ORACLE ACCESS MANAGER



Similar documents
OracleAS Identity Management Solving Real World Problems

Oracle Identity Management for SAP in Heterogeneous IT Environments. An Oracle White Paper January 2007

Authentication: Password Madness

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

Enabling Single Sign-On for Oracle Applications Oracle Applications Users Group PAGE 1

How to Implement Enterprise SAML SSO

Oracle Identity Management: Integration with Windows. An Oracle White Paper December. 2004

Provide access control with innovative solutions from IBM.

Masdar Institute Single Sign-On: Standards-based Identity Federation. John Mikhael ICT Department

D83167 Oracle Data Integrator 12c: Integration and Administration

Alleviating Password Management Demands on Your IT Service Desk SOLUTION WHITE PAPER

Oracle Identity Analytics Architecture. An Oracle White Paper July 2010

identity management in Linux and UNIX environments

Integrating Hitachi ID Suite with WebSSO Systems

DirX Identity V8.5. Secure and flexible Password Management. Technical Data Sheet

Deploying RSA ClearTrust with the FirePass controller

White paper December Addressing single sign-on inside, outside, and between organizations

Oracle Identity Management Concepts and Architecture. An Oracle White Paper December 2003

Identity Management and Single Sign-On

Web Applications Access Control Single Sign On

HOL9449 Access Management: Secure web, mobile and cloud access

Identity Management Overview. Bill Nelson Vice President of Professional Services

Oracle Data Integrator 12c: Integration and Administration

Oracle Data Integrator 11g: Integration and Administration

Linux Single Sign-on: Maximum Security, Minimum Cost

DirX Identity V8.4. Secure and flexible Password Management. Technical Data Sheet

Global Headquarters: 5 Speen Street Framingham, MA USA P F

Web Access Management. RSA ClearTrust. Enhancing control. Widening access. Driving e-business growth. SSO. Identity Management.

CA SiteMinder SSO Agents for ERP Systems

Quest Software Product Guide

IBM Maximo technology for business and IT agility

Oracle Database Security and Audit

White Paper. McAfee Cloud Single Sign On Reviewer s Guide

CA Federation Manager

Oracle Access Manager. An Oracle White Paper

A matter of trust Fujitsu Managed Mobile

Product overview. CA SiteMinder lets you manage and deploy secure web applications to: Increase new business opportunities

Integrated Authentication

Extranet Access Management Web Access Control for New Business Services

Arisant s Identity Management (IdM) for K-12 Education

RSA ACCESS MANAGER. Web Access Management Solution ESSENTIALS SECURE ACCESS TO WEB APPLICATIONS WEB SINGLE SIGN-ON CONTEXTUAL AUTHORIZATION

An Oracle White Paper Dec Oracle Access Management Security Token Service

Contextual Authentication: A Multi-factor Approach

Cisco ASA Adaptive Security Appliance Single Sign-On: Solution Brief

Citrix Password Manager 4.5 Partner and Sales FAQ

How To Use Netscaler As An Afs Proxy

Quest One Identity Solution. Simplifying Identity and Access Management

Best Practices for Secure Remote Access. Aventail Technical White Paper

Quest InTrust. Version 8.0. What's New. Active Directory Exchange Windows

Security Services. Benefits. The CA Advantage. Overview

The Top 5 Federated Single Sign-On Scenarios

Passlogix Sign-On Platform

OPENIAM ACCESS MANAGER. Web Access Management made Easy

AVG Business SSO Partner Getting Started Guide

Why MobilityGuard OneGate?

Oracle Application Express and Oracle E-Business Suite. Love and Mariage!

nexus Hybrid Access Gateway

MIGRATION GUIDE. Authentication Server

WatchGuard SSL 2.0 New Features

PingFederate. SSO Integration Overview

The Power of the Unica Marketing Platform

PRODUCT CATEGORY BROCHURE. Juniper Networks SA Series

Streamline Enterprise Records Management. Laserfiche Records Management Edition

CA Single Sign-On r12.x (CA SiteMinder) Implementation Proven Professional Exam

When millions need access: Identity management in an increasingly connected world

Migration Best Practices for OpenSSO 8 and SAM 7.1 deployments O R A C L E W H I T E P A P E R M A R C H 2015

Administration Guide. SecureLogin 8.0. October, 2013

G Cloud 6 CDG Service Definition for Forgerock Software Services

Critical Issues with Lotus Notes and Domino 8.5 Password Authentication, Security and Management

The Benefits of an Industry Standard Platform for Enterprise Sign-On

Authentication Integration

Architecture Guidelines Application Security

Introduction to SAML

Open Directory. Apple s standards-based directory and network authentication services architecture. Features

NCSU SSO. Case Study

Coveo Platform 7.0. Microsoft Active Directory Connector Guide

Allidm.com. SSO Introduction. Discovering IAM Solutions. Leading the IAM facebook/allidm

Vyom SSO-Edge: Single Sign-On Solution for BMC Remedy

Oracle Database 11g: Security Release 2. Course Topics. Introduction to Database Security. Choosing Security Solutions

ADMINISTERING ADOBE LIVECYCLE MOSAIC 9.5

Leveraging SAML for Federated Single Sign-on:

Avaya Mailbox Manager and Unimax 2nd Nature A Comparison

Business Service Management Cyril Gobrecht Business Solutions Manager Halim Belkhatir Regional Manager. 17 December 2008

An Oracle White Paper December Integrating Oracle Enterprise Single Sign-On Suite Plus with Strong Authentication

Transcription:

ORACLE ACCESS MANAGER LEGACY-TO-OAM ZERO-DOWNTIME SSO MIGRATION BY OTECIA INTERNATIONAL

Content 1. Solution Overview... 3 1.1. Challenges... 3 1.2. Objectives... 4 1.3. Scope... 4 1.4. Results... 4 2. About Otecia International... 5 (V1.2) 1 - Solution Overview-- Page 2 of 5

1. Solution Overview Otecia International, a leading global provider of Identity Management solutions, has developed a proven methodology to let customers quickly, easily, and safely migrate from legacy SSO to the Oracle Access Manager (OAM) SSO with zero-downtime without disruption in service or availability. With the zero-downtime migration capability, Otecia International brings the advantages of rapid enterprise SSO deployment to a wider range of organizations by making it easier to configure and administer highly available industry standards-based enterprise SSO infrastructure. Upon initial user authentication, the solution authentication and authorization plug-ins intercept and migrate user credentials to OAM format. On subsequent user authentication requests, the solution validates successful credential migration and transparently allows users to proceed accessing OAM-protected applications, without negatively affecting endusers experience. The solution requires minimal or no modifications to existing applications that are part of the legacy SSO. 1.1. Challenges In today s world of compliance regulations, organizations are required to protect sensitive data within enterprise applications. Over time, various security policies have been enacted to protect applications. For example, login processes have been put in place to secure the user access, yet access control to the applications has often been integrated within the application logic and separate data stored have been put in place to store credentials. Users have been required to regularly update passwords for each application, yet accommodating such requirements have resulted in the proliferation of insecure practices (writing down passwords, reuse easy-to-guess password combinations, or sharing passwords among users). In a typical scenario, legacy SSO solutions rely on custom-built code to be integrated within each application to enable reduced sign-on capabilities. Other implementations of legacy SSO rely on client-server software to allow users to launch non-sso enabled applications via a centralized SSO infrastructure, acting as a repository for application-specific user credentials. The following challenges have been identified with the continued use of legacy SSO systems: Climbing maintenance cost for non-standard custom-built Single Sign-On framework Increased security risk from storing user account passwords in decryptable format. High deployment and integration cost for new applications Lack of high-availability with legacy SSO implementations (V1.2) 1 - Solution Overview-- Page 3 of 5

1.2. Objectives Migrate users and customers to a more secure industry-standard SSO platform such as Oracle Access Manager Spare customers and employees the hassle of establishing new credentials Zero migration down-time for customers and employees Save costs by reducing help desk support calls Scalable solution supporting over one million customers and employees Built-in high-availability solution 1.3. Scope The solution is built around the Oracle Access Manager foundation to enable web single sign-on across all internet and intranet applications. It includes OAM plug-ins to migrate credentials from a legacy SSO to OAM. The solution serves as an enterprise authentication framework that will work for all applications, including legacy reduced sign-on applications, providing unified authentication processes (including form-based credentials and PKI/digital certificates). The enterprise security framework can optionally accommodate advanced authentication features such as: Concurrent login detection enforcement, allowing one session per user with grace period notification Federated Access Persistent cookie-based authentication The solution will ensure that existing users with legacy authentication credentials will find the transition to the OAM SSO environment transparent. Legacy persistent cookie-based credentials will continue to work and will be automatically replaced with SSO credentials. 1.4. Results The operating cost of the migrated infrastructure is significantly lower than the original legacy SSO infrastructure. Existing customers have commented on the reliability of the solution. End user satisfaction and productivity is greatly improved, while enacting more stringent enterprise security policies to minimize wild-spread insecure practices. Migration to an enterprise single sign-on such as the industry standards-based OAM solution provides for providing centralized management of application authentication, authorization, and auditing to meet compliance regulations requirements. Support costs are reduced by eliminating requirements to track and change multiple user passwords and troubleshooting password management related issues. (V1.2) 1 - Solution Overview-- Page 4 of 5

2. About Otecia International Otecia International is a leading provider of expert consulting services for Identity and Security E-Business enterprise software solutions. Founded in 2004 and headquartered in Washington, DC, Otecia International excels in helping clients across the globe with strengthening enterprise security, lowering operating costs, and improving user productivity. Its team of experts brings exceptional understanding of the technology, adhering to the best industry practices. For more information about our services, please visit our website at http://www.otecia.com Otecia International and Otecia Consulting are trademarks of Otecia International, Inc. 2008 Otecia International, Inc. (V1.2) 2 - About Otecia International-- Page 5 of 5