SlideShare ist ein Scribd-Unternehmen logo
1 von 24
IRM Summit 2014
Incredible Edible Identity
Jamie Nelson
Jonathan Scudder
Jake Feasel
2IRM Summit 2014
Evolution To IRM
Employees
Consumers
Employees &
Partners
Things
Perimeter
Perimeter
Federation
Perimeter-less
Federation
Cloud / SaaS
Perimeter-less
Federation
Cloud
SaaS
Mobility
Attributes
Context
Stateless
Relationships
3IRM Summit 2014
ForgeRock Products
Context-Based Access
Management
Cloud-Focused
Identity Administration
Internet Scale
Directory Services
Unifying Enterprise and Cloud
Identity Infrastructure
No Touch SSO to enterprise,
legacy, and custom apps
Hands-free protection of
mobile apps and APIs
Identity Relationship Management Platform
Only Unified Platform – Only Customer-Scale Platform -- Supports any application, device,
or “thing”
FORGEROCK.COM | CONFIDENTIAL
SecureMobileSecureConnectCloudConnect
4IRM Summit 2014
ForgeRock Deployment
Portals,applications,webservices,API’s
• Registration & Self-Service
• Auditing & Compliance
• Workflow & Reporting
• Native connectors
• REST API
• Authentication & session
• Authorization & policy
• Entitlements
• Federation
• REST API
• Identity Store
• Directory Proxy
• REST API
Partners
• Reverse Proxy
• App Gateway Legacy Apps
ICF
• Identity
Connector
Framework
Identity
Administration
Access
ManagementIdentityData
• Provisioning
• SSO
Cloud Apps
Consumers & Customers
Enterprise Apps
Devices & Things
• Federation
Data Centers
• HA
• Replication
CloudCONNECT
SecureConnect
5IRM Summit 2014
Niche Vendor
Access
Management
Provisioning
Services
Directory
Services
SaaS Bridging Application
Gateway
Mobile
Enablement
Great At One Problem Space
Pick One
FORGEROCK.COM | CONFIDENTIAL
6IRM Summit 2014
Niche Deployment
Portals,applications,webservices,API’s
• Registration & Self-Service
• Auditing & Compliance
• Workflow & Reporting
• Native connectors
• REST API
• Authentication & session
• Authorization & policy
• Entitlements
• Federation
• REST API
• Identity Store
• Directory Proxy
• REST API
Partners
• Reverse Proxy
• App Gateway Legacy Apps
• Identity
Connector
Framework
Identity
Administration
Access
ManagementIdentityData
• Provisioning
• SSO
Cloud Apps
Consumers & Customers
Enterprise Apps
Devices & Things
• Federation
Data Centers
• HA
• Replication
7IRM Summit 2014
Leading Stack Vendors
Acquisition Architecture – Employee Scale – Massive TCO
Access
Manager
Identity
Federation
Identity
Manager
Mobile Security
Suite
Directory
Server
Entitlements
Server
Enterprise
SSO
Identity
Governance
Adaptive
Access
Web Services
Security
Enterprise AppsMobile Apps Things
8IRM Summit 2014
Stack Vendor’s Deployment
Portals,applications,webservices,API’s
Professional
Services
Partners
Legacy Apps
Identity
Administration
Access
ManagementIdentityData
Cloud Apps
Consumers & Customers
Enterprise Apps
Devices & Things
Data Centers
9IRM Summit 2014
Integrated Stack Components
■ Simple, Integrated, Modular, High Scale
■ ForgeRock REST (CREST)
■ Authn and Authz Filters
■ ForgeRock UI
■ OpenID Connect, OAuth, SAML2
10IRM Summit 2014
OpenAM
ForgeRock REST (Commons REST)
Protected Resources
Web
Agents
JavaEE
Agents
Web Services
Agents
User Interface
End User
ForgeRock UI Framework
Core Services
Authentication Entitlements Session AuditOAuth
Core Token ServiceOpenID
Connect
Configuration
Policy
User
Management
Secure Token
Service
XACML Federation
SPIs
Authentication
Plugins
Policy
Plugins
User Mgmt
Plugins
Token
Service
Plugins
Federation
Plugins
Persistence
(OpenDJ)
Universal
Gateway
Management
11IRM Summit 2014
OpenIDM
OSGI
Persistence
(OrientDB)
ForgeRock UI Framework
ForgeRock REST Router
Business Logic (Javascript, Groovy, Java)
Authentication Filter (JASPI)
Jetty Web Server
Configuration
Managed
Users
Sync/Recon
System
(Connectors)
Scheduler
Task
Scanner
Audit/Logs
Policy
ExternalResources
Audit
12IRM Summit 2014
OpenDJ
User Interface
End UserManagement
ForgeRock UI Framework
ForgeRock REST
Core Server
Replication AuditingLDAPV3Caching Monitoring
Password
Policy
Groups
Schema
Management
REST2LDAP
Access
Control
Backend Services
Persistence Connectors LDIF MemoryChange Log
Java SDK/ LDAPv3
Web Application
REST2LDAP
ForgeRock REST
13IRM Summit 2014
CloudConnect
OSGIConfiguration Wizard
OpenIDM
Business Logic (Javascript, Groovy, Java)
Authentication JASPI (AD and IWA)
Jetty Web Server
Salesforce
and LDAP
OAuth
Salesforce
LDAP
Connector
Federation
ForgeRock UI Framework
Reporting and Recon
14IRM Summit 2014
SecureConnect
Core Processing
Http Connector
HTTP Listener
ChainsFilters Functions Handlers
Scripting Audit
15IRM Summit 2014
API Strategy
Conscious, proactive design
Developer-focused Consistent
Easy to useModern
16IRM Summit 2014
API Strategy
Conscious, proactive design
Developer-focused Consistent
Easy to useModern
JSON
REST
ROA
17IRM Summit 2014
API Strategy
OpenIDM
Resource API
OpenAM
Resource API
OpenDJ
Resource API
Common UI / other clients
Resource consumer
18IRM Summit 2014
CREST API
19IRM Summit 2014
CREST Framework
COPYRIGHT 2013 FORGEROCK AS
ROA Framework / CREST API
Router
Services or other
non-resource
oriented architecture
Resource
Normalization
Non-Json
Resource
JsonResource
20IRM Summit 2014
AuthN and AuthZ Filters
21IRM Summit 2014
Open Identity Stack UI Model
■ “Single-Page Web App” style
■ Single UI model for all products
■ Built on ForgeRock REST (CREST)
■ Common UIs for:
– User management
– Registration and Self Service
– Login and Password Reset
■ Build on shared services for Authentication
22IRM Summit 2014
ForgeRock UI Library Stack
 jQuery (General utlity) + jQuery UI (Widgets)
 Backbone.js + Require.js (Modular MVC Architecture)
 Handlebars.js (Templating)
 Underscore.js (General utility)
 Less.js (CSS preprocessor)
 Built on ForgeRock REST and Common Services
 Caters to the web developers of today
23IRM Summit 2014
Demo
■ OpenAM as the IDP
■ OpenDJ as the User and Config Store
■ OpenIDM provisioning to DJ
■ Commons
– ForgeRock REST in OpenAM, OpenIDM, OpenDJ
– Filters protecting OpenIDM
– ForgeRock UI in OpenIDM and OpenAM
24IRM Summit 2014
Questions ?

Weitere ähnliche Inhalte

Was ist angesagt?

OpenIDM: An Introduction
OpenIDM: An IntroductionOpenIDM: An Introduction
OpenIDM: An Introduction
ForgeRock
 

Was ist angesagt? (20)

Open Identity Stack Roadmap
Open Identity Stack RoadmapOpen Identity Stack Roadmap
Open Identity Stack Roadmap
 
Directory Services with the ForgeRock Identity Platform - So What’s New?
Directory Services with the ForgeRock Identity Platform - So What’s New?Directory Services with the ForgeRock Identity Platform - So What’s New?
Directory Services with the ForgeRock Identity Platform - So What’s New?
 
OpenAM: An Introduction
OpenAM: An IntroductionOpenAM: An Introduction
OpenAM: An Introduction
 
Implementing eGov
Implementing eGovImplementing eGov
Implementing eGov
 
Webinar: Access Management with the ForgeRock Identity Platform - So What’s N...
Webinar: Access Management with the ForgeRock Identity Platform - So What’s N...Webinar: Access Management with the ForgeRock Identity Platform - So What’s N...
Webinar: Access Management with the ForgeRock Identity Platform - So What’s N...
 
Webinar: OpenIDM 3.1
Webinar: OpenIDM 3.1Webinar: OpenIDM 3.1
Webinar: OpenIDM 3.1
 
Webinar: OpenAM 12.0 - New Featurs
Webinar: OpenAM 12.0 - New FeatursWebinar: OpenAM 12.0 - New Featurs
Webinar: OpenAM 12.0 - New Featurs
 
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
 
Identity as a Managed Cloud Service
Identity as a Managed Cloud ServiceIdentity as a Managed Cloud Service
Identity as a Managed Cloud Service
 
Shoot Me a Token: OpenAM as an OAuth2 Provider
Shoot Me a Token: OpenAM as an OAuth2 ProviderShoot Me a Token: OpenAM as an OAuth2 Provider
Shoot Me a Token: OpenAM as an OAuth2 Provider
 
Customer Scale: Stateless Sessions and Managing High-Volume Digital Services
Customer Scale: Stateless Sessions and Managing High-Volume Digital ServicesCustomer Scale: Stateless Sessions and Managing High-Volume Digital Services
Customer Scale: Stateless Sessions and Managing High-Volume Digital Services
 
OpenIDM: An Introduction
OpenIDM: An IntroductionOpenIDM: An Introduction
OpenIDM: An Introduction
 
Webinar: Identity Wars: The Unified Platform Awakens
Webinar: Identity Wars: The Unified Platform AwakensWebinar: Identity Wars: The Unified Platform Awakens
Webinar: Identity Wars: The Unified Platform Awakens
 
OpenAM as Flexible Integration Component
OpenAM as Flexible Integration ComponentOpenAM as Flexible Integration Component
OpenAM as Flexible Integration Component
 
Technical Case Study: McKesson - Employing the Open Identity Stack
Technical Case Study: McKesson - Employing the Open Identity StackTechnical Case Study: McKesson - Employing the Open Identity Stack
Technical Case Study: McKesson - Employing the Open Identity Stack
 
OpenID Connect and Single Sign-On for Beginners
OpenID Connect and Single Sign-On for BeginnersOpenID Connect and Single Sign-On for Beginners
OpenID Connect and Single Sign-On for Beginners
 
Pimping the ForgeRock Identity Platform for a Billion Users
Pimping the ForgeRock Identity Platform for a Billion UsersPimping the ForgeRock Identity Platform for a Billion Users
Pimping the ForgeRock Identity Platform for a Billion Users
 
The Future is Now: What’s New in ForgeRock Access Management
The Future is Now: What’s New in ForgeRock Access Management The Future is Now: What’s New in ForgeRock Access Management
The Future is Now: What’s New in ForgeRock Access Management
 
OpenAM Survival Tips
OpenAM Survival TipsOpenAM Survival Tips
OpenAM Survival Tips
 
Enterprise Security Requirements
Enterprise Security RequirementsEnterprise Security Requirements
Enterprise Security Requirements
 

Ähnlich wie Incredible Edible Identity

CA Security - Deloitte IAM Summit - Vasu
CA Security - Deloitte IAM Summit  - VasuCA Security - Deloitte IAM Summit  - Vasu
CA Security - Deloitte IAM Summit - Vasu
Vasu Surabhi
 
Iam suite introduction
Iam suite introductionIam suite introduction
Iam suite introduction
wardell henley
 

Ähnlich wie Incredible Edible Identity (20)

NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
NYC Identity Summit Tech Day: ForgeRock Identity Platform OverviewNYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
 
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
The Future is Now: The ForgeRock Identity Platform, Early 2017 ReleaseThe Future is Now: The ForgeRock Identity Platform, Early 2017 Release
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
 
Trusted by Default: The Forge Security & Privacy Model
Trusted by Default: The Forge Security & Privacy ModelTrusted by Default: The Forge Security & Privacy Model
Trusted by Default: The Forge Security & Privacy Model
 
CA Security - Deloitte IAM Summit - Vasu
CA Security - Deloitte IAM Summit  - VasuCA Security - Deloitte IAM Summit  - Vasu
CA Security - Deloitte IAM Summit - Vasu
 
IBM MobileFirst Reference Architecture 1512 v3 2015
IBM MobileFirst Reference Architecture 1512 v3 2015IBM MobileFirst Reference Architecture 1512 v3 2015
IBM MobileFirst Reference Architecture 1512 v3 2015
 
Iam suite introduction
Iam suite introductionIam suite introduction
Iam suite introduction
 
Triangle Node Meetup : APIs in Minutes with Node.js
Triangle Node Meetup :  APIs in Minutes with Node.jsTriangle Node Meetup :  APIs in Minutes with Node.js
Triangle Node Meetup : APIs in Minutes with Node.js
 
APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...
APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...
APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...
 
Architect day 20181128 - Afternoon Session
Architect day 20181128 - Afternoon SessionArchitect day 20181128 - Afternoon Session
Architect day 20181128 - Afternoon Session
 
Ad fs
Ad fsAd fs
Ad fs
 
CIS14: Early Peek at PingFederate Administrative REST API
CIS14: Early Peek at PingFederate Administrative REST APICIS14: Early Peek at PingFederate Administrative REST API
CIS14: Early Peek at PingFederate Administrative REST API
 
Open Source Identity Management
Open Source Identity ManagementOpen Source Identity Management
Open Source Identity Management
 
OIM11g R2PS2 Architecture
OIM11g R2PS2 ArchitectureOIM11g R2PS2 Architecture
OIM11g R2PS2 Architecture
 
iPlanet presentation
iPlanet presentationiPlanet presentation
iPlanet presentation
 
Melbourne API Management Seminar
Melbourne API Management SeminarMelbourne API Management Seminar
Melbourne API Management Seminar
 
eMAS Indentity and Access Management
eMAS Indentity and Access ManagementeMAS Indentity and Access Management
eMAS Indentity and Access Management
 
Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)
Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)
Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)
 
The 4th Generation Kingland platform
The 4th Generation Kingland platformThe 4th Generation Kingland platform
The 4th Generation Kingland platform
 
“Secure Portal” or WebSphere Portal – Security with Everything
“Secure Portal” or WebSphere Portal – Security with Everything“Secure Portal” or WebSphere Portal – Security with Everything
“Secure Portal” or WebSphere Portal – Security with Everything
 
Leveraging New Features in CA Single-Sign on to Enable Web Services, Social S...
Leveraging New Features in CA Single-Sign on to Enable Web Services, Social S...Leveraging New Features in CA Single-Sign on to Enable Web Services, Social S...
Leveraging New Features in CA Single-Sign on to Enable Web Services, Social S...
 

Mehr von ForgeRock

Mehr von ForgeRock (20)

Digital Identities in the Internet of Things - Securely Manage Devices at Scale
Digital Identities in the Internet of Things - Securely Manage Devices at ScaleDigital Identities in the Internet of Things - Securely Manage Devices at Scale
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
 
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and BeyondGet the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
 
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Sydney: Identity Management  - A Strategic OpportunityIdentity Live Sydney: Identity Management  - A Strategic Opportunity
Identity Live Sydney: Identity Management - A Strategic Opportunity
 
Identity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity CapabilityIdentity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity Capability
 
Identity Live Singapore 2018 Keynote Presentation
Identity Live Singapore 2018 Keynote PresentationIdentity Live Singapore 2018 Keynote Presentation
Identity Live Singapore 2018 Keynote Presentation
 
Identity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote PresentationIdentity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote Presentation
 
Identity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'EmIdentity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'Em
 
Identity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected SocietyIdentity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected Society
 
Identity Live Sydney: Intelligent Authentication
Identity Live Sydney: Intelligent Authentication Identity Live Sydney: Intelligent Authentication
Identity Live Sydney: Intelligent Authentication
 
Identity Live Sydney: Building Trust and Privacy in a Connected Society
Identity Live  Sydney:  Building Trust and Privacy in a Connected SocietyIdentity Live  Sydney:  Building Trust and Privacy in a Connected Society
Identity Live Sydney: Building Trust and Privacy in a Connected Society
 
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep DiveGet the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
 
Get the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - OverviewGet the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - Overview
 
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
ForgeRock and Trusona - Simplifying the Multi-factor User ExperienceForgeRock and Trusona - Simplifying the Multi-factor User Experience
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
 
Opening Keynote (Identity Live Berlin 2018)
Opening Keynote (Identity Live Berlin 2018)Opening Keynote (Identity Live Berlin 2018)
Opening Keynote (Identity Live Berlin 2018)
 
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
 
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
 
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
 
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
 
Shift from GDPR readiness to sustained compliance to improve your business an...
Shift from GDPR readiness to sustained compliance to improve your business an...Shift from GDPR readiness to sustained compliance to improve your business an...
Shift from GDPR readiness to sustained compliance to improve your business an...
 
Intelligent Authentication (Identity Live Berlin 2018)
Intelligent Authentication  (Identity Live Berlin 2018)Intelligent Authentication  (Identity Live Berlin 2018)
Intelligent Authentication (Identity Live Berlin 2018)
 

Kürzlich hochgeladen

TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
mohitmore19
 
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
Health
 

Kürzlich hochgeladen (20)

How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
Microsoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdfMicrosoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdf
 
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
Unlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language ModelsUnlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language Models
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
 
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTV
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
 
Hand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxHand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptx
 
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AISyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial Goals
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.js
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
 
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
 

Incredible Edible Identity

  • 1. IRM Summit 2014 Incredible Edible Identity Jamie Nelson Jonathan Scudder Jake Feasel
  • 2. 2IRM Summit 2014 Evolution To IRM Employees Consumers Employees & Partners Things Perimeter Perimeter Federation Perimeter-less Federation Cloud / SaaS Perimeter-less Federation Cloud SaaS Mobility Attributes Context Stateless Relationships
  • 3. 3IRM Summit 2014 ForgeRock Products Context-Based Access Management Cloud-Focused Identity Administration Internet Scale Directory Services Unifying Enterprise and Cloud Identity Infrastructure No Touch SSO to enterprise, legacy, and custom apps Hands-free protection of mobile apps and APIs Identity Relationship Management Platform Only Unified Platform – Only Customer-Scale Platform -- Supports any application, device, or “thing” FORGEROCK.COM | CONFIDENTIAL SecureMobileSecureConnectCloudConnect
  • 4. 4IRM Summit 2014 ForgeRock Deployment Portals,applications,webservices,API’s • Registration & Self-Service • Auditing & Compliance • Workflow & Reporting • Native connectors • REST API • Authentication & session • Authorization & policy • Entitlements • Federation • REST API • Identity Store • Directory Proxy • REST API Partners • Reverse Proxy • App Gateway Legacy Apps ICF • Identity Connector Framework Identity Administration Access ManagementIdentityData • Provisioning • SSO Cloud Apps Consumers & Customers Enterprise Apps Devices & Things • Federation Data Centers • HA • Replication CloudCONNECT SecureConnect
  • 5. 5IRM Summit 2014 Niche Vendor Access Management Provisioning Services Directory Services SaaS Bridging Application Gateway Mobile Enablement Great At One Problem Space Pick One FORGEROCK.COM | CONFIDENTIAL
  • 6. 6IRM Summit 2014 Niche Deployment Portals,applications,webservices,API’s • Registration & Self-Service • Auditing & Compliance • Workflow & Reporting • Native connectors • REST API • Authentication & session • Authorization & policy • Entitlements • Federation • REST API • Identity Store • Directory Proxy • REST API Partners • Reverse Proxy • App Gateway Legacy Apps • Identity Connector Framework Identity Administration Access ManagementIdentityData • Provisioning • SSO Cloud Apps Consumers & Customers Enterprise Apps Devices & Things • Federation Data Centers • HA • Replication
  • 7. 7IRM Summit 2014 Leading Stack Vendors Acquisition Architecture – Employee Scale – Massive TCO Access Manager Identity Federation Identity Manager Mobile Security Suite Directory Server Entitlements Server Enterprise SSO Identity Governance Adaptive Access Web Services Security Enterprise AppsMobile Apps Things
  • 8. 8IRM Summit 2014 Stack Vendor’s Deployment Portals,applications,webservices,API’s Professional Services Partners Legacy Apps Identity Administration Access ManagementIdentityData Cloud Apps Consumers & Customers Enterprise Apps Devices & Things Data Centers
  • 9. 9IRM Summit 2014 Integrated Stack Components ■ Simple, Integrated, Modular, High Scale ■ ForgeRock REST (CREST) ■ Authn and Authz Filters ■ ForgeRock UI ■ OpenID Connect, OAuth, SAML2
  • 10. 10IRM Summit 2014 OpenAM ForgeRock REST (Commons REST) Protected Resources Web Agents JavaEE Agents Web Services Agents User Interface End User ForgeRock UI Framework Core Services Authentication Entitlements Session AuditOAuth Core Token ServiceOpenID Connect Configuration Policy User Management Secure Token Service XACML Federation SPIs Authentication Plugins Policy Plugins User Mgmt Plugins Token Service Plugins Federation Plugins Persistence (OpenDJ) Universal Gateway Management
  • 11. 11IRM Summit 2014 OpenIDM OSGI Persistence (OrientDB) ForgeRock UI Framework ForgeRock REST Router Business Logic (Javascript, Groovy, Java) Authentication Filter (JASPI) Jetty Web Server Configuration Managed Users Sync/Recon System (Connectors) Scheduler Task Scanner Audit/Logs Policy ExternalResources Audit
  • 12. 12IRM Summit 2014 OpenDJ User Interface End UserManagement ForgeRock UI Framework ForgeRock REST Core Server Replication AuditingLDAPV3Caching Monitoring Password Policy Groups Schema Management REST2LDAP Access Control Backend Services Persistence Connectors LDIF MemoryChange Log Java SDK/ LDAPv3 Web Application REST2LDAP ForgeRock REST
  • 13. 13IRM Summit 2014 CloudConnect OSGIConfiguration Wizard OpenIDM Business Logic (Javascript, Groovy, Java) Authentication JASPI (AD and IWA) Jetty Web Server Salesforce and LDAP OAuth Salesforce LDAP Connector Federation ForgeRock UI Framework Reporting and Recon
  • 14. 14IRM Summit 2014 SecureConnect Core Processing Http Connector HTTP Listener ChainsFilters Functions Handlers Scripting Audit
  • 15. 15IRM Summit 2014 API Strategy Conscious, proactive design Developer-focused Consistent Easy to useModern
  • 16. 16IRM Summit 2014 API Strategy Conscious, proactive design Developer-focused Consistent Easy to useModern JSON REST ROA
  • 17. 17IRM Summit 2014 API Strategy OpenIDM Resource API OpenAM Resource API OpenDJ Resource API Common UI / other clients Resource consumer
  • 19. 19IRM Summit 2014 CREST Framework COPYRIGHT 2013 FORGEROCK AS ROA Framework / CREST API Router Services or other non-resource oriented architecture Resource Normalization Non-Json Resource JsonResource
  • 20. 20IRM Summit 2014 AuthN and AuthZ Filters
  • 21. 21IRM Summit 2014 Open Identity Stack UI Model ■ “Single-Page Web App” style ■ Single UI model for all products ■ Built on ForgeRock REST (CREST) ■ Common UIs for: – User management – Registration and Self Service – Login and Password Reset ■ Build on shared services for Authentication
  • 22. 22IRM Summit 2014 ForgeRock UI Library Stack  jQuery (General utlity) + jQuery UI (Widgets)  Backbone.js + Require.js (Modular MVC Architecture)  Handlebars.js (Templating)  Underscore.js (General utility)  Less.js (CSS preprocessor)  Built on ForgeRock REST and Common Services  Caters to the web developers of today
  • 23. 23IRM Summit 2014 Demo ■ OpenAM as the IDP ■ OpenDJ as the User and Config Store ■ OpenIDM provisioning to DJ ■ Commons – ForgeRock REST in OpenAM, OpenIDM, OpenDJ – Filters protecting OpenIDM – ForgeRock UI in OpenIDM and OpenAM