SlideShare a Scribd company logo
1 of 34
Download to read offline
© Copyright & proprietary Silverside B.V.
Zero Trust on your HCL environment
24-04-2024 - - Antwerp
© Copyright & proprietary Silverside B.V.
+250
CUSTOMERS
3
PLATFORMS
28
EMPLOYEES
25 years
COLLABORATION SPECIALIST
As a specialist in the best collaboration software (including
Microsoft 365, HCL Software and Zoho ONE), we ensure
that users can collaborate smarter and better in a secure
modern digital world.
We guide organizations to the right destination based on
our experience with more than 250 customers. In addition
to our professional knowledge, we believe in happiness at
work and pleasant cooperation. This enables us to achieve
measurable results that will positively surprise you.
Are you joining us?
2
Your dedicated guide
to happiness and success
in the digital world
© Copyright & proprietary Silverside B.V.
Zero Trust in a nutshell
3
© Copyright & proprietary Silverside B.V.
4
© Copyright & proprietary Silverside B.V.
5
Why Zero Trust
Zero Trust in a nutshell
versus
Never trust, always verify
© Copyright & proprietary Silverside B.V.
Verify Explicitly
Always authenticate and
authorize based on all
available data points,
including user identity,
location, device health,
service or workload, data
classification, and anomalies.
6
3 Basic Principles
Zero Trust in a nutshell
© Copyright & proprietary Silverside B.V.
Least Privileged Access
7
3 Basic Principles
Zero Trust in a nutshell
Limit user access with Just-
In-Time and Just-Enough
Access (JIT/JEA), risk-based
adaptive polices, and data
protection to protect both
data and productivity.
© Copyright & proprietary Silverside B.V.
Minimize blast radius for
breaches and prevent lateral
movement by segmenting
access by network, user,
devices, and application
awareness. Verify all sessions
are encrypted end to end.
Use analytics to get visibility,
drive threat detection, and
improve defenses.
8
3 Basic Principles
Zero Trust in a nutshell
Assume Breach
© Copyright & proprietary Silverside B.V.
9
Technology Pillers
Zero Trust in a nutshell
© Copyright & proprietary Silverside B.V.
10
HCL Software and Zero Trust
HCL Connections with Zero Trust Identity
To see what the Zero Trust principles can do with HCL products we
have a few examples:
• HCL Connections with Zero Trust Identity
• Zero Trust Domino security
© Copyright & proprietary Silverside B.V.
HCL Connections with Zero Trust
11
© Copyright & proprietary Silverside B.V.
12
Implement a single user repository
HCL Connections with Zero Trust Identity
Requirements:
• Microsoft Entra ID as main user repository
• Guest access should be supported
• Strong Authentication
Solution:
• Use SAML and OpenID Connect (OIDC) for federation with Microsoft Entra ID
• This does not remove the need for an LDAP repository
© Copyright & proprietary Silverside B.V.
13
LDAP repository
HCL Connections with Zero Trust Identity
Possible options:
• Local Active Directory synchronized with Entra ID Connect
• Use Microsoft Entra ID Domain Services
• An alternative LDAP server that is synchronized with Entra ID
• All users, including guests should be managed within
Active Directory or a different LDAP repository
• A relatively expensive and complex option (starts at 110
euro per month and can go to up +1000 euro)
• Provisioning to an LDAP target is included with Entra ID
Premium P1 and can be combined with OpenLDAP.
© Copyright & proprietary Silverside B.V.
14
Entra ID LDAP provisioning
HCL Connections with Zero Trust Identity
The agent runs on an on-premises server and only requires outbound connectivity
Entra ID Provision Service
Microsoft ECMA
Connector Agent
User Data User Data
© Copyright & proprietary Silverside B.V.
15
OpenLDAP Server
HCL Connections with Zero Trust Identity
1. Configure an OpenLDAP server
2. Setup the LDAP repository on WebSphere
3. Setup the SDI synchronization
TIP: Use different OUs for internal and external account
IBM WebSphere Application Server
IBM DB2
IBM Security Directory Integrator
OpenLDAP
© Copyright & proprietary Silverside B.V.
16
Setup the provisioning
HCL Connections with Zero Trust Identity
Create 2 new Enterprise Applications in Entra ID
• Internal Users
• External Users
© Copyright & proprietary Silverside B.V.
17
Attribute Mapping
HCL Connections with Zero Trust Identity
Make sure that at least the following attributes are configured:
• distinguishedname
• displayName
• givenName
• sn
• uid
• mail
© Copyright & proprietary Silverside B.V.
18
Install and configure the provision agent
HCL Connections with Zero Trust Identity
© Copyright & proprietary Silverside B.V.
19
The result
HCL Connections with Zero Trust Identity
© Copyright & proprietary Silverside B.V.
20
Enable OIDC single sign-on
HCL Connections with Zero Trust Identity
When you now enable OIDC single sign-on
all users will get the Microsoft login pages.
As a result, all security options from Entra ID
will be in place. Including MFA
© Copyright & proprietary Silverside B.V.
Zero Trust and HCL Domino
21
© Copyright & proprietary Silverside B.V.
22
Zero Trust and HCL Domino
Zero Trust – Domino
© Copyright & proprietary Silverside B.V.
23
Zero Trust – Domino
• Login handed over to a standardized "Identity Provider" (IdP); Windows ADFS, MS 365 EntraID, JumpCloud, etc
• It's not a Microsoft proprietary lock-in thing; SAML/ OIDC are std. protocols - there are many IdP providers
• An IdP specializes in secure authentication; user/ pwd, MFA, biometrics, region, trusted sites/ devices
• Single login, used for multiple applications; Notes, Nomad Web, Verse, SameTime, Zoho CRM, etc - Not a synced password!
• Optionally automated login to IdP from trusted device/ network/ Windows account
• Reduce login, prevents multiple login prompts, different passwords and user confusion
© Copyright & proprietary Silverside B.V.
24
Zero Trust – Domino
• The IdP tells Domino that the user is "john.doe@acme.com", through a signed certificate
• Domino validates the signature
• Links user e-mail 'claim' to a Domino user
• User is authenticated
• Extracts id-file from id-vault, kept in RAM
Service Providers (SP)
• Notes client
• Verse mail
• Sametime
• Nomad Web . . .
© Copyright & proprietary Silverside B.V.
25
Zero Trust – Domino
IdP does the authentication, but Notes/ Domino still need to be secure!
• User authenticated by IdP but unknown in Domino, ends up with Default access rights
• Restrict server-access to group or */Org, all users in Address book
• Maintain Deny Access group(s); sync account status from AD/ Entra, detect inactive users in userlicenses.nsf
• Enforce server access settings for all protocols
• Disable Anonymous access (uses 'Default' if not explicitly disabled/ set)
• Notes certificates 1-2 years
• Enable Check public keys
• Enable Internet Lockout
• Set Vaulted IDs Notes to complex passwords, Remove ID-files from person docs
• Vault extract disable by username/ password
• Set a password on server.id
• Remove cert.id/ admin.id from Domino data-folder
• . . .
© Copyright & proprietary Silverside B.V.
26
Zero Trust – Domino
Traveler - No SAML or OIDC with autologin yet
• iPhone mail app
• Traveler app
• Allow registered devices only
• Set a complex internet password trough a QR-code
• Add certificate based authentication
• Disable web-access to .nsf
© Copyright & proprietary Silverside B.V.
27
Zero Trust – Domino
• Assume OS will be compromised
• Implement client/ server .nsf encryption, DAOS encrypted by default
• Set server.id password
• Use read-only accounts where possible (ie ldap bind)
© Copyright & proprietary Silverside B.V.
28
Zero Trust – Domino
• Close unused protocol/ services
• Have a default website for each web-enabled Domino server
• Lockdown default/ anonymous ACL
• Set maximum web access on your .nsf's
• Create ip traps for *.php, *.aspx, etc
© Copyright & proprietary Silverside B.V.
29
Zero Trust – Domino
Mail
• Implement SPF and DKIM, DMARC
• Check your DMARC RUA reports
• Server mail-rules to block external mail from 'hrm@', Manager names, etc
• Use cloud-based spam filters like Mimecast - specialized/ quick reaction
• Train and exercise users on phishing
© Copyright & proprietary Silverside B.V.
30
Zero Trust – Domino
• Enable NRPC port-encryption (client and server)
• Always use TLS for web, smtp, ldap, etc protocols
• Use read-only accounts where possible - ie LDAP bind
• Restrict which hosts can offer (relay) mail to Domino SMTP
• Close ports not needed
© Copyright & proprietary Silverside B.V.
31
Zero Trust – Domino
• Implement network segmentation; put servers, clients and guests in separate networks
• Send cluster traffic over a private network
• Enable firewall on Domino' host/ LAN segments
• Close Domino ports not needed
• Setup reverse [authenticated] http-proxy before web-access
© Copyright & proprietary Silverside B.V.
32
Zero Trust – Domino
• Monitor domlog/ session logs - automatically check source IP/ country
• Build/ collect normal IP-range list
• Sync user status (enabled/ disabled/ removed) with AD/ Entra/ HRM
• Auto-disable accounts not active for x months
• Notes certificate renewal every 1-2 year, validate before renewal
• Enable traps on .php, .aspx, . . . requests and block source-ip
© Copyright & proprietary Silverside B.V.
33
Zero Trust – Domino
Covers a lot
There is no single check-box "Enable Zero Trust"
It is a process/ goal/ framework
Hire a professional
© Copyright & proprietary Silverside B.V.
Thank You!
34
WRAP-UP: ANY QUESTIONS?
Silverside B.V.
Rivium Quadrant 75-5 Capelle aan den IJssel The Netherlands
www.silverside.com
Gert van Kempen
Senior Consultant
g.vankempen@silverside.com
+31 6 22512674
Duco Bergsma
Senior Consultant
d.bergsma@silverside.com
+31 6 51087117

More Related Content

Similar to Ensure the security of your HCL environment by applying the Zero Trust principles

Slide 1 - Authenticated Reseller SSL Certificate Authority
Slide 1 - Authenticated Reseller SSL Certificate AuthoritySlide 1 - Authenticated Reseller SSL Certificate Authority
Slide 1 - Authenticated Reseller SSL Certificate Authority
webhostingguy
 
Openstack identity protocols unconference
Openstack identity protocols unconferenceOpenstack identity protocols unconference
Openstack identity protocols unconference
David Waite
 
Roadmap for Engage - HCL domino and versions
Roadmap for Engage - HCL domino and versionsRoadmap for Engage - HCL domino and versions
Roadmap for Engage - HCL domino and versions
ssuser82a6381
 

Similar to Ensure the security of your HCL environment by applying the Zero Trust principles (20)

Deep Dive on Lambda@Edge - August 2017 AWS Online Tech Talks
Deep Dive on Lambda@Edge - August 2017 AWS Online Tech TalksDeep Dive on Lambda@Edge - August 2017 AWS Online Tech Talks
Deep Dive on Lambda@Edge - August 2017 AWS Online Tech Talks
 
Office 365-single-sign-on-with-adfs
Office 365-single-sign-on-with-adfsOffice 365-single-sign-on-with-adfs
Office 365-single-sign-on-with-adfs
 
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB201904_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
 
HCL Domino V12 Key Security Features Overview
HCL Domino V12 Key Security Features Overview HCL Domino V12 Key Security Features Overview
HCL Domino V12 Key Security Features Overview
 
Slide 1 - Authenticated Reseller SSL Certificate Authority
Slide 1 - Authenticated Reseller SSL Certificate AuthoritySlide 1 - Authenticated Reseller SSL Certificate Authority
Slide 1 - Authenticated Reseller SSL Certificate Authority
 
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
 
Cisco-Wireless-Guest-v10.pptx
Cisco-Wireless-Guest-v10.pptxCisco-Wireless-Guest-v10.pptx
Cisco-Wireless-Guest-v10.pptx
 
CIS 2015 Extreme OpenID Connect - John Bradley
CIS 2015 Extreme OpenID Connect - John BradleyCIS 2015 Extreme OpenID Connect - John Bradley
CIS 2015 Extreme OpenID Connect - John Bradley
 
Openstack identity protocols unconference
Openstack identity protocols unconferenceOpenstack identity protocols unconference
Openstack identity protocols unconference
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 
Envision it Webinar - Extranet Identity Management and Authentication for Sha...
Envision it Webinar - Extranet Identity Management and Authentication for Sha...Envision it Webinar - Extranet Identity Management and Authentication for Sha...
Envision it Webinar - Extranet Identity Management and Authentication for Sha...
 
Keeping your collaboration safe while working remotely
Keeping your collaboration safe while working remotelyKeeping your collaboration safe while working remotely
Keeping your collaboration safe while working remotely
 
Exploring Advanced Authentication Methods in Novell Access Manager
Exploring Advanced Authentication Methods in Novell Access ManagerExploring Advanced Authentication Methods in Novell Access Manager
Exploring Advanced Authentication Methods in Novell Access Manager
 
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
 
Identity Management with the ForgeRock Identity Platform - So What’s New?
Identity Management with the ForgeRock Identity Platform - So What’s New?Identity Management with the ForgeRock Identity Platform - So What’s New?
Identity Management with the ForgeRock Identity Platform - So What’s New?
 
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
 
Mojemoje
MojemojeMojemoje
Mojemoje
 
CIS13: Bootcamp: PingOne as a Simple Identity Service
CIS13: Bootcamp: PingOne as a Simple Identity ServiceCIS13: Bootcamp: PingOne as a Simple Identity Service
CIS13: Bootcamp: PingOne as a Simple Identity Service
 
The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)
 
Roadmap for Engage - HCL domino and versions
Roadmap for Engage - HCL domino and versionsRoadmap for Engage - HCL domino and versions
Roadmap for Engage - HCL domino and versions
 

More from Roland Driesen

Pace.birth of cca.en.public
Pace.birth of cca.en.publicPace.birth of cca.en.public
Pace.birth of cca.en.public
Roland Driesen
 

More from Roland Driesen (20)

PACE, the roadmap for successful user adoption
PACE, the roadmap for successful user adoptionPACE, the roadmap for successful user adoption
PACE, the roadmap for successful user adoption
 
HCL Connections fully implemented at accounting firm NEVB
HCL Connections fully implemented at accounting firm NEVBHCL Connections fully implemented at accounting firm NEVB
HCL Connections fully implemented at accounting firm NEVB
 
What if we adapt the adoption? Change approach based on digital literacy and ...
What if we adapt the adoption? Change approach based on digital literacy and ...What if we adapt the adoption? Change approach based on digital literacy and ...
What if we adapt the adoption? Change approach based on digital literacy and ...
 
Use your IBM Collaboration tools smarter to make your work less stressful
Use your IBM Collaboration tools smarter to make your work less stressfulUse your IBM Collaboration tools smarter to make your work less stressful
Use your IBM Collaboration tools smarter to make your work less stressful
 
PACE Roadmap - Presentation during Engage 2018
PACE Roadmap - Presentation during Engage 2018PACE Roadmap - Presentation during Engage 2018
PACE Roadmap - Presentation during Engage 2018
 
Pace.birth of cca.en.public
Pace.birth of cca.en.publicPace.birth of cca.en.public
Pace.birth of cca.en.public
 
Uitnodiging IGNITE COMES TO YOU – 2017 EDITION
Uitnodiging IGNITE COMES TO YOU – 2017 EDITIONUitnodiging IGNITE COMES TO YOU – 2017 EDITION
Uitnodiging IGNITE COMES TO YOU – 2017 EDITION
 
20170706.moeten naarwillen.hvg.nl
20170706.moeten naarwillen.hvg.nl20170706.moeten naarwillen.hvg.nl
20170706.moeten naarwillen.hvg.nl
 
20170706.wrap up.rhd.nl
20170706.wrap up.rhd.nl20170706.wrap up.rhd.nl
20170706.wrap up.rhd.nl
 
20170706.deeper.rhd.nl
20170706.deeper.rhd.nl20170706.deeper.rhd.nl
20170706.deeper.rhd.nl
 
20170706.keynote.rhd.nl
20170706.keynote.rhd.nl20170706.keynote.rhd.nl
20170706.keynote.rhd.nl
 
Connecting Colours - Teamontwikkeling met Insights Discovery
Connecting Colours - Teamontwikkeling met Insights DiscoveryConnecting Colours - Teamontwikkeling met Insights Discovery
Connecting Colours - Teamontwikkeling met Insights Discovery
 
A new way of Knowledge Networking
A new way of Knowledge NetworkingA new way of Knowledge Networking
A new way of Knowledge Networking
 
Engage 2016 - IBM Verse
Engage 2016 - IBM VerseEngage 2016 - IBM Verse
Engage 2016 - IBM Verse
 
Engage 2016 - Running a collaborative business
Engage 2016 - Running a collaborative businessEngage 2016 - Running a collaborative business
Engage 2016 - Running a collaborative business
 
To adapt, or not to adapt - that is the question!
To adapt, or not to adapt - that is the question!To adapt, or not to adapt - that is the question!
To adapt, or not to adapt - that is the question!
 
Change to the cloud: by psychology pull or technology push?
Change to the cloud: by psychology pull or technology push?Change to the cloud: by psychology pull or technology push?
Change to the cloud: by psychology pull or technology push?
 
Het Nieuwe Werken: de praktijkcase van Silverside
Het Nieuwe Werken: de praktijkcase van SilversideHet Nieuwe Werken: de praktijkcase van Silverside
Het Nieuwe Werken: de praktijkcase van Silverside
 
Welkom in 010: Openingsfeest Silverside
Welkom in 010: Openingsfeest SilversideWelkom in 010: Openingsfeest Silverside
Welkom in 010: Openingsfeest Silverside
 
20141009 michael sampson uitnodiging
20141009 michael sampson uitnodiging20141009 michael sampson uitnodiging
20141009 michael sampson uitnodiging
 

Recently uploaded

如何办理(SUT毕业证书)斯威本科技大学毕业证成绩单本科硕士学位证留信学历认证
如何办理(SUT毕业证书)斯威本科技大学毕业证成绩单本科硕士学位证留信学历认证如何办理(SUT毕业证书)斯威本科技大学毕业证成绩单本科硕士学位证留信学历认证
如何办理(SUT毕业证书)斯威本科技大学毕业证成绩单本科硕士学位证留信学历认证
ogawka
 
Presentation4 (2) survey responses clearly labelled
Presentation4 (2) survey responses clearly labelledPresentation4 (2) survey responses clearly labelled
Presentation4 (2) survey responses clearly labelled
CaitlinCummins3
 
What is paper chromatography, principal, procedure,types, diagram, advantages...
What is paper chromatography, principal, procedure,types, diagram, advantages...What is paper chromatography, principal, procedure,types, diagram, advantages...
What is paper chromatography, principal, procedure,types, diagram, advantages...
srcw2322l101
 
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in PakistanChallenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
vineshkumarsajnani12
 
Powerpoint showing results from tik tok metrics
Powerpoint showing results from tik tok metricsPowerpoint showing results from tik tok metrics
Powerpoint showing results from tik tok metrics
CaitlinCummins3
 
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![© ر
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![©  ر00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![©  ر
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![© ر
nafizanafzal
 

Recently uploaded (20)

如何办理(SUT毕业证书)斯威本科技大学毕业证成绩单本科硕士学位证留信学历认证
如何办理(SUT毕业证书)斯威本科技大学毕业证成绩单本科硕士学位证留信学历认证如何办理(SUT毕业证书)斯威本科技大学毕业证成绩单本科硕士学位证留信学历认证
如何办理(SUT毕业证书)斯威本科技大学毕业证成绩单本科硕士学位证留信学历认证
 
Understanding Financial Accounting 3rd Canadian Edition by Christopher D. Bur...
Understanding Financial Accounting 3rd Canadian Edition by Christopher D. Bur...Understanding Financial Accounting 3rd Canadian Edition by Christopher D. Bur...
Understanding Financial Accounting 3rd Canadian Edition by Christopher D. Bur...
 
A DAY IN LIFE OF A NEGOTIATOR By Pondicherry University MBA Students.pptx
A DAY IN LIFE OF A NEGOTIATOR By Pondicherry University MBA Students.pptxA DAY IN LIFE OF A NEGOTIATOR By Pondicherry University MBA Students.pptx
A DAY IN LIFE OF A NEGOTIATOR By Pondicherry University MBA Students.pptx
 
Chapter 2 Organization Structure of a Treasury
Chapter 2 Organization Structure of a TreasuryChapter 2 Organization Structure of a Treasury
Chapter 2 Organization Structure of a Treasury
 
10 Easiest Ways To Buy Verified TransferWise Accounts
10 Easiest Ways To Buy Verified TransferWise Accounts10 Easiest Ways To Buy Verified TransferWise Accounts
10 Easiest Ways To Buy Verified TransferWise Accounts
 
Presentation4 (2) survey responses clearly labelled
Presentation4 (2) survey responses clearly labelledPresentation4 (2) survey responses clearly labelled
Presentation4 (2) survey responses clearly labelled
 
Home Furnishings Ecommerce Platform Short Pitch 2024
Home Furnishings Ecommerce Platform Short Pitch 2024Home Furnishings Ecommerce Platform Short Pitch 2024
Home Furnishings Ecommerce Platform Short Pitch 2024
 
What is paper chromatography, principal, procedure,types, diagram, advantages...
What is paper chromatography, principal, procedure,types, diagram, advantages...What is paper chromatography, principal, procedure,types, diagram, advantages...
What is paper chromatography, principal, procedure,types, diagram, advantages...
 
A DAY IN THE LIFE OF A SALESPERSON .pptx
A DAY IN THE LIFE OF A SALESPERSON .pptxA DAY IN THE LIFE OF A SALESPERSON .pptx
A DAY IN THE LIFE OF A SALESPERSON .pptx
 
Beyond Numbers A Holistic Approach to Forensic Accounting
Beyond Numbers A Holistic Approach to Forensic AccountingBeyond Numbers A Holistic Approach to Forensic Accounting
Beyond Numbers A Holistic Approach to Forensic Accounting
 
WheelTug Short Pitch Deck 2024 | Byond Insights
WheelTug Short Pitch Deck 2024 | Byond InsightsWheelTug Short Pitch Deck 2024 | Byond Insights
WheelTug Short Pitch Deck 2024 | Byond Insights
 
The Art of Decision-Making: Navigating Complexity and Uncertainty
The Art of Decision-Making: Navigating Complexity and UncertaintyThe Art of Decision-Making: Navigating Complexity and Uncertainty
The Art of Decision-Making: Navigating Complexity and Uncertainty
 
Progress Report - UKG Analyst Summit 2024 - A lot to do - Good Progress1-1.pdf
Progress Report - UKG Analyst Summit 2024 - A lot to do - Good Progress1-1.pdfProgress Report - UKG Analyst Summit 2024 - A lot to do - Good Progress1-1.pdf
Progress Report - UKG Analyst Summit 2024 - A lot to do - Good Progress1-1.pdf
 
How Bookkeeping helps you in Cost Saving, Tax Saving and Smooth Business Runn...
How Bookkeeping helps you in Cost Saving, Tax Saving and Smooth Business Runn...How Bookkeeping helps you in Cost Saving, Tax Saving and Smooth Business Runn...
How Bookkeeping helps you in Cost Saving, Tax Saving and Smooth Business Runn...
 
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in PakistanChallenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
 
Powerpoint showing results from tik tok metrics
Powerpoint showing results from tik tok metricsPowerpoint showing results from tik tok metrics
Powerpoint showing results from tik tok metrics
 
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![© ر
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![©  ر00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![©  ر
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![© ر
 
Most Visionary Leaders in Cloud Revolution, Shaping Tech’s Next Era - 2024 (2...
Most Visionary Leaders in Cloud Revolution, Shaping Tech’s Next Era - 2024 (2...Most Visionary Leaders in Cloud Revolution, Shaping Tech’s Next Era - 2024 (2...
Most Visionary Leaders in Cloud Revolution, Shaping Tech’s Next Era - 2024 (2...
 
First Time Home Buyer's Guide - KM Realty Group LLC
First Time Home Buyer's Guide - KM Realty Group LLCFirst Time Home Buyer's Guide - KM Realty Group LLC
First Time Home Buyer's Guide - KM Realty Group LLC
 
Navigating Tax Season with Confidence Streamlines CPA Firms
Navigating Tax Season with Confidence Streamlines CPA FirmsNavigating Tax Season with Confidence Streamlines CPA Firms
Navigating Tax Season with Confidence Streamlines CPA Firms
 

Ensure the security of your HCL environment by applying the Zero Trust principles

  • 1. © Copyright & proprietary Silverside B.V. Zero Trust on your HCL environment 24-04-2024 - - Antwerp
  • 2. © Copyright & proprietary Silverside B.V. +250 CUSTOMERS 3 PLATFORMS 28 EMPLOYEES 25 years COLLABORATION SPECIALIST As a specialist in the best collaboration software (including Microsoft 365, HCL Software and Zoho ONE), we ensure that users can collaborate smarter and better in a secure modern digital world. We guide organizations to the right destination based on our experience with more than 250 customers. In addition to our professional knowledge, we believe in happiness at work and pleasant cooperation. This enables us to achieve measurable results that will positively surprise you. Are you joining us? 2 Your dedicated guide to happiness and success in the digital world
  • 3. © Copyright & proprietary Silverside B.V. Zero Trust in a nutshell 3
  • 4. © Copyright & proprietary Silverside B.V. 4
  • 5. © Copyright & proprietary Silverside B.V. 5 Why Zero Trust Zero Trust in a nutshell versus Never trust, always verify
  • 6. © Copyright & proprietary Silverside B.V. Verify Explicitly Always authenticate and authorize based on all available data points, including user identity, location, device health, service or workload, data classification, and anomalies. 6 3 Basic Principles Zero Trust in a nutshell
  • 7. © Copyright & proprietary Silverside B.V. Least Privileged Access 7 3 Basic Principles Zero Trust in a nutshell Limit user access with Just- In-Time and Just-Enough Access (JIT/JEA), risk-based adaptive polices, and data protection to protect both data and productivity.
  • 8. © Copyright & proprietary Silverside B.V. Minimize blast radius for breaches and prevent lateral movement by segmenting access by network, user, devices, and application awareness. Verify all sessions are encrypted end to end. Use analytics to get visibility, drive threat detection, and improve defenses. 8 3 Basic Principles Zero Trust in a nutshell Assume Breach
  • 9. © Copyright & proprietary Silverside B.V. 9 Technology Pillers Zero Trust in a nutshell
  • 10. © Copyright & proprietary Silverside B.V. 10 HCL Software and Zero Trust HCL Connections with Zero Trust Identity To see what the Zero Trust principles can do with HCL products we have a few examples: • HCL Connections with Zero Trust Identity • Zero Trust Domino security
  • 11. © Copyright & proprietary Silverside B.V. HCL Connections with Zero Trust 11
  • 12. © Copyright & proprietary Silverside B.V. 12 Implement a single user repository HCL Connections with Zero Trust Identity Requirements: • Microsoft Entra ID as main user repository • Guest access should be supported • Strong Authentication Solution: • Use SAML and OpenID Connect (OIDC) for federation with Microsoft Entra ID • This does not remove the need for an LDAP repository
  • 13. © Copyright & proprietary Silverside B.V. 13 LDAP repository HCL Connections with Zero Trust Identity Possible options: • Local Active Directory synchronized with Entra ID Connect • Use Microsoft Entra ID Domain Services • An alternative LDAP server that is synchronized with Entra ID • All users, including guests should be managed within Active Directory or a different LDAP repository • A relatively expensive and complex option (starts at 110 euro per month and can go to up +1000 euro) • Provisioning to an LDAP target is included with Entra ID Premium P1 and can be combined with OpenLDAP.
  • 14. © Copyright & proprietary Silverside B.V. 14 Entra ID LDAP provisioning HCL Connections with Zero Trust Identity The agent runs on an on-premises server and only requires outbound connectivity Entra ID Provision Service Microsoft ECMA Connector Agent User Data User Data
  • 15. © Copyright & proprietary Silverside B.V. 15 OpenLDAP Server HCL Connections with Zero Trust Identity 1. Configure an OpenLDAP server 2. Setup the LDAP repository on WebSphere 3. Setup the SDI synchronization TIP: Use different OUs for internal and external account IBM WebSphere Application Server IBM DB2 IBM Security Directory Integrator OpenLDAP
  • 16. © Copyright & proprietary Silverside B.V. 16 Setup the provisioning HCL Connections with Zero Trust Identity Create 2 new Enterprise Applications in Entra ID • Internal Users • External Users
  • 17. © Copyright & proprietary Silverside B.V. 17 Attribute Mapping HCL Connections with Zero Trust Identity Make sure that at least the following attributes are configured: • distinguishedname • displayName • givenName • sn • uid • mail
  • 18. © Copyright & proprietary Silverside B.V. 18 Install and configure the provision agent HCL Connections with Zero Trust Identity
  • 19. © Copyright & proprietary Silverside B.V. 19 The result HCL Connections with Zero Trust Identity
  • 20. © Copyright & proprietary Silverside B.V. 20 Enable OIDC single sign-on HCL Connections with Zero Trust Identity When you now enable OIDC single sign-on all users will get the Microsoft login pages. As a result, all security options from Entra ID will be in place. Including MFA
  • 21. © Copyright & proprietary Silverside B.V. Zero Trust and HCL Domino 21
  • 22. © Copyright & proprietary Silverside B.V. 22 Zero Trust and HCL Domino Zero Trust – Domino
  • 23. © Copyright & proprietary Silverside B.V. 23 Zero Trust – Domino • Login handed over to a standardized "Identity Provider" (IdP); Windows ADFS, MS 365 EntraID, JumpCloud, etc • It's not a Microsoft proprietary lock-in thing; SAML/ OIDC are std. protocols - there are many IdP providers • An IdP specializes in secure authentication; user/ pwd, MFA, biometrics, region, trusted sites/ devices • Single login, used for multiple applications; Notes, Nomad Web, Verse, SameTime, Zoho CRM, etc - Not a synced password! • Optionally automated login to IdP from trusted device/ network/ Windows account • Reduce login, prevents multiple login prompts, different passwords and user confusion
  • 24. © Copyright & proprietary Silverside B.V. 24 Zero Trust – Domino • The IdP tells Domino that the user is "john.doe@acme.com", through a signed certificate • Domino validates the signature • Links user e-mail 'claim' to a Domino user • User is authenticated • Extracts id-file from id-vault, kept in RAM Service Providers (SP) • Notes client • Verse mail • Sametime • Nomad Web . . .
  • 25. © Copyright & proprietary Silverside B.V. 25 Zero Trust – Domino IdP does the authentication, but Notes/ Domino still need to be secure! • User authenticated by IdP but unknown in Domino, ends up with Default access rights • Restrict server-access to group or */Org, all users in Address book • Maintain Deny Access group(s); sync account status from AD/ Entra, detect inactive users in userlicenses.nsf • Enforce server access settings for all protocols • Disable Anonymous access (uses 'Default' if not explicitly disabled/ set) • Notes certificates 1-2 years • Enable Check public keys • Enable Internet Lockout • Set Vaulted IDs Notes to complex passwords, Remove ID-files from person docs • Vault extract disable by username/ password • Set a password on server.id • Remove cert.id/ admin.id from Domino data-folder • . . .
  • 26. © Copyright & proprietary Silverside B.V. 26 Zero Trust – Domino Traveler - No SAML or OIDC with autologin yet • iPhone mail app • Traveler app • Allow registered devices only • Set a complex internet password trough a QR-code • Add certificate based authentication • Disable web-access to .nsf
  • 27. © Copyright & proprietary Silverside B.V. 27 Zero Trust – Domino • Assume OS will be compromised • Implement client/ server .nsf encryption, DAOS encrypted by default • Set server.id password • Use read-only accounts where possible (ie ldap bind)
  • 28. © Copyright & proprietary Silverside B.V. 28 Zero Trust – Domino • Close unused protocol/ services • Have a default website for each web-enabled Domino server • Lockdown default/ anonymous ACL • Set maximum web access on your .nsf's • Create ip traps for *.php, *.aspx, etc
  • 29. © Copyright & proprietary Silverside B.V. 29 Zero Trust – Domino Mail • Implement SPF and DKIM, DMARC • Check your DMARC RUA reports • Server mail-rules to block external mail from 'hrm@', Manager names, etc • Use cloud-based spam filters like Mimecast - specialized/ quick reaction • Train and exercise users on phishing
  • 30. © Copyright & proprietary Silverside B.V. 30 Zero Trust – Domino • Enable NRPC port-encryption (client and server) • Always use TLS for web, smtp, ldap, etc protocols • Use read-only accounts where possible - ie LDAP bind • Restrict which hosts can offer (relay) mail to Domino SMTP • Close ports not needed
  • 31. © Copyright & proprietary Silverside B.V. 31 Zero Trust – Domino • Implement network segmentation; put servers, clients and guests in separate networks • Send cluster traffic over a private network • Enable firewall on Domino' host/ LAN segments • Close Domino ports not needed • Setup reverse [authenticated] http-proxy before web-access
  • 32. © Copyright & proprietary Silverside B.V. 32 Zero Trust – Domino • Monitor domlog/ session logs - automatically check source IP/ country • Build/ collect normal IP-range list • Sync user status (enabled/ disabled/ removed) with AD/ Entra/ HRM • Auto-disable accounts not active for x months • Notes certificate renewal every 1-2 year, validate before renewal • Enable traps on .php, .aspx, . . . requests and block source-ip
  • 33. © Copyright & proprietary Silverside B.V. 33 Zero Trust – Domino Covers a lot There is no single check-box "Enable Zero Trust" It is a process/ goal/ framework Hire a professional
  • 34. © Copyright & proprietary Silverside B.V. Thank You! 34 WRAP-UP: ANY QUESTIONS? Silverside B.V. Rivium Quadrant 75-5 Capelle aan den IJssel The Netherlands www.silverside.com Gert van Kempen Senior Consultant g.vankempen@silverside.com +31 6 22512674 Duco Bergsma Senior Consultant d.bergsma@silverside.com +31 6 51087117