Securing the Perimeter: Deploying Identity and Access Management with Free Open Source Software
β Scribed by Michael Schwartz
- Publisher
- Apress
- Year
- 2019
- Tongue
- English
- Leaves
- 383
- Edition
- 1
- Category
- Library
No coin nor oath required. For personal study only.
β¦ Synopsis
Leverage existing free open source software to build an identity and access management (IAM) platform that can serve your organization for the long term. With the emergence of open standards and open source software, itβs now easier than ever to build and operate your own IAM stack.
The most common culprit of the largest hacks has been bad personal identification. In terms of bang for your buck, effective access control is the best investment you can make. Financially, itβs more valuable to prevent than to detect a security breach. Thatβs why Identity and Access Management (IAM) is a critical component of an organizationβs security infrastructure. In the past, IAM software has been available only from large enterprise software vendors. Commercial IAM offerings are bundled as βsuitesβ because IAM is not just one component. Itβs a number of components working together, including web, authentication, authorization, cryptographic, and persistence services.
Securing the Perimeter documents a recipe to take advantage of open standards to build an enterprise-class IAM service using free open source software. This recipe can be adapted to meet the needs of both small and large organizations. While not a comprehensive guide for every application, this book provides the key concepts and patterns to help administrators and developers leverage a central security infrastructure.
Cloud IAM service providers would have you believe that managing an IAM is too hard. Anything unfamiliar is hard, but with the right road map, it can be mastered. You may find SaaS identity solutions too rigid or too expensive. Or perhaps you donβt like the idea of a third party holding the credentials of your usersβthe keys to your kingdom. Open source IAM provides an alternative. Take control of your IAM infrastructure if digital services are key to your organizationβs success.
What Youβll Learn
β’ Understand why you should deploy a centralized authentication and policy management infrastructure
β’ Use the SAML or Open ID Standards for web or single sign-on, and OAuth for API Access Management
β’ Synchronize data from existing identity repositories such as Active Directory
β’ Deploy two-factor authentication services
Who This Book Is For
Security architects (CISO, CSO), system engineers/administrators, and software developers
β¦ Table of Contents
Front Matter ....Pages i-xv
Introduction (Michael Schwartz, Maciej Machulak)....Pages 1-16
LDAP (Michael Schwartz, Maciej Machulak)....Pages 17-57
SAML (Michael Schwartz, Maciej Machulak)....Pages 59-103
OAuth (Michael Schwartz, Maciej Machulak)....Pages 105-149
OpenID Connect (Michael Schwartz, Maciej Machulak)....Pages 151-203
Proxy (Michael Schwartz, Maciej Machulak)....Pages 205-229
Strong Authentication (Michael Schwartz, Maciej Machulak)....Pages 231-265
User-Managed Access (Michael Schwartz, Maciej Machulak)....Pages 267-299
Identity Management (Michael Schwartz, Maciej Machulak)....Pages 301-336
Multiparty Federation (Michael Schwartz, Maciej Machulak)....Pages 337-363
Back Matter ....Pages 365-377
β¦ Subjects
Security; Information Security; Access Management; OAuth; Identity Management; LDAP; SAML; OpenID
π SIMILAR VOLUMES
Project infrastructure and software repositories are now widely available at low cost with easy extraction, providing a foundational base to conduct detailed cyber-archeology at a scale not open to researchers before. Emerging Free and Open Source Software Practices provides a collection of empirica
What is the status of the Free and Open Source Software (F/OSS) revolution? Has the creation of software that can be freely used, modified, and redistributed transformed industry and society, as some predicted, or is this transformation still a work in progress? Perspectives on Free and Open Source
What is the status of the Free and Open Source Software (F/OSS) revolution? Has the creation of software that can be freely used, modified, and redistributed transformed industry and society, as some predicted, or is this transformation still a work in progress? Perspectives on Free and Open Source