Top Banner
Web Access Management and SSO: Transitioning from Sun to Oracle Presented by Zdenek Nejedly Identity, Databases, and Enterprise Access, Computing and Communications Services, University of Guelph, Ontario
15

WAM and SSO: transition from Sun to Oracle

Feb 04, 2022

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: WAM and SSO: transition from Sun to Oracle

Web Access Management and SSO:

Transitioning from Sun to Oracle

Presented by Zdenek Nejedly

Identity, Databases, and Enterprise Access, Computing and Communications Services, University of Guelph, Ontario

Page 2: WAM and SSO: transition from Sun to Oracle

wam

complexity

is increasing exponentially

Page 3: WAM and SSO: transition from Sun to Oracle

CAS Sun AM Oracle AM

150 MB CAS war file, Tomcat, JDK

800 MB AM war files, webserver, LDAP, JDK, sessions...

16,500 MB Fusion Middleware, OAM war files,

WebLogic, OID, Oracle HTTP Server, Oracle Database, RCU, Business Intelligence Publisher, ...

size of compressed installation files

Page 4: WAM and SSO: transition from Sun to Oracle

maturing technologybundled solutions

integration with identity managementadaptive access control

cloud and SaaSmarket consolidation

source: Gartner

trends in WAM products

Page 5: WAM and SSO: transition from Sun to Oracle

Lessons learned from running SSO w/Sun AM

What is Oracle AM and our transition to OAM

from SAM to OAM – the outline

Page 6: WAM and SSO: transition from Sun to Oracle

2007 evaluation – CAS, Sun Access Manager

2008 Sep Sun AM in production, adding SSO partners

2010 Winter Oracle finalizes acquisition of Sun

2010 May UofG SSO reaches entire campus

2011 Summer UofG transitioning to Oracle AM

access management at UofG

Page 7: WAM and SSO: transition from Sun to Oracle

What mattered the most:

clients: packaged solutions (toolkits)

technology: HA cluster

operational: SSO life-cycle monitoring

three years with SSO

Page 8: WAM and SSO: transition from Sun to Oracle

Oracle AM and Sun AM (openSSO)

Page 9: WAM and SSO: transition from Sun to Oracle

deployment of SAM vs. transition to OAMSS

O p

artn

ers

2009 2010 2011

until reaching entire campus

Transitionto OAM

User expectations: SSO interface,

performance, …

Page 10: WAM and SSO: transition from Sun to Oracle

Continuity for campus community:

Minimum effort for content providers:

Critical service aspects - security, availability,

flexibility

goals for the transition

consistent authentication UI

WAM toolkits (ColdFusion, php, PL/SQL)

clustered app and db layer

virtualization of dev and test servers

with solutions

Page 11: WAM and SSO: transition from Sun to Oracle

iterations through 4 stages

Planning

• Standalone OAM for risk prototyping

• Core agents

Clusters

• Virtualized cluster

• Additional agents

Customization

• Authentication UI

• Security and monitoring

Production

• Physical infrastructure in stages

• Load testing and tuning

Post-production tuning

Page 12: WAM and SSO: transition from Sun to Oracle

Application and

client servers on

central VMware

Database

servers on

dedicated

VMware

deployment diagram

Production

servers

Page 13: WAM and SSO: transition from Sun to Oracle

Technology versus licensing:

Patching, security and clustering

complexity:

Multilayer infrastructure:

transition challenges and solutions

staging with

VMware snapshots

cross-disciplinary expertise

risk prototyping

Page 14: WAM and SSO: transition from Sun to Oracle

transitioning to Oracle AM

risks minimized by interfaces (what-if approach)

increasing technical complexity and Oracle licensing

benefits of virtualization/snapshots

clustering for HA and maintainability

summary

For more details: [email protected] see http://docs.identity.uoguelph.ca

Page 15: WAM and SSO: transition from Sun to Oracle

Hugh Smith, Matt Searle IDEAS, UofG

Bosco Tsang, Tony Zhu, Mark Sloggett Managed Servers, UofG

Leo Song, Dennis Xu, David Wang Networking & Security, UofG

Dave Bruce, Angela Spaceley, Dennis Fisher Storage & Backup, UofG

CCS Management Team, UofG

Rick Sidey and Michelle Shen Oracle Corporation

Oracle technical Support staff….

Acknowledgements

THANK YOU

For more details: [email protected] see http://docs.identity.uoguelph.ca