You are on page 1of 12

Welcome

TO OUR PRESENTATION

Anand Subramanian - 01
Selwin Edward - 06
Ankit Shanbhag - 26
Aditya Shirodkar - 29

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


THE GROUP
PRESENTER
SINGLE SIGN-ON 1 of 12
Single Sign-On

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


Anand Subramanian
PRESENTER
SINGLE SIGN ON 2 of 12
What Is Single Sign-ON
Single Sign On (SSO) (also known as IN LAYMAN’S LANGUAGE
Enterprise Single Sign On or "ESSO") is
the ability for a user to enter the same id
”One log-on provides access to
and password to logon to multiple
applications within an enterprise all resources of the network,
LAN, or WAN. “

OR

A mechanism to verify a user across


multiple applications through a single
authentication challenge. E.g.:
WebSphere Portal Server uses Java
Authentication and Authorization
Services to achieve single sign-on.

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


Anand Subramanian
PRESENTER
SINGLE SIGN ON 3 of 12
SSO In Our Day To Day Life

THE UID CARD!!!

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


Anand Subramanian
PRESENTER
SINGLE SIGN ON 4 of 12
SSOand LDAPAuthentication
Most modern single sign on systems use LDAP LDAP directories have a universal
(Lightweight Directory Access Protocol) directories protocol enabling quick interaction
to store the authentication and authorization policies. and exchange of identity information
The Lightweight Directory Access Protocol is between enterprises.
an application protocol for accessing and
maintaining distributed directory information
services over an Internet Protocol (IP) network. LDAP directories can be easily
partitioned to place the directory close
to the end-user, thus improving
It is very quick for doing identity reads against as performance and reducing network
compared to traditional databases. load.

LDAP directories are excellent for doing rapid LDAP


authentication against for any digitized
authentication.

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


Anand Subramanian
PRESENTER
SINGLE SIGN ON 5 of 12
YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE
Anand Subramanian
PRESENTER
SINGLE SIGN ON 6 of 12
Benefits Of Single Sign-ON
Ability to enforce uniform enterprise Removes application developers
authentication and/or authorization from having to understand and
policies across the enterprise. implement identity security in
their applications.
End to end-user audit sessions to
improve security reporting and Usually results in significant
auditing. password help desk cost savings.

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


Ankit Shanbhag
PRESENTER
SINGLE SIGN ON 7 of 12
YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE
Anand Subramanian
PRESENTER
SINGLE SIGN ON 8 of 12
Types of Single Sign-ON
HOLY GRAIL
.

ENTERPRISE SSO

SYNCHRONIZATION

WEB SSO

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


Aditya Shirodkar
PRESENTER
SINGLE SIGN ON 9 of 12
What Is Kerberos?
Kerberos is a computer network Provides mutual authentication —
authentication protocol which allows both the user and the server
individuals communicating over a non- verify each other's identity.
secure network to prove their identity to
one another in a secure manner.

Designed as a client-server model.

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


Selwyn Edward
PRESENTER
SINGLE SIGN ON 10 of 12
The Drawbacks…
Kerberos requires continuous Since the secret keys for all users
availability of a central server. are stored on the central server, a
compromise of that server will
compromise all users’ secret
Kerberos requires the clocks of the keys.
involved hosts to be synchronized.
A compromised client will
compromise the user’s password.
.

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


Selwyn Edward
PRESENTER
SINGLE SIGN ON 11 of 12
Show is over
YOU MAY NOW SIGN-OUT!

YOU ARE LOOKING AT TODAY TOPIC IS WE ARE CURRENTLY HERE


THE GROUP
PRESENTER
SINGLE SIGN ON 12 of 12

You might also like