14
World ® ’1 6 WAM and Federation: Two Great Tastes That Taste Great Together Aaron Berman – WW VP, Single Sign-on & Directory Solutions CA Technologies SCT44T SECURITY

Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

Embed Size (px)

Citation preview

Page 1: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

World®’16

WAMandFederation:TwoGreatTastesThatTasteGreatTogetherAaronBerman– WWVP,SingleSign-on&DirectorySolutionsCATechnologies

SCT44T

SECURITY

Page 2: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

1 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

©2016CA.Allrightsreserved.Alltrademarksreferencedhereinbelongtotheirrespectivecompanies.

Thecontentprovidedinthis CAWorld2016presentationisintendedforinformationalpurposesonlyanddoesnotformanytypeofwarranty. The informationprovidedbyaCApartnerand/orCAcustomerhasnotbeenreviewedforaccuracybyCA.

ForInformationalPurposesOnlyTermsofthisPresentation

Page 3: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

2 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Abstract

WAM&Federation:TwoGreatTastesthatTasteGreatTogether

Choosingtherightapproachtomeetyourneedsiscritical.Choosingthe

wrongapproachcancauseproblemslikeincreasedintegrationcostsand

projectdelays.Learnaboutthedifferencesbetweenfederatedmodels

andPEP/PDPaccessmanagementmodelsforsessionsecurityand

userexperience.

AaronBermanCATechnologiesWWVP,SingleSign-On&DirectorySolutions

Page 4: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

3 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

SingleSign-onCanMeanManyDifferentThings

§ Gettinganidentity fromoneapplicationtoanother§ Maintainingasecuresessionacrossmultipleapplications§ Onlyallowingthecorrect usersaccess§ Security controlsforthesession§ Knowingwhatactions usersaredoing§ URLfilteringtokeepbadrequestsout

Page 5: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

4 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

TwoApproachestoMeetDifferentNeeds

§ Policyenforcementpointstointerceptandexamineeachrequest

§ Sharedsessionacrossmultipleapplications

WEBACCESSMANAGEMENT

§ Identitypassedfromidentityprovidertoapplications

§ ClaimsapproachtoSSO

§ Applicationremainsincontrolofownsecuritypolicies

OPENSTANDARDS

TIGHTLYCOUPLED LOOSELYCOUPLED

Page 6: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

5 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

ChoosingtheWrongApproachCanCauseProblems

§ Increasedintegrationcosts

§ Useofworkaroundstomeetrequirements

§ Customization

§ ProjectDelays

Imagetakenfromhttps://hikingartist.com/thrive/nail-screw/

Choosingtherightapproach tomeetyourneedsiscritical

Page 7: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

6 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

DecisionGuidelines

§ OnPremiseorPaaSapplications

§ Simplecrossapplicationlinking

§ Enforcementofuserauthorization

§ Audit/Timeout/SessionSecurity

WEBACCESSMANAGEMENT

§ ThirdPartysites

§ Applicationshaveanativeintegration

§ Remotelocations

§ Onlyconcernedwithpassingidentity

OPENSTANDARDS

Page 8: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

7 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

SAML

SSOApproachesCanbeCombined…SAMLtoanInternalApplicationWhileMaintainingURLFiltering

EndUser SSOGateway

SSOSession Applicationsession

Application

SessionLinker

Page 9: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

8 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

OAUTH

…andIntegratedInboundSocialSign-onDataPassedtoApplicationsWithoutAccountCreation

EndUser SSOGateway

SocialMedia

Application2

Application1SSO

CADirectorySessionStore

SSOPolicyServer

IdentityData

Page 10: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

9 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

CASingleSign-onOffersBothOptions

Unlimitedwebserveragents

Unlimitedgateways

UnlimitedstandardsbasedSSOforalllicensedusers

CASingleSign-OnFeatures

DeployingasinglesolutionforallSSOneedsreducesITspendandIntegrationcosts

Page 11: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

10 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Summary

Choose therightapproachtomeetyourbusiness

needs

WAMandOpenStandardsdonotcontradict theycompliment

CombineWAM andOpenstandardstogether

Page 12: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

11 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

RecommendedSessions

SESSION# TITLE DATE/TIME

SCT915 DataBreachDigest,JohnGrimm 11/16/2016at12:45pm

SCT45T HowFastIsYourDirectory? 11/16/2016at4:30pm

SCX205 CASSO,AARoadmap 11/18/2016at1:45pm

Page 13: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

12 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Don’tMissOurINTERACTIVESecurityDemoExperience!

SNEAKPEEK!

12 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Page 14: Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together

@CAWORLD#CAWORLD ©2016CA.AllRIGHTSRESERVED.13 @CAWORLD#CAWORLD

Security

FormoreinformationonSecurity,pleasevisit:http://cainc.to/EtfYyw