Top Banner
December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007
32

December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

Dec 14, 2015

Download

Documents

Nelson Sullivan
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

OpenDS Enterprise Directory Services

Trey DrakeAssetWorld 2007

Albuquerque, New Mexico

November 2007

Page 2: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• What• Why• How

Directory Services & OpenDS

Page 3: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Where are my users?• Weak passwords?• Users come and go• I want single sign on!• Who owns enterprise identity?• Sarbanes?! - who, what, when, where?

Look Familiar?

Page 4: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

What

Page 5: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Stores & organizes users & network resources

• Secure• High speed• HA• Replication• Wired into apps, os, email, routers• Upstack services

Directory Service

Page 6: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

Meta Directory – Authoritative DS

HR

FMAX

OpenDS

Meta

schedule

?

salary

user id

Page 7: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

Virtual Directory Service

HR

FMAX

OpenDS

Virtual

Personname

schedulesalary

salary

uid

schedule

?

Page 8: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

Proxy Directory ServiceA-M

N-Z

inactive

? sn=drake

? employee id=1001

Page 9: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Standards, Standards, Standards• Started ~ 1993• IETF (OpenLDAP, Sun, Novell, others)• OpenDS, OpenLDAP, Novell, AD, OID• Network protocol• Distributed

LDAP

Page 10: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Complete directory service• Community effort • FOSS - CDDL• Bootstrapped by Sun• Progress update since 11/06 - remember?

OpenDS

Page 11: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Rich password policy• All platforms• Easy install• Manageable• Extend everywhere• Embedded option• Replication

Fast Facts – Here Today

Page 12: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• No console• No commercial support*• No virtual• No proxy• No transactions*

Fast Facts – What's Missing

Page 13: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

On to the why...

Page 14: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Where are my users?• Weak passwords?• Users come and go• I want single sign on!• Who owns enterprise identity?• Sarbanes?!• Who, what, when, where?

Look Familiar (Again)?

Page 15: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• De-fragment users and policies• Secure, global view• Simple, well known• Extensible, roll your own “person”• Preferred repository for provisioning

systems• Pillar for single sign on

Data Consolidation

Page 16: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

Where are your users & resources?

FMAX

PeoplesoftActive Directory

Home grown

Linux/etc/passwd

Page 17: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

Where they should be

o=any.edu

ou=contractorsou=facultyou=students

ou=staffou=devicesFMAX

PSFT

NIS

SSO

Foo

Page 18: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Simple idea, difficult to implement• Spec outlines the solution

– strength– # tries– login windows– etc

• OpenDS implements the solution• Applications and controls

Password Policy

Page 19: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

Password PolicyOpenDS Policy PluginLDAP Client

Deny with error code/message

Fetch appropriate policy

Evaluate policy

Authenticate with policy

Success

Page 20: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Onboarding - establishing access• Offboarding - terminating access

– Confident?

• Re-establishing access

User Provisioning

Page 21: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

User Silos

Portal HRFMAX

App DBOracle LDAP

Page 22: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Centralized user store infinitely easier• Even so

– Barren FOSS landscape - Identyx – Commercial Sun IDM– Roll your own

User provisioning

Page 23: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Centralize access management• Seamless to end user • Manageable enterprise SSO requires a

consolidated view• Most SSO rely on LDAP• Requires high performance repository• Single SSO, single repository• OpenSSO & OpenDS

Single Sign On

Page 24: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Who owns enterprise identity?• Centralized and federated directories• Apps requiring directory writes• Isolating directories• Crossing regulatory boundaries• OpenDS replication

Identity Ownership

Page 25: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

Identity Ownership

Portal, Blogs

FMAX

Linux, Windows

Enterpriselocal

Page 26: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

Replication• Assured• Fractional

HIPPA filter

Page 27: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Secure channels• Centralized users and policy• Password policy• AAA - Auditing

Sarbanes

Page 28: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Secure LDAP – Supports StartTLS and SSL

• Centralized users and policy• Extensive password policy via controls• Full, high performance activity logging

OpenDS & Sarbanes

Page 29: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Active Directory• Sun DSEE• Oracle • OpenLDAP• Novell• Fedora• Novell• Apache

Other Directories

Page 30: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Single Directory Services Stack• Standards• FOSS• Fast• Extensible• Feature rich• FOSS

OpenDS

Page 31: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• http://www.opends.org• http://treydrake.wordpress.com• [email protected]

Resources

Page 32: December 19, 2006 OpenDS Enterprise Directory Services Trey Drake AssetWorld 2007 Albuquerque, New Mexico November 2007.

December 19, 2006

• Install• Addressbook• Glassfish and OpenDS

Demo!