SlideShare ist ein Scribd-Unternehmen logo
1 von 24
Sun Microsystems, Inc. Sun Access Manager 介绍 蒋健
议程 ,[object Object],[object Object],[object Object],[object Object],[object Object]
访问管理 关键且具有挑战 ! 员工 客户 合作伙伴 行业组织 人事 财务 基本业务 ,[object Object],[object Object],[object Object],[object Object],[object Object],网上业务
典型需求 ,[object Object],[object Object],[object Object],[object Object]
Sun 访问管理策略 ,[object Object],[object Object],[object Object],[object Object]
Access Manager 功能概览 ,[object Object],[object Object],[object Object],[object Object],Directories Databases Business  Applications
AM 基本工作流程 ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
议程 ,[object Object],[object Object],[object Object],[object Object],[object Object]
AM 系统架构 C Applications Java Applications Web / Application Server Java Applications Policy Agent Web / J2EE Container Custom Plugin Modules Custom Plugin Modules Plugin Modules Plugin Modules Access Manager  Services Access Manager APIs Access Manager Framework SPI (Service Provider Interface) Admin CLI (XML) Provided by Sun Java System Access Manager Java APIs Java APIs HTTP(S) HTTP(S) XML/HTTP(S) XML/HTTP(S) Sun Java System Directory Server Web Browser SDK SDK SDK
Access Manager 部署图
议程 ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
认证 ( Authentication) ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
基于策略 (policy) 的授权 ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
策略 (Policy) 架构
单点登录 (Single Sign-On) ,[object Object],[object Object],[object Object]
策略代理 (Policy Agent) ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
SSO 令牌 (Single Sign-On Token) ,[object Object],[object Object],[object Object],[object Object]
Session  特性 ,[object Object],[object Object],[object Object],[object Object]
Web SSO 流程  Agent1 Agent2 Sun Java System Access Manager 资源 1 资源 2 Browser 1.  请求资源 1 4.  验证并创建 SSO token 5.  要求重定向到资源 1 带着  SSO token 9.  请求资源 2 11.  提供资源或拒绝 6.  请求资源 1 2. Agent  检查 SSO Token 10. Agent  检查 SSO Token 以及 Policy 3.  要求登录 8. 提供资源或拒绝 7. Agent  检查 SSO Token 以及 Policy
联合身份 (Identity Federation) ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
SAML  ,[object Object],[object Object],[object Object],[object Object],[object Object]
自由联盟 (Liberty) 项目 ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Federation 流程 AM 1 Client AM 2 2. 请求 AM2 所管理的资源 1.  接受完成 AM1 的认证 3. 通过 SAML,  创建断言,辅件以及包含辅件的 URL 4. 要求重定向到 AM2 5. 重定向到 AM2 6.  通过辅件请求断言 8. 响应请求 7. 提供断言
相关资源 ,[object Object],[object Object],[object Object],[object Object]

Weitere ähnliche Inhalte

Andere mochten auch

Cv For Tamer Full1
Cv For Tamer Full1Cv For Tamer Full1
Cv For Tamer Full1tamernegm
 
Health And Human Services 2005 Legal Program Announcement
Health And Human Services 2005 Legal Program AnnouncementHealth And Human Services 2005 Legal Program Announcement
Health And Human Services 2005 Legal Program Announcementlegaladvice
 
Bib Lia 1
Bib Lia 1Bib Lia 1
Bib Lia 1natan
 
banner
bannerbanner
bannerguru20
 
Iain Power’S Pro Engineer
Iain Power’S Pro EngineerIain Power’S Pro Engineer
Iain Power’S Pro Engineeripower
 
Εμπιστοσύνη στους Θεσμούς, 2008 1ο μέρος
Εμπιστοσύνη στους Θεσμούς, 2008 1ο μέροςΕμπιστοσύνη στους Θεσμούς, 2008 1ο μέρος
Εμπιστοσύνη στους Θεσμούς, 2008 1ο μέροςsmyrnaios
 
what a girl wants? feminine approach of fashion site product designs
what a girl wants? feminine approach of fashion site product designswhat a girl wants? feminine approach of fashion site product designs
what a girl wants? feminine approach of fashion site product designsichloe
 
Credit Stock Presentation 13.11.08
Credit Stock Presentation 13.11.08Credit Stock Presentation 13.11.08
Credit Stock Presentation 13.11.08creditsecurities
 
Forankring af sociale medier
Forankring af sociale medierForankring af sociale medier
Forankring af sociale medierJacob Bøtter
 
Internet & Privacy
Internet & PrivacyInternet & Privacy
Internet & PrivacyPivari.com
 
Adams The Legalized Crime Of Banking And A Constitutional Remedy (1958)
Adams   The Legalized Crime Of Banking And A Constitutional Remedy (1958)Adams   The Legalized Crime Of Banking And A Constitutional Remedy (1958)
Adams The Legalized Crime Of Banking And A Constitutional Remedy (1958)legaladvice
 
Wikipedia come usarla
Wikipedia come usarlaWikipedia come usarla
Wikipedia come usarlaPivari.com
 
Specific Features of Bloodcirculatory System Functioning in Surgeons Working ...
Specific Features of Bloodcirculatory System Functioning in Surgeons Working ...Specific Features of Bloodcirculatory System Functioning in Surgeons Working ...
Specific Features of Bloodcirculatory System Functioning in Surgeons Working ...gritsyuk31
 
Camcorders and Digital Cameras in Japan Market Research & Evaluation (EN)
Camcorders and Digital Cameras in Japan Market Research & Evaluation (EN)Camcorders and Digital Cameras in Japan Market Research & Evaluation (EN)
Camcorders and Digital Cameras in Japan Market Research & Evaluation (EN)highersns
 
Samsung Hope On Slideshare
Samsung Hope On SlideshareSamsung Hope On Slideshare
Samsung Hope On Slidesharedanielgoh
 

Andere mochten auch (20)

241 Un Regalo Para Ti
241 Un Regalo Para Ti241 Un Regalo Para Ti
241 Un Regalo Para Ti
 
Cv For Tamer Full1
Cv For Tamer Full1Cv For Tamer Full1
Cv For Tamer Full1
 
Health And Human Services 2005 Legal Program Announcement
Health And Human Services 2005 Legal Program AnnouncementHealth And Human Services 2005 Legal Program Announcement
Health And Human Services 2005 Legal Program Announcement
 
Bib Lia 1
Bib Lia 1Bib Lia 1
Bib Lia 1
 
banner
bannerbanner
banner
 
Iain Power’S Pro Engineer
Iain Power’S Pro EngineerIain Power’S Pro Engineer
Iain Power’S Pro Engineer
 
Εμπιστοσύνη στους Θεσμούς, 2008 1ο μέρος
Εμπιστοσύνη στους Θεσμούς, 2008 1ο μέροςΕμπιστοσύνη στους Θεσμούς, 2008 1ο μέρος
Εμπιστοσύνη στους Θεσμούς, 2008 1ο μέρος
 
what a girl wants? feminine approach of fashion site product designs
what a girl wants? feminine approach of fashion site product designswhat a girl wants? feminine approach of fashion site product designs
what a girl wants? feminine approach of fashion site product designs
 
Credit Stock Presentation 13.11.08
Credit Stock Presentation 13.11.08Credit Stock Presentation 13.11.08
Credit Stock Presentation 13.11.08
 
Forankring af sociale medier
Forankring af sociale medierForankring af sociale medier
Forankring af sociale medier
 
Marzena śWigoń. Bariery Informacyjne
Marzena śWigoń. Bariery InformacyjneMarzena śWigoń. Bariery Informacyjne
Marzena śWigoń. Bariery Informacyjne
 
Internet & Privacy
Internet & PrivacyInternet & Privacy
Internet & Privacy
 
Ranocchia
RanocchiaRanocchia
Ranocchia
 
Hsc 2008 Day 2
Hsc 2008   Day 2Hsc 2008   Day 2
Hsc 2008 Day 2
 
Adams The Legalized Crime Of Banking And A Constitutional Remedy (1958)
Adams   The Legalized Crime Of Banking And A Constitutional Remedy (1958)Adams   The Legalized Crime Of Banking And A Constitutional Remedy (1958)
Adams The Legalized Crime Of Banking And A Constitutional Remedy (1958)
 
Valle Del Jerte 2008
Valle Del Jerte 2008Valle Del Jerte 2008
Valle Del Jerte 2008
 
Wikipedia come usarla
Wikipedia come usarlaWikipedia come usarla
Wikipedia come usarla
 
Specific Features of Bloodcirculatory System Functioning in Surgeons Working ...
Specific Features of Bloodcirculatory System Functioning in Surgeons Working ...Specific Features of Bloodcirculatory System Functioning in Surgeons Working ...
Specific Features of Bloodcirculatory System Functioning in Surgeons Working ...
 
Camcorders and Digital Cameras in Japan Market Research & Evaluation (EN)
Camcorders and Digital Cameras in Japan Market Research & Evaluation (EN)Camcorders and Digital Cameras in Japan Market Research & Evaluation (EN)
Camcorders and Digital Cameras in Japan Market Research & Evaluation (EN)
 
Samsung Hope On Slideshare
Samsung Hope On SlideshareSamsung Hope On Slideshare
Samsung Hope On Slideshare
 

Ähnlich wie Accessmanager

淘宝开放产品前端实践
淘宝开放产品前端实践淘宝开放产品前端实践
淘宝开放产品前端实践taobao.com
 
Top100summit 腾讯-周健-服务化与体系化解决大量定制小项目开发困境
Top100summit 腾讯-周健-服务化与体系化解决大量定制小项目开发困境Top100summit 腾讯-周健-服务化与体系化解决大量定制小项目开发困境
Top100summit 腾讯-周健-服务化与体系化解决大量定制小项目开发困境drewz lin
 
1026 Windows Server 2008 Active Directory 版權管理服務
1026 Windows Server 2008 Active Directory 版權管理服務1026 Windows Server 2008 Active Directory 版權管理服務
1026 Windows Server 2008 Active Directory 版權管理服務Timothy Chen
 
分会场四Veri sign 信任服务与用户认证
分会场四Veri sign 信任服务与用户认证分会场四Veri sign 信任服务与用户认证
分会场四Veri sign 信任服务与用户认证ITband
 
跨越虚拟化驼峰 如何激活停滞的虚拟化配置
跨越虚拟化驼峰   如何激活停滞的虚拟化配置跨越虚拟化驼峰   如何激活停滞的虚拟化配置
跨越虚拟化驼峰 如何激活停滞的虚拟化配置ITband
 
1116 Windows server 2008 - 使用 IIS 7.0 建置安全站台
1116 Windows server 2008 - 使用 IIS 7.0 建置安全站台1116 Windows server 2008 - 使用 IIS 7.0 建置安全站台
1116 Windows server 2008 - 使用 IIS 7.0 建置安全站台Timothy Chen
 
區塊鏈與金融科技(Blockchain and Fintech)
區塊鏈與金融科技(Blockchain and Fintech)區塊鏈與金融科技(Blockchain and Fintech)
區塊鏈與金融科技(Blockchain and Fintech)HO-HSUN LIN
 
分会场四服务器安全防护的意义与价值
分会场四服务器安全防护的意义与价值分会场四服务器安全防护的意义与价值
分会场四服务器安全防护的意义与价值ITband
 
01.ofm11g概览
01.ofm11g概览01.ofm11g概览
01.ofm11g概览Meng He
 
database
databasedatabase
databases06283
 
Track 2 Session 2_ 電商平台的資安維運與成本管理
Track 2 Session 2_ 電商平台的資安維運與成本管理Track 2 Session 2_ 電商平台的資安維運與成本管理
Track 2 Session 2_ 電商平台的資安維運與成本管理Amazon Web Services
 
单点登录解决方案的架构与实现
单点登录解决方案的架构与实现单点登录解决方案的架构与实现
单点登录解决方案的架构与实现jeffz
 
民间秘方
民间秘方民间秘方
民间秘方dynasty
 
11个步骤应用Spring Security 3(西安尚学堂~付老实)
11个步骤应用Spring Security 3(西安尚学堂~付老实)11个步骤应用Spring Security 3(西安尚学堂~付老实)
11个步骤应用Spring Security 3(西安尚学堂~付老实)Underwind
 
11个步骤应用Spring Security 3
11个步骤应用Spring Security 311个步骤应用Spring Security 3
11个步骤应用Spring Security 3Underwind
 
基于Silverlight的RIA架构及百度应用
基于Silverlight的RIA架构及百度应用基于Silverlight的RIA架构及百度应用
基于Silverlight的RIA架构及百度应用Cat Chen
 

Ähnlich wie Accessmanager (20)

CAREY-Tech SSO
CAREY-Tech SSOCAREY-Tech SSO
CAREY-Tech SSO
 
淘宝开放产品前端实践
淘宝开放产品前端实践淘宝开放产品前端实践
淘宝开放产品前端实践
 
Top100summit 腾讯-周健-服务化与体系化解决大量定制小项目开发困境
Top100summit 腾讯-周健-服务化与体系化解决大量定制小项目开发困境Top100summit 腾讯-周健-服务化与体系化解决大量定制小项目开发困境
Top100summit 腾讯-周健-服务化与体系化解决大量定制小项目开发困境
 
1026 Windows Server 2008 Active Directory 版權管理服務
1026 Windows Server 2008 Active Directory 版權管理服務1026 Windows Server 2008 Active Directory 版權管理服務
1026 Windows Server 2008 Active Directory 版權管理服務
 
分会场四Veri sign 信任服务与用户认证
分会场四Veri sign 信任服务与用户认证分会场四Veri sign 信任服务与用户认证
分会场四Veri sign 信任服务与用户认证
 
跨越虚拟化驼峰 如何激活停滞的虚拟化配置
跨越虚拟化驼峰   如何激活停滞的虚拟化配置跨越虚拟化驼峰   如何激活停滞的虚拟化配置
跨越虚拟化驼峰 如何激活停滞的虚拟化配置
 
1116 Windows server 2008 - 使用 IIS 7.0 建置安全站台
1116 Windows server 2008 - 使用 IIS 7.0 建置安全站台1116 Windows server 2008 - 使用 IIS 7.0 建置安全站台
1116 Windows server 2008 - 使用 IIS 7.0 建置安全站台
 
區塊鏈與金融科技(Blockchain and Fintech)
區塊鏈與金融科技(Blockchain and Fintech)區塊鏈與金融科技(Blockchain and Fintech)
區塊鏈與金融科技(Blockchain and Fintech)
 
分会场四服务器安全防护的意义与价值
分会场四服务器安全防护的意义与价值分会场四服务器安全防护的意义与价值
分会场四服务器安全防护的意义与价值
 
零壹科技 個人資料管理系統 (PIMS) WorkShop
零壹科技 個人資料管理系統 (PIMS) WorkShop零壹科技 個人資料管理系統 (PIMS) WorkShop
零壹科技 個人資料管理系統 (PIMS) WorkShop
 
01.ofm11g概览
01.ofm11g概览01.ofm11g概览
01.ofm11g概览
 
database
databasedatabase
database
 
Track 2 Session 2_ 電商平台的資安維運與成本管理
Track 2 Session 2_ 電商平台的資安維運與成本管理Track 2 Session 2_ 電商平台的資安維運與成本管理
Track 2 Session 2_ 電商平台的資安維運與成本管理
 
单点登录解决方案的架构与实现
单点登录解决方案的架构与实现单点登录解决方案的架构与实现
单点登录解决方案的架构与实现
 
民间秘方
民间秘方民间秘方
民间秘方
 
11个步骤应用Spring Security 3(西安尚学堂~付老实)
11个步骤应用Spring Security 3(西安尚学堂~付老实)11个步骤应用Spring Security 3(西安尚学堂~付老实)
11个步骤应用Spring Security 3(西安尚学堂~付老实)
 
11个步骤应用Spring Security 3
11个步骤应用Spring Security 311个步骤应用Spring Security 3
11个步骤应用Spring Security 3
 
網路安全管理
網路安全管理網路安全管理
網路安全管理
 
OAuth2介紹
OAuth2介紹OAuth2介紹
OAuth2介紹
 
基于Silverlight的RIA架构及百度应用
基于Silverlight的RIA架构及百度应用基于Silverlight的RIA架构及百度应用
基于Silverlight的RIA架构及百度应用
 

Accessmanager

  • 1. Sun Microsystems, Inc. Sun Access Manager 介绍 蒋健
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
  • 8.
  • 9. AM 系统架构 C Applications Java Applications Web / Application Server Java Applications Policy Agent Web / J2EE Container Custom Plugin Modules Custom Plugin Modules Plugin Modules Plugin Modules Access Manager Services Access Manager APIs Access Manager Framework SPI (Service Provider Interface) Admin CLI (XML) Provided by Sun Java System Access Manager Java APIs Java APIs HTTP(S) HTTP(S) XML/HTTP(S) XML/HTTP(S) Sun Java System Directory Server Web Browser SDK SDK SDK
  • 11.
  • 12.
  • 13.
  • 15.
  • 16.
  • 17.
  • 18.
  • 19. Web SSO 流程 Agent1 Agent2 Sun Java System Access Manager 资源 1 资源 2 Browser 1. 请求资源 1 4. 验证并创建 SSO token 5. 要求重定向到资源 1 带着 SSO token 9. 请求资源 2 11. 提供资源或拒绝 6. 请求资源 1 2. Agent 检查 SSO Token 10. Agent 检查 SSO Token 以及 Policy 3. 要求登录 8. 提供资源或拒绝 7. Agent 检查 SSO Token 以及 Policy
  • 20.
  • 21.
  • 22.
  • 23. Federation 流程 AM 1 Client AM 2 2. 请求 AM2 所管理的资源 1. 接受完成 AM1 的认证 3. 通过 SAML, 创建断言,辅件以及包含辅件的 URL 4. 要求重定向到 AM2 5. 重定向到 AM2 6. 通过辅件请求断言 8. 响应请求 7. 提供断言
  • 24.