Highmark Unifies Identity Data With Oracle Virtual Directory. An Oracle White Paper January 2009

Similar documents
Manage Oracle Database Users and Roles Centrally in Active Directory or Sun Directory. Overview August 2008

An Oracle White Paper March Integrating Microsoft SharePoint Server With Oracle Virtual Directory

An Oracle White Paper July Introducing the Oracle Home User in Oracle Database 12c for Microsoft Windows

Oracle Identity Management: Integration with Windows. An Oracle White Paper December. 2004

Oracle BI Publisher Enterprise Cluster Deployment. An Oracle White Paper August 2007

An Oracle White Paper September Directory Services Integration with Database Enterprise User Security

Oracle Directory Services Integration with Database Enterprise User Security O R A C L E W H I T E P A P E R F E B R U A R Y

Achieving Sarbanes-Oxley Compliance with Oracle Identity Management. An Oracle White Paper September 2005

Long User ID and Password Support In JD Edwards EnterpriseOne

Oracle Identity Management Concepts and Architecture. An Oracle White Paper December 2003

Integrating Tutor and UPK Content: A Complete User Documentation Solution. An Oracle White Paper April 2008

Managed Storage Services

Monitoring and Diagnosing Production Applications Using Oracle Application Diagnostics for Java. An Oracle White Paper December 2007

An Oracle White Paper July Oracle Desktop Virtualization Simplified Client Access for Oracle Applications

An Oracle White Paper Released Sept 2008

Technical Upgrade Considerations for JD Edwards World Customers. An Oracle White Paper February 2013

Oracle Role Manager. An Oracle White Paper Updated June 2009

Oracle Business Intelligence Enterprise Edition Plus and Microsoft Office SharePoint Server. An Oracle White Paper October 2008

The Case for a Stand-alone Rating Engine for Insurance. An Oracle Brief April 2009

An Oracle White Paper May Distributed Development Using Oracle Secure Global Desktop

One View Report Samples Financials

Oracle On Demand Infrastructure: Virtualization with Oracle VM. An Oracle White Paper November 2007

Oracle Hyperion Financial Management Virtualization Whitepaper

An Oracle White Paper March Oracle s Single Server Solution for VDI

An Oracle Communications White Paper December Serialized Asset Lifecycle Management and Property Accountability

An Oracle White Paper February Oracle Data Integrator 12c Architecture Overview

Oracle VM Manager Template. An Oracle White Paper February 2009

An Oracle White Paper March Managing Metadata with Oracle Data Integrator

10 Questions to Ask Your On-Demand Contact Center Provider. An Oracle White Paper September 2006

Ensuring Web Service Quality for Service-Oriented Architectures. An Oracle White Paper June 2008

One View Report Samples Warehouse Management

Oracle Primavera Gateway

An Oracle White Paper Released October 2008

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

Mobile-First Strategy. CIO Executive Interview

An Oracle White Paper February Integration with Oracle Fusion Financials Cloud Service

An Oracle White Paper October Frequently Asked Questions for Oracle Forms 11g

Oracle Data Integrator and Oracle Warehouse Builder Statement of Direction

An Oracle White Paper June Integration Technologies for Primavera Solutions

Oracle Real-Time Scheduler Benchmark

Maximum Availability Architecture. Oracle Best Practices For High Availability. Backup and Recovery Scenarios for Oracle WebLogic Server: 10.

Next Generation Siebel Monitoring: A Real World Customer Experience. An Oracle White Paper June 2010

An Oracle White Paper February Real-time Data Warehousing with ODI-EE Changed Data Capture

PeopleSoft Enterprise Directory Interface

An Oracle White Paper June Oracle Database Firewall 5.0 Sizing Best Practices

Oracle Access Manager. An Oracle White Paper

Virtual Compute Appliance Frequently Asked Questions

Express Implementation for Electric Utilities

Driving Down the High Cost of Storage. Pillar Axiom 600

An Oracle Technical Article November Certification with Oracle Linux 6

Top Ten Reasons for Deploying Oracle Virtual Networking in Your Data Center

Lowering E-Discovery Costs Through Enterprise Records and Retention Management. An Oracle White Paper March 2007

An Oracle White Paper Dec Oracle Access Management Security Token Service

Oracle Net Services for Oracle10g. An Oracle White Paper May 2005

Implementing a Custom Search Interface with SES - a case study with search.oracle.com. An Oracle White Paper June 2006

ORACLE DRIVER MANAGEMENT INTEGRATION PACK FOR ORACLE TRANSPORTATION MANAGEMENT AND ORACLE E-BUSINESS SUITE

June, 2015 Oracle s Siebel CRM Statement of Direction Client Platform Support

An Oracle White Paper February Centralized vs. Distributed SIP Trunking: Making an Informed Decision

An Oracle White Paper November Oracle Real Application Clusters One Node: The Always On Single-Instance Database

How To Manage It Asset Management On Peoplesoft.Com

Deliver Oracle BI Publisher documents to Microsoft Office SharePoint Server An Oracle White Paper July 2008

Configuring Oracle SDN Virtual Network Services on Netra Modular System ORACLE WHITE PAPER SEPTEMBER 2015

The Next Generation of Local Government: Transforming Non-Emergency and 311 Call Center Solutions to a Complete Constituent Experience

An Oracle White Paper May Oracle Audit Vault and Database Firewall 12.1 Sizing Best Practices

Digital Asset Management. An Oracle White Paper Updated April 2007

Oracle SQL Developer Migration

Oracle Insurance General Agent Hardware and Software Requirements. Version 8.0

An Oracle Technical Article March Certification with Oracle Linux 7

Oracle Identity Management for SAP in Heterogeneous IT Environments. An Oracle White Paper January 2007

Running Oracle s PeopleSoft Human Capital Management on Oracle SuperCluster T5-8 O R A C L E W H I T E P A P E R L A S T U P D A T E D J U N E

March Oracle Business Intelligence Discoverer Statement of Direction

Rapid Bottleneck Identification A Better Way to do Load Testing. An Oracle White Paper June 2009

Oracle SQL Developer Migration. An Oracle White Paper September 2008

An Oracle White Paper August Oracle OpenSSO Fedlet

How To Manage Content Management With A Single System

Migration Best Practices for OpenSSO 8 and SAM 7.1 deployments O R A C L E W H I T E P A P E R M A R C H 2015

An Oracle Technical Article October Certification with Oracle Linux 5

INFORMATION CONNECTED

ORACLE PROJECT MANAGEMENT

Load Balancing Oracle Web Applications. An Oracle White Paper November 2004

MANAGING A SMOOTH MARKETING AUTOMATION SOFTWARE IMPLEMENTATION

ORACLE VM MANAGEMENT PACK

An Oracle White Paper August Higher Security, Greater Access with Oracle Desktop Virtualization

Managing the Product Value Chain for the Industrial Manufacturing Industry

Business Intelligence and Service Oriented Architectures. An Oracle White Paper May 2007

Siebel CRM On Demand Single Sign-On. An Oracle White Paper December 2006

Oracle Business Intelligence ADF Custom Visualizations and Integration. An Oracle White Paper November 2012

Oracle s BigMachines Solutions. Cloud-Based Configuration, Pricing, and Quoting Solutions for Enterprises and Fast-Growing Midsize Companies

A Comprehensive Solution for API Management

Minutes on Modern Finance Midsize Edition

An Oracle White Paper July Accelerating Database Infrastructure Using Oracle Real Application Clusters 11g R2 and QLogic FabricCache Adapters

Oracle Easy Connect Naming. An Oracle White Paper October 2007

An Oracle White Paper December Advanced Network Compression

An Oracle White Paper September Advanced Java Diagnostics and Monitoring Without Performance Overhead

Get More from Microsoft SharePoint with Oracle Fusion Middleware. An Oracle White Paper January 2008

Transcription:

Highmark Unifies Identity Data With Oracle Virtual Directory An Oracle White Paper January 2009

Highmark Unifies Identity Data With Oracle Virtual Directory Executive Summary... 3 The Challenge: A Single Directory Service... 4 Directory Servers to Directory Service... 4 Deployment Overview... 5 Deployment Scale... 5 Hardware... 5 High Availability... 5 Architecture Diagram... 6 Identity Data Access Configuration... 7 Unifying Identity Data... 7 Removing Duplicate Identities with UniqueEntry Plug-in... 7 In The Future: Providing a Single Profile with Join Adapter... 8 Implementation Process... 8 Benefits and Return On Investment... 8 Technical Benefits... 8 Return On Investment... 9 Conclusion... 9 Highmark Unifies Identity Data With Oracle Virtual Directory Page 2

Highmark Unifies Identity Data with Oracle Virtual Directory EXECUTIVE SUMMARY Oracle Virtual Directory (OVD) has enabled Highmark to reduce the time it took to deploy its new access management solution and portal applications. It also enabled Highmark to clean up its identity data without needing to change the existing source systems. Highmark Inc. is an insurance company based in Harrisburg, Pennsylvania. They provide services to over 2 million customers including many Web-based applications. As part of deploying new Web-based applications they adopted a new access management solution (Oracle Access Manager) and the Web applications were deployed upon a new Web-application infrastructure (IBM Websphere application server and portal). One of the challenges of deploying OAM and Websphere was that identity information was split between two RedHat Directory servers. One RedHat server contained employee attributes and the other contained non-employee credentials for customers and vendors. However, WebSphere and OAM, like other commercial off the shelf (COTS) applications, can only support one user directory. There are also future plans to make use of attributes that exist within a Microsoft Active Directory containing employee information. Highmark wanted a solution that would allow them to access all of the identity information in these directories as a single source without consolidating the identities into a single directory. Highmark deployed OVD to provide a single unified interface to all of the directories to avoid consolidation. It allowed them to quickly go into production by providing a unified view of data from both of their Red Hat directories. It also has the flexibility to add in the Active Directory data in the future when they deploy applications that need to make use of data stored in AD without needing to change any of the other existing applications. OVD also eliminated duplicate user identities without requiring any data changes in the back-end servers. Highmark Unifies Identity Data With Oracle Virtual Directory Page 3

. OVD has enabled Highmark to deploy their access management solution to over 100 applications servicing 2 million user accounts in a short time, provided a quick and high return on investment (ROI). THE CHALLENGE: A SINGLE DIRECTORY SERVICE There were three primary challenges facing Highmark: Accounts in multiple directories (including internal and extranet directory) Select number of duplicate accounts between internal and extranet directory Applications required a single directory service access point The identity information is stored in the following repositories: RedHat Directory (current production) Microsoft Active Directory (planned for future) There are two RedHat Directories. One RedHat Directory is for staff accounts that contain attributes that are used for applications but not stored in AD. The second directory (Extranet Directory that contains over 2 million user accounts) primarily contains customer accounts but does contain a few staff accounts. The staff accounts cannot be removed because there are still legacy applications that connect only to this data. Active Directory is used for Windows logins but is not yet used with OVD because they do not yet have applications that need the data in Active Directory. Directory Servers to Directory Service Highmark needed to simplify their application deployment configuration by providing a single point of contact for all of their identities. However, consolidating all of the data into a single super-directory would be too costly and time consuming. Due to continued support requirements for legacy applications, they could not remove existing directories, and adding another superdirectory for consolidation would add more infrastructure and more data synchronization to maintain and support. More importantly, Highmark had existing processes for provisioning accounts into these various systems that were certified for required regulations. If they were to consolidate and synchronize data, besides all of the technical challenges, the regulatory/security rules would have to be re-implemented & certified. Further complicating the situation was the fact that some users had legitimate accounts in all 3 directories and for various reasons the triple-duplicated accounts could not be removed. Highmark Unifies Identity Data With Oracle Virtual Directory Page 4

After evaluating OVD, the Highmark IT staff was convinced that OVD provided an easy to use, flexible solution that could be quickly implemented without the need for any new synchronization requirements. Highmark chose Oracle to solve these problems because OVD: Allowed them to unify identities without needing to copy data into a new repository Leveraged all of their existing data repositories and certified processes Provided the ability to join data and remove duplicate accounts without modifying the source data Could be used by new applications such as access management as well as the 100+ legacy LDAP enabled applications DEPLOYMENT OVERVIEW Deployment Scale Supports over 2 million accounts Over 100 applications including IBM WebSphere and OAM Hardware Production: 4 x 2 x86 CPU running Linux with hardware load-balancer Sandbox: 2 x 2 x86 CPU running Linux Test: 2 x 2 x86 CPU running Linux High Availability The production systems are configured to be highly available by having duplicate configuration and using a hardware load-balancer to balance load as well redirect traffic if an OVD server were unavailable for any reason. Additionally, OVD LDAP adapters are configured to point to redundant LDAP servers. This includes the ability to send requests to sources located in the primary data-center, but will fail-over to remote facility automatically if LDAP servers in primary facility are unavailable. Highmark Unifies Identity Data With Oracle Virtual Directory Page 5

Architecture Diagram The following is the high-level architecture diagram showing Highmark s OVD current deployment. The following diagram shows Highmark s planned future deployment Highmark Unifies Identity Data With Oracle Virtual Directory Page 6

Identity Data Access Configuration Unifying Identity Data As explained in the earlier sections, there are 2 LDAP sources for identity used today with a 3 rd planned for the future. Highmark configured OVD in the following configuration: Local Store Adapter to hold a root entry (e.g. dc=highmark,dc=com) this entry is static and is used as the search-base by applications. There are two visible adapters to applications one for staff and one for external. Both appear as virtual branches (e.g. ou=staff,dc=highmark,dc=com and ou=external,dc=highmark,dc=com). This way the data can be searched in parallel by any search that specifies a scope of subtree and a search base of dc=highmark,dc=com which is how most applications search an LDAP server. By configuring OVD this way applications are able to see data in all of the directories as a single source. Removing Duplicate Identities with UniqueEntry Plug-in The Staff and Extranet directories have overlapped user data for a subset of staff. OVD supports using a Join adapter to link identity data when it is split, however, in this case, Highmark only wanted to expose the entries in the Staff directory, not any data for the staff member contained in the Extranet. Thus Highmark used the UniqueEntry plug-in, which removes entries based on duplicate attribute values. At Highmark the value they chose was uid. Highmark Unifies Identity Data With Oracle Virtual Directory Page 7

Highmark configured OVD so that whenever one of their applications searched OVD and returned multiple entries if there were any entries had the same uid value as a previous entry, that entry was not returned to the client application. This way Highmark was able to avoid having to change back-end data-stores, which was crucial because there were still applications that depended upon that data. In The Future: Providing a Single Profile with Join Adapter Within Highmark, staff entries can have split-profiles. A split-profile is where identity attributes are split between two or more sources. In Highmark s case they need to reconcile user data in the Active Directory and a RedHat directory. OVD provides the Join adapter, which allows the identity attributes to be unified on the fly using a join rule. There are several pre-defined Join rules and Highmark used the pre-defined SimpleJoinRule. The SimpleJoinRule allows entries between the primary and secondary source to be linked together when the value between listed attributes are the same. For example, if the mail attribute in the secondary is the same as uid in the primary then the join rule would be mail=uid. Or it can be the same attribute like this uid=uid. The benefit of the Join adapter is that when an application retrieves a staff entry, the application sees all of the attributes (assuming it has proper rights to the data) regardless which source they came from. Implementation Process The implementation of OVD was completed by Highmark. They did not hire anyone for third-party assistance. BENEFITS AND RETURN ON INVESTMENT There were several benefits and a significant return on investment for choosing OVD over a meta-directory approach. Technical Benefits Shorter deployment time OVD was up and running in a month. Eliminated duplicate accounts in real-time without changing data at sources. Increased flexibility through decoupling applications from target data sources and through data abstraction and transformation. Highmark Unifies Identity Data With Oracle Virtual Directory Page 8

Return On Investment OVD delivered high and quick ROI as a result of short OVD deployment time, accelerated application deployments, and re-use of existing data-stores. For example, a meta-directory approach would have cost much more. Besides the obvious software costs more hardware would have been needed for storage, backups and monitoring of the synchronization. Additionally, the data would need to be cleaned and normalized before synchronization. This process would have taken at least 18 months to deploy. In comparison, OVD was installed and ready within 1 month. This is because OVD did not require additional storage or data backups. Avoiding additional data storage and backups also provided additional cost savings. Quick OVD deployment also accelerated application deployments including Websphere, OAM, etc. CONCLUSION Highmark is an insurance company that faced a directory services challenge. They had multiple directories but applications required a single directory service. Additionally, they needed to link attributes from two of the directories to create individual virtual entries, while remove duplicate entries without changing the original data sources. OVD provided the solution. It allowed them to unify their identity data without needing to consolidate and it allowed them to clean their data without changing original data source. OVD accelerated Highmark application deployment, eliminated additional regulatory certification requirements, and thus provided quick and high ROI. For more information about Oracle Virtual Directory please see http://www.oracle.com/identity. Highmark Unifies Identity Data With Oracle Virtual Directory Page 9

Oracle Virtual Directory Case Study: Highmark, Inc. January 2009 Author: Mark Wilcox Oracle Corporation World Headquarters 500 Oracle Parkway Redwood Shores, CA 94065 U.S.A. Worldwide Inquiries: Phone: +1.650.506.7000 Fax: +1.650.506.7200 oracle.com Copyright 2005, Oracle. All rights reserved. This document is provided for information purposes only and the contents hereof are subject to change without notice. This document is not warranted to be error-free, nor subject to any other warranties or conditions, whether expressed orally or implied in law, including implied warranties and conditions of merchantability or fitness for a particular purpose. We specifically disclaim any liability with respect to this document and no contractual obligations are formed either directly or indirectly by this document. This document may not be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, without our prior written permission. Oracle, JD Edwards, PeopleSoft, and Retek are registered trademarks of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners.