUs) Move between OUs Supports Secondary Email domains Support for Alias and Send-As settings Supports RBE and RBPM entitlements Account Tracking Support Password sync (one-way) User Profile Information 7

IDM Driver VS GADS 8

Implementation Requires Google Apps for Business Google Apps for Education API Access Enabled Network access to Google Remote Loader IDM Engine 9

Implementation Install the driver modules Download the latest from the Novell Patch site Add the Schema extensions Novell_Google_Schema.sch Be sure to update Designer Packages! Latest versions of the policies and driver configuration 10

Futures Move user mailbox between email domains within the same Google Apps domain Resource Objects Postini Driver New features dependent on Google API updates 11

Single Sign On via SAML

Google Apps Single Sign-On (SSO) Google Supports Two Methods of Single Sign-On: Open ID Simple implementation Auto discovery of identities Service Provider Initiated SSO only Secure Assertion Markup Language (SAML) More Complex Better end-user experience Faster Flexible Supported by Access Manager 13

What is SAML? Security Assertion Markup Language (SAML) is an XML-based standard for exchanging authentication and authorization data between security domains, that is, between an identity provider (a producer of assertions) and a service provider (a consumer of assertions). Source, Wikipedia (http://en.wikipedia.org/wiki/saml) 14

SAML - Service Provider Initiated SSO User/Browser 1 2 3 4 5 Google Apps (Service Provider) Access Manager (Identity Provider) 1. User accesses Google Apps 2. Google generates SAML request and redirects user to IdP. 3. User logs into IdP and gets SAML response (assertion) 4. User is redirected back to Google and sends SAML response 5. Google verifies response and allows user into application 15

Access Manager Quick Overview Reverse Proxy Course Grained Access Control Agent-less Web SSO via Form Fill J2EE Web Agents Fine Grained Access Control SSLVPN Loosely Coupled Identity Stores LDAP Directories e.g. Active Directory, Sun One, edirectory Open Standard Federation and Web SSO Support Liberty Alliance, SAML, and Microsoft WS-Federation 16

Access Manager Identity Provider Base URL is the Identity Provider URL Must be accessible by clients Can use port 443 instead of 8443 (iptables redirect) 17

Access Manager User Store edirectory, AD or SunOne supported out of the box. Other LDAP supported via custom plugins. 18

Access Manager Default Contract 19

Access Manager Trusted Providers 20

Access Manager SP Metadata <md:entitydescriptor xmlns:md="urn:oasis:names:tc:saml:2.0:metadata" entityid="google.com"> <md:spssodescriptor WantAssertionsSigned="true" protocolsupportenumeration="urn:oasis:names:tc:saml:2.0:protocol"> <md:nameidformat> urn:oasis:names:tc:saml:2.0:nameid-format:emailaddress </md:nameidformat> <md:assertionconsumerservice Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://www.google.com/a/samlexperts.com/acs" index="1"/> </md:spssodescriptor> </md:entitydescriptor> Not supplied by Google! You must create. entityid can be domain specific to support multiple Google Apps instances with the same IdP. 21

Access Manager SAML Trust 22

Access Manager SAML Attributes 23

Access Manager Authentication Response 24

25

Google Apps Advanced Tools 26

Google Apps Set up SSO 27

Google Apps Example SSO URLs Sign-in page URL: https://ids1.samlexperts.com:8443/nidp/saml2/sso Sign-out page URL: https://ids1.samlexperts.com:8443/nidp/app/logout Change Password URL: https://pwm.samlexperts.com/pwm/private/changepassword Access Manager IdS Metadata URL: https://ids1.samlexperts.com:8443/nidp/saml2/metadata 28

Single Sign On Demo

Password Self Service Password Management Servlets (PWM) Open Source http://code.google.com/p/pwm/ IdM User Application Novell Self-Service Password Reset (SSPR) http://download.novell.com/download?buildid=plbqmvidc80~ http://www.novell.com/documentation/sspr10/ Note: Based on Open-Source PWM 30

Questions and Answers

This document could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein. These changes may be incorporated in new editions of this document. NetIQ Corporation may make improvements in or changes to the software described in this document at any time. Copyright ActiveAudit, ActiveView, Aegis, AppManager, Change Administrator, Change Guardian, Compliance Suite, the cube logo design, Directory and Resource Administrator, Directory Security Administrator, Domain Migration Administrator, Exchange Administrator, File Security Administrator, Group Policy Administrator, Group Policy Guardian, Group Policy Suite, IntelliPolicy, Knowledge Scripts, NetConnect, NetIQ, the NetIQ logo, PSAudit, PSDetect, PSPasswordManager, PSSecure, Secure Configuration Manager, Security Administration Suite, Security Manager, Server Consolidator, VigilEnt, and Vivinet are trademarks or registered trademarks of NetIQ Corporation or its subsidiaries in the United States and other countries.