SlideShare a Scribd company logo
Open Source Identity
Integration with OpenSSO
April 19, 2008

Pat Patterson
Federation Architect
pat.patterson@sun.com
blogs.sun.com/superpat
Agenda
• Web Access Management
  > The Problem
  > The Solution
  > How Does It Work?
• Federation
  > Single Sign-On Beyond a Single Enterprise
  > How Does It Work?
• OpenSSO
  > Project Overview


                                                2
Typical Problems
• “Every application wants me to log in!”

• “I have too many passwords – my monitor is
  covered in Post-its!”

• “We're implementing Sarbanes-Oxley – we need to
  control access to applications!”

• “We need to access outsourced functions!”

• “Our partners need to access our applications!”
                                                    3
Web Access Management
• Simplest scenario is within a single organization
• Factor authentication and authorization out of web
  applications into web access management (WAM)
  solution
• Can use browser cookies within a DNS domain
• Proxy or Agent architecture implements role-based
  access control (RBAC)
• Users get single sign-on, IT gets control


                                                       4
Single Sign-On Within an Organization



                    Web Server
                                 Web Server
 SSO Server


                                     Application
                                       Server
              End User

                                                   5
How It Works
SSO Server            Browser                 Agent                Application
                            GET hrapp/index.html
                            Redirect to SSO Server
     Authenticate
     Redirect to hrapp/index.html
     (with SSO cookie)
                            GET hrapp/index.html
                            (with SSO cookie)‫‏‬
     Is this user allowed to access hrapp/index.html?
     Yes!
                                                   Allow request to proceed
                           Application response

                                                                                 6
Web Access Management Products
• Sun Java System Access Manager
    > OpenSSO
•   CA (Netegrity) SiteMinder Access Manager
•   IBM Tivoli Access Manager
•   Oracle (Oblix) Access Manager
•   Novell Access Maneger
•   JA-SIG CAS
•   JOSSO

                                               7
Typical Problems
• “Every application wants me to log in!”

• “I have too many passwords – my monitor is
  covered in Post-its!”

• “We're implementing Sarbanes-Oxley – we need to
  control access to applications!”

• “We need to access outsourced functions!”

• “Our partners need to access our applications!”
                                                    8
Single Sign-on between Organizations


• Cookies no longer work
  > Need a more sophisticated protocol

• Can't mandate single vendor solution
  > Need standards for interoperability




                                          9
Single Sign-On Standards

  Liberty    Liberty                       Liberty
“Phase 1”   ID-FF 1.1,1.2                Federation
                                           =
 SAML1      SAML1.1                      SAML2

            Shibboleth      Shibboleth
               1.0,1.1          1.2


            WS-Federation                             WS-Federation
                1.0                                       1.1

  2002         2003           2004         2005         2006

                                                                      10
SAML 2.0 Concepts
                     Profiles
          Combining protocols, bindings, and
        assertions to support a defined use case      Authentication
                                                         Context
                                                        Detailed data on
                    Bindings                          types and strengths
                                                        of authentication
  Mapping SAML protocols onto standard messaging or
             communication protocols


                   Protocols
    Request/response pairs for obtaining assertions
              and doing ID management

                                                       Metadata
                  Assertions                             IdP and SP
       Authentication, attribute and entitlement      configuration data
                     information




                                                                            11
SSO Across Organizations




                    Service    Service
                    Provider   Provider
  Identity
  Provider


                                  Service
                                  Provider
             End User
                                             12
SAML 2.0 SSO Basics
 Identity Provider       Browser         Service Provider
                             GET hrapp/index.html

                             Redirect with SAML Request

         SAML Authentication Request
         Authenticate

         HTML form with SAML Response
                             SAML Response          Service Provider
                                                    examines SAML
                                                    Response and
                                                    makes access
         Response                                   control decision
                                                                       13
SAML 2.0 Assertion
(Abbreviated!)
<Assertion Version="2.0" ID="..." IssueInstant="2007-11-06T16:42:28Z">
    <Issuer>https://pat-pattersons-computer.local:8181/</Issuer>
    <Signature>...</Signature>
    <saml:Subject>
        <saml:NameID Format="urn:oasis:...:persistent" ...>
             ZG0OZ3JWP9yduIQ1zFJbVVGHlQ9M
        </saml:NameID>
        <saml:SubjectConfirmation Method="urn:oasis:...:bearer">
             <saml:SubjectConfirmationData .../>
        </saml:SubjectConfirmation>
    </saml:Subject>
    <saml:Conditions
      NotBefore="2007-11-06T16:42:28Z"
NotOnOrAfter="2007-11-06T16:52:28Z">
        <saml:AudienceRestriction>
             <saml:Audience>
                 https://pat-pattersons-computer.local/example-pat/
             </saml:Audience>
        </saml:AudienceRestriction>
    </saml:Conditions>
    <saml:AuthnStatement AuthnInstant="2007-11-06T16:42:28Z" ...>
        <saml:AuthnContext>
             <saml:AuthnContextClassRef>
                 urn:oasis:...:PasswordProtectedTransport
             </saml:AuthnContextClassRef>
        </saml:AuthnContext>
    </saml:AuthnStatement>
</saml:Assertion>
                                                                         14
SAML 2.0 Adoption
• Sun, IBM, CA – all the usual suspects, except Microsoft
• OpenSAML (Internet2)
  > Java, C++
• OpenSSO (Sun)
  > Java, PHP, Ruby
• SimpleSAMLphp (Feide)
                                              om
• LASSO (Entr'ouvert)                      o.c
  > C/SWIG                             glob
• ZXID (Symlabs)
  > C/SWIG
                                                            15
What is OpenSSO?

                      • OpenSSO 1.0 ==
                        Federated Access
                        Manager 8.0
                      • All FAM 8.0 builds
                        available via
                        OpenSSO
   Open Access.       • Preview Features
   Open Federation.   • Provide Feedback
                      • Review code
                        security
                                             16
OpenSSO Momentum
• In less than 2 years...
  > 650 project members at opensso.org
  > ~15 external committers
  > Consistently in Top 10* java.net projects by mail traffic
     – * of over 3000 projects
• Production deployments
  > www.audi.co.uk
     – 250,000 customer profiles
                                                           .br
  > openid.sun.com                                       ov
     – OpenID for Sun employees                    .....g
  > telenet.be
     – Foundation for fine-grained authorization
                                                                 17
OpenSSO Roadmap
                                        OpenSSO 1.0 / FAM 8.0
                                            Summer 2008

                           OpenSSO                              OpenSSO 1.next /
                OpenSSO    Federation                               FAM 8.1
                 Q3CY06     Q4CY06                                End of 2008
OpenSSO
                                 Access
                                Manager 7.1
                                 Q4CY06
Access
Manager
             Federation
             Manager 7.0
              Q4CY05
Federation
Manager


                                                                                   18
OpenSSO 1.0
Access Management   • Centralized Agent Configuration &
                      Deployment
                    • Centralized Configuration
                    • XACML Request/Response
                    • Wide choice of Application Servers


Federation          •   Fedlet
                    •   Virtual Federation
                    •   Multi-Federation Protocol Hub
                    •   WS-Federation 1.1
                    •   3rd Party WAM Interoperability

                                                           19
OpenSSO 1.0
Identity Services   •   Authentication as a service
                    •   Authorization as a service
                    •   Audit as a service
                    •   Attribute Query as a service
                    •   Secure Trust Authority
                    •   Web Services Security Plug-ins
                    •   SDK for Securing Web Services

                        But that's not all...
                                                         20
OpenSSO Extensions
https://opensso.dev.java.net/public/extensions/

                                   • PHP SAML 2.0 SP implementation
                                     > Picked up by Feide (Norway)
SAML 2.0
                                   • Ruby SAML 2.0 SP implementation
                                   • SAML 2.0 ECP test rig

                                   • OpenID 1.1 Provider
OpenID
                                     > Deployed at openid.sun.com

Client SDK                         • PHP Client SDK implementation

                                   • ActivIdentity 4Tress
Authentication Modules             • Hitachi Finger Vein Biometric
                                   • Information Card (aka CardSpace)
                                                                        21
Participe!
          Join             Download


       Sign up at         OpenSSO 1.0
      opensso.org           Build 4



        Subscribe            Chat

  OpenSSO Mailing Lists     #opensso
                               on
   dev, users, announce   freenode.net


                                         22
Resources
https://opensso.dev.java.net/public/extensions/

OpenSSO                            • http://opensso.org/

SAML @ Globo.com                   • André Bechara video
                                     > http://tinyurl.com/6rugrm
Pat's Blog                         • Superpatterns
                                       > http://blogs.sun.com/superpat/
Daniel Raskin's Blog               • Virtual Daniel
                                       > http://blogs.sun.com/raskin/
                                                                          23
Open Source Identity
Integration with OpenSSO
April 19, 2008

Pat Patterson
Federation Architect
pat.patterson@sun.com
blogs.sun.com/superpat

More Related Content

PDF
Dave Carroll Application Services Salesforce
PDF
Oracle 4월 20일
PPTX
HAD05: Collaborating with Extranet Partners on SharePoint 2010
PPTX
4. tmg 2010 e uag 2010
PDF
The Java EE 7 Platform: Developing for the Cloud (FISL 12)
PDF
OSGi & Java EE in GlassFish @ Silicon Valley Code Camp 2010
PDF
Running your Java EE 6 applications in the Cloud @ Silicon Valley Code Camp 2010
PDF
Web Performance 101 - Gil Givati
Dave Carroll Application Services Salesforce
Oracle 4월 20일
HAD05: Collaborating with Extranet Partners on SharePoint 2010
4. tmg 2010 e uag 2010
The Java EE 7 Platform: Developing for the Cloud (FISL 12)
OSGi & Java EE in GlassFish @ Silicon Valley Code Camp 2010
Running your Java EE 6 applications in the Cloud @ Silicon Valley Code Camp 2010
Web Performance 101 - Gil Givati

What's hot (20)

PPTX
Troubleshooting Federation, ADFS, and More
PDF
The Java EE 7 Platform: Productivity &amp; HTML5 at San Francisco JUG
PDF
OpenSSO Tech Overview Aquarium
PDF
[Infosecworld 08 Orlando] CSRF: The Biggest Little Vulnerability on the Web
PPTX
Everything You Need to Know about Diagnostics and Debugging on Microsoft Inte...
PDF
Configuring kerberos based sso in weblogic
PDF
“Secure Portal” or WebSphere Portal – Security with Everything
PDF
Office 365: Planning and Automating for Hybrid Identity Scenarios in the Clou...
PDF
Xebia adobe flash mobile applications
PDF
Understanding the nuts & bolts of Java EE 6
PDF
Ajax World Fall08
PDF
Java EE 7 at JAX London 2011 and JFall 2011
PDF
Iiw2007b Madsen 01
PDF
Websphere Portal V6.1 Security Overview
PDF
Social Enterprise Java Apps on Heroku Webinar
PDF
Find me if you can – smart fuzzing and discovery! shreeraj shah
PPTX
Security Avalanche
PDF
[Infosecworld 08 Orlando] New Defenses for .NET Web Apps: IHttpModule in Prac...
PDF
Php apache vs iis By Hafedh Yahmadi
PDF
Java EE 6 and GlassFish portfolio
Troubleshooting Federation, ADFS, and More
The Java EE 7 Platform: Productivity &amp; HTML5 at San Francisco JUG
OpenSSO Tech Overview Aquarium
[Infosecworld 08 Orlando] CSRF: The Biggest Little Vulnerability on the Web
Everything You Need to Know about Diagnostics and Debugging on Microsoft Inte...
Configuring kerberos based sso in weblogic
“Secure Portal” or WebSphere Portal – Security with Everything
Office 365: Planning and Automating for Hybrid Identity Scenarios in the Clou...
Xebia adobe flash mobile applications
Understanding the nuts & bolts of Java EE 6
Ajax World Fall08
Java EE 7 at JAX London 2011 and JFall 2011
Iiw2007b Madsen 01
Websphere Portal V6.1 Security Overview
Social Enterprise Java Apps on Heroku Webinar
Find me if you can – smart fuzzing and discovery! shreeraj shah
Security Avalanche
[Infosecworld 08 Orlando] New Defenses for .NET Web Apps: IHttpModule in Prac...
Php apache vs iis By Hafedh Yahmadi
Java EE 6 and GlassFish portfolio
Ad

Viewers also liked (20)

PDF
2015/11/16付 オリジナルiTunes週間トップソングトピックス
PDF
BubbleMap Application
PDF
031+heap2+dltv54+540722+a+ใบความรู้ เพื่อนสนิทมิตรสหาย (1หน้า)
PDF
1администраторы соц. сетей 01.2013
PDF
Busque, Compare Y Si Encuentra Algo Mejor3
DOCX
sam
PPTX
Presentación ciencia. tecnologia y sociedad p1
DOCX
Dx bumil
PDF
Mensajes
DOC
Resume - Mr. Patil Sujay Prabhakar 2016
PPTX
Blogging for your Construction Industry Business
PPTX
PPTX
Marketing & outreach
PDF
Bygg din egen merkevare på nett
PDF
Тара и упаковка
PPTX
PUEMBO DE COTOPAXI. Pablo Guaña
DOC
Top 9 desktop interview questions answers
PDF
Estructura atómica 1º
PDF
Секреты привлекательности: интернет-магазин глазами покупателей
PPT
Qualificação (Curta) Julho 2009
2015/11/16付 オリジナルiTunes週間トップソングトピックス
BubbleMap Application
031+heap2+dltv54+540722+a+ใบความรู้ เพื่อนสนิทมิตรสหาย (1หน้า)
1администраторы соц. сетей 01.2013
Busque, Compare Y Si Encuentra Algo Mejor3
sam
Presentación ciencia. tecnologia y sociedad p1
Dx bumil
Mensajes
Resume - Mr. Patil Sujay Prabhakar 2016
Blogging for your Construction Industry Business
Marketing & outreach
Bygg din egen merkevare på nett
Тара и упаковка
PUEMBO DE COTOPAXI. Pablo Guaña
Top 9 desktop interview questions answers
Estructura atómica 1º
Секреты привлекательности: интернет-магазин глазами покупателей
Qualificação (Curta) Julho 2009
Ad

Similar to Open sso fisl9.0 (20)

PDF
Open Source Identity Integration with OpenSSO
PDF
Otm 2013 c13_e-13b-hagan-mark-otm-soa
PDF
WSO2 Identity Server - Product Overview
PDF
O Dell Secure360 Presentation5 12 10b
KEY
CSG 2012
PDF
Open sso enterprise customer pitch
PDF
Standardizing Identity Provisioning with SCIM
PPTX
Introduction to the WSO2 Identity Server &Contributing to an OS Project
PDF
Introduction to SAML 2.0
PDF
Implementing Authorization
PDF
Application Services On The Web Sales Forcecom
PPTX
Enterprise service bus part 2
PPTX
IdP, SAML, OAuth
PPTX
WSO2Con USA 2014 - Identity Server Tutorial
PDF
Overzicht van de GlassFish technologie, Eugene Bogaart
PDF
21st Century Service Oriented Architecture
PPTX
The Middleware technology that connects the enterprise
PDF
Cloud Best Practices
PPTX
A recipe for standards-based Cloud IdM
PDF
Don't Drop the SOAP: Real World Web Service Testing for Web Hackers
Open Source Identity Integration with OpenSSO
Otm 2013 c13_e-13b-hagan-mark-otm-soa
WSO2 Identity Server - Product Overview
O Dell Secure360 Presentation5 12 10b
CSG 2012
Open sso enterprise customer pitch
Standardizing Identity Provisioning with SCIM
Introduction to the WSO2 Identity Server &Contributing to an OS Project
Introduction to SAML 2.0
Implementing Authorization
Application Services On The Web Sales Forcecom
Enterprise service bus part 2
IdP, SAML, OAuth
WSO2Con USA 2014 - Identity Server Tutorial
Overzicht van de GlassFish technologie, Eugene Bogaart
21st Century Service Oriented Architecture
The Middleware technology that connects the enterprise
Cloud Best Practices
A recipe for standards-based Cloud IdM
Don't Drop the SOAP: Real World Web Service Testing for Web Hackers

Recently uploaded (20)

PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
Cloud computing and distributed systems.
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
KodekX | Application Modernization Development
PDF
Encapsulation theory and applications.pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
Electronic commerce courselecture one. Pdf
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPT
Teaching material agriculture food technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Digital-Transformation-Roadmap-for-Companies.pptx
Cloud computing and distributed systems.
Review of recent advances in non-invasive hemoglobin estimation
Chapter 3 Spatial Domain Image Processing.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Reach Out and Touch Someone: Haptics and Empathic Computing
Network Security Unit 5.pdf for BCA BBA.
Encapsulation_ Review paper, used for researhc scholars
KodekX | Application Modernization Development
Encapsulation theory and applications.pdf
Empathic Computing: Creating Shared Understanding
Electronic commerce courselecture one. Pdf
MIND Revenue Release Quarter 2 2025 Press Release
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
The Rise and Fall of 3GPP – Time for a Sabbatical?
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Teaching material agriculture food technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx

Open sso fisl9.0

  • 1. Open Source Identity Integration with OpenSSO April 19, 2008 Pat Patterson Federation Architect pat.patterson@sun.com blogs.sun.com/superpat
  • 2. Agenda • Web Access Management > The Problem > The Solution > How Does It Work? • Federation > Single Sign-On Beyond a Single Enterprise > How Does It Work? • OpenSSO > Project Overview 2
  • 3. Typical Problems • “Every application wants me to log in!” • “I have too many passwords – my monitor is covered in Post-its!” • “We're implementing Sarbanes-Oxley – we need to control access to applications!” • “We need to access outsourced functions!” • “Our partners need to access our applications!” 3
  • 4. Web Access Management • Simplest scenario is within a single organization • Factor authentication and authorization out of web applications into web access management (WAM) solution • Can use browser cookies within a DNS domain • Proxy or Agent architecture implements role-based access control (RBAC) • Users get single sign-on, IT gets control 4
  • 5. Single Sign-On Within an Organization Web Server Web Server SSO Server Application Server End User 5
  • 6. How It Works SSO Server Browser Agent Application GET hrapp/index.html Redirect to SSO Server Authenticate Redirect to hrapp/index.html (with SSO cookie) GET hrapp/index.html (with SSO cookie)‫‏‬ Is this user allowed to access hrapp/index.html? Yes! Allow request to proceed Application response 6
  • 7. Web Access Management Products • Sun Java System Access Manager > OpenSSO • CA (Netegrity) SiteMinder Access Manager • IBM Tivoli Access Manager • Oracle (Oblix) Access Manager • Novell Access Maneger • JA-SIG CAS • JOSSO 7
  • 8. Typical Problems • “Every application wants me to log in!” • “I have too many passwords – my monitor is covered in Post-its!” • “We're implementing Sarbanes-Oxley – we need to control access to applications!” • “We need to access outsourced functions!” • “Our partners need to access our applications!” 8
  • 9. Single Sign-on between Organizations • Cookies no longer work > Need a more sophisticated protocol • Can't mandate single vendor solution > Need standards for interoperability 9
  • 10. Single Sign-On Standards Liberty Liberty Liberty “Phase 1” ID-FF 1.1,1.2 Federation = SAML1 SAML1.1 SAML2 Shibboleth Shibboleth 1.0,1.1 1.2 WS-Federation WS-Federation 1.0 1.1 2002 2003 2004 2005 2006 10
  • 11. SAML 2.0 Concepts Profiles Combining protocols, bindings, and assertions to support a defined use case Authentication Context Detailed data on Bindings types and strengths of authentication Mapping SAML protocols onto standard messaging or communication protocols Protocols Request/response pairs for obtaining assertions and doing ID management Metadata Assertions IdP and SP Authentication, attribute and entitlement configuration data information 11
  • 12. SSO Across Organizations Service Service Provider Provider Identity Provider Service Provider End User 12
  • 13. SAML 2.0 SSO Basics Identity Provider Browser Service Provider GET hrapp/index.html Redirect with SAML Request SAML Authentication Request Authenticate HTML form with SAML Response SAML Response Service Provider examines SAML Response and makes access Response control decision 13
  • 14. SAML 2.0 Assertion (Abbreviated!) <Assertion Version="2.0" ID="..." IssueInstant="2007-11-06T16:42:28Z"> <Issuer>https://pat-pattersons-computer.local:8181/</Issuer> <Signature>...</Signature> <saml:Subject> <saml:NameID Format="urn:oasis:...:persistent" ...> ZG0OZ3JWP9yduIQ1zFJbVVGHlQ9M </saml:NameID> <saml:SubjectConfirmation Method="urn:oasis:...:bearer"> <saml:SubjectConfirmationData .../> </saml:SubjectConfirmation> </saml:Subject> <saml:Conditions NotBefore="2007-11-06T16:42:28Z" NotOnOrAfter="2007-11-06T16:52:28Z"> <saml:AudienceRestriction> <saml:Audience> https://pat-pattersons-computer.local/example-pat/ </saml:Audience> </saml:AudienceRestriction> </saml:Conditions> <saml:AuthnStatement AuthnInstant="2007-11-06T16:42:28Z" ...> <saml:AuthnContext> <saml:AuthnContextClassRef> urn:oasis:...:PasswordProtectedTransport </saml:AuthnContextClassRef> </saml:AuthnContext> </saml:AuthnStatement> </saml:Assertion> 14
  • 15. SAML 2.0 Adoption • Sun, IBM, CA – all the usual suspects, except Microsoft • OpenSAML (Internet2) > Java, C++ • OpenSSO (Sun) > Java, PHP, Ruby • SimpleSAMLphp (Feide) om • LASSO (Entr'ouvert) o.c > C/SWIG glob • ZXID (Symlabs) > C/SWIG 15
  • 16. What is OpenSSO? • OpenSSO 1.0 == Federated Access Manager 8.0 • All FAM 8.0 builds available via OpenSSO Open Access. • Preview Features Open Federation. • Provide Feedback • Review code security 16
  • 17. OpenSSO Momentum • In less than 2 years... > 650 project members at opensso.org > ~15 external committers > Consistently in Top 10* java.net projects by mail traffic – * of over 3000 projects • Production deployments > www.audi.co.uk – 250,000 customer profiles .br > openid.sun.com ov – OpenID for Sun employees .....g > telenet.be – Foundation for fine-grained authorization 17
  • 18. OpenSSO Roadmap OpenSSO 1.0 / FAM 8.0 Summer 2008 OpenSSO OpenSSO 1.next / OpenSSO Federation FAM 8.1 Q3CY06 Q4CY06 End of 2008 OpenSSO Access Manager 7.1 Q4CY06 Access Manager Federation Manager 7.0 Q4CY05 Federation Manager 18
  • 19. OpenSSO 1.0 Access Management • Centralized Agent Configuration & Deployment • Centralized Configuration • XACML Request/Response • Wide choice of Application Servers Federation • Fedlet • Virtual Federation • Multi-Federation Protocol Hub • WS-Federation 1.1 • 3rd Party WAM Interoperability 19
  • 20. OpenSSO 1.0 Identity Services • Authentication as a service • Authorization as a service • Audit as a service • Attribute Query as a service • Secure Trust Authority • Web Services Security Plug-ins • SDK for Securing Web Services But that's not all... 20
  • 21. OpenSSO Extensions https://opensso.dev.java.net/public/extensions/ • PHP SAML 2.0 SP implementation > Picked up by Feide (Norway) SAML 2.0 • Ruby SAML 2.0 SP implementation • SAML 2.0 ECP test rig • OpenID 1.1 Provider OpenID > Deployed at openid.sun.com Client SDK • PHP Client SDK implementation • ActivIdentity 4Tress Authentication Modules • Hitachi Finger Vein Biometric • Information Card (aka CardSpace) 21
  • 22. Participe! Join Download Sign up at OpenSSO 1.0 opensso.org Build 4 Subscribe Chat OpenSSO Mailing Lists #opensso on dev, users, announce freenode.net 22
  • 23. Resources https://opensso.dev.java.net/public/extensions/ OpenSSO • http://opensso.org/ SAML @ Globo.com • André Bechara video > http://tinyurl.com/6rugrm Pat's Blog • Superpatterns > http://blogs.sun.com/superpat/ Daniel Raskin's Blog • Virtual Daniel > http://blogs.sun.com/raskin/ 23
  • 24. Open Source Identity Integration with OpenSSO April 19, 2008 Pat Patterson Federation Architect pat.patterson@sun.com blogs.sun.com/superpat