SlideShare a Scribd company logo
© 2016 ForgeRock. All rights reserved.
Directory Services with the ForgeRock
Identity Platform - So What’s New?
• Ludovic Poitou – Product Manager
• Rob MacDonald, Product Marketing Director
© 2016 ForgeRock. All rights reserved.
2010 Founded
10 Offices worldwide with headquarters in San Francisco
350+ Employees
450+ Customers
30+ Countries
$52M Funding to date (thru Series C) by Accel Partners,
Foundation Capital and Meritech Capital Partners
ForgeRock is the leading, next-generation,
identity security software platform.
© 2016 ForgeRock. All rights reserved.
Perimeter-Based Security Identity-Centric Security
Enables Digital Business
Untrusted
Trusted
Inhibits Digital Business
Old Security Model is Broken. Security Must Now Be
Identity-Based.
Enables Digital BusinessInhibits Digital Business
© 2016 ForgeRock. All rights reserved.
Changes are adding Complexity
Employees
Employees &
Partners
Perimeter
Perimeter
Federation
Things
Perimeter-less
Federation
Cloud
SaaS
Mobility
Consumers
Perimeter-less
Federation
Cloud / SaaS
ComplexityofScale
Complexity of Experience
© 2016 ForgeRock. All rights reserved.
Identity Access Management
Customers
(millions)
On-premises
People
Applications
and data
PCs
Endpoints
Workforce
(thousands)
Partners and
Suppliers
Customers
(millions)
On-premises Public
Cloud
Private
Cloud
People
Things
(Tens of
millions)
Applications
and data
PCs PhonesTablets
Smart
Watches
Endpoints
Forrester Report Nov 2015: Market Overview: Customer Identity And Access Management (CIAM) Solutions
Identity Relationship Management
Business Has Changed: Enterprises Now Require
Identity Relationship Management (IRM)
Business Has Changed: Enterprises Now Require
Identity Relationship Management (IRM)
© 2016 ForgeRock. All rights reserved.
ForgeRock
A Unified, Agile Platform Approach
Legacy
Software
Acquisition
Architecture
Niche
Vendors
Component
Strategy
FINE-GRAINED
ENTITLEMENTS …ADAPTIVE
AUTHN
IDENTITY
MANAGEMENT
ACCESS
MANAGEMENT
IDENTITY
FEDERATION
DIRECTORY
SERVICES
AUTHORIZATION
SERVICES ? …
IDENTITY PLATFORM
Access Management | Identity Management
Directory Services | Mobile and API Gateway
ForgeRock
PLATFORM
© 2016 ForgeRock. All rights reserved.
Enterprise AppsMobile Apps Things Cloud
Single Architecture | Next Generation | Open | Chip-to-Cloud Deployments | IRM
Identity ManagementAccess Management Directory Services Identity Gateway
Platform Strategy
© 2016 ForgeRock. All rights reserved.
Shared Services : User Interface, Self-Service, REST API, HTTP, Scripting, Audit and Logging
Federation Synchronization
Authentication & Strong
Authentication
Identity Provisioning Application & Service Gateway
Authorization &
UMA Provider
Workflow Engine IoT Identity Gateway
Adaptive Risk Self-Service Password Capture & Replay
UMA Protector
Access Management Identity Management Identity Gateway
Data Store
High Availability
Data Segmentation
LDAP / REST
Directory Services
Open Standards, High Availability, On-Premises, Cloud, Hybrid
The ForgeRock Identity Platform is built from the open source projects OpenAM, OpenIDM, OpenIG and OpenDJ
The ForgeRock Identity Platform
© 2016 ForgeRock. All rights reserved.
Directory Services – Core Capabilities
Data Store
High Availability
Multi-Master Replication
Rest & LDAP
© 2016 ForgeRock. All rights reserved.
REST/JSON
Access Control
Groups
LDAPv3
Caching
Schema Management
Monitoring
Audit Logging
Services Layer
Password Policies
Backend Services Persistence LDIF
Change Log
Replication
Dynamic Attributes
Access Layer ForgeRock REST OpenDJ SDK LDAPv3 DSML
Admin ConsoleUI Layer
ForgeRock Identity Platform: Directory Services
© 2016 ForgeRock. All rights reserved.
Database Backend
• New backend called “PDB”
• Local-backend moved to
similar structure, called “JE”
• Better disk efficiency
• Better performances
• Tuned for OAuth2 and
OpenID Connect services
© 2016 ForgeRock. All rights reserved.
Replication Improvements
• New Replication ChangeLog
• Less disk utilization
• Smarter cleanup
• High Availability and
Failover for “cn=changelog”
© 2016 ForgeRock. All rights reserved.
Splitting Binaries from Data
• At Setup
• How ? instance.loc
• Still 1 instance for 1 set of
binaries
13
© 2016 ForgeRock. All rights reserved.
Other improvements
• Certificate Matching Rules & GSER
(Community Contribution)
• PKCS5S2 Password Storage
• New privilege to access cn=Changelog
• Password Update with REST to LDAP
• New audit capabilities
(across ForgeRock platform)
© 2016 ForgeRock. All rights reserved.
Demo
© 2016 ForgeRock. All rights reserved.
summits.forgerock.com
© 2016 ForgeRock. All rights reserved.
Thank You

More Related Content

PPTX
Webinar: Access Management with the ForgeRock Identity Platform - So What’s N...
PPTX
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
PPTX
Identity Management with the ForgeRock Identity Platform - So What’s New?
PPTX
OpenAM: An Introduction
PPT
Incredible Edible Identity
PPTX
OpenAM - An Introduction
PDF
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
PPTX
Webinar: Extend The Power of The ForgeRock Identity Platform Through Scripting
Webinar: Access Management with the ForgeRock Identity Platform - So What’s N...
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
Identity Management with the ForgeRock Identity Platform - So What’s New?
OpenAM: An Introduction
Incredible Edible Identity
OpenAM - An Introduction
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
Webinar: Extend The Power of The ForgeRock Identity Platform Through Scripting

What's hot (20)

PPT
THE FORGEROCK PLATFORM BIG PICTURE
PDF
ForgeRock Platform Release - Summer 2016
PPTX
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
PPT
Open Identity Stack Roadmap
PPTX
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
PPTX
Webinar: Identity Wars: The Unified Platform Awakens
PDF
Federation in Practice
PPTX
OIS Architecture Review
PPTX
Identity Gateway with the ForgeRock Identity Platform - So What’s New?
PPTX
NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
PPTX
NYC Identity Summit Tech Day: ForgeRock DevOps/Cloud Strategy
PDF
Pimping the ForgeRock Identity Platform for a Billion Users
PDF
The Future is Now: What’s New in ForgeRock Access Management
PDF
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
PDF
Implementing eGov
PPTX
Webinar: OpenAM 12.0 - New Featurs
PDF
OpenAM Best Practices - Corelio Media Case Study
PPTX
NYC Identity Summit Tech Day: Best Practices for API Security
PPTX
Customer Scale: Stateless Sessions and Managing High-Volume Digital Services
PPTX
Webinar: OpenIDM 3.1
THE FORGEROCK PLATFORM BIG PICTURE
ForgeRock Platform Release - Summer 2016
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
Open Identity Stack Roadmap
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
Webinar: Identity Wars: The Unified Platform Awakens
Federation in Practice
OIS Architecture Review
Identity Gateway with the ForgeRock Identity Platform - So What’s New?
NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
NYC Identity Summit Tech Day: ForgeRock DevOps/Cloud Strategy
Pimping the ForgeRock Identity Platform for a Billion Users
The Future is Now: What’s New in ForgeRock Access Management
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
Implementing eGov
Webinar: OpenAM 12.0 - New Featurs
OpenAM Best Practices - Corelio Media Case Study
NYC Identity Summit Tech Day: Best Practices for API Security
Customer Scale: Stateless Sessions and Managing High-Volume Digital Services
Webinar: OpenIDM 3.1
Ad

Viewers also liked (11)

PPT
Child abuse: eric
PPT
INFECCIÓN DEL TRACTO URINARIO EN PEDIATRÍA
PPTX
Handshake for EFL Youth Voices Project
PPTX
Simple Present
PDF
Uniformes empresariales_BIGBANG MÉXICO
PPS
PDF
J K Industrial Corporation, Ludhiana, Forged Coupler
PPTX
Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades
PPTX
Intraoperative challenges in thr
PPT
WCA finance orientation 2015
PPTX
Persentasi teori teori kepribadian s sullivan
Child abuse: eric
INFECCIÓN DEL TRACTO URINARIO EN PEDIATRÍA
Handshake for EFL Youth Voices Project
Simple Present
Uniformes empresariales_BIGBANG MÉXICO
J K Industrial Corporation, Ludhiana, Forged Coupler
Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades
Intraoperative challenges in thr
WCA finance orientation 2015
Persentasi teori teori kepribadian s sullivan
Ad

Similar to Directory Services with the ForgeRock Identity Platform - So What’s New? (20)

PPTX
Webinar: "Entitlements: Taking Control of the Big Data Gold Rush"
PDF
Securing your Applications for the Cloud Age
PPTX
Synergies across APIs and IAM
PDF
The Future is Now: What’s New in ForgeRock Identity Gateway
PDF
Realizing Great Customer Experiences with Adobe® LiveCycle® ES3
PPTX
2014 q3-platform-update-v1.06.johnmathon
PDF
The Future is Now: What’s New in ForgeRock Identity Management
PDF
Sydney Identity Summit: Addressing the New Threat Landscape with Continuous S...
PDF
Oracle Blockchain Platform
PDF
Conduct JBoss EAP 6 seminar
PPTX
BizTalk: Server, Services and Apps
PPT
S+S Architecture Overview
PPTX
Embarcadero RAD server Launch Webinar
PPTX
Introducing the WSO2 Platform
PPTX
Hybrid Integration with SAP
PPTX
Dev ops
PDF
Open Source IoT Project Flogo - Introduction, Overview and Architecture
PDF
CA Security - Deloitte IAM Summit - Vasu
PDF
Digital Reinvention by NRB
PDF
Let’s Talk About the Ipro Platform
Webinar: "Entitlements: Taking Control of the Big Data Gold Rush"
Securing your Applications for the Cloud Age
Synergies across APIs and IAM
The Future is Now: What’s New in ForgeRock Identity Gateway
Realizing Great Customer Experiences with Adobe® LiveCycle® ES3
2014 q3-platform-update-v1.06.johnmathon
The Future is Now: What’s New in ForgeRock Identity Management
Sydney Identity Summit: Addressing the New Threat Landscape with Continuous S...
Oracle Blockchain Platform
Conduct JBoss EAP 6 seminar
BizTalk: Server, Services and Apps
S+S Architecture Overview
Embarcadero RAD server Launch Webinar
Introducing the WSO2 Platform
Hybrid Integration with SAP
Dev ops
Open Source IoT Project Flogo - Introduction, Overview and Architecture
CA Security - Deloitte IAM Summit - Vasu
Digital Reinvention by NRB
Let’s Talk About the Ipro Platform

More from ForgeRock (20)

PDF
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
PPTX
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
PDF
Identity Live Sydney: Identity Management - A Strategic Opportunity
PDF
Identity Live Singapore: Transform Your Cybersecurity Capability
PDF
Identity Live Singapore 2018 Keynote Presentation
PDF
Identity Live Sydney 2018 Keynote Presentation
PDF
Identity Live Singapore: Just Ask 'Em
PDF
Identity Live Singapore: Building Trust & Privacy in a Connected Society
PDF
Identity Live Sydney: Intelligent Authentication
PDF
Identity Live Sydney: Building Trust and Privacy in a Connected Society
PDF
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
PPTX
Get the Exact Identity Solution You Need - In the Cloud - Overview
PDF
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
PDF
Opening Keynote (Identity Live Berlin 2018)
PDF
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
PDF
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
PDF
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
PDF
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
PDF
Shift from GDPR readiness to sustained compliance to improve your business an...
PDF
Intelligent Authentication (Identity Live Berlin 2018)
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote Presentation
Identity Live Singapore: Just Ask 'Em
Identity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Sydney: Intelligent Authentication
Identity Live Sydney: Building Trust and Privacy in a Connected Society
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution You Need - In the Cloud - Overview
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
Opening Keynote (Identity Live Berlin 2018)
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Shift from GDPR readiness to sustained compliance to improve your business an...
Intelligent Authentication (Identity Live Berlin 2018)

Recently uploaded (20)

PPTX
Odoo POS Development Services by CandidRoot Solutions
PDF
System and Network Administration Chapter 2
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
PTS Company Brochure 2025 (1).pdf.......
PPTX
ai tools demonstartion for schools and inter college
PPTX
Introduction to Artificial Intelligence
PPTX
ISO 45001 Occupational Health and Safety Management System
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PPTX
Transform Your Business with a Software ERP System
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PPTX
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
PDF
Nekopoi APK 2025 free lastest update
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
medical staffing services at VALiNTRY
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PDF
top salesforce developer skills in 2025.pdf
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Odoo POS Development Services by CandidRoot Solutions
System and Network Administration Chapter 2
Odoo Companies in India – Driving Business Transformation.pdf
Design an Analysis of Algorithms I-SECS-1021-03
PTS Company Brochure 2025 (1).pdf.......
ai tools demonstartion for schools and inter college
Introduction to Artificial Intelligence
ISO 45001 Occupational Health and Safety Management System
How to Migrate SBCGlobal Email to Yahoo Easily
Upgrade and Innovation Strategies for SAP ERP Customers
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
Transform Your Business with a Software ERP System
How to Choose the Right IT Partner for Your Business in Malaysia
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
Nekopoi APK 2025 free lastest update
Wondershare Filmora 15 Crack With Activation Key [2025
medical staffing services at VALiNTRY
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
top salesforce developer skills in 2025.pdf
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...

Directory Services with the ForgeRock Identity Platform - So What’s New?

  • 1. © 2016 ForgeRock. All rights reserved. Directory Services with the ForgeRock Identity Platform - So What’s New? • Ludovic Poitou – Product Manager • Rob MacDonald, Product Marketing Director
  • 2. © 2016 ForgeRock. All rights reserved. 2010 Founded 10 Offices worldwide with headquarters in San Francisco 350+ Employees 450+ Customers 30+ Countries $52M Funding to date (thru Series C) by Accel Partners, Foundation Capital and Meritech Capital Partners ForgeRock is the leading, next-generation, identity security software platform.
  • 3. © 2016 ForgeRock. All rights reserved. Perimeter-Based Security Identity-Centric Security Enables Digital Business Untrusted Trusted Inhibits Digital Business Old Security Model is Broken. Security Must Now Be Identity-Based. Enables Digital BusinessInhibits Digital Business
  • 4. © 2016 ForgeRock. All rights reserved. Changes are adding Complexity Employees Employees & Partners Perimeter Perimeter Federation Things Perimeter-less Federation Cloud SaaS Mobility Consumers Perimeter-less Federation Cloud / SaaS ComplexityofScale Complexity of Experience
  • 5. © 2016 ForgeRock. All rights reserved. Identity Access Management Customers (millions) On-premises People Applications and data PCs Endpoints Workforce (thousands) Partners and Suppliers Customers (millions) On-premises Public Cloud Private Cloud People Things (Tens of millions) Applications and data PCs PhonesTablets Smart Watches Endpoints Forrester Report Nov 2015: Market Overview: Customer Identity And Access Management (CIAM) Solutions Identity Relationship Management Business Has Changed: Enterprises Now Require Identity Relationship Management (IRM) Business Has Changed: Enterprises Now Require Identity Relationship Management (IRM)
  • 6. © 2016 ForgeRock. All rights reserved. ForgeRock A Unified, Agile Platform Approach Legacy Software Acquisition Architecture Niche Vendors Component Strategy FINE-GRAINED ENTITLEMENTS …ADAPTIVE AUTHN IDENTITY MANAGEMENT ACCESS MANAGEMENT IDENTITY FEDERATION DIRECTORY SERVICES AUTHORIZATION SERVICES ? … IDENTITY PLATFORM Access Management | Identity Management Directory Services | Mobile and API Gateway ForgeRock PLATFORM
  • 7. © 2016 ForgeRock. All rights reserved. Enterprise AppsMobile Apps Things Cloud Single Architecture | Next Generation | Open | Chip-to-Cloud Deployments | IRM Identity ManagementAccess Management Directory Services Identity Gateway Platform Strategy
  • 8. © 2016 ForgeRock. All rights reserved. Shared Services : User Interface, Self-Service, REST API, HTTP, Scripting, Audit and Logging Federation Synchronization Authentication & Strong Authentication Identity Provisioning Application & Service Gateway Authorization & UMA Provider Workflow Engine IoT Identity Gateway Adaptive Risk Self-Service Password Capture & Replay UMA Protector Access Management Identity Management Identity Gateway Data Store High Availability Data Segmentation LDAP / REST Directory Services Open Standards, High Availability, On-Premises, Cloud, Hybrid The ForgeRock Identity Platform is built from the open source projects OpenAM, OpenIDM, OpenIG and OpenDJ The ForgeRock Identity Platform
  • 9. © 2016 ForgeRock. All rights reserved. Directory Services – Core Capabilities Data Store High Availability Multi-Master Replication Rest & LDAP
  • 10. © 2016 ForgeRock. All rights reserved. REST/JSON Access Control Groups LDAPv3 Caching Schema Management Monitoring Audit Logging Services Layer Password Policies Backend Services Persistence LDIF Change Log Replication Dynamic Attributes Access Layer ForgeRock REST OpenDJ SDK LDAPv3 DSML Admin ConsoleUI Layer ForgeRock Identity Platform: Directory Services
  • 11. © 2016 ForgeRock. All rights reserved. Database Backend • New backend called “PDB” • Local-backend moved to similar structure, called “JE” • Better disk efficiency • Better performances • Tuned for OAuth2 and OpenID Connect services
  • 12. © 2016 ForgeRock. All rights reserved. Replication Improvements • New Replication ChangeLog • Less disk utilization • Smarter cleanup • High Availability and Failover for “cn=changelog”
  • 13. © 2016 ForgeRock. All rights reserved. Splitting Binaries from Data • At Setup • How ? instance.loc • Still 1 instance for 1 set of binaries 13
  • 14. © 2016 ForgeRock. All rights reserved. Other improvements • Certificate Matching Rules & GSER (Community Contribution) • PKCS5S2 Password Storage • New privilege to access cn=Changelog • Password Update with REST to LDAP • New audit capabilities (across ForgeRock platform)
  • 15. © 2016 ForgeRock. All rights reserved. Demo
  • 16. © 2016 ForgeRock. All rights reserved. summits.forgerock.com
  • 17. © 2016 ForgeRock. All rights reserved. Thank You

Editor's Notes

  • #15: Finally, OpenDJ 3 includes a large number of new features and improvements. The most significant ones are outline here, but for the complete details, you will need to check the release notes. Certificate Matching Rules… Certificates are based from X.500 standards, the historical parent of LDAP. Both standards use ASN.1 notation and BER encoding, but in different ways. In LDAPv3, the certificates are treated as Opaque Byte Strings. The only thing possible is adding, reading, and comparing certificates as whole. The Certificate Matching Rules define a way to express filters and queries on specific fields within certificates. For example, finding the users who have a certificate with a specific alias, those whose certificates are expiring soon or have expired... PKCS5S2 is secure password storage scheme similar to the PBKDF2 scheme introduced in OpenDJ 2.6. It is compatible with the algorithm used by Atlassian Crowd and allow migration of passwords stored and used in that product. The ”cn=Changelog” suffix is governed by the same global ACIs as all other public name spaces. However, the suffix can contain very sensitive data, including password changes. We’ve addde a privilege to restrict the access to it, in a similar way that there is a ”config read” privilege. REST to LDAP has been enhanced. Most important change is the ability to change passwords now. Finally, across all our products, we’ve added a common auditing capability, with common features and a common output format. This allows to track operations and transactions across the entire ForgeRock Identity Platform, to simplify management and log processing for all products.