セールスフォース・ドットコム identity & security

22

Upload: salesforce-developers-japan

Post on 12-Jul-2015

314 views

Category:

Technology


0 download

TRANSCRIPT

  • CISSP

    Identity & Security

  • Safe Harbor Safe harbor statement under the Private Securities Litigation Reform Act of 1995: This presentation may contain forward-looking statements that involve risks, uncertainties, and assumptions. If any such uncertainties materialize or if any of the assumptions proves incorrect, the results of salesforce.com, inc. could dier materially from the results expressed or implied by the forward-looking statements we make. All statements other than statements of historical fact could be deemed forward-looking, including any projections of subscriber growth, earnings, revenues, or other nancial items and any statements regarding strategies or plans of management for future operations, statements of belief, any statements concerning new, planned, or upgraded services or technology developments and customer contracts or use of our services. The risks and uncertainties referred to above include but are not limited to risks associated with developing and delivering new functionality for our service, our new business model, our past operating losses, possible uctuations in our operating results and rate of growth, interruptions or delays in our Web hosting, breach of our security measures, risks associated with possible mergers and acquisitions, the immature market in which we operate, our relatively limited operating history, our ability to expand, retain, and motivate our employees and manage our growth, new releases of our service and successful customer deployment, our limited history reselling non-salesforce.com products, and utilization and selling to larger enterprise customers. Further information on potential factors that could aect the nancial results of salesforce.com, inc. is included in our annual report on Form 10-K for the most recent scal quarter. This document and others are available on the SEC Filings section of the Investor Information section of our Web site. Any unreleased services or features referenced in this or other press releases or public statements are not currently available and may not be delivered on time or at all. Customers who purchase our services should make the purchase decisions based upon features that are currently available. Salesforce.com, inc. assumes no obligation and does not intend to update these forward-looking statements.

  • Salesforce Identity Identity

  • SAML Appexchange Identity Connect Event Log File (Winter15

  • SAML SAML2.0 OpenAM, Microsoft, Icewall, Oracle, IBM) OAuth2.0/OpenID Connect (Google, Amazon, Facebook, LinkedIn, Microsoft ACS)

  • IDSalesforce

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password

    ID/Password ID/Password

    ID/Password

  • IDSalesforce

    ID/Password

    Active Directory

  • Appexchange

  • Identity Connect Active DirectorySalesforce ADFSActive DirectorySAML

  • LDAP single sign-on and

    user sync

    Windows Linux

    HTTPS trust

  • LDAP

    single sign-on and user sync

    Windows Linux

    HTTPS

    trust

    trust

    Active Directory

    LDAP single sign-on and

    user sync

    /

  • Event Log File (Winter15

  • URI28

    30

    SOAP API/REST API

    10%

    Winter 15

    HTTP/1.1 200 OKDate: Tue, 06 Aug 2013 16:46:10 GMT Sforce-Limit-Info: api-usage=135/5000 Content-Type: application/octetstreamTransfer-Encoding: chunked"EVENT_TYPE", "ORGANIZATION_ID", "TIMESTAMP","USER_ID", "CLIENT_IP,"URI", "REFERRER_URI", "RUN_TIME"URI", "00DD0000000K5xD", "20130728185536.725", "005D0000001REI0,"10.0.62.141", "/00OD0000001ckx3, "https-//na1-salesforce-com/00OD0000001ckx3", "93"

    201372818556 ID005D0000001REI0 SalesforceID00OD0000001ckx3

    1. Apex 2. Apex 3. Apex SOAP 4. Apex 5. API 6. 7. Bulk API 8. 9. 10. 11. 12. 13. 14.

    15. 16. 17.MDAPI 18. 19. 20. 21. 22.REST API 23.Salesforce1 24.Sandbox 25. 26. 27.URI 28.Visualforce

    (API)

  • How Does it work?

    GridForce (Hadoop)

    Oracle

    App Servers

    FFX

    Logs

    Log Shipper

    Parser M/R CSV Files U: ..,.., L: ,,. A: ,,.

    CSV Files U: ..,.., L: ,,. A: ,,.

    CSV Files U: ..,.., L: ,,. A: ,,.

    Splitter M/R

    CRON (1/day)

    Type

    FFX Org

    URI // Id

    Writer

    HDFS Log Files U: ..,.., L: ,,. A: ,,.

    Log Files U: ..,.., L: ,,. A: ,,.

    Log Files U: ..,.., L: ,,. A: ,,.

    CSV Files U: ..,.., L: ,,. A: ,,.

    CSV Files U: ..,.., L: ,,. A: ,,.

    CSV Files U: ..,.., L: ,,. A: ,,.

    CSV Files U: ..,.., L: ,,. A: ,,.

    CSV Files U: ..,.., L: ,,. A: ,,.

    CSV Files U: ..,.., L: ,,. A: ,,.

    /services/data/v29.0/query?q=SELECT+Id+,+EventType+,+LogFile+,+LogDate+,+LogFileLength+FROM+EventLogFile

    BPO

    REST API

    Events

  • Data Archive BigObjects 20 fields

    18 month retention

    Field Audit Trail

    User Event Monitoring 28 types 30 Days CSV Files

    Encryption

    Encrypted custom field type

    HSM/tamper-proof key management

    1 2 3 4

    Winter 15 30 Days Retention Custom events

    Winter 16 Pilot Archive storage 10x

    of production org

    Spring 15 Unlimited fields 10-year retention

    Winter 15 Pilot Encrypt standard

    and custom fields, documents, & attachments

    Customer-managed keys

  • Thank you