SlideShare a Scribd company logo
1 of 31
Building Open Source Identity
Infrastructures
Francesco Chicchiriccò
ilgrosso@apache.org
https://about.me/ilgrosso
Building Open Source Identity
Infrastructures
Francesco Chicchiriccò
ilgrosso@apache.org
https://about.me/ilgrosso
The Identity Management NeedThe Identity Management Need
Identity Vs Account
Source: https://saberhamidi.wordpress.com/2015/02/22/topic-2-should-we-have-more-than-one-online-identity/
Identity Vs Account
• Account
• record containing data about a person
• technical info needed by the information system for
which the account is created and managed
• (Digital) Identity
• representation of a set of claims made by one digital
subject about itself
• ...it's you
Why Identity
Management?• Operational costs
• Multiple sources of identity data
• Manual user provisioning and password reset
• Labor-intensive, paper-based approval
• Compliance
• No record of who has access to which IT resources
• Difficult to deprovision access rights upon termination
• No complete audit trail available
• Hard to prevent unauthorized access
Which identity?
Identity SolutionsIdentity Solutions
Identity Technologies
• Identity Stores
• Storage of user information
• Provisioning Engines
• Synchronize account data across identity stores and a
broad range of data formats, models, meanings and
purposes
• Access Managers
• Security mechanisms that take place when a user is
accessing a specific system or functionality
Identity Store
• Examples
• LDAP / Active Directory
• RDBMS
• Meta and Virtual Directories
• Accounts can be created and managed in one place only
• Each application manages authentication separately
• The user may use the same password for all the
connected applications
...is it enough?
• Heterogeneity of systems
• Lack of a single source of information
• HR for corporate id, Groupware for mail address, ...
• Need for a local user database
• Inconsistent policies
• Lack of workflow management
• Hidden infra management cost, growing with organization
Provisioning Engine
• Keeping the identity stores as much synchronized as
possible (and practical)
• Need to be customizable and flexible
• Priority: non-intrusive
• Focused on application back-end
• Critical: data exchange with identity stores
• Connectors
• Agents
Identity Lifecycle
Access Manager
• Mediator to all access to all applications
• Focused on application front-end
• Aspects
• Authentication
• Single SignOn
• Authorization (OAuth, XACML, ...)
• Federation (SAML, Liberty, ...)
• Mainly applicable to web applications
• Difficult integration with pre-existing apps
Reference Identity Scenario
Identity InfrastructuresIdentity Infrastructures
Gather...
• Number and type of identities
• Number of roles / groups (and what are they used for)
• External resources (all covered by standard connectors?)
• Approval workflow(s)?
• Self-service?
• Which applications to protect?
• Which authentication mechanisms?
• Which authorization types?
...essentially, shape the identity and access flows
...design...
• Schema for various identities (users, roles, groups, ...)
• Identify mapping for all resources
• Not too complex!
• Watch roles size to avoid RBAC's role explosion
• Don't be tempted to redesign the whole network
• Provisioning needs to be flexible
• Reduce impact of access management on existing
applications
• Prioritize requirements
...build...
• Carefully choose the building blocks
• Can't simply buy COTS
• On-premises
• Proprietary
• Open Source
• As-a-service
• Consider prototyping the designed solution (PoC)
...and start again
• IAM is a continuous process, not a turn-key project
• New applications to protect
• New resources to integrate
• Identity flows evolution
• IAM deliveries frequently fail
• Mix of complex and unrelated technologies
• Unexpected interactions
• Mess with internal processes
• Discover Policy Vs Reality
The Open Source Identity StackThe Open Source Identity Stack
Open Source IAM
• Why?
• Flexibility, adaptability and agility
• Cost effectiveness
• Start small and grow
• Solid information security
• No vendor lock-in
• Caveats
• Integration with proprietary software (AD over all)
• Enterprise support availability
Available Components
Selection Criteria
• Open Standards
• Design for integration
• Well-established
• Supported
• Alive
• ...Open Source!
The Identity Ecosystem
• Triggered by open companies in the Open Source IAM area
• Common place for open source players, system integrators
and service providers
• Ensuring IAM open source components work well together
• Easy access to enterprise support providers
• Several options for each single component
• More at http://www.identity-ecosystem.org/
Real World Use CasesReal World Use Cases
Disclaimer
I am V.P. Apache Syncope and CEO of Tirasa, providing
enterprise support and services for Apache Syncope,
so…
don't be surprised Syncope is
everywhere :-)
Disclaimer
I am V.P. Apache Syncope and CEO of Tirasa, providing
enterprise support and services for Apache Syncope,
so…
don't be surprised Syncope is
everywhere :-)
#1 Stadtwerke München
• One of largest German municipal utilities
• Mobile ticketing for public transportation and bike sharing
• self-registration
• login
• password reset
• user suspend / reactivate
• > 250k registered users
• > 80k authentications per day
#2 Ospedali Riuniti Ancona
• University hospital
• Active synchronization from HR to Microsoft Active
Directory
• Centralized provisioning, authentication and authorization of
medical record systems
• Windows domain SSO
• SAML 2.0 federation with regional network
• ~ 5000 users
#3 Stichting Bibliotheek.nl
• Dutch foundation that aims to expand and manage the
Digital National Library
• The IAM infrastructure aims to hold all users of the national
library in the Netherlands, fed by a continuous feed from
the local libraries
• All Dutch library members can authenticate and use digital
services connected to the IAM infrastructure
• > 8 million users
#4 University of Milan
• Very complex provisioning flows involving
• Microsoft Active Directory
• OpenLDAP
• 3 different RDBMS
• Oracle E-Mail Server
• ~ 5k employees
• > 60k students
• ~ 800 roles
Questions?
All text and image content in this document is licensed under the Creative Commons Attribution-Share Alike 3.0 License
(unless otherwise specified). Apache, Syncope, Apache Syncope, the Apache feather logo, the Apache Syncope project logo
and the Apache Syncope logo are trademarks of The Apache Software Foundation. All other marks mentioned may be
trademarks or registered trademarks of their respective owners.

More Related Content

What's hot

WSO2Con USA 2017: Identity and Access Management in the Era of Digital Transf...
WSO2Con USA 2017: Identity and Access Management in the Era of Digital Transf...WSO2Con USA 2017: Identity and Access Management in the Era of Digital Transf...
WSO2Con USA 2017: Identity and Access Management in the Era of Digital Transf...WSO2
 
Red Hat Summit - OpenShift Identity Management and Compliance
Red Hat Summit - OpenShift Identity Management and ComplianceRed Hat Summit - OpenShift Identity Management and Compliance
Red Hat Summit - OpenShift Identity Management and ComplianceMarc Boorshtein
 
WSO2Con USA 2017: Building Enterprise Grade IoT Architectures for Digital Tra...
WSO2Con USA 2017: Building Enterprise Grade IoT Architectures for Digital Tra...WSO2Con USA 2017: Building Enterprise Grade IoT Architectures for Digital Tra...
WSO2Con USA 2017: Building Enterprise Grade IoT Architectures for Digital Tra...WSO2
 
Directory Services with the ForgeRock Identity Platform - So What’s New?
Directory Services with the ForgeRock Identity Platform - So What’s New?Directory Services with the ForgeRock Identity Platform - So What’s New?
Directory Services with the ForgeRock Identity Platform - So What’s New?ForgeRock
 
Fintech Primitives - Wealth Management - MF Pro - Distributor
Fintech Primitives - Wealth Management - MF Pro - DistributorFintech Primitives - Wealth Management - MF Pro - Distributor
Fintech Primitives - Wealth Management - MF Pro - DistributorJainendra Sinha
 
PingOne IDaaS: What You Need to Know
PingOne IDaaS: What You Need to KnowPingOne IDaaS: What You Need to Know
PingOne IDaaS: What You Need to KnowCloudIDSummit
 
Extending Active Directory to Box for Seamless IT Management
Extending Active Directory to Box for Seamless IT ManagementExtending Active Directory to Box for Seamless IT Management
Extending Active Directory to Box for Seamless IT ManagementOkta-Inc
 
SSO with the WSO2 Identity Server
SSO with the WSO2 Identity ServerSSO with the WSO2 Identity Server
SSO with the WSO2 Identity ServerWSO2
 
Company and Market Overview
Company and Market OverviewCompany and Market Overview
Company and Market OverviewOkta-Inc
 
WSO2Con USA 2017: Managing Verifone’s New Payment Device “Carbon” with WSO2’s...
WSO2Con USA 2017: Managing Verifone’s New Payment Device “Carbon” with WSO2’s...WSO2Con USA 2017: Managing Verifone’s New Payment Device “Carbon” with WSO2’s...
WSO2Con USA 2017: Managing Verifone’s New Payment Device “Carbon” with WSO2’s...WSO2
 
WSO2Con USA 2017: Building a Secure Enterprise
WSO2Con USA 2017: Building a Secure EnterpriseWSO2Con USA 2017: Building a Secure Enterprise
WSO2Con USA 2017: Building a Secure EnterpriseWSO2
 
Case Study: University of California, Berkeley and San Francisco
Case Study: University of California, Berkeley and San FranciscoCase Study: University of California, Berkeley and San Francisco
Case Study: University of California, Berkeley and San FranciscoForgeRock
 
2015.04.23 Azure Mobile Services
2015.04.23 Azure Mobile Services2015.04.23 Azure Mobile Services
2015.04.23 Azure Mobile ServicesMarco Parenzan
 
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...Okta-Inc
 
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!ForgeRock
 
Azure security guidelines for developers
Azure security guidelines for developers Azure security guidelines for developers
Azure security guidelines for developers Ivo Andreev
 
WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...
WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...
WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...WSO2
 
CIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean DeubyCIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean DeubyCloudIDSummit
 
Incredible Edible Identity
Incredible Edible IdentityIncredible Edible Identity
Incredible Edible IdentityForgeRock
 
[WSO2Con EU 2017] IAM: Catalyst for Digital Transformation
[WSO2Con EU 2017] IAM: Catalyst for Digital Transformation[WSO2Con EU 2017] IAM: Catalyst for Digital Transformation
[WSO2Con EU 2017] IAM: Catalyst for Digital TransformationWSO2
 

What's hot (20)

WSO2Con USA 2017: Identity and Access Management in the Era of Digital Transf...
WSO2Con USA 2017: Identity and Access Management in the Era of Digital Transf...WSO2Con USA 2017: Identity and Access Management in the Era of Digital Transf...
WSO2Con USA 2017: Identity and Access Management in the Era of Digital Transf...
 
Red Hat Summit - OpenShift Identity Management and Compliance
Red Hat Summit - OpenShift Identity Management and ComplianceRed Hat Summit - OpenShift Identity Management and Compliance
Red Hat Summit - OpenShift Identity Management and Compliance
 
WSO2Con USA 2017: Building Enterprise Grade IoT Architectures for Digital Tra...
WSO2Con USA 2017: Building Enterprise Grade IoT Architectures for Digital Tra...WSO2Con USA 2017: Building Enterprise Grade IoT Architectures for Digital Tra...
WSO2Con USA 2017: Building Enterprise Grade IoT Architectures for Digital Tra...
 
Directory Services with the ForgeRock Identity Platform - So What’s New?
Directory Services with the ForgeRock Identity Platform - So What’s New?Directory Services with the ForgeRock Identity Platform - So What’s New?
Directory Services with the ForgeRock Identity Platform - So What’s New?
 
Fintech Primitives - Wealth Management - MF Pro - Distributor
Fintech Primitives - Wealth Management - MF Pro - DistributorFintech Primitives - Wealth Management - MF Pro - Distributor
Fintech Primitives - Wealth Management - MF Pro - Distributor
 
PingOne IDaaS: What You Need to Know
PingOne IDaaS: What You Need to KnowPingOne IDaaS: What You Need to Know
PingOne IDaaS: What You Need to Know
 
Extending Active Directory to Box for Seamless IT Management
Extending Active Directory to Box for Seamless IT ManagementExtending Active Directory to Box for Seamless IT Management
Extending Active Directory to Box for Seamless IT Management
 
SSO with the WSO2 Identity Server
SSO with the WSO2 Identity ServerSSO with the WSO2 Identity Server
SSO with the WSO2 Identity Server
 
Company and Market Overview
Company and Market OverviewCompany and Market Overview
Company and Market Overview
 
WSO2Con USA 2017: Managing Verifone’s New Payment Device “Carbon” with WSO2’s...
WSO2Con USA 2017: Managing Verifone’s New Payment Device “Carbon” with WSO2’s...WSO2Con USA 2017: Managing Verifone’s New Payment Device “Carbon” with WSO2’s...
WSO2Con USA 2017: Managing Verifone’s New Payment Device “Carbon” with WSO2’s...
 
WSO2Con USA 2017: Building a Secure Enterprise
WSO2Con USA 2017: Building a Secure EnterpriseWSO2Con USA 2017: Building a Secure Enterprise
WSO2Con USA 2017: Building a Secure Enterprise
 
Case Study: University of California, Berkeley and San Francisco
Case Study: University of California, Berkeley and San FranciscoCase Study: University of California, Berkeley and San Francisco
Case Study: University of California, Berkeley and San Francisco
 
2015.04.23 Azure Mobile Services
2015.04.23 Azure Mobile Services2015.04.23 Azure Mobile Services
2015.04.23 Azure Mobile Services
 
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
 
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
 
Azure security guidelines for developers
Azure security guidelines for developers Azure security guidelines for developers
Azure security guidelines for developers
 
WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...
WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...
WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...
 
CIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean DeubyCIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean Deuby
 
Incredible Edible Identity
Incredible Edible IdentityIncredible Edible Identity
Incredible Edible Identity
 
[WSO2Con EU 2017] IAM: Catalyst for Digital Transformation
[WSO2Con EU 2017] IAM: Catalyst for Digital Transformation[WSO2Con EU 2017] IAM: Catalyst for Digital Transformation
[WSO2Con EU 2017] IAM: Catalyst for Digital Transformation
 

Viewers also liked

CXF 3.0, What's new?
CXF 3.0, What's new?CXF 3.0, What's new?
CXF 3.0, What's new?Daniel Kulp
 
PÁSCOA 2014 ..... A páscoa de Jesus Cristo (3/4)
PÁSCOA 2014 ..... A páscoa de Jesus Cristo (3/4)PÁSCOA 2014 ..... A páscoa de Jesus Cristo (3/4)
PÁSCOA 2014 ..... A páscoa de Jesus Cristo (3/4)Luís Carvalho
 
PÁSCOA 2014 .... Origens da Páscoa (1/4)
PÁSCOA 2014 .... Origens da Páscoa (1/4)PÁSCOA 2014 .... Origens da Páscoa (1/4)
PÁSCOA 2014 .... Origens da Páscoa (1/4)Luís Carvalho
 
Identity and Access Management in the Era of Digital Transformation
Identity and Access Management in the Era of Digital TransformationIdentity and Access Management in the Era of Digital Transformation
Identity and Access Management in the Era of Digital TransformationWSO2
 
Ano liturgico.ritmos
Ano liturgico.ritmosAno liturgico.ritmos
Ano liturgico.ritmosRamon Gimenez
 
Semana santa parte 2
Semana santa   parte 2Semana santa   parte 2
Semana santa parte 2mbsilva1971
 
Tríduo pascal - indicações litúrgico-pastorais
Tríduo pascal - indicações litúrgico-pastoraisTríduo pascal - indicações litúrgico-pastorais
Tríduo pascal - indicações litúrgico-pastoraisPNSPS
 
Programação Semana Santa
Programação Semana SantaProgramação Semana Santa
Programação Semana Santasidneybartolo
 
Preparar as festas pascais
Preparar as festas pascaisPreparar as festas pascais
Preparar as festas pascaisNuno Bessa
 
Semana Santa PresentacióN
Semana Santa PresentacióNSemana Santa PresentacióN
Semana Santa PresentacióNguest81a427
 
Ano liturgico
Ano liturgicoAno liturgico
Ano liturgicoJean
 
Celebrações da Semana Santa
Celebrações da Semana SantaCelebrações da Semana Santa
Celebrações da Semana SantaSandro Rezende
 
Formação de Liturgia - 03/11/2013
Formação de Liturgia - 03/11/2013Formação de Liturgia - 03/11/2013
Formação de Liturgia - 03/11/2013eusouaimaculada
 
A celebração da primeira páscoa
A celebração da primeira páscoaA celebração da primeira páscoa
A celebração da primeira páscoaMoisés Sampaio
 
Slide semana santa
Slide semana santaSlide semana santa
Slide semana santajucrismm
 
Formação em Liturgia
Formação em LiturgiaFormação em Liturgia
Formação em Liturgiaiaymesobrino
 
Semana santa formação
Semana santa formaçãoSemana santa formação
Semana santa formaçãombsilva1971
 

Viewers also liked (20)

20100327 Triduo Pasquale
20100327 Triduo Pasquale20100327 Triduo Pasquale
20100327 Triduo Pasquale
 
CXF 3.0, What's new?
CXF 3.0, What's new?CXF 3.0, What's new?
CXF 3.0, What's new?
 
PÁSCOA 2014 ..... A páscoa de Jesus Cristo (3/4)
PÁSCOA 2014 ..... A páscoa de Jesus Cristo (3/4)PÁSCOA 2014 ..... A páscoa de Jesus Cristo (3/4)
PÁSCOA 2014 ..... A páscoa de Jesus Cristo (3/4)
 
PÁSCOA 2014 .... Origens da Páscoa (1/4)
PÁSCOA 2014 .... Origens da Páscoa (1/4)PÁSCOA 2014 .... Origens da Páscoa (1/4)
PÁSCOA 2014 .... Origens da Páscoa (1/4)
 
Eucaristia
EucaristiaEucaristia
Eucaristia
 
Identity and Access Management in the Era of Digital Transformation
Identity and Access Management in the Era of Digital TransformationIdentity and Access Management in the Era of Digital Transformation
Identity and Access Management in the Era of Digital Transformation
 
Ano liturgico.ritmos
Ano liturgico.ritmosAno liturgico.ritmos
Ano liturgico.ritmos
 
Semana santa parte 2
Semana santa   parte 2Semana santa   parte 2
Semana santa parte 2
 
Tríduo pascal - indicações litúrgico-pastorais
Tríduo pascal - indicações litúrgico-pastoraisTríduo pascal - indicações litúrgico-pastorais
Tríduo pascal - indicações litúrgico-pastorais
 
Programação Semana Santa
Programação Semana SantaProgramação Semana Santa
Programação Semana Santa
 
Preparar as festas pascais
Preparar as festas pascaisPreparar as festas pascais
Preparar as festas pascais
 
Semana Santa PresentacióN
Semana Santa PresentacióNSemana Santa PresentacióN
Semana Santa PresentacióN
 
Ano liturgico
Ano liturgicoAno liturgico
Ano liturgico
 
A verdadeira pascoa
A verdadeira pascoaA verdadeira pascoa
A verdadeira pascoa
 
Celebrações da Semana Santa
Celebrações da Semana SantaCelebrações da Semana Santa
Celebrações da Semana Santa
 
Formação de Liturgia - 03/11/2013
Formação de Liturgia - 03/11/2013Formação de Liturgia - 03/11/2013
Formação de Liturgia - 03/11/2013
 
A celebração da primeira páscoa
A celebração da primeira páscoaA celebração da primeira páscoa
A celebração da primeira páscoa
 
Slide semana santa
Slide semana santaSlide semana santa
Slide semana santa
 
Formação em Liturgia
Formação em LiturgiaFormação em Liturgia
Formação em Liturgia
 
Semana santa formação
Semana santa formaçãoSemana santa formação
Semana santa formação
 

Similar to Building open source identity infrastructures

API’s and Micro Services 0.5
API’s and Micro Services 0.5API’s and Micro Services 0.5
API’s and Micro Services 0.5Richard Hudson
 
Getting to Know Enterprise Content Management (ECM) and How It Can Help You
Getting to Know Enterprise Content Management (ECM) and How It Can Help YouGetting to Know Enterprise Content Management (ECM) and How It Can Help You
Getting to Know Enterprise Content Management (ECM) and How It Can Help YouInnoTech
 
SharePoint 2013 ECM & Methodology
SharePoint 2013 ECM & Methodology SharePoint 2013 ECM & Methodology
SharePoint 2013 ECM & Methodology Sonny Thai
 
Building an Identity Management Business Case
Building an Identity Management Business CaseBuilding an Identity Management Business Case
Building an Identity Management Business CaseHitachi ID Systems, Inc.
 
CASE STUDY: UK NATIONAL HEALTH SERVICE
CASE STUDY: UK NATIONAL HEALTH SERVICECASE STUDY: UK NATIONAL HEALTH SERVICE
CASE STUDY: UK NATIONAL HEALTH SERVICEForgeRock
 
Introduction to Web Security
Introduction to Web SecurityIntroduction to Web Security
Introduction to Web SecurityKamil Lelonek
 
IoT mobile app device cloud identity and security architecture
IoT mobile app device cloud identity and security architectureIoT mobile app device cloud identity and security architecture
IoT mobile app device cloud identity and security architectureVinod Wilson
 
A Guide To Single Sign-On for IBM Collaboration Solutions
A Guide To Single Sign-On for IBM Collaboration SolutionsA Guide To Single Sign-On for IBM Collaboration Solutions
A Guide To Single Sign-On for IBM Collaboration SolutionsGabriella Davis
 
Lock it Down: Access Control for IBM i
Lock it Down: Access Control for IBM iLock it Down: Access Control for IBM i
Lock it Down: Access Control for IBM iPrecisely
 
Identity and User Access Management.pptx
Identity and User Access Management.pptxIdentity and User Access Management.pptx
Identity and User Access Management.pptxirfanullahkhan64
 
Phase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionPhase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionEduserv
 
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19Andrew Hughes
 
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision IT
 
Social Media, Cloud Computing, Machine Learning, Open Source, and Big Data An...
Social Media, Cloud Computing, Machine Learning, Open Source, and Big Data An...Social Media, Cloud Computing, Machine Learning, Open Source, and Big Data An...
Social Media, Cloud Computing, Machine Learning, Open Source, and Big Data An...Open Analytics
 
Open Data Summit Presentation by Joe Olsen
Open Data Summit Presentation by Joe OlsenOpen Data Summit Presentation by Joe Olsen
Open Data Summit Presentation by Joe OlsenChristopher Whitaker
 
JDD2015: Security in the era of modern applications and services - Bolesław D...
JDD2015: Security in the era of modern applications and services - Bolesław D...JDD2015: Security in the era of modern applications and services - Bolesław D...
JDD2015: Security in the era of modern applications and services - Bolesław D...PROIDEA
 

Similar to Building open source identity infrastructures (20)

API’s and Micro Services 0.5
API’s and Micro Services 0.5API’s and Micro Services 0.5
API’s and Micro Services 0.5
 
Getting to Know Enterprise Content Management (ECM) and How It Can Help You
Getting to Know Enterprise Content Management (ECM) and How It Can Help YouGetting to Know Enterprise Content Management (ECM) and How It Can Help You
Getting to Know Enterprise Content Management (ECM) and How It Can Help You
 
SharePoint 2013 ECM & Methodology
SharePoint 2013 ECM & Methodology SharePoint 2013 ECM & Methodology
SharePoint 2013 ECM & Methodology
 
Building an Identity Management Business Case
Building an Identity Management Business CaseBuilding an Identity Management Business Case
Building an Identity Management Business Case
 
Hitachi ID Identity Manager
Hitachi ID Identity ManagerHitachi ID Identity Manager
Hitachi ID Identity Manager
 
CASE STUDY: UK NATIONAL HEALTH SERVICE
CASE STUDY: UK NATIONAL HEALTH SERVICECASE STUDY: UK NATIONAL HEALTH SERVICE
CASE STUDY: UK NATIONAL HEALTH SERVICE
 
Introduction to Web Security
Introduction to Web SecurityIntroduction to Web Security
Introduction to Web Security
 
IoT mobile app device cloud identity and security architecture
IoT mobile app device cloud identity and security architectureIoT mobile app device cloud identity and security architecture
IoT mobile app device cloud identity and security architecture
 
A Guide To Single Sign-On for IBM Collaboration Solutions
A Guide To Single Sign-On for IBM Collaboration SolutionsA Guide To Single Sign-On for IBM Collaboration Solutions
A Guide To Single Sign-On for IBM Collaboration Solutions
 
Lock it Down: Access Control for IBM i
Lock it Down: Access Control for IBM iLock it Down: Access Control for IBM i
Lock it Down: Access Control for IBM i
 
Compliance & Identity access management
Compliance & Identity access management Compliance & Identity access management
Compliance & Identity access management
 
Identity and User Access Management.pptx
Identity and User Access Management.pptxIdentity and User Access Management.pptx
Identity and User Access Management.pptx
 
Phase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionPhase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect option
 
Denver ISSA Chapter Meetings - Changing the Security Paradigm
Denver  ISSA Chapter Meetings - Changing the Security ParadigmDenver  ISSA Chapter Meetings - Changing the Security Paradigm
Denver ISSA Chapter Meetings - Changing the Security Paradigm
 
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
 
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
 
Social Media, Cloud Computing, Machine Learning, Open Source, and Big Data An...
Social Media, Cloud Computing, Machine Learning, Open Source, and Big Data An...Social Media, Cloud Computing, Machine Learning, Open Source, and Big Data An...
Social Media, Cloud Computing, Machine Learning, Open Source, and Big Data An...
 
Open Data Summit Presentation by Joe Olsen
Open Data Summit Presentation by Joe OlsenOpen Data Summit Presentation by Joe Olsen
Open Data Summit Presentation by Joe Olsen
 
Hitachi ID Management Suite
Hitachi ID Management SuiteHitachi ID Management Suite
Hitachi ID Management Suite
 
JDD2015: Security in the era of modern applications and services - Bolesław D...
JDD2015: Security in the era of modern applications and services - Bolesław D...JDD2015: Security in the era of modern applications and services - Bolesław D...
JDD2015: Security in the era of modern applications and services - Bolesław D...
 

More from Francesco Chicchiriccò

More from Francesco Chicchiriccò (10)

Perché mai Tirasa? Career Day 2017 - UnivAQ
Perché mai Tirasa? Career Day 2017 - UnivAQPerché mai Tirasa? Career Day 2017 - UnivAQ
Perché mai Tirasa? Career Day 2017 - UnivAQ
 
DevOps practices and tools of a small company in love with open source
DevOps practices and tools of a small company in love with open sourceDevOps practices and tools of a small company in love with open source
DevOps practices and tools of a small company in love with open source
 
Open source identity management 20121106 - apache con eu
Open source identity management   20121106 - apache con euOpen source identity management   20121106 - apache con eu
Open source identity management 20121106 - apache con eu
 
Apache Syncope Identity Manager 20120623 confsl
Apache Syncope Identity Manager 20120623 confslApache Syncope Identity Manager 20120623 confsl
Apache Syncope Identity Manager 20120623 confsl
 
Sviluppo DTT e Sofia
Sviluppo DTT e SofiaSviluppo DTT e Sofia
Sviluppo DTT e Sofia
 
Scrum: una metodologia agile
Scrum: una metodologia agileScrum: una metodologia agile
Scrum: una metodologia agile
 
Service Delivery Network
Service Delivery NetworkService Delivery Network
Service Delivery Network
 
Automatic Server Provisioning
Automatic Server ProvisioningAutomatic Server Provisioning
Automatic Server Provisioning
 
Workflow e dintorni
Workflow e dintorniWorkflow e dintorni
Workflow e dintorni
 
Hands On Cocoon
Hands On CocoonHands On Cocoon
Hands On Cocoon
 

Recently uploaded

Call Us 🏨 8800357707 🔝 Call Girls in Aerocity (Delhi NCR)
Call Us  🏨 8800357707 🔝 Call Girls in Aerocity (Delhi NCR)Call Us  🏨 8800357707 🔝 Call Girls in Aerocity (Delhi NCR)
Call Us 🏨 8800357707 🔝 Call Girls in Aerocity (Delhi NCR)monikaservice1
 
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...riyaescorts54
 
🔝Call Girls In INA Colony Call Us ➥ 8800357707 In Call Out Call Both With Hig...
🔝Call Girls In INA Colony Call Us ➥ 8800357707 In Call Out Call Both With Hig...🔝Call Girls In INA Colony Call Us ➥ 8800357707 In Call Out Call Both With Hig...
🔝Call Girls In INA Colony Call Us ➥ 8800357707 In Call Out Call Both With Hig...monikaservice1
 
9811611494,Low Rate Call Girls In Connaught Place Delhi 24hrs Available
9811611494,Low Rate Call Girls In Connaught Place Delhi 24hrs Available9811611494,Low Rate Call Girls In Connaught Place Delhi 24hrs Available
9811611494,Low Rate Call Girls In Connaught Place Delhi 24hrs Availablenitugupta1209
 
(9599264170) ↫ Call Girls In Rk Puram ↫ Delhi NCR
(9599264170) ↫ Call Girls In Rk Puram ↫ Delhi NCR(9599264170) ↫ Call Girls In Rk Puram ↫ Delhi NCR
(9599264170) ↫ Call Girls In Rk Puram ↫ Delhi NCREscort Service
 
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...aakahthapa70
 
Genuine Call Girls In {Mahipalpur Delhi} 9667938988 Indian Russian High Profi...
Genuine Call Girls In {Mahipalpur Delhi} 9667938988 Indian Russian High Profi...Genuine Call Girls In {Mahipalpur Delhi} 9667938988 Indian Russian High Profi...
Genuine Call Girls In {Mahipalpur Delhi} 9667938988 Indian Russian High Profi...aakahthapa70
 
KAKINADA CALL GIRL 92628/71154 KAKINADA C
KAKINADA CALL GIRL 92628/71154 KAKINADA CKAKINADA CALL GIRL 92628/71154 KAKINADA C
KAKINADA CALL GIRL 92628/71154 KAKINADA CNiteshKumar82226
 
Call Girls in Majnu ka Tilla Delhi 💯 Call Us 🔝9711014705🔝
Call Girls in Majnu ka Tilla Delhi 💯 Call Us 🔝9711014705🔝Call Girls in Majnu ka Tilla Delhi 💯 Call Us 🔝9711014705🔝
Call Girls in Majnu ka Tilla Delhi 💯 Call Us 🔝9711014705🔝thapagita
 
Call Girls In Sector 29, (Gurgaon) Call Us. 9711911712
Call Girls In Sector 29, (Gurgaon) Call Us. 9711911712Call Girls In Sector 29, (Gurgaon) Call Us. 9711911712
Call Girls In Sector 29, (Gurgaon) Call Us. 9711911712Delhi Escorts Service
 
100% Real Call Girls In New Ashok Nagar Delhi | Just Call 9711911712
100% Real Call Girls In New Ashok Nagar Delhi | Just Call 9711911712100% Real Call Girls In New Ashok Nagar Delhi | Just Call 9711911712
100% Real Call Girls In New Ashok Nagar Delhi | Just Call 9711911712Delhi Escorts Service
 
NAGPUR CALL GIRL 92628*71154 NAGPUR CALL
NAGPUR CALL GIRL 92628*71154 NAGPUR CALLNAGPUR CALL GIRL 92628*71154 NAGPUR CALL
NAGPUR CALL GIRL 92628*71154 NAGPUR CALLNiteshKumar82226
 
💚😋Bangalore Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Bangalore Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Bangalore Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Bangalore Escort Service Call Girls, ₹5000 To 25K With AC💚😋Sheetaleventcompany
 
Call Girls in Lahore || 03081633338 || 50+ ❤️ Sexy Girls Babes for Sexual - vip
Call Girls in Lahore || 03081633338 || 50+ ❤️ Sexy Girls Babes for Sexual - vipCall Girls in Lahore || 03081633338 || 50+ ❤️ Sexy Girls Babes for Sexual - vip
Call Girls in Lahore || 03081633338 || 50+ ❤️ Sexy Girls Babes for Sexual - vipAyesha Khan
 
Call Girls in Karachi || 03081633338 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03081633338 || 50+ Hot Sexy Girls Available 24/7Call Girls in Karachi || 03081633338 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03081633338 || 50+ Hot Sexy Girls Available 24/7Ayesha Khan
 
Call Girls in Chattarpur Delhi 💯 Call Us 🔝9667422720🔝
Call Girls in Chattarpur Delhi 💯 Call Us 🔝9667422720🔝Call Girls in Chattarpur Delhi 💯 Call Us 🔝9667422720🔝
Call Girls in Chattarpur Delhi 💯 Call Us 🔝9667422720🔝Lipikasharma29
 
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...aakahthapa70
 
Call Girls In {Green Park Delhi} 9667938988 Indian Russian High Profile Girls...
Call Girls In {Green Park Delhi} 9667938988 Indian Russian High Profile Girls...Call Girls In {Green Park Delhi} 9667938988 Indian Russian High Profile Girls...
Call Girls In {Green Park Delhi} 9667938988 Indian Russian High Profile Girls...aakahthapa70
 
▶ ●─Cash On Delivery Call Girls In ( Sector 63 Noida )꧁❤⎝8375860717⎠❤꧂
▶ ●─Cash On Delivery Call Girls In ( Sector 63 Noida )꧁❤⎝8375860717⎠❤꧂▶ ●─Cash On Delivery Call Girls In ( Sector 63 Noida )꧁❤⎝8375860717⎠❤꧂
▶ ●─Cash On Delivery Call Girls In ( Sector 63 Noida )꧁❤⎝8375860717⎠❤꧂door45step
 

Recently uploaded (20)

Call Girls In Saket Delhi 9953056974 (Low Price) Escort Service Saket Delhi
Call Girls In Saket Delhi 9953056974 (Low Price) Escort Service Saket DelhiCall Girls In Saket Delhi 9953056974 (Low Price) Escort Service Saket Delhi
Call Girls In Saket Delhi 9953056974 (Low Price) Escort Service Saket Delhi
 
Call Us 🏨 8800357707 🔝 Call Girls in Aerocity (Delhi NCR)
Call Us  🏨 8800357707 🔝 Call Girls in Aerocity (Delhi NCR)Call Us  🏨 8800357707 🔝 Call Girls in Aerocity (Delhi NCR)
Call Us 🏨 8800357707 🔝 Call Girls in Aerocity (Delhi NCR)
 
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
 
🔝Call Girls In INA Colony Call Us ➥ 8800357707 In Call Out Call Both With Hig...
🔝Call Girls In INA Colony Call Us ➥ 8800357707 In Call Out Call Both With Hig...🔝Call Girls In INA Colony Call Us ➥ 8800357707 In Call Out Call Both With Hig...
🔝Call Girls In INA Colony Call Us ➥ 8800357707 In Call Out Call Both With Hig...
 
9811611494,Low Rate Call Girls In Connaught Place Delhi 24hrs Available
9811611494,Low Rate Call Girls In Connaught Place Delhi 24hrs Available9811611494,Low Rate Call Girls In Connaught Place Delhi 24hrs Available
9811611494,Low Rate Call Girls In Connaught Place Delhi 24hrs Available
 
(9599264170) ↫ Call Girls In Rk Puram ↫ Delhi NCR
(9599264170) ↫ Call Girls In Rk Puram ↫ Delhi NCR(9599264170) ↫ Call Girls In Rk Puram ↫ Delhi NCR
(9599264170) ↫ Call Girls In Rk Puram ↫ Delhi NCR
 
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
 
Genuine Call Girls In {Mahipalpur Delhi} 9667938988 Indian Russian High Profi...
Genuine Call Girls In {Mahipalpur Delhi} 9667938988 Indian Russian High Profi...Genuine Call Girls In {Mahipalpur Delhi} 9667938988 Indian Russian High Profi...
Genuine Call Girls In {Mahipalpur Delhi} 9667938988 Indian Russian High Profi...
 
KAKINADA CALL GIRL 92628/71154 KAKINADA C
KAKINADA CALL GIRL 92628/71154 KAKINADA CKAKINADA CALL GIRL 92628/71154 KAKINADA C
KAKINADA CALL GIRL 92628/71154 KAKINADA C
 
Call Girls in Majnu ka Tilla Delhi 💯 Call Us 🔝9711014705🔝
Call Girls in Majnu ka Tilla Delhi 💯 Call Us 🔝9711014705🔝Call Girls in Majnu ka Tilla Delhi 💯 Call Us 🔝9711014705🔝
Call Girls in Majnu ka Tilla Delhi 💯 Call Us 🔝9711014705🔝
 
Call Girls In Sector 29, (Gurgaon) Call Us. 9711911712
Call Girls In Sector 29, (Gurgaon) Call Us. 9711911712Call Girls In Sector 29, (Gurgaon) Call Us. 9711911712
Call Girls In Sector 29, (Gurgaon) Call Us. 9711911712
 
100% Real Call Girls In New Ashok Nagar Delhi | Just Call 9711911712
100% Real Call Girls In New Ashok Nagar Delhi | Just Call 9711911712100% Real Call Girls In New Ashok Nagar Delhi | Just Call 9711911712
100% Real Call Girls In New Ashok Nagar Delhi | Just Call 9711911712
 
NAGPUR CALL GIRL 92628*71154 NAGPUR CALL
NAGPUR CALL GIRL 92628*71154 NAGPUR CALLNAGPUR CALL GIRL 92628*71154 NAGPUR CALL
NAGPUR CALL GIRL 92628*71154 NAGPUR CALL
 
💚😋Bangalore Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Bangalore Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Bangalore Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Bangalore Escort Service Call Girls, ₹5000 To 25K With AC💚😋
 
Call Girls in Lahore || 03081633338 || 50+ ❤️ Sexy Girls Babes for Sexual - vip
Call Girls in Lahore || 03081633338 || 50+ ❤️ Sexy Girls Babes for Sexual - vipCall Girls in Lahore || 03081633338 || 50+ ❤️ Sexy Girls Babes for Sexual - vip
Call Girls in Lahore || 03081633338 || 50+ ❤️ Sexy Girls Babes for Sexual - vip
 
Call Girls in Karachi || 03081633338 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03081633338 || 50+ Hot Sexy Girls Available 24/7Call Girls in Karachi || 03081633338 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03081633338 || 50+ Hot Sexy Girls Available 24/7
 
Call Girls in Chattarpur Delhi 💯 Call Us 🔝9667422720🔝
Call Girls in Chattarpur Delhi 💯 Call Us 🔝9667422720🔝Call Girls in Chattarpur Delhi 💯 Call Us 🔝9667422720🔝
Call Girls in Chattarpur Delhi 💯 Call Us 🔝9667422720🔝
 
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
 
Call Girls In {Green Park Delhi} 9667938988 Indian Russian High Profile Girls...
Call Girls In {Green Park Delhi} 9667938988 Indian Russian High Profile Girls...Call Girls In {Green Park Delhi} 9667938988 Indian Russian High Profile Girls...
Call Girls In {Green Park Delhi} 9667938988 Indian Russian High Profile Girls...
 
▶ ●─Cash On Delivery Call Girls In ( Sector 63 Noida )꧁❤⎝8375860717⎠❤꧂
▶ ●─Cash On Delivery Call Girls In ( Sector 63 Noida )꧁❤⎝8375860717⎠❤꧂▶ ●─Cash On Delivery Call Girls In ( Sector 63 Noida )꧁❤⎝8375860717⎠❤꧂
▶ ●─Cash On Delivery Call Girls In ( Sector 63 Noida )꧁❤⎝8375860717⎠❤꧂
 

Building open source identity infrastructures

  • 1. Building Open Source Identity Infrastructures Francesco Chicchiriccò ilgrosso@apache.org https://about.me/ilgrosso Building Open Source Identity Infrastructures Francesco Chicchiriccò ilgrosso@apache.org https://about.me/ilgrosso
  • 2. The Identity Management NeedThe Identity Management Need
  • 3. Identity Vs Account Source: https://saberhamidi.wordpress.com/2015/02/22/topic-2-should-we-have-more-than-one-online-identity/
  • 4. Identity Vs Account • Account • record containing data about a person • technical info needed by the information system for which the account is created and managed • (Digital) Identity • representation of a set of claims made by one digital subject about itself • ...it's you
  • 5. Why Identity Management?• Operational costs • Multiple sources of identity data • Manual user provisioning and password reset • Labor-intensive, paper-based approval • Compliance • No record of who has access to which IT resources • Difficult to deprovision access rights upon termination • No complete audit trail available • Hard to prevent unauthorized access
  • 8. Identity Technologies • Identity Stores • Storage of user information • Provisioning Engines • Synchronize account data across identity stores and a broad range of data formats, models, meanings and purposes • Access Managers • Security mechanisms that take place when a user is accessing a specific system or functionality
  • 9. Identity Store • Examples • LDAP / Active Directory • RDBMS • Meta and Virtual Directories • Accounts can be created and managed in one place only • Each application manages authentication separately • The user may use the same password for all the connected applications
  • 10. ...is it enough? • Heterogeneity of systems • Lack of a single source of information • HR for corporate id, Groupware for mail address, ... • Need for a local user database • Inconsistent policies • Lack of workflow management • Hidden infra management cost, growing with organization
  • 11. Provisioning Engine • Keeping the identity stores as much synchronized as possible (and practical) • Need to be customizable and flexible • Priority: non-intrusive • Focused on application back-end • Critical: data exchange with identity stores • Connectors • Agents
  • 13. Access Manager • Mediator to all access to all applications • Focused on application front-end • Aspects • Authentication • Single SignOn • Authorization (OAuth, XACML, ...) • Federation (SAML, Liberty, ...) • Mainly applicable to web applications • Difficult integration with pre-existing apps
  • 16. Gather... • Number and type of identities • Number of roles / groups (and what are they used for) • External resources (all covered by standard connectors?) • Approval workflow(s)? • Self-service? • Which applications to protect? • Which authentication mechanisms? • Which authorization types? ...essentially, shape the identity and access flows
  • 17. ...design... • Schema for various identities (users, roles, groups, ...) • Identify mapping for all resources • Not too complex! • Watch roles size to avoid RBAC's role explosion • Don't be tempted to redesign the whole network • Provisioning needs to be flexible • Reduce impact of access management on existing applications • Prioritize requirements
  • 18. ...build... • Carefully choose the building blocks • Can't simply buy COTS • On-premises • Proprietary • Open Source • As-a-service • Consider prototyping the designed solution (PoC)
  • 19. ...and start again • IAM is a continuous process, not a turn-key project • New applications to protect • New resources to integrate • Identity flows evolution • IAM deliveries frequently fail • Mix of complex and unrelated technologies • Unexpected interactions • Mess with internal processes • Discover Policy Vs Reality
  • 20. The Open Source Identity StackThe Open Source Identity Stack
  • 21. Open Source IAM • Why? • Flexibility, adaptability and agility • Cost effectiveness • Start small and grow • Solid information security • No vendor lock-in • Caveats • Integration with proprietary software (AD over all) • Enterprise support availability
  • 23. Selection Criteria • Open Standards • Design for integration • Well-established • Supported • Alive • ...Open Source!
  • 24. The Identity Ecosystem • Triggered by open companies in the Open Source IAM area • Common place for open source players, system integrators and service providers • Ensuring IAM open source components work well together • Easy access to enterprise support providers • Several options for each single component • More at http://www.identity-ecosystem.org/
  • 25. Real World Use CasesReal World Use Cases
  • 26. Disclaimer I am V.P. Apache Syncope and CEO of Tirasa, providing enterprise support and services for Apache Syncope, so… don't be surprised Syncope is everywhere :-) Disclaimer I am V.P. Apache Syncope and CEO of Tirasa, providing enterprise support and services for Apache Syncope, so… don't be surprised Syncope is everywhere :-)
  • 27. #1 Stadtwerke München • One of largest German municipal utilities • Mobile ticketing for public transportation and bike sharing • self-registration • login • password reset • user suspend / reactivate • > 250k registered users • > 80k authentications per day
  • 28. #2 Ospedali Riuniti Ancona • University hospital • Active synchronization from HR to Microsoft Active Directory • Centralized provisioning, authentication and authorization of medical record systems • Windows domain SSO • SAML 2.0 federation with regional network • ~ 5000 users
  • 29. #3 Stichting Bibliotheek.nl • Dutch foundation that aims to expand and manage the Digital National Library • The IAM infrastructure aims to hold all users of the national library in the Netherlands, fed by a continuous feed from the local libraries • All Dutch library members can authenticate and use digital services connected to the IAM infrastructure • > 8 million users
  • 30. #4 University of Milan • Very complex provisioning flows involving • Microsoft Active Directory • OpenLDAP • 3 different RDBMS • Oracle E-Mail Server • ~ 5k employees • > 60k students • ~ 800 roles
  • 31. Questions? All text and image content in this document is licensed under the Creative Commons Attribution-Share Alike 3.0 License (unless otherwise specified). Apache, Syncope, Apache Syncope, the Apache feather logo, the Apache Syncope project logo and the Apache Syncope logo are trademarks of The Apache Software Foundation. All other marks mentioned may be trademarks or registered trademarks of their respective owners.