pre-con ed: multiple implementation and access models for ca sso

37
World ® ’1 6 Pre-Con Ed: Multiple Implementation and Access Models for CA Single Sign-On (CA SSO) SCX09E SECURITY

Upload: ca-technologies

Post on 08-Jan-2017

171 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

World®’16

Pre-ConEd:MultipleImplementationandAccessModelsforCASingleSign-On(CASSO)

SCX09E

SECURITY

Page 2: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

2 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

©2016CA.Allrightsreserved.Alltrademarksreferencedhereinbelongtotheirrespectivecompanies.

Thecontentprovidedinthis CAWorld2016presentationisintendedforinformationalpurposesonlyanddoesnotformanytypeofwarranty. The informationprovidedbyaCApartnerand/orCAcustomerhasnotbeenreviewedforaccuracybyCA.

ForInformationalPurposesOnlyTermsofthisPresentation

Page 3: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

3 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Abstract

Today’sorganizationsneedtodomorethanjustsecuretheon-premise applicationsrunningintheirdatacenters.Modernorganizationsalsohaveapplicationsrunninginplatform-as-a-service(PaaS)datacenters,suchasAzureorAmazonandonmobileplatforms,andhaveagrowingnumberofSaaSapplications(suchasWebEx).Additionally,applicationscontinuetobemovedaroundacrossthesedifferentimplementationandaccessmodels,changinglocations(on-premise toAWS,forexample)andchangingtheacceptablemethodsofuserauthentication.Mixinthedynamicofausergainingaccessviadifferentdevices(laptop,tablet,BYOD)andyoucanseehowcomplicatedlifegetsforauserandanITsecurityprofessional.Inthissession,we’lldiscussvariousPaaS,managedandSaaSimplementationmodelsandhowtosecureapplicationsofallvarieties.

AaronBerman

HerbMehlhorn

KathyHickeyCATechnologies

Page 4: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

4 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Agenda

THEITCHALLENGE

EVOLVINGDEPLOYMENTARCHITECTURES

METHODSOFAPPLICATIONINTEGRATION

OVERLAYINGACCESSMETHODSWITHDEPLOYMENTARCHITECTURES

1

2

3

4

Page 5: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

5 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD5 ©2016CA.AllRIGHTSRESERVED.

TheChallengeofToday’sITEnvironment

§ EVERYTHING isinmotion– Users– Devices– Applications– DataCenters

Page 6: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

6 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

EndUser Apps Security

ApplicationsandSecurityintheDataCenter

OnPremiseDataCenter

Page 7: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

7 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

ApplicationsandSecurityintheDataCenter

EndUsers Apps Security

OnPremiseDataCenter

Page 8: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

8 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

TheDeploymentArchitectureattheStartoftheJourney

DataCenter1

DataCenter2

EndUsers

Page 9: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

9 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

TheDeploymentArchitectureattheStartoftheJourney

EndUsers

DataCenter1

DataCenter2

ThirdPartyApps

Page 10: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

10 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

EvolvingDeploymentArchitectures

PAASEndUsers

DataCenter1

DataCenter2

ThirdPartyApps

Page 11: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

11 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

EvolvingDeploymentArchitectures

EndUsersThirdPartyApps

DataCenter1

DataCenter2

PAAS

Page 12: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

12 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

EvolvingDeploymentArchitectures

PAAS

ManagedandHostedServices

EndUsers

DataCenter1

DataCenter2

ThirdPartyApps

Page 13: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

13 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

EvolvingDeploymentArchitectures

PAASSAASEndUsers

ManagedandHostedServices

DataCenter1

DataCenter2

ThirdPartyApps

Page 14: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

14 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

KeyPaaSConsideration– ExposedtoPublic?

PAASEndUsers

DataCenter1

DataCenter2

Page 15: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

15 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

KeyPaaSConsideration– ExposedtoPublic?

PAAS

VPNforPrivateAccessOnly

EndUsers

DataCenter1

DataCenter2

Page 16: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

16 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

KeyPaaSConsideration– ExposedtoPublic?

EndUsers

DataCenter1

DataCenter2

PAAS

VPNforPrivateAccessOnly

Page 17: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

17 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

KeyConsiderationsforPaaSDeploymentConsideration PrivateSegment Public Segment

Locationofuserrepository (PIIdataatrest)

BackupandRecovery

HAandfailover

Network AddressTranslation

Encryption ofData

Monitoring Performance

Log collection

VPNGateway atfrontendofPaaS

Load balancerexposedtoInternet

BastionServer

Front endfirewall&threatprevention

Page 18: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

18 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

PotentialPaaSComponentDeployment

LoadBalancer

ExternalLoadBalancer

LoadBalancer

Location#1

SSOPolicyServers

SSOAgents/AccessGtwy

Location#2 Location#3

Threat/Bastion

CorporateLocation

ExternalUsers

VPN

Page 19: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

19 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

FlexibleSolutiontoMeetManyNeedsinaSingleDeployment

CASingleSign-On

OpenStandards

SOAPandRESTAPIs

PolicyEnforcementGateway(AccessGateway)

OpenFormatToken

PolicyEnforcementConnectors

(Agents)

Page 20: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

20 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

ApplicationIntegrationMethodscanbeUsedbyThemselvesorTogether§ AccessGateway+Agent=differentwaystosecureanappbasedonaccess

§ Gateway(orAgent)+Federation=URLlevelfilteringwithlowintegrationcostsforappsthatalreadyspeakSAML

§ Openformatcookie+API=agentlessSSOandexternalizedauthorizationcontrolsforappsoutsidethedatacenter

§ Federation+API=StandardsbasedSSOforinternalapplicationswiththeabilitytodoauthorizationcalls

§ Agent+API=securesessionmanagementandauthorizationwithlesscommunicationbetweenappandpolicyserver

Page 21: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

21 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

PotentialPaaSComponentDeploymentNoVPNConnectingPaaSandInternalDataCenter

LoadBalancer

PaaSDataCenter

Applications

CorporateLocation

LoadBalancer

LoadBalancer

SSOPolicyServers

SSOAgents/AccessGtwy

OpenFormatCookie

Page 22: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

22 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

PotentialPaaSComponentDeploymentNoVPNConnectingPaaSandInternalDataCenter

LoadBalancer

LoadBalancer

PaaSDataCenter

SSOPolicyServers

SSOAgents/AccessGtwy

CorporateLocation

LoadBalancer

LoadBalancer

SSOPolicyServers

SSOAgents/AccessGtwy

CADirectoryorOtherUserStore

DisparateSSO

OpenFormatCookie

SAML

Page 23: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

23 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

PotentialPaaSComponentDeploymentVPNConnectingPaaSandInternalDataCenter

LoadBalancer

PaaSDataCenter

SSOPolicyServers

SSOAgents/AccessGtwy

CorporateLocation

VPN

LoadBalancer

LoadBalancer

SSOPolicyServers

SSOAgents/AccessGtwy

CADirectoryorOtherUserStore

AgentCommunication

RestAPICommunication

12.52SP1CR4introducedtheabilitytodisableIsAuthorized

callsfromAgents

Page 24: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

24 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

PotentialPaaSComponentDeploymentVPNConnectingPaaSandInternalDataCenter

LoadBalancer

LoadBalancer

PaaSDataCenter

SSOPolicyServers

SSOAgents/AccessGtwy

CorporateLocation

VPN

LoadBalancer

LoadBalancer

SSOPolicyServers

SSOAgents/AccessGtwy

CADirectoryorOtherUserStore

AgentCommunication

DisparateSSO

Page 25: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

25 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

CybersecurityfortheHybridEnterpriseProvidingInherentSecurityControlsinaTransparentandSeamlessWay

HYBRIDENTERPRISETraditionalDataCenter PrivateCloud PublicCloud- IaaS SaaSApplications

§ CentralizeAuthentication§ FederateIdentities§ SingleSign-on§ SessionReplayProtection

§ SingleLogout§ IdentityMappingacrosstheenterprise§ UserActivitymonitoringandauditing§ Inspectionofeveryrequest

UsingSecuritytoSolveToday’sBusinessRequirements

AuthenticationAuthorization

&AccessManagement

SingleSign-On SessionSecurity

Page 26: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

26 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

CASupportsaWideVarietyofDeploymentOptions

TraditionalOnPremiseDeployedandManaged

SaaS

ManagedOnPremise

ManagedoffPremise

TraditionallyManaged–CloudDeployed

Softwareinstalledinlocaldatacenters– managedbyemployees

Softwareinstalledinlocaldatacenters– managedbyCAorCAPartner

SoftwareinstalledinClouddatacenters– managedbyemployees

SoftwareinstalledinHostedenvironmentsdatacenters–managedbyCAorPartners

Softwareasaservice– managedbyemployees

Page 27: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

27 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

TwoApproachestoSingleSignOn

§ Usercanbecentrallyauthenticatedorlocallyauthenticated

§ AllCommunicationbetweenbrowserandwebserverisinterceptedandinspected

§ Eachrequestcanbeexaminedforvalidity,tampering,andauthorization

§ Asinglesharedsessionspansallapplications

§ Identityinformationisplacedintorequestsoapplicationcanreadtheidentity

§ Userdirectlyaccesswebsitetolaunch(toplevelanddeeplinkedbookmarks)

TIGHTLYCOUPLED§ UseriscentrallyAuthenticated

§ Atokencontainingidentityandsecurityattributesiscreatedandthenpassedtotheapplication

§ Applicationreadstokencreatesapplicationspecificsession

§ Applicationisresponsibleforauthorization,sessionsecurityandhonoringsecurityclaims

§ Tokenmaybeonetimeuseormaybepresentedoneachrequest

§ Launchedbyaccessinglaunchpad orbyaccessingacustomizedURL

LOOSELYFEDERATED

Most3rd PartySaaSapplications(Salesforce,Concur)onlysupportLooselyFederatedModel

Page 28: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

28 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

DeploymentOptionCapabilities

TraditionalOnPremiseDeployedandManaged

SaaS

ManagedOnPremise

ManagedoffPremise

TraditionallyManaged–CloudDeployed

TightlyandLooselyCoupled

TightlyandLooselycoupled

TightlyandLooselyCoupled

LooselyCoupledOnly

TightlyandLooselyCoupled

Page 29: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

29 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

SingleSign-on

Authentication(SaaS-firstmodel) CAIdentity

Service

Userprovisioning&deprovisioning

SingleSign-onRogueandorphanaccountdetectionandremediation

CASingleSign-On

On-premisesapps

SaaSApps

Peoplesource(optional)

Authentication(Hybridmodel)

SingleSign-on

ANewHybridDeploymentModelCASSOandCAIdentityService

Page 30: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

30 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

TheLaunchpadisdynamicallypopulatedattimeofloginbaseduponwhattheenduserhas

accessto

Accesstoonprem CASSOprotectedapplicationsisavailable– truehybrid

support

ANewHybridDeploymentModelCASSOandCAIdentityService

CAIdentityService

Page 31: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

31 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

§ PredefinedintegrationwithCASingleSign-On

§ FewclickstoimportexistingCASSOprotectedresources

§ ExistingCASSOpoliciesdynamicallyevaluatedtodeterminewhogetsaccess

§ OptiontoenableCASSOastheidentityprovider

ANewHybridDeploymentModelSimplifiedWorkforceExperience

Page 32: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

32 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

EndUsers

DataCenter1

DataCenter2

ThirdPartyApps CAIdentityService

SaaSApplication

AHybridDeploymentArchitecturewithCAIdentityService

Page 33: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

33 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

CybersecurityfortheHybridEnterpriseProvidingInherentSecurityControlsinaTransparentandSeamlessWay

HYBRIDENTERPRISETraditionalDataCenter PrivateCloud PublicCloud- IaaS SaaSApplications

§ CentralizeAuthentication§ FederateIdentities§ SingleSign-on§ SessionReplayProtection

§ SingleLogout§ IdentityMappingacrosstheenterprise§ UserActivitymonitoringandauditing§ Inspectionofeveryrequest

UsingSecuritytoSolveToday’sBusinessRequirements

AuthenticationAuthorization

&AccessManagement

SingleSign-On SessionSecurity

Page 34: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

34 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Questions?

Page 35: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

35 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

RecommendedSessions

SESSION# TITLE DATE/TIME

SCX16E Pre-ConEd:Who’smindingtheSSOstore 11/15/2016at1:00pm

SCT44TTechTalk:WebAccessManagementandFederation–TwoGreatTastesthatTasteGoodTogether 11/16/2016at11:30am

SCX20S CARoadmap:Authentication,SingleSign-On,Directory 11/17/2016 at1:45pm

SCT43T HybridAppLauchpad 11/17/2016at3:45pm

Page 36: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

36 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Don’tMissOurINTERACTIVESecurityDemoExperience!

SNEAKPEEK!

36 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Page 37: Pre-Con Ed: Multiple Implementation and Access Models for CA SSO

37 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

THANKYOU

Stayconnectedatcommunities.ca.com