Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Building Single Sign-On (Epam Case Study)

Avatar for Yuliya Yuliya
October 30, 2014

Building Single Sign-On (Epam Case Study)

Aliaksei Surovy, EPAM Enterprise Architect

Avatar for Yuliya

Yuliya

October 30, 2014
Tweet

Other Decks in Programming

Transcript

  1. • Enterprise Problems in EPAM • SSO as a Solution

    of the Enterprise Problems – What is SSO? – How it works – Strategy & Tactics – Implementation Agenda Confidential 2
  2. Aliaksei Surovy • EPAM Enterprise Architect • Architecture Excellence Initiative

    Coordinator • EPAM Microsoft Competency Center Expert • EPAM SSO Team • Solution Architect About Me Confidential 3
  3. EPAM Problems Confidential 5 PMC EPIS … and many others

    EPAM Tube QPF EPAM Cloud Orchestration
  4. Single Sign-On (SSO) - it is a property of access

    control of multiple related, but independent software systems. With this property a user logs in once and gains access to all systems without being prompted to log in again at each of them. What is SSO? Confidential 7
  5. SSO • AS IS – Current Landscape & Stakeholders (Infrastructure

    & Systems) – Requirements (Scenarios, Wishes) • Analysis & Design – Choose Protocols – Choose SSO Tool – Prove Of Concepts (POCs) – Technical Proposal • Implementation – Environments Setup (Staging & Production Environments) – Integration (Knowledge Base) • Policy – Application Registration Workflow Strategy & Tactics Confidential 9
  6. SSO Chronology Confidential 10 • Understand Current Landscape • Define

    Focus Group (Critical Internal Systems & Stakeholders) • Gathering Requirements & Wishes • Build POC • Prove Of Concept (Validate Requirements & Wishes) • Create Technical Proposal • Build SSO Infrastructure • Integrate Applications into SSO
  7. SSO • Active Directory Federation Service 3.0 is a feature

    of Windows Server 2012 R2 Standard Edition Protocols: – WS-Federation (passive) – WS-Trust 2005/1.3 (active) – SAML 1.1/2.0 – OAuth 2.0 (3-legged only) Token Formats: – SAML 1.1/2.0 – JWT • Big part of EPAM infrastructure is Windows • EPAM MSFT CC has AD FS 2.0 experience EPAM Solution: AD FS 3.0 Confidential 11
  8. SSO • Single Sign-Out • Federation with other Security Token

    Services (STS) • Multi-Factor Authentication • BYOD Support AD FS 3.0: Extra Features Confidential 13