WebSSO and Access Management with LemonLDAP::NG

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    WebSSO and Access Management with LemonLDAP::NG - Presentation Transcript

    1. WebSSO and Access Management LemonLDAP::NG Clément OUDOT
      • Single Sign On and Access Management
      • LemonLDAP::NG
      • Demonstration
      Table of contents
    2. Single Sign On
      • SSO is designed for users:
        • One login/password to remember (or even better with physical token)
        • One authentication screen for all applications
      • SSO can also provides:
        • A dynamic list of authorized applications
        • A single access point (portal) to information system
    3. Access Management
      • Access Management is designed for system administrators:
        • Single point of authentication (easy to audit)
        • Set access rights to applications
        • Use enterprise directory for authentication and authorization
    4. Enterprise SSO
    5. Delegation SSO
    6. Reverse-proxy SSO
    7. LemonLDAP::NG
      • LemonLDAP::NG is a free WebSSO project:
        • GPL licence
        • OW2 Forge: http://lemonldap.ow2.org
      • Use standard Apache2 installation
      • Use mod_perl to hook Apache requests
      • Provides:
        • Portal with dynamic application list
        • Graphical management interface
        • Wide integration (LDAP, Kerberos, SQL, CAS, SSL, SOAP, etc.)
    8. Architecture overview
    9. How it works
    10. Some screen shots
    11. LDAP forever
      • LemonLDAP::NG can use LDAP for:
        • Authentication
        • Authorization
        • Password modification
        • Groups
        • Configuration storage
        • Session storage
    12. LDAP password policy
      • LemonLDAP::NG is compatible with the draft of LDAP password policy (overlay ppolicy in OpenLDAP):
        • Display if account is locked or expired
        • Display warning time and graces remaining
        • Force password change after reset
        • Show constraints error on password modification (size, history, etc.)
    13. Authentication backends
      • LemonLDAP::NG can use several authentication backends:
        • LDAP (the default)
        • SSL (through Apache)
        • Kerberos (through Apache)
        • CAS
        • Liberty Alliance (replaced soon by SAML2)
        • Any other Apache authentication methods
        • SOAP (portal chaining)
    14. More features
      • Application provisioning trough HTTP headers
      • Logon hours with time zone management
      • RBAC model
      • Cross-domain
      • Session sharing over network
      • HTTP Basic authentication forward
      • Password reset by mail
      • Notifications
      • Active Directory support
    15. Full integrated applications
    16. Thank you for your attention Visit us at our stand 107 - hall 7.2b

    + coudotcoudot, 4 months ago

    custom

    419 views, 0 favs, 7 embeds more stats

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 419
      • 312 on SlideShare
      • 107 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 10
    Most viewed embeds
    • 56 views on http://www.toolinux.com
    • 17 views on http://www.linagora.org
    • 15 views on http://wiki.lemonldap.ow2.org
    • 7 views on http://toolinux.com
    • 6 views on http://www.toolinux.org

    more

    All embeds
    • 56 views on http://www.toolinux.com
    • 17 views on http://www.linagora.org
    • 15 views on http://wiki.lemonldap.ow2.org
    • 7 views on http://toolinux.com
    • 6 views on http://www.toolinux.org
    • 5 views on http://linagora.org
    • 1 views on http://209.85.229.132

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories