Documentation Home
> Sun OpenSSO Enterprise 8.0 Technical Overview
Sun OpenSSO Enterprise 8.0 Technical Overview
Book Information
Index
A
B
C
D
E
F
G
H
I
J
L
M
N
O
P
R
S
T
U
V
W
X
Preface
Part I An Overview of Sun OpenSSO Enterprise 8.0
Chapter 1 Introducing OpenSSO Enterprise
What is OpenSSO Enterprise?
What Does OpenSSO Enterprise Do?
What Are the Functions of OpenSSO Enterprise?
Access Control
Federation Management
Web Services Security
Identity Web Services
What Else Does OpenSSO Enterprise Offer?
Chapter 2 Examining OpenSSO Enterprise
The Client/Server Architecture
How OpenSSO Enterprise Works
Core Services
Authentication Service
Policy Service
Session Service
Logging Service
Identity Repository Service
Federation Services
Web Services Stack
Web Services Security and the Security Token Service
Identity Web Services
Global Services
Realms
Additional Components
Data and Data Stores
Configuration Data
Identity Data
Generic Lightweight Directory Access Protocol (LDAP) version 3
LDAPv3 Plug-in for Active Directory
LDAPv3 Plug-in for Tivoli Directory
Sun Directory Server With FAM Core Services
Sun Directory Server With Full Schema (including Legacy)
Access Manager Repository Plug-in
Authentication Data
The bootstrap File
Policy Agents
Security Agents
OpenSSO Enterprise Tools
ssoadm Command Line Interface
Session Failover Tools
Client SDK
Service Provider Interfaces for Plug-ins
Authentication Service SPI
Federation Service SPI
Identity Repository Service SPI
Policy Service SPI
Service Configuration Plug-in
Chapter 3 Simplifying OpenSSO Enterprise
Installation and Configuration
Configuration Data Store
Centralized Agent Configuration
Common Tasks Wizard
Third Party Integration
Sun Java System Identity Manager
Computer Associates SiteMinder
Oracle Access Manager
Chapter 4 Deploying OpenSSO Enterprise
Deployment Architecture 1
Deployment Architecture 2
Part II Access Control Using OpenSSO Enterprise
Chapter 5 User Sessions and the Session Service
About the Session Service
User Sessions and Single Sign-on
Session Data Structures and Session Token Identifiers
Chapter 6 Models of the User Session and Single Sign-On Processes
Basic User Session
Initial HTTP Request
User Authentication
Session Validation
Policy Evaluation and Enforcement
Logging the Results
Single Sign-On Session
Cross-Domain Single Sign-On Session
Session Termination
User Ends Session
Administrator Ends Session
OpenSSO Enterprise Enforces Timeout Rules
Session Quota Constraints
Chapter 7 Authentication and the Authentication Service
Authentication Service Overview
Authentication Service Features
Account Locking
Authentication Chaining
Fully Qualified Domain Name Mapping
Persistent Cookies
Session Upgrade
JAAS Shared State
Security
Authentication Modules
Authentication Types
Configuring for Authentication
Core Authentication Module and Realm Configuration
Authentication Configuration Service
Login URLs and Redirection URLs
Authentication Graphical User Interfaces
Authentication Service User Interface
Distributed Authentication User Interface
Authentication Service Programming Interfaces
Chapter 8 Authorization and the Policy Service
Authorization and Policy Service Overview
The Policy and the Referral
Policy
Rules
Subjects
Conditions
Response Providers
Referral
Realms and Access Control
Policy Service Programming Interfaces
XACML Service
XACML in OpenSSO Enterprise
XACML Programming Interfaces
Part III Federation Management Using OpenSSO Enterprise
Chapter 9 What is Federation?
The Concept of Federation
Identity Federation
Provider Federation
The Concept of Trust
How Federation Works
Chapter 10 Federation Management with OpenSSO Enterprise
Key Federation Management Features
The Fedlet
Secure Attribute Exchange/Virtual Federation Proxy
Authentication at Identity Provider
Virtual Federation at Identity Provider
Virtual Federation at Service Provider
Global Single Logout
Multi-Federation Protocol Hub
The Federation Framework Architecture
Chapter 11 Choosing a Federation Option
Federation Options
Using SAML
About SAML v2
Key Features
Administration
Application Programming Interfaces
Service Provider Interfaces
JavaServer Pages
About SAML v1.x
Which Flavor of SAML to Use?
Using SAML v2 or OpenSSO Enterprise CDSSO
Using SAML v1.x or Liberty ID-FF
Using the Liberty ID-FF
Liberty ID-FF Features
Federated Single Sign-On
Auto-Federation
Bulk Federation
Authentication and Authentication Context
The Common Domain for Identity Provider Discovery
The Common Domain
The Common Domain Cookie
The Writer Service and the Reader Service
Identifiers and Name Registration
Global Logout
Dynamic Identity Provider Proxying
About the Liberty ID-FF Process
Using WS-Federation
Part IV The Web Services Stack, Identity Services, and Web Services Security
Chapter 12 Accessing the Web Services Stack
About the Web Services Stack
Web Services Stack Architecture
Web Services Stack Process
Using the Web Services Stack
With SAML v2 or Liberty ID-FF
With the Authentication Web Service
Implemented Services
Authentication Web Service
Authentication Web Service Process
Authentication Web Service API
Which Authentication Service to Use?
Discovery Service
Discovery Service Process
Discovery Service Architecture
Discovery Service API
SOAP Binding Service
SOAP Binding Service Components
SOAPReceiver Servlet
RequestHandler Interface
SOAP Binding Service Process
SOAP Binding Service API
Liberty Personal Profile Service
Liberty Personal Profile Service Design
Liberty Personal Profile Service Process
Data Services API
Chapter 13 Delivering Identity Web Services
About Identity Web Services
Identity Web Service Styles
SOAP and WSDL
REST
Identity Web Services Architecture
Chapter 14 Securing Web Services and the Security Token Service
About Web Services Security
Web Services Interoperability Technology
WS-Security Specification
WS-Trust Specification
Liberty Alliance Project Specifications
JSR-196 Specification
Web Services Security in OpenSSO Enterprise
Web Services Security Internal Architecture
Web Services Security Deployment Architecture
Security Token Service
Security Agents
HTTP Security Agent
SOAP Security Agent
Supported Liberty Alliance Project Security Tokens
Supported Web Services-Interoperability Basic Security Profile Security Tokens
Web Services Security and Security Token Service Interfaces
com.sun.identity.wss.provider
com.sun.identity.wss.security
com.sun.identity.wss.sts
Part V Additional Features
Chapter 15 Recording Events with the Logging Service
Logging Service Overview
About the Logging Service
Configuring the Logging Service
Recording Events
Log File Formats and Log File Types
Log File Formats
Flat File Format
Relational Database Format
Log File Types: Error and Access
Secure Logging
Remote Logging
OpenSSO Enterprise Component Logs
Logging Service Interfaces
Chapter 16 Getting Starting with the OpenSSO Enterprise Samples
Server Samples
Client SDK Samples
Command Line Interface Samples
© 2010, Oracle Corporation and/or its affiliates