Integrate 'Oracle Forms', 'Oracle Reports', 'Oracle



Similar documents
ESMA REGISTERS OJ/26/06/2012-PROC/2012/004. Questions/ Answers

DIGIPASS Authentication for Citrix Access Gateway VPN Connections

Centralized Oracle Database Authentication and Authorization in a Directory

SOFTWARE DEFINED SOLUTIONS JEUDI 19 NOVEMBRE Nicolas EHRMAN Sr Presales SDS

OracleAS Identity Management Solving Real World Problems

DIGIPASS Authentication for GajShield GS Series

SchoolBooking SSO Integration Guide

RAPPORT FINANCIER ANNUEL PORTANT SUR LES COMPTES 2014

Single Sign-On Access Management A Technical Framework on Access Management Systems

USER MANUAL KNOWLEDGE CENTER - PORTAL

Accessing the Media General SSL VPN

Remote Authentication and Single Sign-on Support in Tk20

Il est repris ci-dessous sans aucune complétude - quelques éléments de cet article, dont il est fait des citations (texte entre guillemets).

Kerberos and Windows SSO Guide Jahia EE v6.1

Desktop Configurations For General Ledger and Financial Reports. User Guide

Configuring Single Sign-on for WebVPN

VERALAB LDAP Configuration Guide

Magento Extension Point of Sales User Manual Version 1.0

SSO Plugin. HP Service Request Catalog. J System Solutions. Version 3.6

The Weakest Link : Securing large, complex, global Oracle ebusiness Suite solutions

Configuring Sponsor Authentication

2.3 - Installing the moveon management module - SQL version

Migrating a Discoverer System to Oracle Business Intelligence Enterprise Edition

Security Assertion Markup Language (SAML) Site Manager Setup

Authentication and Single Sign On

JANVIER 2013 / CATALOGUE DES FORMATIONS

Securing SAS Web Applications with SiteMinder

Lytecube Technologies. EnCircle Automation. User Guide

Administrer les solutions Citrix XenApp et XenDesktop 7.6 CXD-203

Upgrade of Business Systems Data Warehouse Reporting

LinShare project version 0.8 File sharing and vault application

BusinessObjects Enterprise InfoView User's Guide

Configuring User Identification via Active Directory

Using Internet or Windows Explorer to Upload Your Site

Identity Hub Service Desk Handbook. Document Ref: NSWG/MS/SG/v1.0 December, Version 1.0

WirelessOffice Administrator LDAP/Active Directory Support

The following information is provided by ARX, Inc. to aid customers in their evaluation of CoSign for SharePoint (C4SP).

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

ADMINISTERING ADOBE LIVECYCLE MOSAIC 9.5

Adobe Connect LMS Integration for Blackboard Learn 9

enterprise^ IBM WebSphere Application Server v7.0 Security "publishing Secure your WebSphere applications with Java EE and JAAS security standards

Deploying Oracle Business Intelligence Publisher in J2EE Application Servers Release

Manage Oracle Database Users and Roles Centrally in Active Directory or Sun Directory. Overview August 2008

Stockage distribué sous Linux

SAP NetWeaver AS Java

Crystal Reports Installation Guide

OnDemand. Getting Started Guide

Guide for Setting Up Your Multi-Factor Authentication Account and Using Multi-Factor Authentication

Active Directory Requirements and Setup

Entrust Managed Services PKI Administrator s Quick Start Guide

Avatier Identity Management Suite

InfoView User s Guide. BusinessObjects Enterprise XI Release 2

NuFirewall. Open-source authenticating firewall

Online Timesheets Guide for Contractors

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

An Oracle White Paper October Frequently Asked Questions for Oracle Forms 11g

Installation Guide. Tech Excel January 2009

Session Code*: 0310 Demystifying Authentication and SSO Options in Business Intelligence. Greg Wcislo

Using Microsoft Active Directory for Checkpoint NG AI SecureClient

Integrating OID/SSO with E- Business Suite and Third-Party SSO Solutions. Presented by Paul Jackson (Norman Leach)

Contents About the Contract Management Post Installation Administrator's Guide... 5 Viewing and Modifying Contract Management Settings...

Introduction. Connection security

Luminis to Banner Single Sign-On

Migrating helpdesk to a new server

Alcatel-Lucent Extended Communication Server Active directory synchronization : installation and administration

HELP DOCUMENTATION E-SSOM INSTALLATION GUIDE

Integrating Webalo with LDAP or Active Directory

1. How to Register Forgot Password Login to MailTrack Webmail Accessing MailTrack message Centre... 6

HP Client Automation Standard Fast Track guide

360 Online authentication

Authentication in Apache Lenya

Release Bulletin Sybase ETL Small Business Edition 4.2

Sage 300 ERP Installation and Administration Guide

AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle

Quel pilote ètes-vous

September 9 11, 2013 Anaheim, California 507 Demystifying Authentication and SSO Options in Business Intelligence

White Paper Cybercom & Axiomatics Joint Identity & Access Management (R)evolution

Ameritas Single Sign-On (SSO) and Enterprise SAML Standard. Architectural Implementation, Patterns and Usage Guidelines

INUVIKA OVD SUPPORT SUPPORT SYSTEM GUIDE. Mathieu Schires Version 1.1 Published 28/04/2015

Active Directory LDAP

Aradial Installation Guide

How to configure your Windows PC post migrating to Microsoft Office 365

Crystal Reports Server Quick Installation Guide

Quick Start Guide to Logging in to Online Banking

Configuring the Cisco ISA500 for Active Directory/LDAP and RADIUS Authentication

Using CertAgent to Obtain Domain Controller and Smart Card Logon Certificates for Active Directory Authentication

SAP BusinessObjects Business Intelligence Platform Document Version: 4.1 Support Package Business Intelligence Launch Pad User Guide

Purpose... 1 Overview... 1 Installation... 2 Configuration... 2 Using the Adapter... 3 Tips and Troubleshooting... 4 Known Issues... 4 Notes...

Long User ID and Password Support In JD Edwards EnterpriseOne

SecureAware on IIS8 on Windows Server 2008/- 12 R2-64bit

External Authentication with Checkpoint R75.40 Authenticating Users Using SecurAccess Server by SecurEnvoy

OBIEE 11g Security it s as easy as 1-2-3!

Fax User Guide 07/31/2014 USER GUIDE

BarTender Print Portal. Web-based Software for Printing BarTender Documents WHITE PAPER

DIGIPASS Authentication for Sonicwall Aventail SSL VPN

Transcription:

Integrate 'Oracle Forms', 'Oracle Reports', 'Oracle Discoverer' with Oracle Single Sign On', 'Oracle Internet Directory' and 'Virtual Private Database' for the Luxembourg communities. How to make sure that a user can only use the products he is allowed to use and see only the data he is allowed to see using 1 username/password login.

Integrating it all at sigi Agenda Introduction VDS Computing Sigi Project Constraints Solution ORACLE-VDS Application structure overview Issues not covered with standard Oracle Example of a logon procedure Advantages of this solution

VDS Computing: History Since 1982 7 55 employees Turnover from 1.5 6.0 million Euro International Focus VDS- Computing Luxembourg sàrl VDS- Computing UK Ltd. ISO 9001 certified

VDS Computing: Services Consulting Analysis Development Project Management Installation Training Support Outsourcing

VDS Computing: Products Software Financial and logistics Software on Oracle : Piton Business Intelligence Turn-key Development on Oracle Hardware Design Implementation Management

Presentation of SIGI

Project Constraints Centralised IT Infrastructure Secure network between Cities and the Datacenter Secure Data(Base) (account- and budget info) Intuitive and Open Applications Rich User Interface Cutting Edge Technology

Solution ORACLE-VDS Database ORACLE 9i Enterprise Edition (EE) Virtual Private Database Advanced Security Option (Enterprise Users) Application Server ORACLE 10g EE Single Sign On Oracle Internet Directory (LDAP) Thin Client: MS Internet Explorer Forms, Reports and Discoverer Services Oracle Portal XML-Interface RAD Development Tools Designer, Forms et Reports

Application Architecture Application Server IAS Database Data Filters by VPD Scheme: Read Scheme Upd. LDAP Directory Forms Reports Data PORTAL GESCOM Other Applications Discoverer Business Logic Authentification Read Access ASO

Application Architecture Oracle Portal Intra- or Internet website builder/publisher. No programming skills needed. Oracle Forms Build and run OLAP-applications Moved from character based via client/server Now 3-tier architecture

Application Architecture Oracle Reports Reporting tool. Run using a report server (with possibility to run in batch) Possibility to e-mail the result or retrieve it from a repository via the web. Oracle Discoverer Business Intelligence tool Design without DB-knowledge Design without extra programs using a java applet.

Application Architecture SSO : Single Sign On Authenticate once, then authenticate automatically for different products. OID : Oracle Internet Directory A standard (LDAP) way to hold security data. Virtual Private Database Limit user acces on record level. Allow a user only to see what he is allowed to see without extra programming.

Security issues NOT solved with standard Oracle Forms / reports menu Definition who can use which forms is maintained inside the application Definition who can run which report is maintained inside the application

Example of a Logon Procedure User : Marcel DUPONT of the city SEPTFONTAINES Log into portal Login : mdupont.septfontaines Password SSO : abcdefgh1 Result: User gets the portal pages he is allowed to see

Example of a Logon Procedure User clicks on the URL to start the forms application. Based on the SSO info, forms checks if the user is allowed to start the application The resource information is retrieved from the OID Resource information : Database logon information for forms.

Example of a Logon Procedure Resource: Login : mdupont.septfontaines Password : ##### (secret) Database : REC1 Forms application starts and logs onto the DB In the database mdupont.septfontaines is unkown as a schema user : ASO is activated.

Example of a Logon Procedure Advanced Security Option : The database asks the OID if the user mdupont.septfontaines is allowed to log into the DB with the password ##### The OID replies ok and map this user to the schema recdev The user is connected to the DB.

Example of a Logon Procedure The logon in the DB fires a logon trigger Using the ASO info (mdupont) the OID is interrogated to find his community (septfontaines). The context is set to activate the VPD. Virtual Private Database For Each select/insert/update/delete statement an additional where community= septfontaines is added

Example of a Logon Procedure The forms application is started User sees only info he is allowed to see User can start reports (also using ASO and VPD because the same logon-info is used) User can see the reports he has run with the results The user can only see his reports (Reports server is also SSO enabled.) The user can start a discoverer report

Example of a Logon Procedure Discoverer AS10G Rel2. Is started User logs into the database as the discoverer user SSO information is available during the DB logon Using the SSO info (mdupont) the OID is interrogated to find his community (septfontaines). The context is set to activate the VPD. The user can only interrogate info from his community.

Advantages of this solution Central standard security maintenance. Security is independent from development (developer doesn t have to think about security) Application security is maintained in the OID, not in Forms/reports. Data security is maintained in the DB using VPD Data security setup is done automatically

Advantages of this solution Integration with other front-ends with guaranteed security. MS office integration possible : ODBC connection to get info from the DB (with VPD active).net integration possible MS Active Directory integration possible

Le progiciel de GEStion COMmunale du Luxembourg

Historique du projet Situation de départ : 100 sites délocalisés Développement de GESCOM autour de la plate-forme propriétaire HP3000 Novembre 2001 : annonce par HP de l arrêt du HP3000 programmé au 31 décembre 2006 Nouveau projet GESCOM : 2002 : pilotes architecture et développement 2003 et 2004 : réécriture 2005 : finalisation et début de la migration

Organisation de GESCOM Une architecture applicative sécurisée Gestion des utilisateurs au travers un LDAP Sécurité d accès aux données confiée à la DB Applications avec un point d entrée unique Portail applicatif avec SSO Des solutions de Reporting performantes Déploiement facilité (Browser, Acrobat Reader)

Bilans Bilan technique Démarches imposées par les SSO et VPD Bénéfices immédiats grâce aux SSO et VPD Bilan utilisateurs SSO avec Modules intégrés Sécurité rassurante et transparente Bilan financier Charge importante pour la mise au point de l architecture Largement récupéré lors du développement et de la maintenance

Questions - Réponses