Riešenia a technológie pre jednotnú správu používateľov

Similar documents
UiB 1. april 04. Sun Microsystems

Architecting the Identity-Enabled Enterprise. The Directory Interoperability Forum

Identität und Autorisierung als Grundlage für sichere Web-Services. Dr. Hannes P. Lubich IT Security Strategist

Enterprise SOA Experience Workshop. Module 8: Operating an enterprise SOA Landscape

CLI users are not listed on the Cisco Prime Collaboration User Management page.

Setting Up Resources in VMware Identity Manager (On Premises) Modified on 30 AUG 2017 VMware AirWatch 9.1.1

IBM Tivoli Identity Manager V5.1 Fundamentals

SysAid Technical Presentation. Phone (Toll-Free US): Phone: +972 (3)

zentrale Sicherheitsplattform für WS Web Services Manager in Action: Leitender Systemberater Kersten Mebus

Oracle Identity Manager 11gR2-PS2 Hands-on Workshop Tech Deep Dive Upgrade

SAML-Based SSO Solution

Realms and Identity Policies

Realms and Identity Policies

SAML-Based SSO Solution

Introducing ArisID An open source, declarative identity API for developers

The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into

The Fedlet: Real World Examples

Setting Up Resources in VMware Identity Manager. VMware Identity Manager 2.8

ArcGIS Server and Portal for ArcGIS An Introduction to Security

App Gateway Deployment Guide

Q u e s t i o n m a r k C o n f e r e n c e

ITCertMaster. Safe, simple and fast. 100% Pass guarantee! IT Certification Guaranteed, The Easy Way!

IBM Lotus Domino Product Roadmap

Microsoft Azure Course Content

New trends in Identity Management

Identity-Powered Security

ServiceNow Deployment Guide

Security Challenges on the Road Ahead. Tim Mather, CISO

All about SAML End-to-end Tableau and OKTA integration

IBM Lotus Quickr STEW Technical Overview

Tivoli Federated Identity Manager. Sven-Erik Vestergaard Certified IT Specialist Security architect SWG Nordic

IBM C Exam. Volume: 65 Questions

WSO2 Identity Management

Using Your Own Authentication System with ArcGIS Online. Cameron Kroeker and Gary Lee

"Charting the Course to Your Success!" MOC B Implementing Forefront Identity Manager 2010 Course Summary

Copyright 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 12

Hyperion System 9 Financial Management release

Novell Access Manager 3.1

Introduction to Identity Management Systems

Sun Java Composite Application Platform Suite

Customizing a Packaged Application for a J2EE Environment: A Case Study. Leslie Tierstein TopTier Consulting, Inc.

Hyperion System 9 Strategic Finance release

IBM IBM IBM Tivoli Federated Identity Manager V6.1. Practice Test. Version

Setting Up Resources in VMware Identity Manager

Centrify Identity Services for AWS

Setting Up Resources in VMware Identity Manager (SaaS) Modified 15 SEP 2017 VMware Identity Manager

CLI users are not listed on the Cisco Prime Collaboration User Management page.

Architecture & Deployment

ArcGIS for Server: What s New. Philip Heede, Jay Theodore

ArcGIS Server Components: An Introduction to Server IT

Why Choose MS Azure?

ArcGIS Enterprise Security: An Introduction. Gregory Ponto & Jeff Smith

IBM Tivoli Netcool Service Quality Manager V4.1.1

SSO Integration Overview

Deployment Scenario: WebSphere Portal Mashup integration and page builder

ARIS Platform Matrix ARIS Products Version 9.8 April 2015

Anycast. Ľubor Jurena CEO Michal Kolárik System Administrator

PDF / JAVA ENTERPRISE FOR SAP

Advanced Deployment Architectures for Oracle E-Business Suite

1z0-479 oracle. Number: 1z0-479 Passing Score: 800 Time Limit: 120 min.

Realms and Identity Policies

Identity and capability management and federation

The essential toolkit for effective AD management: The Integrations Handbook

BEYOND AUTHENTICATION IDENTITY AND ACCESS MANAGEMENT FOR THE MODERN ENTERPRISE

Manage SAML Single Sign-On

Identity Management (IdM) is a crosscutting focus area for DHS

Oracle Application Express: Administration 1-2

OpenIAM Identity and Access Manager Technical Architecture Overview

1 Hitachi ID Group Manager. 2 Agenda. Managing the User Lifecycle Across On-Premises and Cloud-Hosted Applications

Single Sign-on Implementation Best Practices

SAML-Based SSO Configuration

Add OKTA as an Identity Provider in EAA

VMWARE HORIZON CLOUD WITH VMWARE IDENTITY MANAGER QUICK START GUIDE WHITE PAPER MARCH 2018

Building the Enterprise

IBM Security Identity Manager Version Glossary IBM

COMPONENTS/PRODUCTS IN OIM

Oracle Developer Day

User Management in Resource Manager

IBM Tivoli Storage Resource Manage. nidun

Page 1. Oracle9i OLAP. Agenda. Mary Rehus Sales Consultant Patrick Larkin Vice President, Oracle Consulting. Oracle Corporation. Business Intelligence

SAML-Based SSO Configuration

Implementing Forefront Identity Manager 2010

271 Waverley Oaks Rd. Telephone: Suite 206 Waltham, MA USA

RSA Exam 050-v71-CASECURID02 RSA SecurID Certified Administrator 7.1 Exam Version: 6.0 [ Total Questions: 140 ]

ebusiness Suite goes SOA

Front Office for NetBackup Guide Self-service backup & restore

NetIQ Identity Manager Driver for SAP Portal Implementation Guide. February 2018

Oracle Enterprise Manager Ops Center. Introduction. Provisioning Oracle Solaris 10 Operating Systems 12c Release 2 ( )

Copyright 2013, Oracle and/or its affiliates. All rights reserved.

Annex 10 Standard Profile Specification and Request Form for Services

SharePoint 2019 and Extranet User Manager

Securing an Oracle Private Cloud using Oracle Directory Suite

plugin deployment guide

Total Content Integrator Support Matrix Updated: January 8, 2016

Sun Java System Access Manager Release Notes for Microsoft Windows

Mozy. Administrator Guide

Configuration Guide - Single-Sign On for OneDesk

Obsah. SOA REST REST princípy REST výhody prest. Otázky

VIEVU Solution AD Sync and ADFS Guide

Identity Provider for SAP Single Sign-On and SAP Identity Management

Transcription:

Riešenia a technológie pre jednotnú správu používateľov Radovan Semančík

Agenda Úvod: Identity Crisis Technológie správy používateľov Postup nasadenia Záver

Súčasný stav IT Security Nekonzistentné bezpečnostné politiky Nekonzistentné databázy používateľov Perimeter security je neefektívna Rýchle vírusové infekcie Útoky z vnútra organizácie Patching doesn't work Identity Crisis

Identity Crisis Nikto nevie, kto má mať kam prístup Nikto nevie, kde všade má zamestnanec prístup Prístupy na firewall/vpdn iné ako do IS Mobility vs Security Vysoké náklady: help desk, prestoje, zmeny It's clear identity has become a strategic business issue, not just a technology issue. -- Jamie Lewis, president of consultancy Burton Group

Mýtus centralizácie Jedna databáza/directory/čokoľvek Rýchlo nekonzistentná Nákladné na údržbu Bezpečnostné riziko Nie vždy technologicky možné (SQL join, offline,...) Nutná synchronizácia Nekonzistencia Rôzne UID Rôzne typy prístupových práv Neexistuje štruktúra rolí

Agenda Úvod: Identity Crisis Technológie správy používateľov Postup nasadenia Záver

Technológie správy používateľov Directory Server (LDAP) Nutná podmienka, nie však postačujúca Len databáza, žiadna inteligencia Provisioning system Synchronizácia údajov, workflow Organizačná štruktúra role Metadirectory Jednoduché pravidlá, obmedzenia (rovnaké uid) User Management, Doménové systémy,... Jednoduché, jednoúčelové, prvý krok

User Provisioning HR Provisioning Server SPML EAI Apps Solaris LDAP Oracle Directory Server Enterprise Portal Windows Domains SAP Linux DB Apps Group Ware

Spôsob práce Provisioning Servera Provisioning Server Directory Server HR Solaris 34567889 Radovan Semančík IT Architect System Division SSH LDAP HR: 34567889 LDAP: uid=rsemancik,... Solaris: semancik Oracle: RSE SQL dn: uid=rsemancik,o=bgs ou: sys role: itarchitect userpassword:... Oracle semancik:x:101:100:radovan Semancik:... RSE Radovan Semancik 34567889

Databáza vs Metadata Databáza Metadata 34567889 Radovan Semančík IT Architect System Division uid: 101 HR: 34567889 LDAP: uid=rsemancik,... Solaris: semancik Oracle: RSE

Agenti vs Rozhrania Agentový prístup Bezagentový prístup Cieľový systém Cieľový systém Proprietárne rozhranie Agent Verejné rozhranie Provisioning Server Provisioning Server

HR Workflow 34567889 Radovan Semančík IT Architect System Division WfMC TC-1023 BGS semancik:x:101:.. group: admin NET SYS Log IP Data SE Devel Directory Server Java login: semancik role: teamleader division: SYS

Dôležité špecifikácie Lightweight Directory Access Protocol (LDAP) Directory Services Markup Language (DSML) Service Provisioning Markup Language (SPML) Project Liberty Specification, Phase I Project Liberty Specification, Phase II WS-Security WS-Federation

Service Provisioning Markup Language Jazyk pre Provisioning systémy založený na XML Štandardizácia: OASIS Provisioning Services Technical Committee Založené na DSMLv2, spolupracuje so SAML a WS- Security Štandardné rozhranie ľahká integrácia SPML SPML

Liberty Alliance Project Directory Server Identity Provider SAML SAML Service Provider SAML Service Provider Portal

Agenda Úvod: Identity Crisis Technológie správy používateľov Postup nasadenia Záver

User Management Projects Central User Management Project Centrálna správa zamestnaneckých prístupov Výrazné finančné šetrenie Provisioning Server (Sun Java System Identity Manager) Customer Identity Management Project Správa zákazníckych prístupov Veľké množstvo záznamov, málo systémov Metadirectory, Directory-based replikátory

Digital Identity Projects Single Sign-On Project Intra-enterprise systematic SSO Základ komponentu pre SOA SSO server (Sun Java System Access Manager) Digital Identity (Federation) Project Externé (internet) SSO Externé zdieľanie atribútov Identity Provider

Agenda Úvod: Identity Crisis Technológie správy používateľov Postup nasadenia Záver

Záver Jednotná správa používateľov je prvý nutný krok Single Sign-On a Digital Identity až potom Orientácia na štandardy Dobrá architektúra It is possible to deploy identity in incremental steps, but you won't succeed if you haven't built an overall plan before you start. -- Phil Becker, Digital ID World

Otázky

Ďakujem za pozornosť Ing. Radovan Semančík Business Global Systems, a.s. Pluhová 2 83248 Bratislava semancik@bgs.sk