Novell eDirectory™ Deployment at Hydro Quebec Richard Cabana Enterprise Technology Account Manager Novell Canada Ltd.

Slides:



Advertisements
Similar presentations
automated single login access to Novell storage resources
Advertisements

Prepared by Dept. of Information Technology & Telecommunication, May 1, 2015 DoITT Identity Management Security, Provisioning, Authentication.
Novell iChain ® 2.x Configuration Using the Web Server Accelerator Wizard Cary Andrews Senior Software Engineer Novell, Inc.
Active Directory: Final Solution to Enterprise System Integration
02/12/00 E-Business Architecture
Database Systems: Design, Implementation, and Management Eighth Edition Chapter 15 Database Administration and Security.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Creating a Secured and Trusted Information Sphere in Different Markets Giuseppe Contino.
Identity and Access Management
Understanding Active Directory
Securing Access in a Heterogeneous Network Environment Providing Interoperability between Microsoft Windows 2000 and Heterogeneous Networks Securing Authentication.
#CONVERGE2014 Session 1304 Managing Telecom Directories in a Distributed or Multi-Vendor Environment David Raanan Starfish Associates.
© 2008 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Automates Infrastructure Outsourcing.
Cognizance Identity and Access Management Identity Management ● Authentication ● Authorization ● Administration The next generation security solution
Identity and Access Management Business Ready Security Solutions.
Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. Danita Zanrè Senior Consultant Caledonia.
Module 10: Designing an AD RMS Infrastructure in Windows Server 2008.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
Windows 2000 Active Directory Service COSC 513 Yongquan Cai 03/10/2001.
Using Novell iChain ® 2 to Deliver Internal Network Access without a VPN Brian Six Technical Account Manager Novell, Inc.
Novell iManager Introduction and Overview James Whitchurch Director—Software Engineering Novell, Inc. Karl Ford Engineering.
iChain ® 2.1: Introduction and Overview Lee Howarth Product Manager Novell, Inc.
Simplify and Strengthen Security with Oracle Application Server Allan L Haensgen Senior Principal Instructor Oracle Corporation Session id:
UNITED STATES. Understanding NDS for Directory- Enabled Solutions Ed Shropshire, NDS Developer Program Manager Novell, Inc.
TWSd - Security Workshop Part I of III T302 Tuesday, 4/20/2010 TWS Distributed & Mainframe User Education April 18-21, 2010  Carefree Resort  Carefree,
Upgrading Legacy Novell Directory Services ® to Novell eDirectory ™ 8.6 Rick Killpack WSS Engineer Novell, Inc. Connie.
Sudha Iyer Principal Product Manager Oracle Corporation.
Introduction to NDS ® iMonitor Duane Buss Senior Software Engineer Novell, Inc. Tom Doman Senior Software Engineer Novell,
Using Novell GroupWise ® 6 Monitor Duane Kuehne Software Engineer Novell, Inc. Danita Zanre Senior Consultant NSC Sysop,
Keeping Your Business Online with eDirectory ™ Backup and Restore Brian Hawkins Software Engineer Novell, Inc. Roger.
Introduction to Novell GroupWise ® Administrative Object API Glade Monson Software Engineer Novell, Inc.
® Gradient Technologies, Inc. Inter-Cell Interworking Access Control Across the Boundary Open Group Members Meeting Sand Diego, CA USA April 1998 Brian.
1 MIIS IAM Nationwide Journey - MIIS & IAM. 2 Agenda 1.Introduction Original objectives Definition of terms 2.MIIS 3.IAM Introduction Definition Approach.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Understanding Novell DirXML™ Technology
Business Productivity Infrastructure Optimization Campaign 1 Day 2: Topic: Unified Communications and Collaboration (UCC) Partners will understand Microsoft.
9 Systems Analysis and Design in a Changing World, Fourth Edition.
FSU Metadirectory Project The Issue of Identity Management Executive Overview.
Dave Horne eSolutions Deployment Mgr Novell, Inc. Designing and Managing Novell DirXML ™ Deployments.
DirXML ™ Competitive Comparisons Ed Anderson Director, Product Management Novell, Inc. Joe Skehan Product Management Directory.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
Integrating Active Directory with eDirectory ™ Using Novell Account Manager Reid Oakes Technical Team Manager Novell, Inc.
1 Active Directory Service in Windows 2000 Li Yang SID: November 2000.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
TechNet Architectural Design Series Part 5: Identity and Access Management Gary Williams & Colin Brown Microsoft Consulting Services.
Creating Custom User Management Plug-ins for iManager Eugene Baron Consultant III Novell, Inc. Adam Ruth Senior Software.
1 CEG 2400 Fall 2012 Directory Services Directory Services eDirLDAP Active Directory.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Web-based Storage Access John Pugh Corp Technology Strategist Novell, Inc. Scott Villinski Corp Technology Strategist
Secure Connected Infrastructure
Intermediate Programming with GroupWise® C3POs™
Programming with NetWare® XPlat APIs
Novell Account Management Introduction and Overview
Creating Novell Portal Services Gadgets: An Architectural Overview
Novell BrainShare 2002 Success in the City: Implementing Novell Solutions at the City of Los Angeles Bob Gillette Information Systems Manager City of Los.
Securing the Net: Web Authentication Using SecureLogin
Novell BorderManager® 3.7: Technical Overview
Upgrading Legacy Novell Directory Services® to Novell eDirectory™ 8.6
Jumpstart Solution: Novell Active Information Portal
Extending the Net: Novell Portal Solutions Overview
Novell BrainShare 2002 Government Success Story: CRM with Novell Portal Services and eDirectory™ Trent Badger Product Manager Novell, Inc.
Novell iPrint Deployment Strategies
Novell Government Solutions
Introducing Novell IPv6 Stack
Six Reasons to Get NetWare® 6 over Windows
It’s one Net for Mac Users Too
Automating Mainframe Authentication Using SecureLogin
Novell eDirectory™ Competitive Comparisons
Introduction to Novell GroupWise® Token API
Presentation transcript:

Novell eDirectory™ Deployment at Hydro Quebec Richard Cabana Enterprise Technology Account Manager Novell Canada Ltd. Benoit Moreau Senior Consultant Hydro Quebec

Vision…one Net A world where networks of all types—corporate and public, intranets, extranets, and the Internet—work together as one Net and securely connect employees, customers, suppliers, and partners across organizational boundaries Mission To solve complex business and technical challenges with Net business solutions that enable people, processes, and systems to work together and our customers to profit from the opportunities of a networked world

Who Is Hydro Quebec? Canada’s largest crown corporation Over 20,000 employees servicing 3.5 million citizens Assets of $40 billion Annual sales of $8 billion International sales and engineering of Hydro Power

Hydro Quebec Divisions Hydro Quebec distribution  Dedicated to maintaining power to Quebec residents and commercial/private companies and institutions Trans-energy  International expertise on power distribution and transmission networks

Hydro Quebec Divisions (cont.) Production  Generation of over 32,274 megawatts of power Engineering  Consultation internationally on all aspects of power distribution

Putting It into Context No unique data source for interrogation Existence of too many directories Redundant information and data entry Very difficult to administrate Information had various levels of accuracy Increased operational costs

Goal of the Corporate Directory Corporate directory should regroup all information that would be potentially re-usable in other applications or directories Provide Hydro Quebec with a unique authentication and directory lookup Ensure the availability and access of the integrated information Reduce overall costs of adding new applications

Process of Evaluation Do the different operating systems have databases that can be treated as directories? All major operating systems and applications contain a database which could be used to manage users and their access privileges

The Road to a Unified Directory Is there a product that would permit Hydro Quebec to administer a single directory across all of their main operating systems? Novell eDirectory™

The Birth of a New Directory Strategy Hydro Quebec decides the first phase of their directory strategy  Regrouping their disparate operating systems under one unifying directory: Workforce Directory

Workforce Directory Unify user IDs of the different operating systems Increase overall security by increasing to the highest possible denominator Reduce overall OS management costs Reduce the number of management consoles Simplify the management of user privileges

Corporate Directory Corporate repository where all systems, applications, and information concerning individuals, groups, roles, and application definitions reside In brief, the corporate directory contains the information and definitions in which the enterprise will need to interact

Workforce Directory Regrouping of the identities of multiple operating systems into one unifying directory The workforce directory permits the management of Sun, RS 6000, Windows NT or other operating systems within Hydro Quebec’s workforce

Workforce Directory (cont.) In summary...  The workforce directory manages rights and access privileges to all informatics exploited by Hydro Quebec

DBA Subsico Entrust LiveLink GetAccess Cognos Exchange Novell 3.12, 4.11, 5.1 OS390 SolarisAIX Structure Users Recuperation of corporate access Simplification of user credentials and login Administrators Authentication Access Administration Centralized administration Uniform security for all operating systems Administration of Access databases

DBA Subsico Entrust LiveLink GetAccess Cognos Exchange Department Novell 3.12, 4.X, 5.X NDS 8.5 OS390 NDS 8.5 Solaris NDS 8.5 AIX NDS 8.5 Users Recuperation of corporate access Simplification of user credentials and login Administrators Authentication Access Centralized administration Uniform security for all operating systems Administration of Access databases Workforce directory NDS 8.5 Structure Administration

DBA Subsico Entrust LiveLink GetAccess Cognos Exchange Department Novell 3.12, 4.X, 5.X NDS 8.5 OS390 NDS 8.5 Solaris NDS 8.5 AIX NDS 8.5 Users Recuperation of corporate access Simplification of user credentials and login Administrators Authentication Access Centralized administration Uniform security for all operating systems Administration of Access databases Workforce directory NDS 8.5 Structure Administration

DBA Subsico Entrust LiveLink GetAccess Cognos Exchange Users Recuperation of corporate access Simplification of user credentials and login Administrators Authentication Access Centralized administration Uniform security for all operating systems Administration Logical structure Physical structure Corporate directory (eDirectory) Department Novell 3.12, 4.X, 5.X NDS 8.5 OS390 NDS 8.5 Solaris NDS 8.5 AIX NDS 8.5 Workforce directory NDS 8.5 Administration

DBA Subsico Entrust LiveLink GetAccess Cognos Exchange Users Recuperation of corporate access Simplification of user credentials and login Administrators Authentication Access Centralized administration Uniform security for all operating systems Administration Logical structure Physical structure Corporate directory (eDirectory) Department Novell 3.12, 4.X, 5.X NDS 8.5 OS390 NDS 8.5 Solaris NDS 8.5 AIX NDS 8.5 Workforce directory NDS 8.5 Administration

Evolution of Hydro Quebec’s Directory Strategy Multiple heterogeneous directories Information was subsequently regrouped by enterprise Operating systems and their directories were then consolidated One large corporate directory to which all other directories synchronize

Synchronization Is there a tool that exists that is based on industry standards and that could synchronize data to and from multiple sources? Introducing DirXML™

But First…XML XML is an industry standard that defines the protocol of exchange of information (data) between different heterogeneous sources

Products Available on the Market DirXML MMS (Microsoft Metadirectory Services) Few others

Hydro Quebec’s Metadirectory Comprises two main directories and synchronization tools  Corporate Directory (administration and white pages)  Workforce Directory (authentication and rights)  DirXML and connectors

DirXML (synchronization rules) DBA Subsico Entrust LiveLink GetAccess Cognos Exchange Users Recuperation of corporate access Simplification of user credentials and login Administrators Authentication Access Centralized administration Uniform security for all operating systems Administration Logical structure Physical structure Corporate tree NDS 8.5 Department Novell 3.12, 4.X, 5.X NDS 8.5 OS390 NDS 8.5 Solaris NDS 8.5 AIX NDS 8.5 Workforce tree NDS 8.X Bidirectional synchronization Administration

DBA Subsico Entrust LiveLink GetAccess Cognos Exchange Users Recuperation of corporate access Simplification of user credentials and login Administrators Authentication Access Centralized administration Uniform security for all operating systems Administration Logical structure Physical structure DirXML (synchronization rules) Corporate tree NDS 8.5 Department Novell 3.12, 4.X, 5.X NDS 8.5 OS390 NDS 8.5 Solaris NDS 8.5 AIX NDS 8.5 Workforce tree NDS 8.X Access to Public Key Information (PKI) Administration Authentication Bidirectional synchronization

AD Root IREQ Directory Supplies group Directory Access DBA Subsico Entrust LiveLink GetAccess Cognos Exchange Users Recuperation of corporate access Simplification of user credentials and login Administrators Access Centralized administration Uniform security for all operating systems Administration DirXML (synchronization rules) Logical structure Physical structure Corporate tree NDS 8.5 Department Novell 3.12, 4.X, 5.X NDS 8.5 OS390 NDS 8.5 Solaris NDS 8.5 AIX NDS 8.5 Workforce tree NDS 8.X Access to Public Key Information (PKI) Administration Authentication Bidirectional synchronization

Supplies group Infra- bureautique Infra-NT IREQ Trans-Energie DBA Subsico Entrust LiveLink GetAccess Cognos Exchange Access Users Recuperation of corporate access Simplification of user credentials and login Administrators Access Centralized administration Uniform security for all operating systems Administration Logical structure Physical structure AD Root IREQ Directory DirXML (synchronization rules) Corporate tree NDS 8.5 Department Novell 3.12, 4.X, 5.X NDS 8.5 OS390 NDS 8.5 Solaris NDS 8.5 AIX NDS 8.5 Workforce tree NDS 8.X Access to Public Key Information (PKI) Administration Authentication Bidirectional synchronization

What Did Hydro Quebec Gain? Centralized administration Data is always “fresh” and integrated Increased control over security Reduced costs for managing their infrastructure User benefits by single ID Simplified administration Can define the lifecycle of an object

Single Sign-on Challenges  Over 45 passwords per employee (on average)  Multiple trees (ADS and eDirectory)  Different support groups  Too many administrators

Solution: Secure Login Three month pilot/prototype Testing to be done on Entrust, Microsoft Exchange Success measurements  Ease of administration  Ease of use for clients  Integration with Novell Modular Authentication Services (NMAS™)  Integration with Hydro Quebec Client Shell

Challenges Hydro Quebec had wanted to make Entrust PKI X.509 certificates the default standard for network authentication Additionally, all users would be given Entrust client side encryption as a standard desktop configuration

Solution: NMAS™ But wait...  The login method for Entrust PKI didn’t exist

NMAS Project Six-month prototype Entrust method developed for Hydro Quebec  Development time took half a day for alpha prototype Method now included in NMAS Enterprise edition Allows login credentials to be handled by Entrust Authority

Proposed Secure Login/NMAS Architecture