Department of Industry and Science



Similar documents
CA Nimsoft Service Desk

SAML-Based SSO Solution

The increasing popularity of mobile devices is rapidly changing how and where we

SAML-Based SSO Solution

Getting Started with AD/LDAP SSO

New Single Sign-on Options for IBM Lotus Notes & Domino IBM Corporation

ONSITE TRACK EASY Yancoal Contractor Management Portal Portal User Guide: Company Registration. Yancoalcontractors.com.

Agenda. How to configure

Certification Practice Statement

Digital Signing without the Headaches

Avaya Credential Management System User Guide

Microsoft Office 365 Using SAML Integration Guide

Enabling Federation and Web-Single Sign-On in Heterogeneous Landscapes with the Identity Provider and Security Token Service Supplied by SAP NetWeaver

Identity Hub Service Desk Handbook. Document Ref: NSWG/MS/SG/v1.0 December, Version 1.0

Ameritas Single Sign-On (SSO) and Enterprise SAML Standard. Architectural Implementation, Patterns and Usage Guidelines

Single sign-on for ASP.Net and SharePoint

SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

Copyright: WhosOnLocation Limited

ADFS Integration Guidelines

HP Software as a Service

ShareFile Security Overview

ACTIVID APPLIANCE AND MICROSOFT AD FS

How To Create A Single Sign On For Blackboard

ASIAN PACIFIC TELECOMMUNICATIONS PTY LTD STANDARD FORM OF AGREEMENT. Schedule 3 Support Services

USING FEDERATED AUTHENTICATION WITH M-FILES

Service Catalogue. 0984v1

Guide for Setting Up Your Multi-Factor Authentication Account and Using Multi-Factor Authentication. Mobile App Activation

Operating Level Agreement for NYU Login Service

HKUST CA. Certification Practice Statement

PROVIDING SINGLE SIGN-ON TO AMAZON EC2 APPLICATIONS FROM AN ON-PREMISES WINDOWS DOMAIN

IT Services. Service Level Agreement

Digital Signature Application

Configuring Single Sign-On from the VMware Identity Manager Service to Office 365

Deploying RSA ClearTrust with the FirePass controller

Flexible Identity Federation

Server based signature service. Overview

E-Authentication Federation Adopted Schemes

TIB 2.0 Administration Functions Overview

Configuring ADFS 3.0 to Communicate with WhosOnLocation SAML

Single Sign-On Implementation Guide

INTEGRATE SALESFORCE.COM SINGLE SIGN-ON WITH THIRD-PARTY SINGLE SIGN-ON USING SENTRY A GUIDE TO SUCCESSFUL USE CASE

Security Assertion Markup Language (SAML) Site Manager Setup

PKD Board ICAO PKD unclassified B-Tec/37. Procedures for the ICAO Public Key Directory

EVault Endpoint Protection 7.0 Single Sign-On Configuration

SAM Context-Based Authentication Using Juniper SA Integration Guide

SECUREAUTH IDP AND OFFICE 365

HP Software as a Service. Federated SSO Guide

Service Definition. ADNS Domain V0.4. Signoff. Name Role Signature & Date. Jim Leeper. Windows Platform. Page 1

Richmond Systems. Self Service Portal

Securing Adobe PDFs. Adobe - Certified Document Services Registration Authority (RA) Training. Enterprise Security. ID Verification Services

This section includes troubleshooting topics about single sign-on (SSO) issues.

Identity Server Guide Access Manager 4.0

Meeting the FDA s Requirements for Electronic Records and Electronic Signatures (21 CFR Part 11)

ADFS for. LogMeIn and join.me authentication

IAM Application Integration Guide

Statement of Service Enterprise Services - AID Microsoft IIS

SAML v1.1 for.net Developer Guide

CS 356 Lecture 28 Internet Authentication. Spring 2013

SAML Security Option White Paper

Protecting Juniper SA using Certificate-Based Authentication. Quick Start Guide

How To Use Saml 2.0 Single Sign On With Qualysguard

Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER

Using SAML for Single Sign-On in the SOA Software Platform

The Challenges of Web single sign-on

Single-Sign-On between On-Premises and the Cloud: Leveraging Windows Azure Active Directory to authenticate custom solutions and Apps

Single Sign-On Implementation Guide

Card Management System Integration Made Easy: Tools for Enrollment and Management of Certificates. September 2006

Statement of Service Enterprise Services - MANAGE Microsoft IIS

GlobalSign Enterprise PKI Support. GlobalSign Enterprise Solution EPKI Administrator Guide v2.4

Securing Web Services With SAML

Guide for Completing EIDM Account setup for Migrated IACS Users who are currently inactive

Internet Banking Internal Control Questionnaire

IBM WebSphere Application Server

Google Apps SSO to Office 365 Integration

Google Apps SSO to Office 365 Integration

Your Gateway to Electronic Payments & Financial Services. Getting Started Guide - English

SAML SSO Configuration

Equens Certificate Policy

Leveraging SAML for Federated Single Sign-on:

DocuSign Information Guide. Single Sign On Functionality. Overview. Table of Contents

Federated Identity in the Enterprise

Configuring Single Sign-on from the VMware Identity Manager Service to ServiceNow

Portal Recipient Guide

Arizona Health Information Exchange Marketplace. Requirements and Specifications Health Information Service Provider (HISP)

TRIPwire HSIN Federation:

Visa Checkout Integration Guide V1.0

Directory Integration with Okta. An Architectural Overview. Okta Inc. 301 Brannan Street San Francisco, CA

OneLogin Integration User Guide

Federal PKI (FPKI) Community Transition to SHA-256 Frequently Asked Questions (FAQ)

Procedure for How to Enroll for Digital Signature

Service Description. 3SKey. Connectivity

Web Services Security and Federated Identity Management

Cybersecurity and Secure Authentication with SAP Single Sign-On

Adlib Hosting - Service Level Agreement

WEBKINCSTAR ONLINE SECURITIES TRADING - TERMS AND CONDITIONS OF USE

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

Multi-Factor Authentication for OWA in Exchange Online Dedicated

Absorb Single Sign-On (SSO) V3.0

Transcription:

Services Catalogue

Department of Industry and Science

Contents 1 Introduction 2 VANguard Services 2 About the VANguard Services Catalogue 2 Contact Details 2 2 VANguard Services 3 User Authentication Service (UAS) 4 Signature Verification Service (SVS) 6 Timestamping Service (TSS) 8 Security Token Service (STS) 10 Federated Authentication Service (FAS) 14 3 Related Services 16 Certificate Issuance Service 16 Technical Support Desk 17 External Monitoring Portal 18 Solution Assistance and Advice 19 VANguard Service Catalogue 1

1 Introduction VANguard is a whole of government program delivered by the Department of Industry and Science. VANguard delivers a range of authentication services to secure business to government (B2G) and government to government (G2G) online transactions. These services are driven by the requirement to increase the uptake of electronic commerce in Australia and to help reduce the compliance burden on business interacting with government. VANguard Services User Authentication Service The User Authentication Service (UAS) verifies a business user s online identity for access to secure government agency websites using a single login. UAS allows agencies and users to securely interact with government with the assurance of each other s identity. Signature Verification Service The Signature Verification Service (SVS) verifies a business user s digital credential when used to sign an agency s online form. A business user s digital credential is recognised as having equal legal status to a traditional signature. A signed form submitted to an agency can be sent to the SVS to confirm the validity of the digital credential. The service verifies the digital signature and provides the online identity information of the signatory. Timestamping Service The Timestamping Service (TSS) records a date and time for an electronic transaction using certified date and time from the National Measurement Institute (NMI). An agency can use the timestamp as evidence of the transaction. A timestamp request containing electronic content is issued over the internet for a timestamp token. The TSS issues a hashed timestamp of the electronic transaction record. A transaction can still be timestamped even if the entire transaction content is not made available to VANguard. Security Token Service The Security Token Service (STS) generates an electronic security token to ensure transactions between two parties, either business or government, or between agencies, are secure. The STS provides the technology for an agency to authenticate a second party without having to store any digital identity information. The STS also includes a delegation feature that allows an agency to act on behalf of a business user with another agency. Federated Authentication Service The Federated Authentication Service (FAS) allows users logged on to their own agency s network to authenticate and then use web applications in another agency. Authentication occurs transparently without additional credentials or software being required on the user s computer. About the VANguard Services Catalogue The Services Catalogue: Provides an overview of the authentication rservices VANguard has on offer. Explains what VANguard clients can expect from rour services. Contact details VANguard Customer Department of Industry and Science Physical Address: Industry House 10 Binara Street Canberra City ACT 2601 Postal Address: GPO Box 9839 Canberra ACT 2601 Email: vanguard.customer@industry.gov.au 2 Department of Industry and Science

2 VANguard Services Service Description Each service is described as follows: Description Standard service features Delivery scope Delivery channels Service hours Service level Test environment Reporting User requirements Service initiation Service support Standard costs Related services Additional information Process diagram A brief non-technical description of the service. Features and functions of the service available to all client organisation users who receive the service. These are provided under the Service Level Agreement (SLA). The client organisation units who are able to receive the service. How the service is to be received for example, via a computer, the internet or email. Timeframes and hours when the service is operational. The expectations for standards of service delivery in non-technical terms. Availability of a test environment. Frequency of reports and description of content. Prerequisites the client organisation users must fulfil in order to successfully use the service. Tasks that client organisations, or their users, must complete in order to successfully use the service. Where client organisation users can go to obtain support for the service. Any client organisation or unit costs for provision of the standard service features. Other services that are associated with the service. Reference material that supports the service for example, guides or standards. A high level business process model describing the service. VANguard Service Catalogue 3

User Authentication Service (UAS) - Single Sign-On Service Description Standard service features Delivery scope Delivery channels The User Authentication Service (UAS) verifies a business user s digital identity for access to secure agency portals and websites with a single login. This service obtains, verifies and provides agencies with an assertion of a user s identity. Login. Re-login (session timeout). Re-authentication (for important transactions). Supports a range of digital credentials. Supports customisable user interface. Provides a standard security token (SAML). Government agencies (federal, state and local). Internet (browser-based). Service hours 24 x 7. Service level Availability: 99.5% for standard business hours (08:00 to 18:00 AEST Monday to Friday) and 98.5% for non-business hours. Latency: Return responses within three seconds for 95% of requests. Integrity: Responses are clearly distinguished as either processed successfully or in error. All responses are digitally signed. Test environment Reporting User requirements Service initiation Service support Standard costs Agencies have unlimited access to a dedicated testing environment for integration with this service. Monthly reports on transaction volumes, service availability and service performance. The user must assert their online identity using a recognised digital credential. When a business user attempts to login to an agency website, the agency connects to this service. The business user is presented with the whole of government login screen and is required to assert their identity. If a business user has recently been authenticated (in the same browser session) then those authentication details are used. Technical Service Desk. Agencies provide support to their users. This service incurs no charge for small transaction volumes. Larger transaction volumes are offered on a cost recovery basis subject to negotiation with VANguard. Agencies are responsible for their integration costs with this service. Related services Certificate Issuance Service. External Monitoring Portal. Solution Assistance and Advice. 4 Department of Industry and Science

Additional information UAS Technical Service Contract. Common Elements Technical Service Contract. VANguard Service Level Agreement (SLA). VANguard Memorandum of Understanding (MOU). VANguard website: www.vanguard.business.gov.au. VANguard Service Catalogue 5

Signature Verification Service (SVS) Description Standard service features The Signature Verification Service (SVS) can verify a person s digital signature across a range of formats. Agencies send signed PDF forms, data signed using the Cryptographic Message Syntax format or signed XML content to the service to verify that the digital signature is valid. Supported formats: PDF document signatures (up to five on a single document). XML-DSIG (XML signature syntax and processing). CMS (Cryptography Message Syntax). Provides a standard security token (SAML). Delivery scope Delivery channels Government agencies (federal, state and local). Web service. Service hours 24 x 7. Service level Availability: 99.5% for standard business hours (08:00 to 18:00 AEST Monday to Friday) and 98.5% for non-business hours. Latency: Return responses within three seconds for 95% of requests for an XML or PDF with one signature that is less than 1MB in size. Integrity: Responses are clearly distinguished as either processed successfully or in error. All responses are digitally signed. Test environment Reporting User requirements Service initiation Service support Standard costs Agencies have unlimited access to a dedicated testing environment for integration with this service. Monthly reports on transaction volumes, service availability and service performance. A business user must digitally sign a PDF form, sign XML-based content, or a signed CMS document. The agency connects to this service to verify the business user's digital signature on the form or XML-based content. Technical Service Desk. Agencies provide support to their users. This service incurs no charge for small transaction volumes. Larger transaction volumes are offered on a cost recovery basis subject to negotiation with VANguard. Agencies are responsible for their integration costs with this service. Related services Certificate Issuance Service. External Monitoring Portal. Solution Assistance and Advice. 6 Department of Industry and Science

Additional information SVS Technical Service Contract. Common Elements Technical Service Contract. VANguard Service Level Agreement (SLA). VANguard Memorandum of Understanding (MOU). Web Service Definition Language (WSDL). VANguard website: www.vanguard.business.gov.au. VANguard Service Catalogue 7

Timestamping Service (TSS) Description The Timestamping Service (TSS) proves what a transaction looked like at a particular point in time by recording its digital fingerprint (timestamp) along with the date and time the transaction occurred. Using certified time from the National Measurement Institute, the TSS issues a digitally signed timestamp of the transaction. An agency can use the timestamp as evidence that a transaction existed in a particular form at the point in time the timestamp was issued. Standard service features Delivery scope Delivery channels Two supported formats: RCF3161 (Time-Stamp protocol). XML-DSIG (XML Digital Signature Services Standard). Government agencies (federal, state and local). Web service. Service hours 24 x 7. Service level Availability: 99.5% for standard business hours (08:00 to 18:00 AEST Monday to Friday) and 98.5% for non-business hours. Latency: Return responses within three seconds for 95% of requests for files less than 200KB in size. Integrity: Responses are clearly distinguished as either processed successfully or in error. All responses are digitally signed. Test environment Reporting Service initiation Service support Standard costs Agencies have unlimited access to a dedicated testing environment for integration with this service. Monthly reports on transaction volumes, service availability and service performance. The agency connects to this service to obtain a timestamp token for the electronic content. Technical Service Desk. Agencies provide support to their users. This service incurs no charge for small transaction volumes. Larger transaction volumes are offered on a cost recovery basis subject to negotiation with VANguard. Agencies are responsible for their integration costs with this service. Related services Certificate Issuance Service. External Monitoring Portal. Solution Assistance and Advice. 8 Department of Industry and Science

Additional information TSS Technical Service Contract. Common Elements Technical Service Contract. VANguard Service Level Agreement (SLA). VANguard Memorandum of Understanding (MOU). Web Service Definition Language (WSDL). VANguard website: www.vanguard.business.gov.au. VANguard Service Catalogue 9

Security Token Service (STS) Description Standard service features Delivery scope Delivery channels The Security Token Service (STS) ensures that transactions are secure between a business and a government agency, or between government agencies. A business or an agency obtains a security token that identifies it. The token is then secured for use by the intended recipient. The STS validates a request from an initiating party and, on success, issues a security token (SAML). The token and information identifying the initiating party is only accessible to the agency. Government agencies (federal, state and local). The service request must be signed using a recognised digital certificate issued by VANguard. Web service. Service hours 24 x 7. Service level Availability: 99.5% for standard business hours (08:00 to 18:00 AEST Monday to Friday) and 98.5% for non-business hours. Latency: Return responses within three seconds for 95% of requests. Integrity: Responses are clearly distinguished as either processed successfully or in error. All responses are digitally signed. Test environment Reporting Service initiation Service support Standard costs Agencies have unlimited access to a dedicated testing environment for integration with this service. Monthly reports on transaction volumes, service availability and service performance. The business or initiating agency can obtain a security token that identifies them to the relying agency. Technical Service Desk. Agencies provide support to their users. This service incurs no charge for small transaction volumes. Larger transaction volumes are offered on a cost recovery basis subject to negotiation with VANguard. Agencies are responsible for their integration costs with this service. Related services Certificate Issuance Service. External Monitoring Portal. Solution Assistance and Advice. 10 Department of Industry and Science

Additional information STS Technical Service Contract. Common Elements Technical Service Contract. VANguard Service Level Agreement (SLA). VANguard Memorandum of Understanding (MOU). Web Service Definition Language (WSDL). VANguard website: www.vanguard.business.gov.au. VANguard Service Catalogue 11

Security Token Service (STS) with Delegation Description Standard service features Delivery scope Delivery channels The Security Token Service (STS) ensures that transactions are secure between a business and an agency, or between government agencies. The STS with Delegation enables agencies, acting on behalf of business users, to conduct secure online business. The STS with Delegation validates the request from an initiating party, and on success, issues a security token. The security token contains the identities of both the initiating party and the business user. This information is only available to the relying party agency. Government agencies (federal, state and local). The service request must be signed using a recognised digital credential issued by VANguard. Web service. Service hours 24 x 7. Service level Availability: 99.5% for standard business hours (08:00 to 18:00 AEST Monday to Friday) and 98.5% for non-business hours. Latency: Return responses within three seconds for 95% of requests. Integrity: Responses are clearly distinguished as either processed successfully or in error. All responses are digitally signed. Test environment Reporting User requirements Service initiation Service support Standard costs Agencies have unlimited access to a dedicated testing environment for integration with this service. Monthly reports on transaction volumes, service availability and service performance. The business user has authenticated with the initiating party agency using the User Authentication Service. The initiating party requests a security token from VANguard that can be used to verify identity with a relying party agency. Technical Service Desk. Agencies provide support to their users. This service incurs no charge for small transaction volumes. Larger transaction volumes are offered on a cost recovery basis subject to negotiation with VANguard. Agencies are responsible for their integration costs with this service. Related services User Authentication Service (UAS). Certificate Issuance Service. External Monitoring Portal. Solution Assistance and Advice. 12 Department of Industry and Science

Additional information STS Technical Service Contract. UAS Technical Service Contract. Common Elements Technical Service Contract. VANguard Service Level Agreement (SLA). VANguard Memorandum of Understanding (MOU). Web Service Definition Language (WSDL). VANguard website: www.vanguard.business.gov.au. VANguard Service Catalogue 13

Federated Authentication Service (FAS) Description Standard service features Delivery scope Delivery channels The Federated Authentication Service (FAS) allows users logged on to their own agency s network to authenticate and then use web applications in another agency. Authentication occurs transparently without additional credentials or software being required on the user s computer. The FAS currently supports the WS-Federation Protocol only. SAML protocol support may be added at a later time. The service returns SAML 1.1 tokens for maximum compatability with existing Vendor products. SAML 2 products may be available in the future. Government agencies (federal, state and local). The service request must be signed using a recognised digital credential issued by VANguard. Internet (browser-based). Service hours 24 x 7. Service level Availability: 99.5% for standard business hours (08:00 to 18:00 AEST Monday to Friday) and 98.5% for non-business hours. Latency: Return responses within three seconds for 95% of requests. Integrity: Responses are clearly distinguished as either processed successfully or in error. All responses are digitally signed. Test environment Reporting User requirements Service initiation Service support Standard costs Agencies have unlimited access to a dedicated testing environment for integration with this service. This test environment can be used for testing user organisation access, and agency service integration, independently. Monthly reports on transaction volumes, service availability and service performance. User organisations must support WS-Federation, for example by installing Microsoft Active Directory Federation Services (ADFS). When a business user attempts to login to an agency website, the agency redirects the user to this service for authentication. A business user can navigate directly to this service, and then be redirected to the service provider after authentication. Technical Service Desk. Agencies provide support to their users. This service is provided on a cost recovery basis subject to negotiation with VANguard. Agencies are responsible for their integration costs with this service. Related services User Authentication Service (UAS). Certificate Issuance Service. External Monitoring Portal. Solution Assistance and Advice. 14 Department of Industry and Science

Additional information FAS Technical Service Contract. Common Elements Technical Service Contract. VANguard Service Level Agreement (SLA). VANguard Memorandum of Understanding (MOU). VANguard website: www.vanguard.business.gov.au. VANguard Service Catalogue 15

3 Related Services Certificate Issuance Service Description Standard service features Delivery scope Delivery channels Service hours Service level Test environment Service initiation Service support Standard costs VANguard provides an agency with a digital certificate to authenticate requests for VANguard services. The agency certificates can also be used to facilitate other government to government communication. Issuance of an agency digital certificate is based on a 100 point evidence of identity (EOI) check for two required custodians. VANguard will manage the following aspects of an agency digital certificate issued to the agency: Notification of pending expiration. Revocation on request. Reissue on expiration or revocation. Government agencies (federal, state and local). Production is onsite at an agency to conduct the EOI checks and to assist the agency in the generation of certificates. Standard business hours (08:00 to 18:00 AEST Monday to Friday). Standard business hours (08:00 to 18:00 AEST Monday to Friday). Test credentials required to access the third party test environment can be requested by any agency that has signed a Memorandum of Understanding (MOU). Email request. Technical Service Desk. Agencies provide support to their users. This service incurs no charge. Related services Technical Service Desk. Solution Assistance and Advice. Additional information VANguard Service Level Agreement (SLA). VANguard Memorandum of Understanding (MOU). 16 Department of Industry and Science

Technical Service Desk Description Standard service features Delivery scope Delivery channels Service hours Service level User requirements The Technical Service Desk operates 24/7 to support email and phone requests. This is the first point of contact for issues or queries relating to VANguard government authentication services, along with 2nd and 3rd level support to address escalated requests. Provide resolution of incident or service requests for all VANguard services including: Information on service interruptions and changes. Email contact for incident or service request logging. Logging, prioritising and communicating request statuses as per SLAs. The service will be provided to agencies that have a signed SLA with VANguard. Email, telephone. Standard business hours (08:00 to 18:00 AEST Monday to Friday). Outside of these hours the agency will be directed to a Department of Industry on-call staff member. Phones: Answered within two minutes during full support hours 95% - minimum. Answered within 15 minutes between on-call hours 95% - minimum. Email/Form: Specific issue acknowledgment within 15 minutes during full support hours 95% - minimum. Users must provide a clear and specific description of the problem or request, including any error messages received. Service initiation Email: servicedesk@industry.gov.au Phone: 1800 000 384 or (02) 6213 7007. Service support Standard costs Feedback on performance can be provided to the Technical Service Desk. This service incurs no charge. Related services External Monitoring Portal. Solution Assistance and Advice. Additional information Process diagram VANguard Service Level Agreement (SLA). VANguard Memorandum of Understanding (MOU). N/A. VANguard Service Catalogue 17

External Monitoring Portal Description Standard service features Delivery scope Delivery channels VANguard provides a public portal that indicates the availability status of the suite of VANguard services in near real-time. Indicates VANguard service availability. Government agencies (federal, state and local). Internet (browser-based), XML download. Service hours 24 x 7. Service level Service initiation Service support Standard costs VANguard does not guarantee the availability of the External Monitoring Portal. URL. Technical Service Desk. Agencies provide support to their users. This service incurs no charge. Agencies are responsible for their integration costs with this service. Related services Solution Assistance and Advice. Additional information VANguard Service Level Agreement (SLA). VANguard Memorandum of Understanding (MOU). 18 Department of Industry and Science

Solution Assistance and Advice Description Delivery scope Delivery channels Service hours Service initiation Provide technical and business advice, tools, best-practice PKI standards and other resources to assist agencies to enable whole of government authentication services and adopt best practice. Government agencies (federal, state and local). Telephone, email. Standard business hours (08:00 to 18:00 AEST Monday to Friday). Contact: VANguard Customer Department of Industry and Science Physical Address: Industry House 10 Binara Street Canberra City ACT 2601 Postal Address: GPO Box 9839 Canberra ACT 2601 Email: vanguard.customer@industry.gov.au Standard costs This service incurs no charge. VANguard Service Catalogue 19

Department of Industry and Science

VANguard Service Catalogue

22 Department of Industry and Science > vanguard.business.gov.au