Mechanics of Oracle Portal and Identity Management Mechanics of Oracle Portal and Identity Management Paper 36768 Sanjeev Mohan Golden Gate University,

Slides:



Advertisements
Similar presentations
Directory Infrastructure Roadmap Overcoming Fragmented Identities - Roadmap to a Reliable Directory Infrastructure Thorsten Butschke & Dr. Martin Dehn.
Advertisements

DIGIDOC A web based tool to Manage Documents. System Overview DigiDoc is a web-based customizable, integrated solution for Business Process Management.
Welcome to Middleware Joseph Amrithraj
Common ISO/RTO Architecture ISO/RTO Information Technology Committee Walter A. Pfuntner, Jr, PhD, PE Chairman, ITC Architecture Working Group
Introduction to z/OS Security Lesson 4: There’s more to it than RACF
Microsoft Learning Gateway for HE Rob Miles – Hull University, Lecturer Romola Ganguli – Microsoft Education Technology Advisor.
FSU Directory Project The Issue of Identity Management Jeff Bauer Florida State University
IBM Software Group ® Accessing Domino via Outlook iNotes Access for Microsoft Outlook - Notes Domino 5.5 – Domino Access for MS Outlook - Notes Domino.
Benefits of CA Technology & HVB Bank Romania Study Case Bucharest, May 31, 2005.
Active Directory: Final Solution to Enterprise System Integration
June 1, 2001 Enterprise Directory Service at College Park David Henry Office of Information Technology University of Maryland College Park
CS603 Active Directory February 1, 2001.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Building Enterprise Information Portal using Oracle Portal 3
Identity and Access Management: Strategy and Solution Sandeep Sinha Lead Product Manager Windows Server Product Management Redmond,
Identity and Access Management
Access and Identity Management for Enterprise Portals Rohit Gupta Director, Identity Management Product Management Oracle Corporation.
E-Business: Intra-Business E-Commerce
A centralized system.  Active Directory is Microsoft's trademarked directory service, an integral part of the Windows architecture. Like other directory.
Copyright 2005 © Persistent Systems ( 1 Overview of Persistent’s Custom Connector Offering.
Directory services Unit objectives
The Internetworked E-Business Enterprise
Ihr Logo Data Explorer - A data profiling tool. Your Logo Agenda  Introduction  Existing System  Limitations of Existing System  Proposed Solution.
Technology Overview. Agenda What’s New and Better in Windows Server 2003? Why Upgrade to Windows Server 2003 ?  From Windows NT 4.0  From Windows 2000.
CIS 375—Web App Dev II Microsoft’s.NET. 2 Introduction to.NET Steve Ballmer (January 2000): Steve Ballmer "Delivering an Internet-based platform of Next.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
USM Regional PeopleSoft Conference
A detailed look at the Microsoft Windows Infrastructure at UWE including Active Directory (AD), MIIS, Exchange, SMS, IIS, SQL Server, Terminal Services.
SURENDER SARA 10GAS Building Corporate KPI’s
Using AS 10g with EBS What are the Benefits of Integrating AS 10g with Oracle Applications?
E-Business Activities at the University of California, Berkeley Barbara H. Morgan Director, Strategic Technology Planning Common Solutions Group Tucson,
Simplify and Strengthen Security with Oracle Application Server Allan L Haensgen Senior Principal Instructor Oracle Corporation Session id:
Directory Service
Building Secure, Flexible and Scalable Environments using LDAP - SANS Orlando Sacha Faust PricewaterhouseCoopers
Riva Managed Identity Integration for Active Directory and Novell ® GroupWise ® Aldo Zanoni CEO, Managing Director Omni Technology Solutions
Implementing LDAP Client/Server System for Directory Service By Maochun Sun Project Advisor: Dr. Chung-E Wang Department of Computer Science California.
1 Introduction to Microsoft Windows 2000 Windows 2000 Overview Windows 2000 Architecture Overview Windows 2000 Directory Services Overview Logging On to.
Nsure Idntity Manager & Oracle Internet Directory Michel Bluteau Field Corporate Strategist Nsure Identity Management Novell Québec.
Sudha Iyer Principal Product Manager Oracle Corporation.
MEDIU Learning for HE Ahmad Nimer | Project Manager.
Introduction to Lightweight Directory Access Protocol Introduction Danny Conte Conte Consultants Inc. Jan 31 st 2002.
PRESENTATION | OBLIX CORPORATE OVERVIEW Oblix Introduction Securely Managing Business in a Connected World.
“Confidential –Internal Halliburton Use Only. © 2004 Halliburton. All Rights Reserved.” Portal Brief OracleAS Portal A component of Oracle Application.
FSU Metadirectory Project The Issue of Identity Management Executive Overview.
The HEP White Pages Project Ray Jackson CERN / IT - Internet Services Group 23rd April HEPiX/HEPNT Conference, LAL-Orsay, France.
System Center Lesson 4: Overview of System Center 2012 Components System Center 2012 Private Cloud Components VMM Overview App Controller Overview.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
OASIS | November 16, 2003 Organization for the Advancement of Structured Information Standards OASIS OASIS | November 18, 2003 Web Services Remote Portlets.
Enterprise Portals Empowering Business via Technology Rajesh Moparthi.
Oracle HFM Implementation Boot Camp
1 Active Directory Service in Windows 2000 Li Yang SID: November 2000.
Microsoft Identity Integration Server & Role Base Access Theo Kostelijk Consultant Microsoft BV
Oracle’s Hyperion Planning Architecture Browser/Office Client Windows* / UNIX / Linux Server Web Data EntryMS Office IntegrationReporting and Analysis.
Enteprise Content Management from Microsoft. 20% structured 80% unstructured 90% of unstructured data is unmanaged Volume of data is increasing ~36%/year.
1 CEG 2400 Fall 2012 Directory Services Directory Services eDirLDAP Active Directory.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Windows Active Directory – What is it? Definition - Active Directory is a centralized and standardized system that automates network management of user.
The FederID project The First Identity Management and Federation Free Software.
1 Directory Services  What is a Directory Service?  Directory Services model  Directory Services naming model  X.500 and LDAP  Implementations of.
Secure Connected Infrastructure
New Developments in Central Directory Service and Account Provisioning Dan Menicucci Enterprise Architect - University of Pittsburgh.
Introduction to LDAP Frank A. Kuse.
Novell Account Management Introduction and Overview
CONTENT: Introduction of the evolution of enterprise portals.
Introduction to z/OS Security Lesson 4: There’s more to it than RACF
ApplinX Rod Carlson Senior Technical Lead.
Collaborative Business Solutions
OracleAS Identity Management
James Cowling Senior Technical Architect
Presentation transcript:

Mechanics of Oracle Portal and Identity Management Mechanics of Oracle Portal and Identity Management Paper Sanjeev Mohan Golden Gate University, San Francisco

Topics  Introduction  Business Requirements  Case Study: Golden Gate University  Portal  Identity Management (LDAP)  Single Sign On (SSO)

Case Study: Golden Gate University’s Legacy Environment  Operating systems: Solaris, Windows, MPE/ix, Netware, Mac OS, Digital Unix  Hardware platforms: SUN (Sparc), Dell (Intel), HP 3000, Macintosh, DEC Alpha  Databases: Oracle, SQL Server, Access, FoxPro, HP Image  Development: Coldfusion, HTML, Javascript, UniBasic  No common code, data, OS, management process, customer experience

GGU ’ s new Web Architecture

Business Requirements: Challenges  Profusion of stand alone servers and applications  Redundant storage of data  Inaccurate / Out-of-Sync data  Lack of Consolidated view of data  Inability to produce business intelligence

Business Requirements: Why Portal?  Higher productivity for the employees by providing single point of access to integrated applications.  Better employee communication and collaboration.  More efficient business process and improvements  Help make an organization more competitive. A well designed portal could provide an organization with a differentiation over its competition.  Better customer satisfaction and retention.  Lower cost and better utilization of the staff e.g. IT support, HR staff etc.  Lower cost by reducing the number of servers.

Integration Levels  Integration of Databases  Data Warehouse  Enterprise Application Integration (EAI)  Application Level Integration  Web Services  Portal

Integration Architecture ERPERP CRMCRM EM A I L LOBLOB LEGACyLEGACy

Portal Definition  The term portal is often misused and many describe it as an entry point into a site e.g. a company’s home page.  Portals provide an organizations’ customers and employee an integrated access to applications and services in a highly secure and customizable manner.

Portals  Enterprise Portal – Internal / Corporate Portal – eBusiness Portal  Public Internet Portal  Appliance Portal  Vertical Portal

Portal features – End User  Access to Enterprise Applications (Self Service)  Categorization of External / Unstructured Content (Taxonomy)  Collaboration Tools  Personal Organization Tools  Search Tool  Personalization / Customization Tools

Portal features – Technology  Identity Management  Single Sign On  Content Management System  Highly Available and Secure Infrastructure  Administration Tools  User Interface Services e.g. Wireless Support

Portal Vendors  Pure Play Vendors – Epicentric (acquired by Vignette), Plumtree, Hummingbird, Citrix NFuse, CA CleverPath, Corechange Coreport  Application Server Vendors – BEA WebLogic, IBM WebSphere, Oracle 9iAS, Sun One and BroadVision InfoExchange  ERP Vendors (Oracle, People Soft, SAP)  BI Vendors (Brio, Cognos, SAS, Business Objects)  Others (UPortal, TIBCO, ATG, Microsoft SharePoint )

Oracle Portal Architecture

Oracle 9iAS R2 Components Mid-tierInfrastructure HTTP Server BC4J; OC4J_Demo; OC4J_Home; OC4J_Portal OC4J_Demo; OC4J_Home; OC4J_DAS Clickstream PortalInternet Directory SSO Webcache

 Strategic and primary interface for students, faculty, staff, alumni (through Oracle Single Sign On (OSSO)  Portal as a subset of the GGU web site  Support for portal standards (JSR 168, WSRP)  Robust Portal Integration Framework (PDK) – Ease of portal page and portlet development – Extensible portlets – calendar, eLearning, Business Intelligence, OEM 4.0, ERP – External 3 rd -party Portlets  Clickstream Analysis Why Oracle Portal?

Identity Management  An infrastructure to centralize the management of users and the privileges assigned to them  User life cycle management – creation of a new user account, modification, assignment of roles and privileges and finally deletion of the user account.

Business Requirements: Challenges  User information available in multiple systems – redundancy  Programs needed to sync user data  Data is not consistent / accurate  Security issues when accounts are not deleted for ex-employees

What is a Directory / What is it not?  Directory is a specialized database  Doesn’t contain tables, columns, relations  Contains attributes (single valued / multi valued)  Access is not via SQL but via a protocol such as LDAP (Lightweight Directory Access Protocol)  Tuned for fast reads but not writes

LDAP Schema – Building Blocks  Entries (details for persons / resources)  Attributes  Primary Key – E.g. Distinguished Name or DN  Examples: – dn: uid = jdoe, ou = hr, o = acme, dc = com – dn: cn = smohan, dc = ggu, dc = edu

Object Class  Group of attributes  Uniquely identified by Abstract Syntax Notation (ASN.1) object identifiers (OID)  Vendor includes standard classes as well as proprietary.  Example “Person” object class contains: – Mandatory attributes: cn (common name) and sn (surname) – Optional attributes: userPassword, telephoneNumber etc.

Object Class Hierarchy inetOrgPerson ( ) Top ( ) Person ( ) organizationalPerson ( )

Proprietary / User-Defined Object Class  Oracle proprietary: orclSubscriber  GGU user-defined: gguPerson  Internet Assigned Numbers Authority (IANA) assigns a “private enterprise number”  gguPerson attributes: ClassesEnrolledIn, StudentId etc.

Directory Integration  Identify Systems of record: HR, , PBX  Some data only in directory – MD5 hashed user password  Synchronization of sources of data with directory  Create users’ roles and group memberships (Access Control Policy)  Setup Delegated Administration

OID Applications at GGU  Intranet / Portal user authentication  Database User Authentication  OS Authentication  Oracle Net Directory Naming  Wireless User Authentication using RADIUS  Integration with Oracle 11i eBusiness Suite

LDAP Product Vendors  Novell eDirectory  Sun One  Oracle Internet Directory (OID)  Microsoft Active Directory  OpenLDAP  Entrust (GetAccess) / IBM (Tivoli Policy Director) Netegrity (SiteMinder) / Entegrity (AssureAccess) RSA Security (ClearTrust) / Oblix (NetPoint)

Oracle Internet Directory (OID)  Underlying storage is the database so we get all the benefits of Oracle 9i R2 (RMAN backup, Replication)  Required by Oracle Portal, Collaboration Suite and future Oracle products and Oracle SSO  Integrates with Oracle HRMS, iPlanet and Microsoft Active Directory  Oracle Delegated Administration Service

Business Requirements: Challenges  Help desk inundated with password resets  Users leaving passwords on their desks  Users wasting time trying to remember passwords  Applications forcing password changes causing more confusion  Applications not securing password adequately

Single Sign On - Benefits  Ease of administration  User convenience  Higher security  Eases development  Reduces help desk support calls

SSO Standards and Vendors  Microsoft.NET Passport (Kerberos)  Liberty Alliance (Security Assertion Markup language - SAML) ---  Oracle Single Sign On (OSSO)  Computer Associates (eTrust)  IBM (Access360)

Single Sign On - Architecture Client Web browser Apache web server (mod_sso) SSO Server / Identity Provider LDAP Authenticated Portal Page / application

Question & Answers