SlideShare ist ein Scribd-Unternehmen logo
1 von 2
FEDERATED SINGLE SIGN-ON: HOW TO MAKE IT WORK FOR THE
WEB

For federated single sign-on (sso) to work on the web, it needs to be brain-dead easy for
web developers.
Asking developers to implement OpenID Connect is not the answer for everyone, although
with better high level libraries, this will hopefully become easier. Also, I think it’s widely
understood that not all domains will want to rely on external authentication service
providers.

While everyone knows passwords suck… responsible for 80% of Internet security breaches…
the answer is sometimes just “better authentication.”
The OX open source access management platform lets you use open source software to
launch your own IDP that implements the OpenID Connect standard — the same protocol
being adopted by Google.
So don’t knock federated login just because you want to hold your own secrets… make
sure you align with the standards so web developers won’t have to learn your (probably
insecure) proprietary authentication API.
Also, take a look at UMA if you want to go beyond authentication, and use OAuth2 for
authorization!
A great tool for developers would be to use an Apache plugin to protect their application.
This is the reason Gluu started a Crowdtilt campaign to fund “UMA and OpenID Connect
Plugins for Apache.“
We’re nearing the deadline for funding this plugin and any and all contributions are greatly
appreciated.
Article Resource:- http://gluu.jimdo.com/federated-single-sign-on-how-to-make-it-workfor-the-web

Weitere ähnliche Inhalte

Mehr von Gluu

First o auth 2.0 and saml identity federation platform to be shown by gluu
First o auth 2.0 and saml identity federation platform to be shown by gluuFirst o auth 2.0 and saml identity federation platform to be shown by gluu
First o auth 2.0 and saml identity federation platform to be shown by gluu
Gluu
 
How & why gluu’s open source authorization and authentication platform was ch...
How & why gluu’s open source authorization and authentication platform was ch...How & why gluu’s open source authorization and authentication platform was ch...
How & why gluu’s open source authorization and authentication platform was ch...
Gluu
 
East hackathon api’s for art
East hackathon api’s for artEast hackathon api’s for art
East hackathon api’s for art
Gluu
 
Gluu’s vision
Gluu’s visionGluu’s vision
Gluu’s vision
Gluu
 
Gluu and canonical to demonstrate instant application security using ubuntu j...
Gluu and canonical to demonstrate instant application security using ubuntu j...Gluu and canonical to demonstrate instant application security using ubuntu j...
Gluu and canonical to demonstrate instant application security using ubuntu j...
Gluu
 
Currency of identifiers ii
Currency of identifiers iiCurrency of identifiers ii
Currency of identifiers ii
Gluu
 
Shibboleth identity provider (idp) what it is, and why you should consider a ...
Shibboleth identity provider (idp) what it is, and why you should consider a ...Shibboleth identity provider (idp) what it is, and why you should consider a ...
Shibboleth identity provider (idp) what it is, and why you should consider a ...
Gluu
 
Federated identity and open id connect why higher ed needs ox
Federated identity and open id connect why higher ed needs oxFederated identity and open id connect why higher ed needs ox
Federated identity and open id connect why higher ed needs ox
Gluu
 
Web access management using o auth2 and saml – wam 2.0
Web access management using o auth2 and saml – wam 2.0Web access management using o auth2 and saml – wam 2.0
Web access management using o auth2 and saml – wam 2.0
Gluu
 
Packt publishing book proposal api and mobile access management
Packt publishing book proposal api and mobile access managementPackt publishing book proposal api and mobile access management
Packt publishing book proposal api and mobile access management
Gluu
 
Postcard from identity next 2013
Postcard from identity next 2013Postcard from identity next 2013
Postcard from identity next 2013
Gluu
 

Mehr von Gluu (19)

The currency of identifiers
The currency of identifiersThe currency of identifiers
The currency of identifiers
 
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
 
Gluu sxsw 2015 interactive picks
Gluu sxsw 2015 interactive picksGluu sxsw 2015 interactive picks
Gluu sxsw 2015 interactive picks
 
17 recommended requirements for an identity and access management poc
17 recommended requirements for an identity and access management poc17 recommended requirements for an identity and access management poc
17 recommended requirements for an identity and access management poc
 
Top 10 applications for multi factor authentication in higher education
Top 10 applications for multi factor authentication in higher educationTop 10 applications for multi factor authentication in higher education
Top 10 applications for multi factor authentication in higher education
 
First o auth 2.0 and saml identity federation platform to be shown by gluu
First o auth 2.0 and saml identity federation platform to be shown by gluuFirst o auth 2.0 and saml identity federation platform to be shown by gluu
First o auth 2.0 and saml identity federation platform to be shown by gluu
 
How & why gluu’s open source authorization and authentication platform was ch...
How & why gluu’s open source authorization and authentication platform was ch...How & why gluu’s open source authorization and authentication platform was ch...
How & why gluu’s open source authorization and authentication platform was ch...
 
East hackathon api’s for art
East hackathon api’s for artEast hackathon api’s for art
East hackathon api’s for art
 
Gluu’s vision
Gluu’s visionGluu’s vision
Gluu’s vision
 
Gluu and canonical to demonstrate instant application security using ubuntu j...
Gluu and canonical to demonstrate instant application security using ubuntu j...Gluu and canonical to demonstrate instant application security using ubuntu j...
Gluu and canonical to demonstrate instant application security using ubuntu j...
 
Currency of identifiers ii
Currency of identifiers iiCurrency of identifiers ii
Currency of identifiers ii
 
Shibboleth identity provider (idp) what it is, and why you should consider a ...
Shibboleth identity provider (idp) what it is, and why you should consider a ...Shibboleth identity provider (idp) what it is, and why you should consider a ...
Shibboleth identity provider (idp) what it is, and why you should consider a ...
 
Federated identity and open id connect why higher ed needs ox
Federated identity and open id connect why higher ed needs oxFederated identity and open id connect why higher ed needs ox
Federated identity and open id connect why higher ed needs ox
 
Web access management using o auth2 and saml – wam 2.0
Web access management using o auth2 and saml – wam 2.0Web access management using o auth2 and saml – wam 2.0
Web access management using o auth2 and saml – wam 2.0
 
Packt publishing book proposal api and mobile access management
Packt publishing book proposal api and mobile access managementPackt publishing book proposal api and mobile access management
Packt publishing book proposal api and mobile access management
 
Gluu oscon submission
Gluu oscon submissionGluu oscon submission
Gluu oscon submission
 
Go west young federation
Go west young federationGo west young federation
Go west young federation
 
 Use case for asimba as saml proxy
 Use case for asimba as saml proxy Use case for asimba as saml proxy
 Use case for asimba as saml proxy
 
Postcard from identity next 2013
Postcard from identity next 2013Postcard from identity next 2013
Postcard from identity next 2013
 

Federated single sign on how to make it work for the web

  • 1. FEDERATED SINGLE SIGN-ON: HOW TO MAKE IT WORK FOR THE WEB For federated single sign-on (sso) to work on the web, it needs to be brain-dead easy for web developers. Asking developers to implement OpenID Connect is not the answer for everyone, although with better high level libraries, this will hopefully become easier. Also, I think it’s widely understood that not all domains will want to rely on external authentication service providers. While everyone knows passwords suck… responsible for 80% of Internet security breaches… the answer is sometimes just “better authentication.” The OX open source access management platform lets you use open source software to launch your own IDP that implements the OpenID Connect standard — the same protocol being adopted by Google.
  • 2. So don’t knock federated login just because you want to hold your own secrets… make sure you align with the standards so web developers won’t have to learn your (probably insecure) proprietary authentication API. Also, take a look at UMA if you want to go beyond authentication, and use OAuth2 for authorization! A great tool for developers would be to use an Apache plugin to protect their application. This is the reason Gluu started a Crowdtilt campaign to fund “UMA and OpenID Connect Plugins for Apache.“ We’re nearing the deadline for funding this plugin and any and all contributions are greatly appreciated. Article Resource:- http://gluu.jimdo.com/federated-single-sign-on-how-to-make-it-workfor-the-web