Authentication
Single Sign On (SSO)
WebSSO
WebAuth
Description:
Use a model similar to Peoplesoft v8 SSO (WebKDC and WAS)
• Cookie (consumed by web apps),
• ID and Proxy token (consumed by WAS) and
• Main token (consumed by webKDC)
Written in Perl and support Apache 2.0, C++/Perl API.
Highly scalable (Stateless design).
Vulnerable to browser hack because of non-opaque cookie
Strong Authentication
by Mechanism
PKI (X.509 Cert)
Definition
When a user accesses web application:
• (Prerequisite:) Certificate is installed in user’s browser
• User visits web application and browser authenticates without user interaction
• Server checks certificate against trust store to validate user’s identity
• Server asserts user identity to application
Shared Directory
Security Framework
Gabriel
Access Management
Definition:
Access Management is often used to describe broader systems that use
both authentication and authorization services
PERMIS
User Management
Directory Services
ApacheDS
Sub Projects
Mitosis
Virtual Directory
Penrose
Meta Directories
Ganymede
Description:
It is a data-mastering service for a customizable collection of
network directory services which provides a high quality (and
concurrent) user interface and lots of interactive feedback.
It does not directly play a role in monitoring LDAP servers or of doing
real-time translations of LDAP queries across data services
Identity Systems
Passel
