Extending CAS SSO Out of the Box - Presentation Transcript
live. learn. work. play.
Expanding CAS SSO Out of the Box
A Presentation By:
Jason Shao, Director of Product Development
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
SSO Overview
We Love SSO
Convenience for users accessing multiple systems
Integration in workflows/user experience
Reduced Costs of user-support load related to
password, username, and credentials
Security of services located both on and off-site
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
SSO Overview
We Hate SSO
Integration typically performed application –by-
application – extremely slow and labor intensive
Integration of closed-source/blackbox systems can
be extremely painful
Integration with hosted/SaaS applications may be
impossible
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 1: SSO Protocol Support
Approach 1: SSO Protocol Support
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 1: SSO Protocol Support
Approach 1: Advantages
Standard
Supportable
Allows tight integration &capabilities
Typically protects user credentials
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 1: SSO Protocol Support
Approach 1: Dis-Advantages
Requires Manufacturer/Service Support
Potential incompatibilities in implementation
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 2: Custom SSO API Integration
Approach 2: Custom SSO API Integration
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 2: Custom SSO API Integration
Approach 2: Advantages
Supported
Typically protects user credentials
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 2: Custom SSO API Integration
Approach 2: Dis-Advantages
Requires Manufacturer/Service Support
Configuration on the product side can be difficult
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 3: Automated Credential Replay (Common Sign-On Services)
Approach 3: Advantages
Convenient for End Users
No modifications to target systems required
No credential storage required
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 3: Automated Credential Replay (Common Sign-On Services)
Approach 3: Dis-Advantages
Parameters and formats can change between
different software versions
May require specific network/domain settings to
support some login processes
Exposes User Credentials
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 3a: Stored Credential Replay (Separate Services)
Approach 3a: Advantages
No modifications to target systems required
May be the only way to integrate some systems
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Approach 3a: Stored Credential Replay (Separate Services)
Approach 3a: Dis-Advantages
Parameters and formats can change between
different software versions
May require specific network/domain settings to
support some login processes
Requires storage and management of user
credentials
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Look and Feel Consistency
Acknowledgements
CAS Development Team
Sacramento State &Clearpass Development Team
Development staff at CampusEAI
Our many members
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
live. learn. work. play.
Expanding CAS SSO Out of the Box
A Presentation By:
Jason Shao, Director of Product Development
1940 East 6th Street • 11th Floor • Cleveland • Ohio 44114 • Tel: 216.589.9626 • Fax: 216.589.9639 • info@campuseai.org• http://www.campuseai.org
0 comments
Post a comment