20
Open Identity Summit Federation in practice Víctor Aké OpenAM Product Manager ForgeRock

Federation in Practice

Embed Size (px)

DESCRIPTION

Presented by Victor Ake, OpenAM Product Manager and ForgeRock Co-Founder at ForgeRock Open Identity Stack Summit, June 2013.

Citation preview

Page 1: Federation in Practice

Open Identity Summit

Federation in practice

Víctor Aké OpenAM Product Manager ForgeRock

Page 2: Federation in Practice

Open Identity Summit

Applications and data within the firewall perimeter Users within the enterprise Difficult to roll out new services

OLD ACCESS CONTROL

Page 3: Federation in Practice

Open Identity Summit

Hanseatic League (Hansa) Trade Confederation Centuries 13th – 17th

Trading outside the walls Secure Membership agreement Follow protocol

Page 4: Federation in Practice

Open Identity Summit

Partners

Outsourcing

Suppliers

Customers

Information, services and users outside the fireWALL

Page 5: Federation in Practice

Open Identity Summit

FEDERATION Federalism is a political concept in which a group of members are bound together by covenant (Latin: foedus, covenant*) with a governing representative head.

*Agreement

Page 6: Federation in Practice

Open Identity Summit

SChengen Area

It is a group of 26 European countries that have abolished passport and immigration controls at their common borders.

!  Present your security token at the entrance

!  Travel seamlessly within the area

Page 7: Federation in Practice

Open Identity Summit

Partners

Outsourcing

Suppliers

Customers

Commercial Applications

In-house dev applications

Legacy applications

Directory

Databases

Active Directory

Enterprise

FEDERATED IDENTITY

Is the means of linking a person´s electronic identity and attributes, stored across multiple distinct identity management systems

Page 8: Federation in Practice

Open Identity Summit

Benefits of Federated identity Provides Single Sign On for an enhanced user experience

Share information across partners securely and privately

Promote adoption of new services

Reduces costs

Cloud friendly

Mobile friendly

Page 9: Federation in Practice

Open Identity Summit

Identity Federation Standards

SAML 2.0 Ws-federation ID-FF

Page 10: Federation in Practice

Open Identity Summit

Identity Provider, Asserting PARTY, IdP

Service Provider, Relaying party,

Consumer, SP

Circle of Trust

Service Provider, Relaying party,

Consumer, SP

Agreements principal

Authenticate Obtain Token

Present token Access resource

Identity Federation actors

Page 11: Federation in Practice

Open Identity Summit

! Enterprise connected to Cloud SaaS, partners, suppliers, etc

! Customers using social authentication

SaaS

Private Cloud

Social

Partners Outsourcing

Suppliers

Commercial Applications

In-house dev applications

Legacy applications

Directory

Databases

Active Directory

Use cases

Page 12: Federation in Practice

Open Identity Summit

! SaaS/IDaas Providing services to Enterprises

! Social authentication to SaaS and IDaaS

Multi-tenant IdP

Multi-tenant SP

IDaas

SaaS

Social

Commercial Applications

In-house dev applications

Legacy applications

Directory

Databases

Active Directory

Use cases

Page 13: Federation in Practice

Open Identity Summit

Web App

Native App

Native App

Web App

Login App

RE

ST/

OA

uth2

/Ope

nID

Con

nect

Authentication

Authorization

Attribute Delivery

Federation

SSO

Token Persistence

Session Mgmt

OAuth2 Provider

OpenAM

Cloud

Enterprise

Use cases

Page 14: Federation in Practice

Open Identity Summit

SP to IdP Mesh

IdP$

IdP$

IdP$

IdP$

SP$

SP$

SP$

Page 15: Federation in Practice

Open Identity Summit

IdP Proxy

IdP$

IdP$

IdP$

IdP$

SP$

SP$

SP$IdP

Proxy

Page 16: Federation in Practice

Open Identity Summit

Federation is more than SSO SAML 2.0

IdP, SP, IdP Proxy, Attribute Query Provider, Attribute Authority, Authentication Authority, XACML PEP, XACML PDP

WS-Federation IdP, SP

ID-FF IdP, SP

OAuth 2.0 RESTful Authorization protocol

Page 17: Federation in Practice

Open Identity Summit

OpenAM + family Openam Full blown Federation OpenAM Fedlet

Lightweight SAML 2.0 SP OpenIG and Fedlet

Powerful combination of integration and SAML 2.0

Page 18: Federation in Practice

Open Identity Summit

Walkthrough on how to configure OpenAM to achieve SSO to GoogleApps & SalesForce using SAML2

Page 19: Federation in Practice

Open Identity Summit

IDP

SP SP

Circle of Trust

SSO to Google apps and salesforce

demo.openam.org

Page 20: Federation in Practice

Q & A

Víctor Aké OpenAM Product Manager ForgeRock

Thanks !