Jasig Central Authentication Service in Ten Minutes

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Notes on slide 1

    Just one of these needs to be compromised, to attack user “forever”!

    2 Favorites

    Jasig Central Authentication Service in Ten Minutes - Presentation Transcript

    1. Jasig CAS in 10 Minutes Copyright Unicon, Inc., 2009. Some Rights Reserved. This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License. http://creativecommons.org/licenses/by-sa/3.0/us/ Some content drawn from prior presentations at Jasig conferences. Andrew Petro Unicon, Inc. 4 & 5 November, 2009
    2. What is CAS? open source single sign on for the Web
    3. Multi-Sign-On for the Web
    4. At Least with One Username/Password?
    5. All Applications Touch Passwords
    6. Any Compromise Leaks Primary Credentials
    7. Adversary Then Can Run Wild
    8. The Solution
      • What if there were only one login form in your organization, only one application trusted to touch primary credentials?
    9. Delete Your Login Forms
    10. Webapps No Longer Touch Passwords
    11. Adversary Compromises Only Single Apps
    12.  
    13. Webapps No Longer Touch Passwords
    14. Provided Authentication Handlers
      • LDAP
        • Fast bind
        • Search and bind
      • Active Directory
        • LDAP
        • Kerberos (JAAS)
      • JAAS
      • JDBC
      • RADIUS
      • SPNEGO
      • Trusted
      • X.509 certificates
      • Writing a custom authentication handler is easy
    15. What About Portals?
      • Need to go get interesting content from different systems.
      • E-mail
      • Calendar
      • E-Learning
      • Student Information System
    16. Password Replay Portal Password-Protected Service Password-Protected Service Password-Protected Service Channel Channel Channel PW PW PW PW PW PW PW PW PW PW PW
    17. Look Ma, No Password!
      • Without a password to replay, how am I going to authenticate my portal to other applications?
      ?
    18. “ Proxy” CAS
      • Some Web applications “proxy” authentication to backing services on behalf of the user
      • “ Proxied” applications/services may themselves proxy authentication to others
      • CAS authenticates both the end user and the proxy
    19. CAS – More than Authentication
      • Return attributes of logged on users
      • Adding support for standards
        • OpenID
        • SAML
      • Single Sign-Out
      • RESTful API
      • Support for clustering
      • Services management
      • Remember me (long-term SSO)
    20. Unicon Services for CAS
      • Implementation Planning
      • Branding and User Experience
      • Installation and Configuration
      • Custom Development
      • Consulting and Mentoring
      • CASification of uPortal, Sakai, and other applications
      • Upgrades
      • For more information, please visit
      • http://www.unicon.net/services/cas
    21. Questions? Andrew Petro [email_address] www.unicon.net

    + Andrew PetroAndrew Petro, 4 months ago

     

    599 views, 2 favs, 0 embeds more

    About this presentation

    CC Attribution-ShareAlike LicenseCC Attribution-ShareAlike License

    • Total Views 599
      • 599 on SlideShare
    • Favorites 2
    • Downloads 4
    Embed views

    more

    Embed views

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint

    Categories