Novell Access Manager



Similar documents
SSL VPN Server Guide. Access Manager 3.2 SP2. June 2013

SSL VPN Server Guide Access Manager 3.1 SP5 January 2013

Access Gateway Guide Access Manager 4.0 SP1

2 Downloading Access Manager 3.1 SP4 IR1

SSL VPN Server Guide. Access Manager 4.0. November 2013

Setup Guide Access Manager 3.2 SP3

Get Cloud Ready: Secure Access to Google Apps and Other SaaS Applications

Agenda. How to configure

Novell Access Manager SSL Virtual Private Network

How To Use Netiq Access Manager (Netiq) On A Pc Or Mac Or Macbook Or Macode (For Pc Or Ipad) On Your Computer Or Ipa (For Mac) On An Ip

Perceptive Experience Single Sign-On Solutions

OpenAM. 1 open source 1 community experience distilled. Single Sign-On (SSO) tool for securing your web. applications in a fast and easy way

Zendesk SSO with Cloud Secure using MobileIron MDM Server and Okta

Setup Guide Access Manager Appliance 3.2 SP3

Identity Server Guide Access Manager 4.0

NetIQ Access Manager. Developer Kit 3.2. May 2012

How To Connect A Gemalto To A Germanto Server To A Joniper Ssl Vpn On A Pb.Net 2.Net (Net 2) On A Gmaalto.Com Web Server

nexus Hybrid Access Gateway

SAML 2.0 SSO Deployment with Okta

Configuring. Moodle. Chapter 82

TIBCO Spotfire Platform IT Brief

Novell Access Manager

HOL9449 Access Management: Secure web, mobile and cloud access

Configuring Global Protect SSL VPN with a user-defined port

Step by Step Guide to implement SMS authentication to F5 Big-IP APM (Access Policy Manager)

Single Sign On for ShareFile with NetScaler. Deployment Guide

NetIQ Identity Manager Setup Guide

Building Secure Applications. James Tedrick

Add Microsoft Azure as the Federated Authenticator in WSO2 Identity Server

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

Securing ArcGIS Server Services: First Steps

INUVIKA OPEN VIRTUAL DESKTOP ENTERPRISE

How to create a SP and a IDP which are visible across tenant space via Config files in IS

Configuring EPM System for SAML2-based Federation Services SSO

Configuration Worksheets for Oracle WebCenter Ensemble 10.3

This chapter describes how to use the Junos Pulse Secure Access Service in a SAML single sign-on deployment. It includes the following sections:

PKI for Electronic Commerce

Policy Guide Access Manager 3.1 SP5 January 2013

New Single Sign-on Options for IBM Lotus Notes & Domino IBM Corporation

Sharepoint server SSO

How to Implement Enterprise SAML SSO

F5 BIG-IP: Configuring v11 Access Policy Manager APM

NetIQ Access Manager 4.1

Installation Guide Access Manager 4.0 SP2

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

SAML Security Option White Paper

Access Management Analysis of some available solutions

Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management

DEPLOYMENT GUIDE Version 1.0. Deploying the BIG-IP Edge Gateway for Layered Security and Acceleration Services

Web Services Security: OpenSSO and Access Management for SOA. Sang Shin Java Technology Evangelist Sun Microsystems, Inc. javapassion.

Apigee Gateway Specifications

OpenSSO: Cross Domain Single Sign On

Administering Jive Mobile Apps

Protect Everything: Networks, Applications and Cloud Services

Filr 2.0 Administration Guide. April 2016

NetIQ Access Manager 3.2 integration

ADMINISTRATOR S GUIDE

Flexible Identity Federation

AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle

IMPLEMENTING SINGLE SIGN- ON USING SAML 2.0 ON JUNIPER NETWORKS MAG SERIES JUNOS PULSE GATEWAYS

SSL VPN User Guide Access Manager 3.1 SP5 January 2013

Flexible Identity Federation

How To Get A Single Sign On (Sso)

Introduction to the Mobile Access Gateway

Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

PingFederate. Salesforce Connector. Quick Connection Guide. Version 4.1

INUVIKA OPEN VIRTUAL DESKTOP FOUNDATION SERVER

SAML single sign-on configuration overview

SSL-TLS VPN 3.0 Certification Report. For: Array Networks, Inc.

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

Step by step guide to implement SMS authentication to Cisco ASA Clientless SSL VPN and Cisco VPN

Authentication Methods

API-Security Gateway Dirk Krafzig

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

The Who, What, When, Where and Why of IAM Bob Bentley

365 Services. 1.1 Configuring Access Manager Prerequisite Adding the Office 365 Metadata. docsys (en) 2 August 2012

Deploying RSA ClearTrust with the FirePass controller

BlackBerry Enterprise Service 10. Version: Configuration Guide

Egnyte Single Sign-On (SSO) Installation for OneLogin

Communication ports used by Citrix Technologies. July 2011 Version 1.5

SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

Use Enterprise SSO as the Credential Server for Protected Sites

WebNow Single Sign-On Solutions

Single Sign On. SSO & ID Management for Web and Mobile Applications

TUT5860 Troubleshooting and Optimizing NetIQ Access Manager

Secure the Web: OpenSSO

Copyright 2014 Oracle and/or its affiliates. All rights reserved.

Interwise Connect. Working with Reverse Proxy Version 7.x

BlueCoat s Guide to Authentication V1.0

Configuration Guide BES12. Version 12.1

Shibboleth Identity Provider (IdP) Sebastian Rieger

Introduction to Endpoint Security

About Me. Software Architect with ShapeBlue Specialise in. 3 rd party integrations and features in CloudStack

esoc SSA DC-I Part 1 - Single Sign-On and Access Management ICD

INTEGRATION GUIDE. DIGIPASS Authentication for Salesforce using IDENTIKEY Federation Server

Configuring Single Sign-On for Documentum Applications with RSA Access Manager Product Suite. Abstract

Transcription:

Novell Access Manager Product Overview Kiran Mova

Agenda Introduction Architecture IDP AG SSL VPN Administration Console How it works? Web SSO Federation SSO Protect HTTP Resources Protect non-http Resources 2 2011 NetIQ Corporation. All rights reserved.

Introduction Access Manager is a set of components that help to : Provide Web and Federated SSO Protect HTTP/Non-HTTP enterprise servers Provide SSO to Legacy Web Servers Also allows customers to extend : Authentication Mechanisms using Authentication SDK Authentication against Custom User stores using LDAP Server Plugin Policy Engine using Policy Extension API 3 2011 NetIQ Corporation. All rights reserved.

Sample NAM Deployment InnerWeb Access Gateway (innerweb.novell.com) VersionOne (v1.innerweb.novell.com) Employee Self Service (psselfservice.innerweb.novell.com) Identity Provider (login.innerweb.novell.com) SSLVPN (sslvpn.innerweb.novell.com) 4 2011 NetIQ Corporation. All rights reserved.

Architecture NAM 1..3 User Federated Identity Providers SAML 2.0, SAML 1.x, Liberty, WS Fed Web SSO Federated SSO Non-HTTP server Access Load Balancer(s) Identity Servers, Access Gateways, SSLVPNs 1 Identity Provider (Authenticate) 1 Access Gateway (Authorized Access) VPN SSL VPN (Authorized Access) 1 1 Audit, Alerts Configuration, Policy Administration Console J2EE Agent (Authorized Access) Web UI User Directory (LDAP) Administrator Authentication Servers (RADIUS, etc.,) Mission Critical and Enterprise Data Systems. HTTP and non-http 5 2011 NetIQ Corporation. All rights reserved.

Admin Console Key Features Administration Console Configure Components Monitor Health and Statistics of Individual Components Policy Administration Certificate Management Delegated Administration Persistent configuration store Granular Auditing (embedded NSure Audit Server) 6 2011 NetIQ Corporation. All rights reserved.

Architecture AC Federated Identity Providers NAM Administration Console edirectory Web UI (HTTPS) Administrator User Load Balancer Authenticate Identity Provider Access Gateway Nsure Audit Server Audit (TCP) Audit Cache Alerts (HTTPS) Device Manager (imanager/tomcat) JCC Configuration/ Commands (HTTPS) LDAPS Cert Configure (LDAPS) Config, Policy, Certificate Store Clustering (edirectory Replica) Configuration, Policy (LDAPS) User Directory (LDAP) Authentication Servers (RADIUS, etc.,) Mission Critical and Enterprise Data Systems. HTTP and non-http SSL VPN 7 2011 NetIQ Corporation. All rights reserved.

Identity Provider Key Features Identity Provider (IdP) Authentication (includes x509, RADIUS..) Federated Authentication (SAML/ADFS) Associate Roles and Attributes with authenticated user Capable of authenticating against multiple User ID stores like edirectory, Active Directory Sun One etc., Extensible Authentication and Policy framework SP (Service Provider) Agent Shared Component Redirects all authentication requests to IdP Maintains a cache of user data fetched from IdP Evaluates Policies by requesting additional data from IdP. 8 2011 NetIQ Corporation. All rights reserved.

Architecture - IDP Federated Identity Providers NAM Identity Provider Audit (TCP) Alerts(HTTPS) Administration Console SAML 2.0, SAML 1.x, Liberty, WS Fed (HTTPS) Load Balancer Audit Agent Authentication & Attribute Services (Tomcat) JCC RMI Configuration (HTTPS) Configuration, Policy (LDAPS) User Data (LDAP[S] ) Custom Connections Web UI Administrator User Directory (LDAP) Authenticate 2 Clustering (JGROUPS) Authentication Servers (RADIUS, etc.,) User Access Gateway SSL VPN Liberty and Attribute Service (HTTPS) Mission Critical and Enterprise Data Systems. HTTP and non-http 9 2011 NetIQ Corporation. All rights reserved.

Access Gateway Key Features Access Gateway (AG) Authentication (via Identity Server) Authorization Single sign-on to Legacy Web Servers (form-fill, identity injection) Identity injection (personalization) Secure exchange (SSLizer) Multi Homing Load Balancing URL Normalization/ Rewriting Caching Policy Extensions API 10 2011 NetIQ Corporation. All rights reserved.

Architecture - AG Federated Identity Providers User Load Balancer Authenticate SAML 2.0, SAML 1.x, Liberty, WS Fed (HTTPS) 2 NAM Identity Provider Access Gateway Clustering (JGROUPS) HTTP(S) AJP Liberty and Attribute Service (HTTPS) Audit (TCP) Session Cache SSL VPN Alerts(HTTPS) Configuration (HTTPS) Active MQ Administration Console Web UI Administrator User Directory (LDAP) Audit Agent JCC RMI Configuration, Policy (LDAPS) SP Authentication Agent Gateway Policy Extension API Servers Manager (RADIUS, etc.,) HTTP Apache Instance Config Messages HTTP(S) Mission Critical and Enterprise Data Systems. HTTP and non-http 11 2011 NetIQ Corporation. All rights reserved.

SSLVPN Key Features SSL VPN Provide Secure access to Non-HTTP Applications Enterprise mode (full access) or KIOSK mode (application access) Client Integrity Check and Policy Based Access Desktop Clean-up / Secure Folder 12 2011 NetIQ Corporation. All rights reserved.

Architecture SSLVPN (Server) Federated Identity Providers NAM Identity Provider Audit (TCP) Administration Console Alerts(HTTPS) SAML 2.0, SAML 1.x, Liberty, WS Fed (HTTPS) Access Gateway HTTP(S) Liberty and Attribute Service (HTTPS) Configuration (HTTPS) Web UI Administrator User Directory (LDAP) Load Balancer HTTP Authentication Servers (RADIUS, etc.,) 2 User Authenticate HTTP(S) SSL SSL SP Agent STunnel Open VPN Server Audit Agent Conn Mgr Socks Server JCC Configuration(LDAPS) TCP Mission Critical and Enterprise Data Systems. HTTP and non-http SSL VPN 13 2011 NetIQ Corporation. All rights reserved.

Architecture SSLVPN Client (KIOSK) NAM SSL VPN Client Stunnel Policy Engine Socks Client SSL SP Agent STunnel Open VPN Server Audit Agent Conn Mgr Socks Server JCC SSL VPN TCP Mission Critical and Enterprise Data Systems. HTTP and non-http Application User 14 2011 NetIQ Corporation. All rights reserved.

Architecture SSLVPN Client (Enterprise) NAM SSL VPN Client Open VPN Client TUN Driver SSL over TCP/UDP SP Agent STunnel Open VPN Server Audit Agent Conn Mgr Socks Server JCC SSL VPN TCP/UDP Mission Critical and Enterprise Data Systems. HTTP and non-http Application User 15 2011 NetIQ Corporation. All rights reserved.

Recent/Current Initiatives... Access Management On Demand Federation Hub Simplification Creating products out of individual components 16 2011 NetIQ Corporation. All rights reserved.

Simplification 17 2011 NetIQ Corporation. All rights reserved.

How it works?

Web SSO User Service Provider (Web Server) Identity Provider User Id Store 1 SP Agent Redirects to IdP for authentication If authenticated goto (4) If not, seek credentials 2 Post Credentials 3 Validate Credentials 4 IdP Redirects to SP Agent with Auth Token 5 Verify Token Create User Session, form a token to send to SP Agent Respond with Assertion, including user attributes/roles Provide Access 19 2011 NetIQ Corporation. All rights reserved.

Federated SSO User Identity Provider User Id Store Federated Identity Provider 1 Request for Authentication (SAML/Liberty/WSFed) If authenticated goto (8) If not, redirect to Trusted Federated Identity Provider Configuration Store 2 Send AuthRequest to Federated IdP If not authenticated seek credentials 5 IdP Receives the authentication 6 Verify Token 6 Provide AuthResponse with authentication details Map to Local user or Autoprovision the user. 7 Create user session and store persistent federation mapping 8 Respond with Auth Token 20 2011 NetIQ Corporation. All rights reserved.

Protect HTTP Resources User Access Gateway Identity Provider User Id Store Web Server(s) 1 Access v1.innerweb.novell.com If authenticated goto (7) If not, redirect to SP Agent 2 SP Agent Redirects to IdP for authentication If authenticated goto (5) If not, seek credentials 3 Post Credentials 4 Validate Credentials 5 IdP Redirects to SP Agent with Auth Token 6 Verify Token Create User Session, form a token to send to SP Agent Respond with Assertion, including user attributes/roles 7 Authorization Policy 8 Redirect to Access Resource 9 Form fill, Identity Injection, Load Balance 10 URL Rewriting, Cache 21 2011 NetIQ Corporation. All rights reserved.

Access to Non-HTTP Resources User SSL VPN Client 1 Login to SSL VPN (using IdP or AG) SSL VPN If authorized user, push the SSL VPN Client Enterprise Server(s) 2 Accept and Install Client Install Client Integrity Check Establish VPN Tunnel Client Policy Update VPN Tunnel 3 Access Enterprise Server Virtual/HookingAdapter, takes request, routes through tunnel. 4 Authorize Access, Forward 5 Logout Desktop Clean up 22 2011 NetIQ Corporation. All rights reserved.

www.novell.com/accessmanager 23 2011 NetIQ Corporation. All rights reserved.

Worldwide Headquarters 1233 West Loop South Suite 810 Houston, TX 77027 USA 1 713.548.1700 (Worldwide) 888.323.6768 (Toll-free) info@netiq.com NetIQ.com http://community.netiq.com 24 2011 NetIQ Corporation. All rights reserved.

nts in or changes to the software described in this document at any time., Group Policy Administrator, Group Policy Guardian, Group Policy Suite, IntelliPolicy, Knowledge Scripts, NetConnect, NetIQ, the NetIQ