Identity Management and eid Integration



Similar documents
White paper December Addressing single sign-on inside, outside, and between organizations

An Oracle White Paper July Oracle Desktop Virtualization Simplified Client Access for Oracle Applications

Introducing etoken. What is etoken?

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

DirX Identity V8.5. Secure and flexible Password Management. Technical Data Sheet

eid Security Frank Cornelis Architect eid fedict All rights reserved

The Sun Virtual Desktop + VMware Virtualization. Jaap Romers Solution Architect, CNE Software Practice Sun Microsystems

SAP Single Sign-On 2.0 Overview Presentation

DirX Identity V8.4. Secure and flexible Password Management. Technical Data Sheet

EXPLORING SMARTCARDS: AN INDEPENDENT LOOK TO TECHNOLOGIES AND MARKET

Entrust Managed Services PKI Administrator Guide

An Oracle White Paper August Higher Security, Greater Access with Oracle Desktop Virtualization

OpenSSO: Simplify Your Single-Sign-On Needs. Sang Shin Java Technology Architect Sun Microsystems, inc. javapassion.com

Biometric SSO Authentication Using Java Enterprise System

Service management White paper. Manage access control effectively across the enterprise with IBM solutions.

WHITE PAPER. Smart Card Authentication for J2EE Applications Using Vintela SSO for Java (VSJ)

Oracle Business Intelligence Publisher. 1 Oracle Business Intelligence Publisher Certification. Certification Information 10g Release 3 (

Single Sign-On Architectures. Jan De Clercq Security Consultant HPCI Technology Leadership Group Hewlett-Packard

Centrify Server Suite, Standard Edition

Agenda. How to configure

Migration Best Practices for OpenSSO 8 and SAM 7.1 deployments O R A C L E W H I T E P A P E R M A R C H 2015

Gabriel Magariño. Software Engineer. Overview Revisited

Role Based Identity and Access Management Basic Infrastructure for New Citizen Services and Lean Internal Administration

SEC100 Secure Authentication and Data Transfer with SAP Single Sign-On. Public

Using SAP Logon Tickets for Single Sign on to Microsoft based web applications

Product overview. CA SiteMinder lets you manage and deploy secure web applications to: Increase new business opportunities

Moving to Multi-factor Authentication. Kevin Unthank

Entrust Managed Services PKI Administrator s Quick Start Guide

An Oracle White Paper Dec Oracle Access Management Security Token Service

CRESCENDO SERIES Smart Cards. Smart Card Solutions

PortWise Access Management Suite

Biometric Single Sign-on using SAML

An Oracle White Paper July Introducing the Oracle Home User in Oracle Database 12c for Microsoft Windows

<Insert Picture Here> Oracle Identity And Access Management

SAP Secure Operations Map. SAP Active Global Support Security Services May 2015

MQ Authenticate User Security Exit Overview

PortWise Access Management Suite

IBM Tivoli Remote Control

Converged Smart Card for Identity Assurance Solutions. Crescendo Series Smart Cards

An Oracle White Paper May Distributed Development Using Oracle Secure Global Desktop

Secure the Web: OpenSSO

PROTECT YOUR WORLD. Identity Management Solutions and Services

Identity opens the participation age. Dr. Rainer Eschrich. Program Manager Identity Management Sun Microsystems GmbH

Oracle Virtual Desktop Infrastructure. VDI Demo (Microsoft Remote Desktop Services) for Version 3.2

Thin Clients: Secure and Cost Effective Client Access Devices for Government Organizations

RSA ACCESS MANAGER. Web Access Management Solution ESSENTIALS SECURE ACCESS TO WEB APPLICATIONS WEB SINGLE SIGN-ON CONTEXTUAL AUTHORIZATION

Introducing Systemwalker Operation Manager V13.3. July 2008 FUJITSU LIMITED

Access to Webmail services via a Non Trust Computer

Architectural Overview

An introduction to EJBCA and SignServer

Sun and Oracle: Joining Forces in Identity Management

1 Building an Identity Management Business Case. 2 Agenda. 3 Business Challenges

Security Best Practices for Microsoft Azure Applications

OracleAS Identity Management Solving Real World Problems

Implementing and Administering Security in a Microsoft Windows Server 2003 Network

NETWRIX IDENTITY MANAGEMENT SUITE

ORACLE MOBILE APPLICATION FRAMEWORK DATA SHEET

WatchGuard SSL 2.0 New Features

BlackBerry Enterprise Server for Microsoft Office 365 preinstallation checklist

CERN Single Sign On. Emmanuel Ormancey CERN IT/IS. CERN IT Department CH-1211 Genève 23 Switzerland

ACE Management Server Deployment Guide VMware ACE 2.0

SAP Web Application Server Security

Biometric Single Sign-on using SAML Architecture & Design Strategies

New Single Sign-on Options for IBM Lotus Notes & Domino IBM Corporation

Managed Services PKI 60-day Trial Quick Start Guide

MAESON MAHERRY. 3 Factor Authentication and what it means to business. Date: 21/10/2013

Security solutions Executive brief. Understand the varieties and business value of single sign-on.

GlassFish Security. open source community experience distilled. security measures. Secure your GlassFish installation, Web applications,

Technical notes for HIGHSEC eid App Middleware

The Oracle Mobile Security Suite: Secure Adoption of BYOD

WEBLOGIC SERVER MANAGEMENT PACK ENTERPRISE EDITION

Using EMC Unisphere in a Web Browsing Environment: Browser and Security Settings to Improve the Experience

Quest One Identity Solution. Simplifying Identity and Access Management

Card Management System Integration Made Easy: Tools for Enrollment and Management of Certificates. September 2006

Provide access control with innovative solutions from IBM.

Non-Employee VPN Quick Start Guide

Single Sign-On Access Management A Technical Framework on Access Management Systems

Oracle Virtual Desktop Infrastructure. Administrator's Guide for Release 3.5

Windows in a Browser Secure Remote Access with HOB RD VPN

Single Sign-On for SAP R/3 on UNIX with Centrify DirectControl and Microsoft Active Directory

SAML-Based SSO Solution

RSA Digital Certificate Solution

RSA SecurID Two-factor Authentication

Microsoft vs. Red Hat. A Comparison of PKI Vendors

Software Token Security & Provisioning: Innovation Galore!

Global eid Developments. Detlef Eckert Chief Security Advisor Microsoft Europe, Middle East, and Africa

RSA Security. RSA, RC2, RC4, RC5, MD5 AES RC6 PKCS RSA Keon PKI. RSA BSAFE 5 Web. RSA SecurID 4000

How To Login To Webex Online

Transcription:

Identity Management and eid Integration Luc Wijns > Principal Architect > Security Ambassador & CISSP > Sun Microsystems

Agenda Sun Identity Management Integration of the eid Card > Authentication & Signature > Mobility > SSO Sun Secure Global Desktop

Identity Management Enables Security Market Forecast: Identity Revenue Shift: Identity & Access Management (IDC) From Enterprise to Extranet Projects $ Billions 4 3 2 1 0 2005 2006 2007 Identity Revenue Mix 100% 6 5 80% 60% 40% 20% 0% 2005 Key Business Drivers: > Regulatory compliance (Sox, HIPPA, > > > > Basle II...) Enterprise security (e.g. Identity Theft) Employee life-cycle management IT cost-reduction Extranet models (partners, customers) 2006 2007 2008 Drivers: > Increase in Extranet business models for new revenues (B2B & B2C) > Availability of key enabling technologies and standards like Federation > Saturation of Enterprise-focused Identity opportunities

Sun Identity Management Portfolio Innovative. Integrated. Integratable. Collaborative Enterprise Federation Manager Directory Server Identity Manager SPE Access Manager Identity Auditor Enterprise Edition Enterprise Everything required to manage identities within the extended enterprise and across collaborative networks all completely integratable with dynamic, heterogeneous IT environments. OpenSSO Identity Manager

Directory Server Enterprise Edition Directory Server Enteprise Edition NEW GRAPHIC Directory Server Directory Proxy Server Password Synchronisation for Windows

Access Management Product Line Access Manager Federation Manager Policy Management Single Sign On Federated Identity Management OpenSSO

Product Line Landscape OpenSSO Access Manager Federation Manager Developer Intranet Extranet > Authentication > Single-domain SSO > Agents > > > > Policy Management Policy Enforcement Federation (IdP) Identity Web Services > Federation (SP) > Identity Web Services

Identity Management Product Line Identity Manager Identity Auditor Identity Manager SPE Automated User provisioning Secure, automated password management User self service and delegated administration Auditing and reporting for compliance

EID Integration SNAP: Secure Network Access Platform JavaCard Sun Ray Thin Client Solaris 10, OpenSC/OpenCT and PC/SC components Sun Java System Access Manager

Mobility with Security Belgian eid Integration JVM Java Card eid Certificates and Keys Card Serial Number Pkcs#11 / Pkcs#15 cardlet

Mobility with Security SNAP: Secure Network Access Platform System Security: Perimeter Security Hardened OS Domain Security U Ne ser w Mo Lo vin ca g tio to n User Moves Session to New Sun Ray System Security: Stateless Client Access Management: Dynamic Network ID and Access Control Java Card Authentication Ne Use w rm Su o v n L in oc g to ati on User Starts Session on Home Sun Ray Ne Enc twork S rypt ecu ed T rity: raffi c Network Security: Encrypted Traffic

End-to-End Integration Demo Citizens Java Card Secure Token Belpic Applet &Certificates Java Card Access Services & Identity Fat /Thin Client Java Enterprise System Back-End Server SunRay JDS Solaris JES Java 2 Runtime Edition Card client SW OpenSC PC/SC LibUSB Web front-end Application Server Web Server Identity back-end Access Manager Directory Server Authority National Register

Non Intrusive Integration Architecture Citizens/E mployees Services & Identity Access/ Edge Web front-end Application Server Web Server PAM using pkcs#11 Java Card Secure Token Authority Java 2 Runtime Edition Fat /Thin Client National Register Java Enterprise System Web/App Server SunRay OCSP Call or CRLs Client SSL for Validation Authentication Belpic Applet &Certificates Java Card Other Cards other applets Gov and Enterprises Card client SW OpenSC PC/SC IFD Handle Windows is also here Java Enterprise System Identification Access Authentication Manager Authorization Identity back-end Access Manager Directory Server

Mobility, Authentication and Signature System Authentication Solaris 10, and SunRay user authentication > User Login using credentials on the eid card (OpenSC PAM framework) Web SSO Certificate based authentication from Solaris 10 > Mozilla user authenticates on two applications protected by Access Manager > Access Manager to integrate with the Government PKI E-Mail Signature > User connected to his Private e-mail account, sign e-mail with the card on a SunRay > User validates the signature on the Enterprise e-mail account

Sun Secure Global Desktop Delivering the Same Applications to a Sun Ray Client MS Excel on Windows 2003 Mozilla Firefox on Solaris OS Explorer on Windows Vista SAP on Mainframe MS Word on Windows 2000 3270 application

Secure Remote Access Windows 2000 Windows XP RDP Sun Secure Global Desktop Windows 2003 Windows 2000 AIP RDP Windows XP Mobile UNIX Mainframe/ AS/400 Apps X11 Sun Ray Server Software Sun Ray Ultrathin Client ALP 3270/ 5250 Sun Ray Ultrathin Client Access Clients

Copyright 2005 Sun Microsystems, Inc. All rights reserved. Sun, Sun Microsystems, the Sun logo, Java, StarOffice, Solaris, Sun StorEdge, J2EE, SunSpectrum, N1, iforce, Java Card, and The Network Is The Computer are trademarks or registered trademarks of Sun Microsystems, Inc. in the United States and other countries. All SPARC trademarks are used under license and are trademarks or registered trademarks of SPARC International, Inc. in the United States and other countries. Products bearing SPARC trademarks are based upon an architecture developed by Sun Microsystems, Inc. AMD, Opteron, the AMD logo, the AMD Opteron logo are trademarks or registered trademarks of Advanced Micro Devices. THANK YOU! Luc.wijns@sun.com

Sun Java System Identity Manager First converged provisioning and meta-directory solution Benefits: Enhance security Lower costs Improve productivity Features: NEW GRAPHIC Securely managing identity profiles and permissions throughout the entire identity lifecycle Automated user provisioning Secure, automated password management User self service and delegated administration Identity data synchronization Non-invasive, flexible architecture Auditing and reporting

Sun Java System Identity Auditor Industry s first proactive, virtualized, automated and sustainable identity auditing solution Benefits: NEW GRAPHIC Helping achieve effective compliance, lowered risk, and improved audit performance Help achieve ongoing compliance Help lower costs Minimize security risks Features: Proactive, automated visibility into identity controls Repeatable, sustainable compliance and improved audit performance Integrate with existing identity management solutions 19