idp proxy concept: accessing identity data sources everywhere!

17
IRM Summit 2014 IDP PROXY CONCEPT Accessing Identity Data Sources Everywhere! Peter Major

Upload: forgerock

Post on 10-May-2015

666 views

Category:

Software


0 download

DESCRIPTION

Peter Major, Support Engineer at ForgeRock, presents on IDP Proxy Concept in a Breakout Session at the 2014 IRM Summit in Phoenix, Arizona.

TRANSCRIPT

Page 1: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

IRM Summit 2014

IDP PROXY CONCEPTAccessing Identity Data Sources Everywhere!

Peter Major

Page 2: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

About me■ Working with OpenSSO/OpenAM since 2009

■ Support/Sustaining Engineer at ForgeRock since 2011

■ Contact– @majorpetya– [email protected]– http://blogs.forgerock.org/petermajor– https://github.com/aldaris/

Page 3: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

SAML Federations■ Provides a standardized solution for web browser

single sign on

■ Introduces the concept of federated identities

■ Widely used

Page 4: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

Terminology■ Identity Provider (IdP): the authoritative source of

identity data

■ Service Provider (SP): content provider

■ Assertion: a set of information about the logged in user

Page 5: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

Basic SAML setup

Page 6: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

Basic SAML flow

Page 7: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

Basic SAML setup

Page 8: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

IdP Proxy setup

Page 9: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

Page 10: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

STORK■ Secure idenTity acrOss boRders linKed

■ European eID Interoperability Platform

■ Establish e-relations across borders

Page 11: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

STORK

Page 12: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

STORK

Page 13: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

STORK

Page 14: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

STORK

Page 15: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

IRM

Page 16: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

Demo

Page 17: IDP Proxy Concept: Accessing Identity Data Sources Everywhere!

‹#›IRM Summit 2014

Questions?