Posts Tagged ‘SSO’

SiteMinder Experts List

Wednesday, February 10th, 2010

2310866391_eef389df61_mOver the past year we’ve seen a definite rise in the number of SiteMinder conversations on social networks. Whether it’s job opportunitiestechnical issues, or SiteMinder tips, the social universe is talking about the enterprise security application we’ve all come to know and love (always love, right? ;-) ).

One thing we’ve noticed that the SiteMinder community can do a better job of is helping people to understand where to look for help with their SiteMinder needs. On the Twitter side, we’ve created a list of SiteMinder professionals who frequent that network. These are folks we’ve interacted with or accounts that tend to generate interesting links related to SSO and enterprise security.

Of course, you can also sign up and participate in our SSOhelp community.

By the way, good news for those of you who are interested in Radiant Logic VDS: there’s a list for you too! Follow our list of Radiant Logic professionals.

We’ll continue to grow both lists over time, and if you feel you should be added then feel free to drop us a line @coreblox.

http://www.flickr.com/photos/fboyd/ / CC BY-SA 2.0

CA SiteMinder Expands Open Source Support

Monday, February 8th, 2010

opensource_logoThis morning I noticed an interesting item in my news feed that CA SiteMinder has been expanded to support web applications and services running on JBoss Enterprise Middleware. This means that popular platforms such as JBoss Enterprise Application Platform, JBoss Enterprise Portal Platform, and JBoss Enterprise SOA Platform are now fully in play for CA SiteMinder customers.

Anyone who is familiar with enterprise software can tell horror stories about its acquisition & maintenance costs, not to mention the frustration that comes when an internal team identifies a bug that must await a formal fix from the vendor because its root cause lies in the source code. Only those who have experienced this pain can fully appreciate the value of the open source model. The CoreBlox team leveraged an open source platform during the early stages of the company and we were continually impressed by the passionate community that backed it up and was always willing to help. It’s encouraging to see a large corporation like CA recognize the importance of extending SiteMinder support to those who choose to build their infrastructures (either solely or partly) on open source technologies. Well done, CA!

CoreBlox.com Changes

Tuesday, January 19th, 2010

If you’re paying close attention to the CoreBlox web site (and I know you are!), you might have noticed some recent changes we’ve made to better answer that age-old question: what the heck do you guys do?? The truth is that most of our consulting work centers on some specialized enterprise security concepts and technologies that our visitors have never heard of. So to offer a little more guidance, we’ve added a new CoreBlox Technologies section. The sub-pages in this section include:

Keep watching for more changes we’ll be deploying in the coming weeks. In the meantime, we’re here to help. Please don’t hesitate to contact us if you’re in the midst of planning new initiatives, or even if you just want to bounce some ideas around. Also check out our SSOhelp community where some of the brightest minds in the security space are exchanging ideas and helping each other through tough challenges.

Why RockYou Should Have Federated Identities

Friday, December 18th, 2009

In case you haven’t seen the news, RockYou’s users have become casualties in the latest web privacy breach. TechCrunch detailed RockYou’s numerous transgressions here:

Earlier today news spread that social application site RockYouhad suffered a data breached that resulted in the exposure of over 32 Million user accounts. To compound the severity of the security breach, it was found that RockYou are storing all user account data in plain text in their database, exposing all that information to attackers. RockYou have yet to inform users of the breach, and their blog is eerily silent – but the details of the security breach are going from bad to worse.

32 million users. If you thought you were having a bad day, imagine what RockYou’s leadership team is dealing with. Winning back the trust of a single user can be challenging, let alone the other 31,999,999.

RockYou has some 'splaining to do

RockYou has some 'splaining to do

Of course it’s easy to pile on RockYou for the many boneheaded decisions that led to this breach. Users can’t protect themselves if they don’t have the proper tools, and the act of promoting the use of simple passwords by practicing non-existent password policies is a virtual invitation to hackers. Sadly enough, even stricter policies could not have saved RockYou since they elected to store passwords in the clear. In the applications world this is the ultimate rookie mistake, and it’s difficult to imagine a company like RockYou making it.

Unfortunately the impact of RockYou’s mistakes has ripple effects for other social network partners. As TechCrunch revealed, RockYou collected user credentials for integrated sites such as Facebook and MySpace and stored them (in clear text) in their database. So if you’re one of the unfortunate RockYou users who submitted login credentials for both those networks, you have more than just your RockYou data to worry about.

So besides following through on their promise and not storing the data to begin with, what could RockYou have done to work around the issue of exposing login credentials from their partner networks to hackers? That’s easy: FEDERATE! Federated authentication is a protocol that allows companies to trust incoming login requests from known sources, thereby eliminating the need for storing a separate login and password. Simply stated, federation is single sign-on deployed across the internet. This means user identities are more portable, the user experience is more seamless, and the login data is more secure since it does not need to be stored in multiple locations.

Facebook Connect login option

Facebook Connect login option

Sounds complicated, right? But the reality is you’re probably already using forms of federation in your every day web experience. Authentication services like Facebook Connect and Twitter’s oAuth are examples of federation in action. Why expose yourself to more risk by storing credentials when you can simply piggyback on what your partner is already doing?

Of course, the value of federation isn’t limited to social networks. Large enterprises like CA are using federated security models to drive partnerships and other business relationships. Our own Todd Clayton has described a vision for a Federation Oriented Architecture where the principles of identity federation are applied other data. There is no doubt the need for identity federation is on the rise, and we expect to see plenty of work in this area in 2010.

Unfortunately hindsight cannot save RockYou from the embarrassment over this mess. The users who choose to stay with them can only hope they’ll learn from their mistakes.

Video: Extending SiteMinder with RadiantOne

Tuesday, August 25th, 2009

Last month, our very own Todd Clayton presented a webinar for Radiant Logic called Evolve Your SiteMinder Portal Through Virtualization—Without Breaking the Bank”.  He discussed the benefits of using a RadiantOne virtual directory with CA SiteMinder, some of which include:

  • Identify, correlate, and integrate identities from multiple user populations across security domains.
  • Publish different profile views for SSO, authorization, and profile management.
  • Create unified profiles of all users for different application contexts.
  • Build an abstraction layer so SiteMinder can access attributes without any changes to your existing infrastructure.
  • Develop an environment that easily accommodates future expansion and new business requirements.

Please feel free to contact us for more info on how these two products can work together.

-Dave

On the Road Again

Monday, November 10th, 2008

Just a quick announcement that our fearless leader Todd Clayton once again finds himself with a busy travel schedule over the next couple of weeks. For the next 3 days he’ll be attending the Gartner Identity and Access Management Summit in Orlando, FL. Or at least that’s what he tells us. After all, there’s another Orlando destination that could prove to be too tempting for Todd.

Next week, Todd will be attending CA World 08 at the Venetian Congress Center and Sands Expo in Las Vegas, NV from Monday 11/17 through Wednesday 11/19. Amazingly this will be Todd’s first trip to Vegas, so we highly encourage people to get him out and show him the sights. He was devestated to learn that Celine Dion is no longer doing her Vegas show, but we’ve assured him he’ll find other ways to enjoy his free time.

As always, we encourage you to connect with Todd if you’re planning to attend either of these events. Here’s a photo so you can pick him out in a crowd:

Todd on horseback

Todd in Colorado

(Just to be clear, he will not be on horseback at either event.)

Enterprise Microblogging Security

Tuesday, October 14th, 2008

Last week I read an article that was co-written by one of the most knowledgeable social media experts I follow on Twitter, Aaron Strout of Mzinga, and Joe Cascio of JoeCascio.net.  The article is titled Is the Enterprise Ready for Microblogging Tools Like Twitter?. It was full of useful information that any organization would want to consider before using a tool like Yammer or Present.ly, but the pieces that caught my eye were listed under the Key Considerations section:

“Single Sign-On (SSO): A growing problem in the social media world right now is identity proliferation. With some notable exceptions that accept OpenID, most sites still require you to create yet another account in their system (or identity domain). In most enterprises, a fair amount of effort has already been expended on establishing single sign-on through the intranets’ LDAP registry. It would be highly desirable to leverage this capability to enroll employees in the microblogging system. So, an enterprise microblogging solution must have flexibility in adapting to existing ID and sign-on registries.”

Then further down:

“Security: This will probably be of paramount concern at least initially in most businesses. Most corporations are very aware of keeping internal communications safe from prying outside eyes. An enterprise microblogging solution must provide for fine-grained authorization and trustworthy security of communications. Management, through the IT department will want to be able to restrict who can see certain posts.”

Some would say that the beauty of Twitter is its lack of walls. Granted you can globally secure your updates so that only those you approve may see them or leverage the DM feature to send private messages, but for the most part communication is done in the clear for all the Twitter community to see. But when discussions turn to private topics like corporate strategy and departmental policies, the need for enterprise microblogging to be secure becomes paramount. In other words, you don’t want that jab about a competitor’s product to become public because the person who made it was foolish enough to set their password = “password”.

So how secure are these new microblogging tools? A quick check of Yammer’s API Documentation shows the following:

“Authentication is done using HTTP Basic Authentication. The username is the full email address of the user, and the password is the same used to authenticate to the yammer.com web interface.”

It’s the same with Present.ly’s API Documentation:

“Just as with the Twitter API, the Present.ly API can be accessed via HTTP Basic authentication. The primary difference is that there is no data accessible without authentication in the Present.ly API, since the data is all private.”

For those who aren’t familiar with Basic Authentication, Wikipedia points out its main weakness:

“Although the scheme is easily implemented, it relies on the assumption that the connection between the client and server computers is secure and can be trusted. Specifically, the credentials are passed as plaintext and could be intercepted easily. The scheme also provides no protection for the information passed back from the server.”

This entry is not intended to knock Yammer or Present.ly for their API security protocols. I’m sure when their founders set out to deliver their solutions, security was barely a blip on their radars. But this is a security hole that Yammer & Present.ly’s customers will need to address if they want to provide secure microblogging environments for their employees.

If you’re part of an organization that needs help implementing SSO to a microblogging solution, or if you have any other security needs related to microblogging, we’d love to hear from you! CoreBlox has broad experience creating quick and effective solutions to these types of issues, and chances are we could help you figure this out. Drop us a line at info@coreblox.com, or feel free to contact me directly on Twitter.

For those folks who work in the Identity & Access Management space or just have a general interest in this area- what are your thoughts on the security challenges that these microblogging solutions pose? Anything you see that makes their situations unique relative to other applications that are covered by enterprise security?

Thank you, SiteMinder

Tuesday, August 19th, 2008

Seven years ago when I was working for Onyx Software, I led a CRM implementation for a Waltham, MA based company called Netegrity. Netegrity had made an early arrival to the Identity & Access Management (IAM) party, and its SiteMinder solution for single sign-on (SSO) had been wildly successful with Fortune 500 companies. About a year later when I was looking to reduce my travel load and get a view of the CRM world from the other side, I joined Netegrity’s Business Systems group where I began working with my fellow CoreBlox co-founders. Three years later CA acquired Netegrity, and shortly after that we launched CoreBlox.

Normally I would end that last paragraph with “And the rest is history…”, but it’s important to recognize a major component that has allowed our start-up to defy the odds and celebrate three years as a self-funded business: SiteMinder. There’s no doubt that having a strong, smart, versatile team has been a key to our success, but it would be difficult to pursue our Web 2.0 initiatives (such as our I Have Kids app which is up to 60,000 users!) if we were unable to find consistent sources of revenue to fund them. Our team’s SiteMinder expertise has allowed us to establish ourselves as a boutique firm in a niche market, and it has opened doors in other spaces such as directory virtualization and SAML/federation. In a down economy, IAM spending has remained strong enough to provide us with the engagements we need to drive our business forward:

… the number of organizations planning to roll out identity and access management solutions in the next 12 to 18 months increased 11 [percentage points], moving from 49 percent in 2006 to 60 percent in 2008.

As with any product or service that one works with on a daily basis, it’s easy to focus on gaps and frustrations. Sometimes we need to step back and recognize that what makes the solution complex leads to the opportunities that those who know it well can enjoy.

So on behalf of the entire CoreBlox team, I’d like to offer a sincere THANK YOU to SiteMinder. May you continue to send great opportunities and clients our way!

Single Sign-On and Virtual Directories: A Match Made in Heaven

Friday, May 9th, 2008

Single sign-on (SSO) alone is not enough to deliver a unified customer experience. This becomes more apparent as companies attempt to implement cross application SSO for disparate sets of users. SSO falls short as companies expand beyond a defined set of internal-only users into cross business unit applications and especially for applications geared towards external users. While SSO tools allow companies to interweave applications running on disparate platforms into complex mashups presenting a unified view of information, they often lack the mechanism to relate users across the systems. Enter the virtual directory server. By combining the power of SSO with the abilities of a virtual directory server to correlate user information based upon complex matching rules, companies gain a unique ability to easily bring together applications while reducing integration costs and time to market.

The concept dubbed “Identity Acquisition” exemplifies these benefits. In essence, this is the ability for companies to quickly subsume applications and users into a broader infrastructure that allows easy presentation of a unified appearance and linking of application functions. Through the use of a virtual directory, companies can create a unified view of a user across all of their applications and leverage that information to present a single set of security roles to SSO applications. This allows SSO products to pass the correct identity to the underlying application regardless of the differences in user directories and attributes. Without a mechanism for identifying these users in a composite view, SSO provides superficial benefits lacking the ability to deliver a common experience as a user moves across these disparate applications. Just because a user may be xyz@company.com in one application, they could be identified as id=130203 in another. Although SSO can grant the user access to both applications, without a correlation established and a way to leverage that correlation to create a unified profile, the ability to deliver a common experience to that user across both systems is lost.

Typically companies have a set of key objectives when looking to deliver a common user experience. These may include the ability to:

  • Efficiently roll-in newly identified applications
  • Integrate multiple user bases into a common delivery platform and exploit the “up-sell” factor.
  • Expedite the integration of newly acquired identities and applications to reduce confusion and increase satisfaction
  • Create a repeatable process with known costs and timelines
  • Reduce security concerns and increase compliance of managing multiple identifies and non-centralized application policies

A combined SSO and virtual directory infrastructure enables companies to meet these requirements and to provide an agile platform for changes in business objectives and processes.

How to Put the Pieces Together

The key to laying this foundation is to create a technology stack that includes a flexible set of tools that allows for easy acquisition of identities into a common platform. Recently, we were faced with the challenge of assisting a company that was making multiple acquisitions. They needed to continue to give their customers a common view of technical support during the assimilation period of the acquired systems into the broader application environment. Upon closer examination of the support tools currently in use the company discovered that they:

  • Needed to increase customer satisfaction
  • Needed to drive down technical support costs
  • Found too few customers utilizing self-help options (approximately 20%)
  • Were losing revenue due to a lack of ability to perform entitlement checking
  • Had too many environments to effectively manage and no centralized control
  • Found it difficult to support customers who had products from different business units because they were supported by different systems
  • Had increasing demands upon limited resources such as legacy applications

One of the key goals of the project was to entice customers to use self-help options. The objectives included:

  • Single Sign-on, for customers to login only once
  • Global Search, so that customers could search view content-rich knowledgebase content across all support systems
  • Unified issue resolution capabilities across business units
  • A new base security architecture to accommodate future expansion

The overall solution was made up of the following components:

  • RadiantLogic RadiantOne Virtual Directory

Consolidates and caches user profiles (including all necessary attributes) from all user repositories into a single LDAP source, enabling the Policy Server to authenticate and authorize users against a single directory

  • CA SiteMinder

Enables enterprise security and single sign-on capabilities across all application platforms

  • SAP Portal

Allows a single front-end presentation layer across all legacy systems

  • IBM WCDS/OmniFind

Unified 3rd-generation knowledgebase across all acquired systems

  • CA eTrust Directory/MS SQL/Sybase/MySQL/ADAM

Backend application user stores containing the various disparate identities specific to that application

The following diagram highlights the solution landscape:

Solution Overview

Each of these components allowed the company to establish a base platform for current requirements while also creating capacity for future acquisitions. RadiantOne played a key role by providing to SiteMinder a central location for user authentication and authorization through virtualizing multiple instances of the same user distributed across all systems, into a single global profile.

Measurable Results

The new system greatly increased the company’s ability to meet the desired goals. The platform ensured that:

  • All external technical support systems are available through a single login and through single sign-on
  • They are able to present unified entitlements and system access for customers owning multiple products
  • Customer have the ability to search across all content regardless of differences in physical location of the data, improving self-service
  • The enhancements to the identity security infrastructure reduced costs

The effort yielded an increase both in customer and employee satisfaction as well as a significant reduction in the time required to make system changes. This combination of SSO and virtual directory technology delivered a match made not only in heaven, but also right here in our data centers.