How To Get A Single Sign On (Sso)



Similar documents
New Single Sign-on Options for IBM Lotus Notes & Domino IBM Corporation

Web Access Management and Single Sign-On

Allidm.com. SSO Introduction. Discovering IAM Solutions. Leading the IAM facebook/allidm

User Management Tool 1.5

Single Sign-On. Security and comfort can be friend. Arnd Langguth. September, 2006

ABOUT TOOLS4EVER ABOUT DELOITTE RISK SERVICES

NCSU SSO. Case Study

Choosing an SSO Solution Ten Smart Questions

Enabling Single Sign-On for Oracle Applications Oracle Applications Users Group PAGE 1

Approaches to Enterprise Identity Management: Best of Breed vs. Suites

Agenda. How to configure

Extending Identity and Access Management

Passlogix Sign-On Platform

Leverage Active Directory with Kerberos to Eliminate HTTP Password

Single Sign-on (SSO) technologies for the Domino Web Server

USER GUIDE. Lightweight Directory Access Protocol (LDAP) Schoolwires Centricity

Getting Started with AD/LDAP SSO

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

Security solutions Executive brief. Understand the varieties and business value of single sign-on.

PingFederate. SSO Integration Overview

White paper December Addressing single sign-on inside, outside, and between organizations

managing SSO with shared credentials

Password Power 8 Plug-In for Lotus Domino Single Sign-On via Kerberos

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

Single Sign On. SSO & ID Management for Web and Mobile Applications

PingFederate. Integration Overview

Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department

Flexible Identity Federation

Administration Guide. SecureLogin 8.0. October, 2013

SAML SSO Configuration

Strategic Identity Management for Industrial Control Systems

API-Security Gateway Dirk Krafzig

Directory Integration with Okta. An Architectural Overview. Okta Inc. 301 Brannan Street San Francisco, CA

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

OVERVIEW. DIGIPASS Authentication for Office 365

Identity Management Basics. OWASP May 9, The OWASP Foundation. Derek Browne, CISSP, ISSAP

Biometric Single Sign-on using SAML

Single sign-on enabled OpenCms

Directory Integration with Okta. An Architectural Overview. Okta White paper. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

Service Desk R11.2 Upgrade Procedure - Resetting USD passwords and unlocking accounts in etrust Web Admin

Web Services Security: OpenSSO and Access Management for SOA. Sang Shin Java Technology Evangelist Sun Microsystems, Inc. javapassion.

SCAS: AN IMPROVED SINGLE SIGN-ON MODEL BASE ON CAS

Critical Issues with Lotus Notes and Domino 8.5 Password Authentication, Security and Management

BlackBerry Enterprise Server for Microsoft Office 365 preinstallation checklist

Copyright

Secure Your Enterprise with Usher Mobile Identity

SAML-Based SSO Solution

SAML:The Cross-Domain SSO Use Case

Open Source Identity Integration with OpenSSO

SINGLE & SAME SIGN-ON ASPECTS

Single Sign-On Architectures. Jan De Clercq Security Consultant HPCI Technology Leadership Group Hewlett-Packard

- Identity & Access Management

Citrix Password Manager Using the Account Self-Service Feature. Citrix Password Manager 4.6 with Service Pack 1 Citrix XenApp 5.0, Platinum Edition

OPENIAM ACCESS MANAGER. Web Access Management made Easy

Novell Access Manager

Active Directory Integration WHITEPAPER

Get Cloud Ready: Secure Access to Google Apps and Other SaaS Applications

QLIKVIEW MOBILE SECURITY

Vyom SSO-Edge: Single Sign-On for BMC Remedy

Ensuring Enterprise Data Security with Secure Mobile File Sharing.

CA SiteMinder. Implementation Guide. r12.0 SP2

Enterprise SSO Manager (E-SSO-M)

Server-based Password Synchronization: Managing Multiple Passwords

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

OpenSSO: Cross Domain Single Sign On

OpenAM. 1 open source 1 community experience distilled. Single Sign-On (SSO) tool for securing your web. applications in a fast and easy way

Ensure that your environment meets the requirements. Provision the OpenAM server in Active Directory, then generate keytab files.

SECUREAUTH IDP AND OFFICE 365

Biometric SSO Authentication Using Java Enterprise System

Windows Server 2008/2012 Server Hardening

The Role of Federation in Identity Management

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

EXECUTIVE VIEW. SecureAuth IdP. KuppingerCole Report

Linux Single Sign-on: Maximum Security, Minimum Cost

Leveraging SAML for Federated Single Sign-on:

Integrating IBM Cognos 8 BI with 3rd Party Auhtentication Proxies

Advanced Authentication

PortWise 4.7. PortWise Sales FAQ. Sales FAQ & Licensing Guide

Deploying RSA ClearTrust with the FirePass controller

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

Installation Guide SecureLogin 8.1

Enterprise Single Sign-On City Hospital Cures Password Pain. Stephen Furstenau Operations and Support Director Imprivata, Inc.

Access Management Analysis of some available solutions

How To Create A Single Sign On

Active Directory Integration twitter.com/onelogin ONELOGIN WHITEPAPER

Clientless SSL VPN Users

Enterprise Single Sign-on (ESSO)

White paper December IBM Tivoli Access Manager for Enterprise Single Sign-On: An overview

Red Hat Enterprise IPA Identity & Access Management for Linux and Unix Environments. Dragos Manac

An Oracle White Paper December Implementing Enterprise Single Sign-On in an Identity Management System

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

Citrix Password Manager 4.1

Transcription:

Single Sign-On Vijay Kumar, CISSP

Agenda What is Single Sign-On (SSO) Advantages of SSO Types of SSO Examples Case Study Summary

What is SSO Single sign-on is a user/session authentication process that permits a user to enter one name and password in order to access multiple applications. The process authenticates the user for all the applications they have been given rights to and eliminates further prompts when they switch applications during a particular session.

Advantages Reduced operational cost Reduced time to access data, eg. ER. Improved user experience, no password lists to carry Advanced security to systems Ease burden on developers Centralized management of users, roles. Fine grained auditing Effective compliance (SOX..)

Identity Management Encompasses directory services authentication and authorization services certificate authorities administration consoles single sign-on provisioning services.

Types of SSO Password Synchronization Legacy SSO (Employee SSO) Web SSO Cross domain (realm) SSO Federated SSO

Password Synchronization A process that coordinates passwords across multiple computers and devices and/or applications Each computer, device, application still authenticates but behind the scene Products: MTech s P-Synch SecurePass SAM Pass Synch

Legacy SSO Aka Enterprise or Employee SSO After primary authentication intercepts further login prompts and fills them for you. Learns as you use different apps. Legacy apps that are unable to externalize user authentication through screen scraping)

Citrix Password Manager Installs on Citrix clients or Windows server Self service password reset and account unlock Hot swappable desktop (unlike Windows or Novell) Integrated with User Provisioning software LDAP based storage of credentials Multifactor authentication support

Basic Web SSO Browser based application Cookie support is required. Single sign-on to applications deployed on a single web server (domain)

Cross Domain SSO Multiple realms that manage user credentials. A user authenticated in one realm gets signed-on to an application using another realm typically with in the same enterprise

Novell SecureLogin True SSO for Web applications Windows host (Windows Application Server) Legacy (Client Server) applications Mutiple identities and password policies stored in edir in encrypted form Novell client is installed on each workstation, User can access apps from any workstation Optionally cache credentials on workstation Transparent pw expirations and resets

Novell SecureLogin

Sun Java Access Manager

Oblix (Oracle)

Federated SSO Extend SSO across enterprises One of the goals of the Liberty Alliance Advantages Establishment of trusted partnerships New revenue opportunities New, efficient, and production biz models Why is this hard to implement? SAML (OASIS) Liberty Alliance builds fed ident on top of SAML

Liberty model for federated SSO

Microsoft Windows Server 2003 R2 adds Active Directory Federation Service Web Services based SSO Use Active Directory in non-windows env Microsoft Identity Integration Server 2003 SSO and account management features agents" that handle protocol translation between Active Directory ADFS provides federated SSO based on WS-*

Summary SSO is saves money and enhances security But.there are risks. Malicious user gets hold of unattended desktop Malicious processes/services sign on as you to services that they are not supposed to.

References Sun Java System Access Manager etrust Secure Sign-On Oracle IDM IBM Tivoli Access Manager Novell SecureLogin Citrix Password Manager Liberty Alliance Yale CAS (Central Authentication Service) Integrates well with Spring based Acegi