oracle entitlement server - managing organisations

20
The most comprehensive Oracle applications & technology content under one roof Oracle Entitlement Server Managing Organizations

Upload: peter-mclarty

Post on 05-Dec-2014

308 views

Category:

Technology


1 download

DESCRIPTION

Do you require a way to manage Complex Application Entitlements across a range of applications?

TRANSCRIPT

Page 1: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Oracle Entitlement Server

Managing Organizations

Page 2: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

What are we here for

• Learn about what OES does• How it might be used to solve problems• Demo maybe

Page 3: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Security

• Specialized area• Brittle security when built in• Difficult to change

Page 4: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

The Problems

• Managing access to resources• Governance• Auditing• Accommodating changes

Page 5: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Identity Management

• RBAC• Authentication and Authorization• Latency high response for authorization

Page 6: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

OES Overview

Page 7: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Entitlement Server Features

• XACML• Fine Grain Entitlement Management• RBAC• ABAC

Page 8: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

XACML and Database

• Database auditing can be done with XACML – Note 1375460.1

• Database security is not currently available• Use database http server to query PEP• Database performance???

Page 9: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Business Problem

• Application has rules• Rules need to change• Are your rules hard coded?• Policy engine provides way to support

Page 10: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Admin Console

• CRUD on policy and objects• Mapping policies to users• Policies• Resources• Entitlements• Roles• Applications

Page 11: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Roles – Role Categories

• Roles – User, developer, manager• Role Categories are tags

Page 12: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Role Hierarchies

• Set up Role Hierarchies • Director -> Manager -> Call Centre Worker• Employee -> Payroll Admin -> Accountant• Role Mapping – Dynamic Assignment

Page 13: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Resources

• Add resources• A resource can be a URL or field on a page • A business object – transfer funds• Authorization Policy to grant or deny• Can the user complete a task• Time based access

Page 14: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Entitlements

• Action that can be performed on a resource• Uses the legal actions defined in parent

resource type• Targets – could be more than one resource

Page 15: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Policy

• Has at least one principal – user, role, Ex or app

• At least one target• Grant/deny permissions • Conditions

Page 16: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Attributes & Functions

• Used in conditions• Attribute can be dynamically assigned a value• Evaluated at run time -perhaps location• Can be multivalued list• Condition builder

Page 17: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Condition Builder

Page 18: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Administration

• Delegated administration• Application Administration• View or manage rights• Policy Domains to delegate• Allows for delegation to specific areas

Page 19: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Questions

Page 20: Oracle Entitlement Server  - Managing Organisations

The most comprehensive Oracle applications & technology content under one roof

Bio

• Peter McLarty• Director Turagit Consulting• Chameleon• DBA, Middleware, Architecture• http://www.turagit.com