Luminis to Banner Single Sign-On



Similar documents
Implement and Deploy Banner 7 Channels

PeopleAdmin and Banner HR Interface

Georgia Tech s Luminis IV Beta Testing

High-Availability and Scalability

Web Services Integration Case Study - Housing

Active Directory Account Provisioning (ADAP)

Banner overview. Authentication to Banner & 3 rd Party Apps. Authorization to Banner & 3 rd Party Apps

The Luminis Portal and Dashboard Reports

Going Through Withdrawals at WSU Presented by: Bhavani Koneru and Scott Owczarek Wayne State University March 20, 2007 Course ID: 282

PowerCAMPUS Portal and Active Directory

Banner DBA Survival Guide

HIGHER EDUCATION. What can we help you achieve? SunGard Banner Financial Aid

Single Sign-on (SSO) technologies for the Domino Web Server

Crystal Report tips and Techniques

Load Testing your Banner Systems

Scoring Big with Automated Payroll Deductions

Managing Your Workflow System

Agenda. How to configure

Password Manager Using Luminis APIs

SAML Security Option White Paper

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

Banner Client--PayPal Merchant

Teamcenter Security Services Installation/Customization. Publication Number TSS00001 R

AAI for Mobile Apps How mobile Apps can use SAML Authentication and Attributes. Lukas Hämmerle

CA Performance Center

New Single Sign-on Options for IBM Lotus Notes & Domino IBM Corporation

Banner Training and Help Desk Plan

BANNER WEB TAILOR RELEASE GUIDE. Release 8.5 November 2011

Authentication Methods

Single Sign On for TouchNet Products Workbook. Information Technology Services

OpenLogin: PTA, SAML, and OAuth/OpenID

Integrating WebSphere Portal V8.0 with Business Process Manager V8.0

Securing SAS Web Applications with SiteMinder

PingFederate. Salesforce Connector. Quick Connection Guide. Version 4.1

How To Use Netscaler As An Afs Proxy

CA Nimsoft Service Desk

Absorb Single Sign-On (SSO) V3.0

Configuring Single Sign-on from the VMware Identity Manager Service to ServiceNow

Faculty & Advisor Banner Self-Service Guide V2.0

HP Asset Manager. Implementing Single Sign On for Asset Manager Web 5.x. Legal Notices Introduction Using AM

SSO Plugin. HP Service Request Catalog. J System Solutions. Version 3.6

Luminis Platform Banner Document Management Suite Portal Guide. Release November 2011

Authentication and Single Sign On

SUNGARD SUMMIT 2007 sungardsummit.com 1

Setting up LDAP settings for LiveCycle Workflow Business Activity Monitor

Entrust Managed Services PKI Administrator Guide

Copyright

Synology SSO Server. Development Guide

Microsoft Office 365 Using SAML Integration Guide

Banner Security: A Functional View

OneLogin Integration User Guide

CA SiteMinder. Federation Security Services Release Notes. r12.0 SP3

For details about using automatic user provisioning with Salesforce, see Configuring user provisioning for Salesforce.

Use Enterprise SSO as the Credential Server for Protected Sites

Single Sign On. SSO & ID Management for Web and Mobile Applications

Integrating IBM Cognos 8 BI with 3rd Party Auhtentication Proxies

Safewhere*Identify 3.4. Release Notes

INUVIKA OPEN VIRTUAL DESKTOP ENTERPRISE

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

DEPLOYMENT GUIDE. SAML 2.0 Single Sign-on (SSO) Deployment Guide with Ping Identity

Getting Started with AD/LDAP SSO

McAfee One Time Password

CA Adapter. Installation and Configuration Guide for Windows. r2.2.9

Configuring Salesforce

SAML Authentication Quick Start Guide

Remote Authentication and Single Sign-on Support in Tk20

SUNGARD SUMMIT 2007 sungardsummit.com 1. Microsoft PowerShell. Presented by: Jeff Modzel. March 22, 2007 Course ID 453. A Community of Learning

Single Sign-on Integration With PKI

Zendesk SSO with Cloud Secure using MobileIron MDM Server and Okta

TROUBLESHOOTING RSA ACCESS MANAGER SINGLE SIGN-ON FOR WEB-BASED APPLICATIONS

Reconciling Loans: Financial Aid through Finance

Active Directory Quick Reference Guide for PowerCAMPUS Self-Service 7.x. Release 5 July 2011

PingFederate. Identity Menu Builder. User Guide. Version 1.0

HP Software as a Service. Federated SSO Guide

Sage Accpac CRM 5.8. Self Service Guide

CA SiteMinder. Implementation Guide. r12.0 SP2

Connected Data. Connected Data requirements for SSO

Qualtrics Single Sign-On Specification

Configuring. Moodle. Chapter 82

Copyright: WhosOnLocation Limited

Onegini Token server / Web API Platform

Deploying RSA ClearTrust with the FirePass controller

QLIKVIEW MOBILE SECURITY

Configuring Parature Self-Service Portal

Configuring. SuccessFactors. Chapter 67

CA Spectrum and CA Embedded Entitlements Manager

IMPLEMENTING SINGLE SIGN- ON USING SAML 2.0 ON JUNIPER NETWORKS MAG SERIES JUNOS PULSE GATEWAYS

linux20 (R12 Server) R Single Node SID - TEST linux1 (10gAS Server) Oracle 10gAS ( ) with OID SID - asinf server name

Configuring SuccessFactors

TIBCO Spotfire Web Player 6.0. Installation and Configuration Manual

How To Get A Single Sign On (Sso)

SAP Mobile - Webinar Series SAP Mobile Platform 3.0 Security Concepts and Features

A detailed walk through a CAS authentication

Transcription:

SUNGARD SUMMIT 2007 sungardsummit.com 1 Luminis to Banner Single Sign-On Presented by: Rajesh Kumar Les von Holstein SunGard Higher Education Tuesday 8:30 AM March 20, 2007 A Community of Learning

Session Rules of Etiquette Please turn off your cell phone/pager If you must leave the session early, please do so as discreetly as possible Please avoid side conversation during the session Thank you for your cooperation! 2

Agenda Session goal: Introduction to SSO Configuring SSO to Banner INB/SSB SSO flow for Banner INB/SSB Luminis IV Support 3

SUNGARD SUMMIT 2007 sungardsummit.com 4 Introduction to SSO A Community of Learning

Introduction to SSO CPIP Campus Pipeline Integration Protocol Used in integration with third party applications Banner SSB/INB Banner Xtender Solutions WorkFlow 5

Introduction to SSO Many servers and configs involved, and many layers Luminis Server App Server Database Server Client Browser 6

SUNGARD SUMMIT 2007 sungardsummit.com 7 Configuring SSO to INB A Community of Learning

Banner SSO-INB Steps Configuring SSO INB Create an Encryption Key Used in DES Encryption with DBMS_OBFUSCATION_TOOLKIT Create Entries in LDAP to Store Configuration Import ldif files Configure Parameters using GUAUPRF Update New Entries in LDAP for INB Update LDAP using LDAP browser 8

Banner SSO-INB Steps Configuring SSO INB Configure Parameters using GUAUPRF 9

Banner SSO-INB Steps Configuring SSO INB Update New Entries in LDAP for INB Update LDAP using LDAP browser 10

Banner SSO-INB Steps Configuring SSO INB Create DADs for Running SSO Normal DAD Special DAD Verify Configuration Steps in BannerConfigure Parameters Debug scripts can be run to print and verify configuration parameters Configure your Luminis Server Add sctinb as es application to Luminis Test Create a test Link to confirm SSO 11

Banner SSO-INB Overview PLSQL web packages GOKSSSO, GOKCSSO, GOKKSSO Implements CPIP Protocol to interact with Luminis Cptool option used to add a filter that tells Luminis to send the Luminis ID/Password sctinb config url specified to point to GOKSSSO in Luminis 12

SUNGARD SUMMIT 2007 sungardsummit.com 13 Configuring SSO to Banner Self-Service A Community of Learning

Banner SSO Banner Self-Service Steps for Configuring SSO Banner Self-Service Create Entries in LDAP to Store Configuration Values Import sso_parms_sserv.ldif Update New Entries in LDAP for SSB Update entries using LDAP browser 14

Banner SSO Banner Self-Service Steps for Configuring SSO Banner Self-Service Configure WebTailor for LDAP Server Update twgbldap table Used in LDAP Bind 15

Banner SSO Banner Self-Service Steps for Configuring SSO Banner Self-Service Update WebTailor Parameters Import sso_parms_sserv.ldif Verify Configuration Steps in Self-Service Update entries using LDAP browser Configure your Luminis Server 16

Banner SSO-SSB Luminis Config PLSQL web packages GOKSSSO, GOKCSSO, GOKKSSO Implements CPIP Protocol to interact with Luminis sctssb added as es application to Luminis Cptool option used to add a filter that tells Luminis to send the Luminis ID/Password sctssb config url specified to point to GOKSSSO in Luminis 17

Banner SSO-SSB GOKSSSO provides URLs required by CPIP using LDAP parameters to build them GetConfig URL provides the rest in a response Authenticate key routine routine in GOKSSSO Gets ID/Password from Luminis Attempts bind Encrypts into a pipe named randomly Passes value back to Luminis for redirect or pickup 18

Banner SSO-SSB Luminis pickup URL sent to browser and redirected back to App Server Decrypts user/password off pipe Maps to Banner SSB ID Create SSB Login cookie CPSESSID vs SESSID Redirect to SSB page 19

SUNGARD SUMMIT 2007 sungardsummit.com 20 SSO Flow for INB A Community of Learning

Browser A Luminis INB DB A simple diagram B C D Yeah, right! E F G H I J K M L N O P Q R 21

Browser A Luminis INB DB A Client clicks on Banner INB link, Luminis receives request B D E C F G H I J K M L N O P Q R 22

Browser A Luminis INB DB B through G are only performed once per startup of the Luminis System. This is when Luminis calls its config routines. B Luminis calls the configurl set in the Luminis configuration for the INB system defined in the es.systems parameter. This url calls the database procedure gokssso.p_getconfig Version2. N O R B G H M D E J K C F I L P Q 23

Browser A Luminis INB DB C P_GetConfigVersion2 is a database call which tells Luminis which URLs to call for login and logout. B G H D E C F I J K M L N O P Q R 24

Browser A Luminis INB DB D The procedure calls back to the Luminis server LDAP for configuration data B D E C F G H I J K M L N O P Q R 25

Browser A Luminis INB DB E Configuration data returned to database and URLs built to be sent back to Luminis B D E C F G H I J K M L N O P Q R 26

Browser A Luminis INB DB F URLs passed back to INB server for transfer to Luminis B D E C F G H I J K M L N O P Q R 27

Browser A Luminis INB DB G Data sent to Luminis Server B D C E F G H I J K M L N O P Q R 28

Browser A Luminis INB DB H Luminis server uses config data received to build logon request. B D E C F G H I J K M L N O P Q R 29

Browser A Luminis INB DB I procedure gokssso.p_cp_login called to process login B D E C F G H I J K M L N O P Q R 30

Browser A Luminis INB DB J procedure revalidates the credentials received B D E C F G H I J K M L N O P Q R 31

Browser A Luminis INB DB K if credentials are valid, process continues B D E C F G H I J K M L N O P Q R 32

Browser A Luminis INB DB L procedure encrypts the credentials, generates a token and creates a database pipe containing the data. The token is also the pipe name. B G H D E C F I J K M L N O P Q R 33

Browser A Luminis INB DB M URL sent back to Luminis as the pickup url which includes the token. B D E C F G H I J K M L N O P Q R 34

Browser A Luminis INB DB N Luminis communicates the pickup url back to the browser as a redirect B D E C F G H I J K M L N O P Q R 35

Browser A Luminis INB DB O Browser redirects to the pickup url, which is a call to procedure gokcsso.p_call_banner B D E C F G H I J K M L N O P Q R 36

Browser A Luminis INB DB P INB startup Java Applet receives authentication info from Database Pipe B D E C F G H I J K M L N O P Q R 37

Browser A Luminis INB DB Q Authentication information passed in memory to the Oracle forms applet B D E C F G H I J K M L N O P Q R 38

Browser A Luminis INB DB R Forms applet starts and Banner session is started. B D E C F G H I J K M L N O P Q R 39

SUNGARD SUMMIT 2007 sungardsummit.com 40 SSO flow for Banner Self- Service A Community of Learning

B/C Luminis calls the configurl calls the database procedure gokssso.p_getconfigver sion2_sserv. P_GetConfigVersion2 _sserv is a database call which tells Luminis which URLs to call for login and logout. Browser A Luminis B G H D E J SSB C F I DB I procedure gokssso.p_cp_login_sserv called to process login N M K L P SSB session is started due to existence of CPSESSID cookie O P 41

SUNGARD SUMMIT 2007 sungardsummit.com 42 Luminis IV Support A Community of Learning

Luminis IV Support Banner General 7.4.1 Luminis IV and III.3.3 will be supported Changes were to support LoginID changes Luminis Channels For Banner 7.2 Luminis IV and III.3.3 will be supported Support for Locale Deployment Descriptors were modified for Luminis IV support 43

Questions & Answers 44

Thank You! Les von Holstein Rajesh Kumar Rajesh.Kumar@SungardHE.com Les.vonHolstein@SungardHE.com Please complete the online class evaluation form SunGard, the SunGard logo, Banner, Campus Pipeline, Luminis, PowerCAMPUS, Matrix, and Plus are trademarks or registered trademarks of SunGard Data Systems Inc. or its subsidiaries in the U.S. and other countries. Third-party names and marks referenced herein are trademarks or registered trademarks of their respective owners. 2007 SunGard. All rights reserved. 45