rmll 2014 - lemonldap::ng - what's new under the sson

21
What's new under the SSOn? Clément OUDOT [email protected]

Upload: oudot-clement

Post on 12-Jun-2015

536 views

Category:

Technology


0 download

DESCRIPTION

Presentation of WebSSO LemonLDAP::NG and focus on new features from 1.4 release

TRANSCRIPT

Page 1: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

What's new under the SSOn?

Clément [email protected]

Page 2: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

2

About the SSOpeaker

Page 3: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

3

LemonLDAP::NG PreSSOntation

Page 4: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

4

SSOme history

2003 2006 2010 2014

Project creation

NG version

SAMLCAS

OpenID

1.4 release

Page 5: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

5

It's SSO simple!

User

Web Application

WebSSO Portal

1

2

3

Page 6: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

6

CompSSOnents

CommonCommon

ManagerManager HandlerHandler

PortalPortal

Administration interface

User interactions

Applications protection

Page 7: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

7

Page 8: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

8

AuthenticaSSOn backends

LDAPLDAPADAD

ApacheApache SAMLSAML

CASCAS RadiusRadius OpenIDOpenID

WebIDWebID

BrowserBrowserIDID

DBIDBI

YubikeyYubikey

Page 9: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

9

Self SSOrvice

Password Password changechange

Password Password resetreset

Login Login historyhistory

Page 10: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

10

Identity protoSSOls gateway

SAMLSAMLCASCAS

OpenIDOpenID

Page 11: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

11

VerSSOn 1.4

Page 12: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

12

Bootstrap SSOkin

Page 13: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

13

SSOelf register service

Fill a form

First nameLast nameEmail

Validate by clicking link in email

Receive login and password in email

Page 14: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

14

use Mouse; # AweSSOme Perl

Configuration Configuration attributesattributes SessionsSessions

HandlerHandler CaptchaCaptcha

Page 15: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

15

SSOession identifiers

MD5SHA256

8c7fef2b3820ecdea49614be7b769c62

9be0bab50d1c14b51264a7194fc2517cb25a5788e860cf672823dff434348dba

Page 16: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

16

SAML IDP SSO initiated

11

22

IdentityProvider

ServiceProvider

http://auth.example.com/saml/singleSignOn?IDPInitiated=1&spConfKey=myserviceprovider

Page 17: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

17

Nginx SSOpport

LUA Perl

Work in progressHandler available on GitHub

Page 18: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

18

QueSSOtions?

Page 19: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

19

SSOanks

RMLL Staff

RMLL Security track leaders

LemonLDAP::NG team

LINAGORA

Page 20: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

20

SSOtay tunedhttp://lemonldap-ng.org

IRC #lemonldap-ng@freenode

http://mail.ow2.org/wws/

@lemonldapng

http://www.ohloh.net/p/lemonldap-ng

Page 21: RMLL 2014 - LemonLDAP::NG - What's new under the SSOn

21

See you SSOn!