Beruflich Dokumente
Kultur Dokumente
Federation in practice
Applications and data within the firewall perimeter Users within the enterprise Difficult to roll out new services
The dictionary
Federalism is a political concept in which a group of members are bound together by covenant (Latin: foedus, covenant*) with a governing representative head.
*Agreement
SChengen Area
It is a group of 26 European countries that have abolished passport and immigration controls at their common borders.
!! Present your security token at the entrance !! Travel seamlessly within the area
Customers Outsourcing
Databases
Directory
FEDERATED IDENTITY
Active Directory
Enterprise
Partners Suppliers Is the means of linking a persons electronic identity and attributes, stored across multiple distinct identity management systems
ID-FF
Ws-federation
SAML 2.0
Federation support
OAUTH 2.0! ID-FF" Shibboleth 1.0/1.1" Shibboleth 2#
(SAML2)"
OpenID" Connect!
REST/JSON
SAML 1.0"
SAML 1.x"
OpenAM"
WS-Federation 1.0"
Use Cases
!! Enterprise connected to Cloud SaaS, partners, suppliers, etc !! Customers using social authentication
Social
Databases
SaaS
Directory
Active Directory
Use Cases
!! SaaS/IDaas Providing services to Enterprises !! Social authentication to SaaS and IDaaS
Social
Databases
SaaS
Directory
Multi-tenant IdP
Active Directory
Private Cloud
Multi-tenant SP
Cloud
Login App
REST
OAuth2
Enterprise
14
SP to IdP Mesh
IdP SP IdP SP IdP SP IdP
IdP Proxy
IdP SP IdP SP SP
IdP Proxy
IdP IdP
WS-Federation
IdP, SP
ID-FF
IdP, SP
OAuth 2.0
RESTful Authorization protocol
OpenID Connect
Uses OAUTH2 tokens, adds services
OpenAM + family
OpenAM
Full blown Federation
OpenAM Fedlet
Lightweight SAML 2.0 SP
Custom federation
2
Application
1
Reverse Proxy
Policy Agent
Application
OpenAM 6
Application
SP
Policy Agent
Application
Fedlet
19
IDP
Circle of Trust
SP
SP
SP
Federation in practice