He was not sure what were the possible integrations provided by CA SSO Access Gateway with his backend applications.
I showed him the diagram below. Self-explanatory.
- SAML (Federation)
- REST/JSON
- OpenID Connect
- HTTP Header (Web Agent)
.
The OWASP Top 10 focuses on identifying the most serious risks for a broad array of organizations. For each of these risks, we provide generic information about likelihood and technical impact using the following simple ratings scheme, which is based on the OWASP Risk Rating Methodology.
In this new release we’ve taken a significant step forward in security – something that all too often gets overlooked in the rush for SSO. The latest release of CA SiteMinder addresses the challenge of session stealing and replay with a new patent-pending technology that leverages the proven capabilities from our CA Advanced Authentication product line to map a CA SiteMinder session to a particular device. We can then detect if a session is stolen and replayed through a different device, at which time the session is invalidated and security is preserved.
OpenAM adaptive authentication capabilities now include the Device Print authentication module (OPENAM-1375). The Device Print module uses characteristics of a system, including installed fonts, screen resolution, timezone, and also geolocation to uniquely identify the system. The Device Print module includes all of the functionality associated with the HOTP authentication module.
XenMobile delivers enterprise grade MDM with role-based management, configuration, security and support for corporate and employee-owned devices. Users enroll their devices, enabling IT to provision policies and apps to those devices automatically, blacklist or whitelist apps, detect and protect against jailbroken devices, troubleshoot device and app issues, and wipe or selectively wipe a device that is lost, stolen or out of compliance. Users can use any device they choose, while IT can ensure compliance of corporate assets and secure corporate content on the device.
The XenMobile App Controller is a SAML-compliant identity provider that connects to the enterprise directory, reads the authorization policies configured and provides the appropriate secure SAML tokens for user sign-on to federation-enabled applications. To interoperate with older applications that do not support SAML, XenMobile can act as a password manager, storing user credentials and providing them securely so users don’t have to remember their app credentials. Built into XenMobile is a long list of “connectors” for applications that have all the required interaction logic leveraging APIs that the applications expose; for example, APIs to create user accounts within those applications based on authorization policies. With App Controller, authorized applications are exposed to users through Worx Home, forming an enterprise app store and providing users a single place to authenticate and get access to all their enterprise applications.
- Least privilege access
– to help ensure that users have the minimum access to do their job
- Decouple security from administration
– don’t allow non-security personnel to change security settings
- Fine-grained control over admin access
– helps contain the damage if a system is breached
- Shared account management
– to eliminate shared passwords and improve accountability
- User activity auditing
– track and audit all access to help identify potential attack attempts
- Information protection
– control not only access to information, but its use