8
2013 Open Stack Identity Summit - France Use of OpenAM at VAL-I- PAC

OpenAM Best Practices: Use of OpenAM at VAL-I-PAC

Embed Size (px)

DESCRIPTION

ACA IT-Solutions Security Specialist Jan Van den Bergh details OpenAM best practices at VAL-I-PAC as part of a joint Case Study session with Everett and IS4U, moderated by ForgeRock VP of Services Steve Ferris and Director of Support Tim Rault-Smith.

Citation preview

Page 1: OpenAM Best Practices: Use of OpenAM at VAL-I-PAC

2013 Open Stack Identity Summit - France

Use of OpenAM at VAL-I-PAC

Page 2: OpenAM Best Practices: Use of OpenAM at VAL-I-PAC

About myself

• Jan Van den Bergh

[email protected]

@janvdbergh

• IAM Architect and Security Specialist at ACA IT-Solutions.

Page 3: OpenAM Best Practices: Use of OpenAM at VAL-I-PAC

About VAL-I-PAC

• Non-profit organization consisting of about 50 companies from a broad cross section of industries.

• Controls how industrial packaging waste is managed in Belgium.

• Provides services to over 8.000 Belgian companies.

Page 4: OpenAM Best Practices: Use of OpenAM at VAL-I-PAC

The application landscape

MonaLisa+ ODO

Leonardo

IBMCognos

CRM

Amazon EC2 Cloud

Google Apps

OpenAM

Page 5: OpenAM Best Practices: Use of OpenAM at VAL-I-PAC

Key features

• Different authentication mechanisms:

Username / password – Belgian eID card – MyDigipass

• Different integration mechanisms:

SAML – Agent-based – Custom connector (OSGI).

• Automatic deployment using scripts:• Quickly deploy and redeploy different environments.

• Reduces errors and down-time.

Page 6: OpenAM Best Practices: Use of OpenAM at VAL-I-PAC

Key features

• Leverages the EC2 cloud.• Quickly set up / replace hosts.

• Add environments when they are needed.

Page 7: OpenAM Best Practices: Use of OpenAM at VAL-I-PAC

Later enhancements• Automatic deployments using Chef.

• HTML 5 adaptive screen layout.

• Reusable components:• OpenAM connector for custom applications (replaces agents).

• Custom authentication modules (eID – OpenID – RememberMe).

• Deployment scripts.

• Invite mechanism (= delegated administration)

• SaaS model using REST services.

Page 8: OpenAM Best Practices: Use of OpenAM at VAL-I-PAC

Some best practices

• Use OpenAM only for access management.

• Do not add new features to the UI.(Instead, set up a different application using the SDK.)

• Invest in automated install and configuration.

• Do not underestimate the required effort.