Top Banner
27

Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

May 29, 2019

Download

Documents

lythuy
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD
Page 2: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Hochverfügbarkeit von Identity und Access Management Infrastruktur mit Oracle

Abdi Mohammadi Principal Sales Consulting Security / Identity & Access Management Juni 2014

Page 3: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle’s products remains at the sole discretion of Oracle.

3

Page 4: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Agenda

1

2

3

4

5

Definition

IAM Platform and architecture

IAM Components

Resources

Q&A

Oracle Confidential – Internal/Restricted/Highly Restricted 4

Page 5: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Definition

Oracle Confidential – Internal/Restricted/Highly Restricted 5

Page 6: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

High Availability

Availability total time

total time down time

http://en.wikipedia.org/wiki/High_availability

Availability % Downtime per year

99% 3.65 days

99.9% 8.76 hours

99.99% 52.56 minutes

99.999% 5.26 minutes

99.9999% 31.5 seconds

99.99999% 3.15 seconds

No Single Points of Failure

Reliable crossover

Detection of failures

HA

Page 7: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Requirements: No Single Point of Failure

Redundancy

Load

balan

cing

Failo

ver

Real Application Cluster

Replication

Page 8: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

IAM Platform and architecture

Oracle Confidential – Internal/Restricted/Highly Restricted 8

Page 9: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

IAM Plattform

Page 10: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

IAM Architecture

Page 11: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

IAM Components

Oracle Confidential – Internal/Restricted/Highly Restricted 11

Page 12: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Oracle Unified Directory Directory Server Multimaster Replication & Proxy

Replication

Loadbalancer

Client

Client

OUD Proxy OUD Proxy

OUD OUD

Replication OUD OUD Replication OUD OUD

Datacenter 1 Datacenter 2

Loadbalancer

Replication

Page 13: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Oracle Internet Directory Directory Server & Virtual Directory Server

Loadbalancer

Client Loadbalancer

Client

OVD OVD

OID OID OID OID Replication

OID OID

Datacenter 1 Datacenter 2

Database RAC Database RAC Database RAC

Page 14: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Identity Manager Architecture

OPSS

OES

MDS

SOA

OIM

Page 15: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Identity Manager HA

Database RAC

Directory

Page 16: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Access Manager Architecture

Page 17: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Access Manager HA

Database RAC

Directory

Page 18: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Identity Federation Architecture

Page 19: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Identity Federation HA

Database RAC

Directory

Page 20: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Mobile & Social Architecture

Page 21: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Mobile & Social HA

Page 22: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Resources

Oracle Confidential – Internal/Restricted/Highly Restricted 22

Page 23: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Oracle® Fusion Middleware High Availability Guide for Oracle Identity and Access Management

http://docs.oracle.com/cd/E40329_01/doc.1112/e28391/toc.htm

Identity Management 11.1.2 Enterprise Deployment Blueprint

http://www.oracle.com/technetwork/database/availability/maa-deployment-blueprint-1735105.pdf

The Oracle Identity Management Platform: Identity Services at Internet Scale http://www.oracle.com/us/products/middleware/identity-management/idm-platform-wp-1652810.pdf

The Oracle Identity and Access Management Platform Whitepaper http://www.oracle.com/technetwork/middleware/id-mgmt/overview/oracle-idm-wp-11gr2-1708738.pdf

Oracle Identity Management

http://www.oracle.com/identity

http://www.oracle.com/technetwork/middleware/id-mgmt/overview/index.html

Links

Page 24: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. |

Social Networks Blogs.oracle.com/OracleIDM

Facebook.com/OracleIDM

Twitter@OracleIDM

Page 25: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. | Oracle Confidential – Internal/Restricted/Highly Restricted 25

Page 26: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD

Copyright © 2014 Oracle and/or its affiliates. All rights reserved. | Oracle Confidential – Internal/Restricted/Highly Restricted 26

Page 27: Hochverfügbarkeit von Identity und Access Management ... fileOracle Internet Directory Directory Server & Virtual Directory Server Loadbalancer Client Loadbalancer Client OVD OVD