Skip to Content
Sun and Oracle
Channel Sun
How to Buy
Log In
Français
Page d’accueil docs.sun.com
>
Sun OpenSSO Enterprise 8.0
> Sun OpenSSO Enterprise 8.0 Technical Overview
Sun OpenSSO Enterprise 8.0 Technical Overview
Rechercher uniquement dans ce livre
Aide pour la recherche
Contenues dans
Sun OpenSSO Enterprise 8.0
Trouver plus de documentation
Explorer la documentation par titre
Explorer la documentation par produit
Ressources d'assistance comprises
Formations Sun
Portail d'administration système BigAdmin
Centre de support Sun
Sun Solve
Télécharger cet ouvrage au format PDF (6303 Ko)
Sun OpenSSO Enterprise 8.0 Technical Overview
Index
A
B
C
D
E
F
G
H
I
J
L
M
N
O
P
R
S
T
U
V
W
X
Book Information
Preface
Before You Read This Book
Related Books
OpenSSO Enterprise 8.0 Core Documentation
Related Product Documentation
Searching Sun Product Documentation
Documentation, Support, and Training
Third-Party Web Site References
Sun Welcomes Your Comments
Default Paths and Directory Names
Typographic Conventions
Shell Prompts in Command Examples
Symbol Conventions
An Overview of Sun OpenSSO Enterprise 8.0
1. Introducing OpenSSO Enterprise
What is OpenSSO Enterprise?
What Does OpenSSO Enterprise Do?
What Are the Functions of OpenSSO Enterprise?
Access Control
Federation Management
Web Services Security
Identity Web Services
What Else Does OpenSSO Enterprise Offer?
2. Examining OpenSSO Enterprise
The Client/Server Architecture
How OpenSSO Enterprise Works
Core Services
Authentication Service
Policy Service
Session Service
Logging Service
Identity Repository Service
Federation Services
Web Services Stack
Web Services Security and the Security Token Service
Identity Web Services
Global Services
Realms
Additional Components
Data and Data Stores
Configuration Data
Identity Data
Generic Lightweight Directory Access Protocol (LDAP) version 3
LDAPv3 Plug-in for Active Directory
LDAPv3 Plug-in for Tivoli Directory
Sun Directory Server With FAM Core Services
Sun Directory Server With Full Schema (including Legacy)
Access Manager Repository Plug-in
Authentication Data
The bootstrap File
Policy Agents
Security Agents
OpenSSO Enterprise Tools
ssoadm Command Line Interface
Session Failover Tools
Client SDK
Service Provider Interfaces for Plug-ins
Authentication Service SPI
Federation Service SPI
Identity Repository Service SPI
Policy Service SPI
Service Configuration Plug-in
3. Simplifying OpenSSO Enterprise
Installation and Configuration
Configuration Data Store
Centralized Agent Configuration
Common Tasks Wizard
Third Party Integration
Sun Java System Identity Manager
Computer Associates SiteMinder
Oracle Access Manager
4. Deploying OpenSSO Enterprise
Deployment Architecture 1
Deployment Architecture 2
Access Control Using OpenSSO Enterprise
5. User Sessions and the Session Service
About the Session Service
User Sessions and Single Sign-on
Session Data Structures and Session Token Identifiers
6. Models of the User Session and Single Sign-On Processes
Basic User Session
Initial HTTP Request
User Authentication
Session Validation
Policy Evaluation and Enforcement
Logging the Results
Single Sign-On Session
Cross-Domain Single Sign-On Session
Session Termination
User Ends Session
Administrator Ends Session
OpenSSO Enterprise Enforces Timeout Rules
Session Quota Constraints
7. Authentication and the Authentication Service
Authentication Service Overview
Authentication Service Features
Account Locking
Authentication Chaining
Fully Qualified Domain Name Mapping
Persistent Cookies
Session Upgrade
JAAS Shared State
Security
Authentication Modules
Authentication Types
Configuring for Authentication
Core Authentication Module and Realm Configuration
Authentication Configuration Service
Login URLs and Redirection URLs
Authentication Graphical User Interfaces
Authentication Service User Interface
Distributed Authentication User Interface
Authentication Service Programming Interfaces
8. Authorization and the Policy Service
Authorization and Policy Service Overview
The Policy and the Referral
Policy
Rules
Subjects
Conditions
Response Providers
Referral
Realms and Access Control
Policy Service Programming Interfaces
XACML Service
XACML in OpenSSO Enterprise
XACML Programming Interfaces
Federation Management Using OpenSSO Enterprise
9. What is Federation?
The Concept of Federation
Identity Federation
Provider Federation
The Concept of Trust
How Federation Works
10. Federation Management with OpenSSO Enterprise
Key Federation Management Features
The Fedlet
Secure Attribute Exchange/Virtual Federation Proxy
Authentication at Identity Provider
Virtual Federation at Identity Provider
Virtual Federation at Service Provider
Global Single Logout
Multi-Federation Protocol Hub
The Federation Framework Architecture
11. Choosing a Federation Option
Federation Options
Using SAML
About SAML v2
Key Features
Administration
Application Programming Interfaces
Service Provider Interfaces
JavaServer Pages
About SAML v1.x
Which Flavor of SAML to Use?
Using SAML v2 or OpenSSO Enterprise CDSSO
Using SAML v1.x or Liberty ID-FF
Using the Liberty ID-FF
Liberty ID-FF Features
Federated Single Sign-On
Auto-Federation
Bulk Federation
Authentication and Authentication Context
The Common Domain for Identity Provider Discovery
The Common Domain
The Common Domain Cookie
The Writer Service and the Reader Service
Identifiers and Name Registration
Global Logout
Dynamic Identity Provider Proxying
About the Liberty ID-FF Process
Using WS-Federation
The Web Services Stack, Identity Services, and Web Services Security
12. Accessing the Web Services Stack
About the Web Services Stack
Web Services Stack Architecture
Web Services Stack Process
Using the Web Services Stack
With SAML v2 or Liberty ID-FF
With the Authentication Web Service
Implemented Services
Authentication Web Service
Authentication Web Service Process
Authentication Web Service API
Which Authentication Service to Use?
Discovery Service
Discovery Service Process
Discovery Service Architecture
Discovery Service API
SOAP Binding Service
SOAP Binding Service Components
SOAPReceiver Servlet
RequestHandler Interface
SOAP Binding Service Process
SOAP Binding Service API
Liberty Personal Profile Service
Liberty Personal Profile Service Design
Liberty Personal Profile Service Process
Data Services API
13. Delivering Identity Web Services
About Identity Web Services
Identity Web Service Styles
SOAP and WSDL
REST
Identity Web Services Architecture
14. Securing Web Services and the Security Token Service
About Web Services Security
Web Services Interoperability Technology
WS-Security Specification
WS-Trust Specification
Liberty Alliance Project Specifications
JSR-196 Specification
Web Services Security in OpenSSO Enterprise
Web Services Security Internal Architecture
Web Services Security Deployment Architecture
Security Token Service
Security Agents
HTTP Security Agent
SOAP Security Agent
Supported Liberty Alliance Project Security Tokens
Supported Web Services-Interoperability Basic Security Profile Security Tokens
Web Services Security and Security Token Service Interfaces
com.sun.identity.wss.provider
com.sun.identity.wss.security
com.sun.identity.wss.sts
Additional Features
15. Recording Events with the Logging Service
Logging Service Overview
About the Logging Service
Configuring the Logging Service
Recording Events
Log File Formats and Log File Types
Log File Formats
Flat File Format
Relational Database Format
Log File Types: Error and Access
Secure Logging
Remote Logging
OpenSSO Enterprise Component Logs
Logging Service Interfaces
16. Getting Starting with the OpenSSO Enterprise Samples
Server Samples
Client SDK Samples
Command Line Interface Samples
News Center
About Sun
Contact Sun
Terms of Use
Privacy
Copyright
1994-2009
Sun Microsystems, Inc.