Identity and Access Management



Similar documents
Enterprise Identity Management Reference Architecture

RSA ACCESS MANAGER. Web Access Management Solution ESSENTIALS SECURE ACCESS TO WEB APPLICATIONS WEB SINGLE SIGN-ON CONTEXTUAL AUTHORIZATION

Product overview. CA SiteMinder lets you manage and deploy secure web applications to: Increase new business opportunities

CA SiteMinder. Implementation Guide. r12.0 SP2

Access Management Analysis of some available solutions

<Insert Picture Here> Oracle Identity And Access Management

Oracle Business Intelligence Publisher. 1 Oracle Business Intelligence Publisher Certification. Certification Information 10g Release 3 (

Sun and Oracle: Joining Forces in Identity Management

Oracle Platform Security Services & Authorization Policy Manager. Vinay Shukla July 2010

<Insert Picture Here> Oracle I&AM: Service Oriented Security - a flexible Security Foundation For Next-Generation Applications

Contents. Primavera P6 Tested Configurations Release Version: Date: December 2013 Revision:

Tested configuration for Major versions of Primavera:-

This document lists the configurations that have been tested for the Oracle Primavera P6 version 7.0 release.

Oracle Fusion Middleware 11g Release 1 IDM Suite

Identity Management Overview. Bill Nelson Vice President of Professional Services

An Oracle White Paper Dec Oracle Access Management Security Token Service

Foglight. Managing Java EE Systems Supported Platforms and Servers Guide

Novell Access Manager

Enabling Single Sign-On for Oracle Applications Oracle Applications Users Group PAGE 1

Contents. BMC Atrium Core Compatibility Matrix

CA SiteMinder SSO Agents for ERP Systems

OracleAS Identity Management Solving Real World Problems

Oracle Identity Analytics Architecture. An Oracle White Paper July 2010

Secure the Web: OpenSSO

Oracle Access Manager. An Oracle White Paper

NetIQ Identity Manager Setup Guide

Approaches to Enterprise Identity Management: Best of Breed vs. Suites

Oracle E-Business Suite (R12) Integration with OID/OAM 11g

Q3FY11 Oracle OPN Specialized Security Pillar Executive Webcast

Highmark Unifies Identity Data With Oracle Virtual Directory. An Oracle White Paper January 2009

Kenneth Hee Director, Business Development Security & Identity Management. Oracle Identity Management 11g R2 Securing The New Digital Experience

DEPLOYMENT ROADMAP March 2015

IBM Rational Asset Manager

ORACLE FUSION MIDDLEWARE PROFILE

<Insert Picture Here> Oracle Policy Automation System Requirements

Oracle Identity Management Concepts and Architecture. An Oracle White Paper December 2003

Crystal Reports XI Release 2 - Service Pack 6

Adobe LiveCycle ES Update 1 System Requirements Adobe LiveCycle ES Foundation-based solution components

> Please fill your survey to be eligible for a prize draw. Only contact info is required for prize draw Survey portion is optional

Contents. BMC Remedy AR System Compatibility Matrix

Web Services Security: OpenSSO and Access Management for SOA. Sang Shin Java Technology Evangelist Sun Microsystems, Inc. javapassion.

Crystal Reports XI Release 1 for Windows

CA Adapter. Installation and Configuration Guide for Windows. r2.2.9

CA Service Desk Manager Release 12.5 Certification Matrix

ActiveVOS Server Architecture. March 2009

IBM Unica PredictiveInsight Version Publication Date: June 7, Recommended Software Environments and Minimum System Requirements

GlassFish Security. open source community experience distilled. security measures. Secure your GlassFish installation, Web applications,

The Unique Alternative to the Big Four. Identity and Access Management

Oracle Desktop Virtualization

Enterprise Content Management Strategy and Vision Roel Stalman

ManageEngine (division of ZOHO Corporation) Infrastructure Management Solution (IMS)

Oracle SOA Suite Then and Now:

White paper December Addressing single sign-on inside, outside, and between organizations

IGEL Universal Management. Installation Guide

OpenSSO: Simplify Your Single-Sign-On Needs. Sang Shin Java Technology Architect Sun Microsystems, inc. javapassion.com

Synchronization Agent Configuration Guide

TIBCO ActiveMatrix BusinessWorks Process Monitor Server. Installation

Enterprise Deployment of the EMC Documentum WDK Application

An Oracle White Paper October Frequently Asked Questions for Oracle Forms 11g

System requirements. Java SE Runtime Environment(JRE) 7 (32bit) Java SE Runtime Environment(JRE) 6 (64bit) Java SE Runtime Environment(JRE) 7 (64bit)

Communiqué 4. Standardized Global Content Management. Designed for World s Leading Enterprises. Industry Leading Products & Platform

Superior Court of Orange County 08/13/ Civic Center Drive West Santa Ana, CA 92701

System Requirements and Platform Support Guide

LiveCycle Software Compatibility Matrix

Securing SAS Web Applications with SiteMinder

Oracle Fusion Middleware

IBM Security Access Manager for Web

PingFederate. SSO Integration Overview

Oracle Privileged Account Manager 11gR2. Karsten Müller-Corbach

Oracle Reference Architecture and Oracle Cloud

Tivoli Endpoint Manager for Remote Control Version 8 Release 2. User s Guide

Mitigating Information Security Risks of Cloud Computin

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

Thales ncipher modules. Version: 1.2. Date: 22 December Copyright 2009 ncipher Corporation Ltd. All rights reserved.

IBM Enterprise Content Management Software Requirements

CA Identity Manager. Installation Guide (WebLogic) r12.5 SP8

Crystal Reports XI Release 2 for Windows Service Pack 3

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

Oracle Identity Manager (OIM) as Enterprise Security Platform - A Real World Implementation Approach for Success

Liferay Portal Performance. Benchmark Study of Liferay Portal Enterprise Edition

Oracle Identity Management for SAP in Heterogeneous IT Environments. An Oracle White Paper January 2007

IBM Tivoli Directory Integrator

Centrify Server Suite, Standard Edition

White Paper Cybercom & Axiomatics Joint Identity & Access Management (R)evolution

StreamServe Persuasion SP5 Supported platforms and software

White Paper Delivering Web Services Security: The Entrust Secure Transaction Platform

THE NEW DIGITAL EXPERIENCE

Cloud Database Demystified to Deliver SaaS Customer Value

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

Novell Access Manager

Web Development Kit Applications Language Pack Installation and Release Notes

Oracle IDM Integration with E-Business Suite & Middleware Technologies

Robert Honeyman Honeyman IT Consulting.

IBM Tivoli Monitoring for Databases

Perceptive Experience Single Sign-On Solutions

Web Applications Access Control Single Sign On

IBM Tivoli Remote Control

An Oracle White Paper February Oracle Data Integrator 12c Architecture Overview

System Requirements. SAS Regular Price Optimization 4.2. Server Tier. SAS Regular Price Optimization Long Jobs Server

This research note is restricted to the personal use of

Transcription:

<Insert Picture Here> Apresentação de solução da Oracle para autorização de usuários em aplicativos/sistemas Identity and Access Management Alexandre Freire Principal Sales Solution Security Specialist Identity and Access Management GRC Technology Oracle Latin America Strategic Accounts

<Insert Picture Here> Oracle Entitlements Server Introdução

Oracle Identity and Access Management Commitment to Leadership & Innovation Innovate Lead Id. Assurance Partner Alliance Oracle Access Management Suite Acquisition of BEA OES Acquisition of Bharosa OAAM Acquisition of Bridgestream ORM Identity Governance Framework Market Leader in Forrester s IAM Wave Oracle IdM Eco-system Oracle esso Leader in Gartner s UP & WAM Magic Quadrant Oracle Identity and Access Management Suite Identity Audit and Compliance offering Build Acquisition of OctetString OVD Acquisition of Thor OIM Acquisition of Oblix OAM, OIF & OWSM Acquisition of Phaos Federation and WS technologies Oracle Internet Directory 1999 2005 2006 2007 2008

Leader in Magic Quadrants Oracle assumes the No. 1 position - Earl Perkins, Perry Carpenter, Aug. 15 2008 (Research G00159740) User Provisioning, H2 2008 Web Access Management, H2 2008 Magic Quadrant Disclaimer: The Magic Quadrant is copyrighted by Gartner, Inc. and is reused with permission. The Magic Quadrant is a graphical representation of a marketplace at and for a specific time period. It depicts Gartner's analysis of how certain vendors measure against criteria for that marketplace, as defined by Gartner. Gartner does not endorse any vendor, product or service depicted in the Magic Quadrant, and does not advise technology users to select only those vendors placed in the "Leaders" quadrant. The Magic Quadrant is intended solely as a research tool, and is not meant to be a specific guide to action. Gartner disclaims all warranties, express or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Comentários do Gartnet sobre Entitlements Oracle WAM Market - Strengths Trends for 2008 Oracle Market now segmentation sells OAM as (access part of management integrated suites of vs. access management commodity WAM components, vs. consumer including extranets): Oracle Identity The strategic Federation, Oracle direction Entitlements for WAM tools Server is diverging and Oracle as the Adaptive market Access matures. Manager, Larger, enterprise-focused providing improved vendors authorization (IBM, CA, functionality Sun, Novell, beyond Web Oracle, applications, Evidian and as Siemens) well as fraud are detection developing capabilities. access The wide range management of access suites, management which include functions WAM, platform in the suite access puts Oracle control, on fine-grained an excellent entitlement footing with management, broad suite offerings identity from IBM federation and CA. and, often, Web services security tools, combined with unified administration and audit facilities. Smaller vendors (for example, Cafesoft and P2 Security) are focused on low-cost, low-complexity SMB offerings. A few vendors (including EMC/RSA Security and Entrust) are focused specifically on the consumer extranet. Source: http://mediaproducts.gartner.com/reprints/oracle/article48/article48.html

Market Leader According To Oracle has established itself as Leader. - The Forrester Wave: Identity And Access Management, Q1 2008 Oracle reached the top of our evaluation through a combination of the breadth, depth, interoperability, and packaging of its IAM features alongside the strategy and current state of market execution on its application-centric identity vision. - The Forrester Wave: Identity And Access Management, Q1 2008

Oracle s Identity Management Suite Identity Admin. Role Manager Identity Manager Access Management Identity Management 2.0 Adaptive Access Manager Entitlements Server Web Services Manager Core Platform Access Manager Identity Federation Enterprise Single Sign-On Directory Services Virtual Directory Internet Directory Authentication Service for OS Audit & Compliance Identity Management Suite Manageability Enterprise Manager IdM Pack

<Insert Picture Here> Oracle Entitlements Server Arquitetura Funcional

Oracle Entitlement Server O que é? É um Sistema de Controle de Privilégios que possibilta uma definição centralizada de privilégios de complexas aplicações e a execução runtime dos controles destes privilégios. Permite externalizar o controle de privilégios Separa as decisões de segurança, da lógica de negócio das aplicações; Centraliza a gestão das políticas de acesso para vários ambientes de aplicações.

Oracle Entitlement Server O que é? Modelo de Políticas suporta a hierarquica natural dos objetos de negócio, roles e direitos de acesso. Protege tanto os componetes de software (ex. URLs, EJBs, etc.) quanto os objetos de negócio (ex. Contas, registros de pacientes, etc.). Prove uma implantação flexível e de fácil integração com os sistemas de segurança e identidades existentes.

Entitlements Server Gerenciamento de direitos Presentation Tier Business Logic Tier Data Access Tier Databases Policy Decision Point Entitlements Management Policy Decision Point Policy Decision Point Policy Decision Point Repositório de políticas centralizado Aproveita e potencializa os investimentos existentes em segurança e Identity Management Enforcement da Política de Segurança da corporação Tira a responsabilidade da criação e manutenção das políticias da mão dos desenvolvedores Controle quem pode fazer, ou ver algo, quando e como.

Oracle Entitlements Server Architecture Policy Decision Point (PDP) (Standalone) Browser Policy Administration Point (PAP) Admin Server SSM ATN ATZ RM AD CM Admin Server Policies XACML 2.0 Policy Policy Decision Point (PDP/PEP) (Embedded) App Server Entitlements Server SSM ATN ATZ RM AD CM Client Plan Old Java Object (POJO).Net Client Generic SOAP Client Policy Information Point (PIP) Entitlements Entitlements LDAP Relational DB Service Data Objects Attribute Retriever API Embedded Entitlements SSM ATN ATZ RM AD CM User or application directories or database that contain information that is required to make an access decision. Entitlements Server Such information includes user, group, and resource attributes. Oracle Confidential For Internal Use Only

OES Administration Server (PAP) Web Browser OES Admin Server (J2EE) Admin UI Application Entitlements API SSM Mgmt Tools Management API ATN ATZ RM AD CM Policy Loader/Exporter Policy Store Policy Files Policy Distributor Admin Scripts To SSMs Runs on WebLogic, Tomcat, WebSphere Web-based Admin Console Policy Reporting Management Tools Management API via Java and Web Services Transactional policy distribution to SSMs Oracle Confidential For Internal Use Only

Security Service Module (PDP) Security Service Module Framework API Authentication Authorization Role Mapping Auditing Cred Mapping Identity Directories Entitlements Entitlements Secure Audit Logs External Application Integrate with LDAP, RDBMS, Custom Identity Stores Leverage multiple stores simultaneously Assert identity from SSO or custom tokens Establishes JAAS Subject Provide Grant/Deny decisions based upon policies Integrate external entitlement attribute data from LDAP, RDBMS, SDO Dynamically map users to Roles based upon policy Log messages generated by framework events Write to everything from log4j to secured filesystems Describe custom handlers for various events Translate credentials into custom formats Helps propagate identity across disparate systems Oracle Confidential For Internal Use Only

SSM Configurations Standalone Server (PDP) Entitlements Server SSM ATN ATZ RM AD CM J2EE/JVM (PDP/PEP) Embedded Entitlements SSM ATN ATZ RM AD CM Java API.Net API SOAP API XACML 2.0 Oracle DB (with VPD) SharePoint WebLogic Server, Tomcat, Websphere Plain Old Java Object (POJO) Oracle Service Bus Documentum Client/Content Server* SSMs are kept synchronized with central policy store Handle push from Admin Server Retrieve policy upon startup SSMs maintain local persistent caches of relevant policy SSMs maintain local caches of attribute and policy decisions Oracle Confidential For Internal Use Only

OES Access Policy OES Access policy is used to grant or deny privileges to resources in the application to specific users, groups, or roles Authorization Request Authorization Response Grant (view, /app/sales/revenuereport, /role/manager) if region = East ; Effect Grant Deny Delegate Action Read Write View Resources Subjects Constraint Boolean Attributes Eval Functions Maps to Application Objects Based on Identity Store(s) Read from External Data Oracle Confidential For Internal Use Only

OES Role Policy OES role policy is used to dynamically determine role membership Authorization Request Authorization Response Grant (/role/executive, /app/sales/, /sgrp/manager) if level > 5; Effect Grant Deny Delegate Roles Based on Resources Maps to Subjects Constraint Boolean Attributes Eval Functions Application Based on Read from Objects Identity Store(s) External Data Oracle Confidential For Internal Use Only

Entitlements Management Gerenciamento centralizado Gerenciamento dos Entitlements User Roles Application Resources Authorization Policies Role Membership Policies Create Separation of Duties Rules Distribute Entitlements to SSMs Administração das Identidades User Identity Directories User Attributes Auditoria Run Policy Reports Oracle Confidential For Internal Use Only

Entitlements Lifecycle Enforcement das Policies sem alterar as aplicações Operations and Compliance Staff Business Owner Developer Developer Oracle Entitlements Server Security Administrator

<Insert Picture Here> Oracle Entitlements Server Arquitetura Técnica

OAM-OAAM-OES Arquitetura OAM Admin OVD Oracle Access Server Access Manager Partners Web Server 1 (Web Gate) Oracle Internet Directory Load-balancer OAAM Server (OASA) Application Server 1 (SSM) Vendors Web Server 2 (Web Gate) Oracle XE Database Policy Store OAAM Sever (OARM) OES Admin Application Server 2 (SSM) Entitlement Server

OES Arquitetura Plataformas (PAP) Table 1 Core Components Component Platforms Operating Systems Admin Console Browser MS IE 6.0, 7.0 Windows 2000 SP4, 2003 R2, XP SP2 E-UI Browser MS IE 6.0, 7.0 Firefox 2.0.x Windows 2000 SP4, 2003 R2, XP SP2 Admin Server Platform WebLogic Server 1 9.2 MP2 WebLogic Server 10.0 MP1 WebLogic Server 10gR3 (10.3) 2 WebSphere Application Server 6.1 3 Tomcat 5.5.23 4 Sun Solaris 8, 9, 10 (32-bit) Windows 2000 SP4, 2003 R2, XP SP2, Red Hat Adv. Server 3.0, 4.0 Suse Linux 5 9.2 & 10.0 AIX 5.3 6 OES Policy Store Oracle 9.2.0.5, 10.1.2, 10.2.0.2, 11.1.0.6 Sybase 12.5.3, 15 MS-SQL 2000 & 2005 PointBase 5.1 DB2 Universal DB Enterprise Server 9.1 User Directory Oracle Identity Directory 10.1.4.2 Microsoft Active Directory 2000 & 2003 7 Microsoft ADAM SunONE Directory Server v5.2 Novell edirectory v8.7.31 Open LDAP v2.2.24 Oracle 9.2.0.5, 10.1.2, 10.2.0.2, 11g Sybase 12.5.3, 15 DB2 Enterprise Server Edition 9.1 MS-SQL 2000 & 2005

OES Arquitetura Plataformas (SSM) Table 2 Security Modules Category Platform Version(s) Windows 1 Solaris RHAS 2 Suse 3 9.2, 10.0 AIX 5.3 4 8, 9, 10 3.0, 4.0 Web Services / RMI MS.NET 1.1 & 2.0 5 WL Workshop 9.0, 10.0 Studio 3.0 Yes Yes Yes Yes No Oracle WebLogic Products WebLogic Server 6 8.1.5, 8.1.6, 9.2.2, 10.0 MP1, 10.3 7 WebLogic Portal 8.1.5, 8.1.6, 9.2.2, 10.0.1, 10.2 WebLogic Integration 9.2.2 Yes Yes Yes Yes No Other Oracle Products ODSI (formerly ALDSP) 2.5, 3.0, 3.1 8 OSB (formerly ALSB) 2.6, 3.0 9 OBPM (formerly ALBPM) 6.0 Yes Yes Yes Yes No IBM WebSphere WebSphere 6.1 Yes Yes Yes Yes Yes Java Sun JVM 1.4.2, 5.0, 6.0 JRockit 1.4.2, 5.0, 6.0 IBM JDK 1.4.2, 5.0 10 Yes Yes Yes Yes No Web Servers Apache Yes Yes Yes Yes No MS IIS 6.0 11 Other Applications Oracle Database 10g Documentum Content Server v5 Microsoft Office SharePoint Server 2007 Yes Yes Yes No Yes N/A No Yes N/A No Yes N/A No Yes N/A

High Availability - Runtime Security Module/PDP continues to provide security services even if external components it relies on (such as authentication database, for example) become unavailable. Failover for authentication sources Failover for entitlement sources (attribute retrievers) Failover for Credential Mapper sources For data replication between data sources we recommend to use vendor specific approach or use solutions like Oracle RAC Runtime independence of SM/PDP from Admin Server Application Environment Security Framework Security Service Module Authentication Providers Auditing Providers Role Providers Authorization Providers Credential Providers Source specific replication Primary Authentication Source Back-up Authentication Source Primary Entitlements Source Source specific replication Back-up Entitlements Source Oracle Confidential For Internal Use Only

High Availability Management Time New York Tokyo London Application Environment Application Environment Application Environment SSM SSM SSM Primary Admin Server Secondary Admin Server Primary OES DB RDBMS specific replication Secondary OES DB OES Administrator OES Administrator OES Administrator Oracle Confidential For Internal Use Only

High Availability Management Time New York Tokyo London Application Environment Application Environment Application Environment SSM SSM SSM Primary Admin Server Secondary Admin Server Primary ALES DB Secondary ALES DB ALES Administrator ALES Administrator ALES Administrator Oracle Confidential For Internal Use Only

D E M O N S T R A T I O N Oracle Entitlements Server Live demonstration on a Vmware environment