IBM FileNet Security P8 Authentication and Single Sign-On
IBM FileNet Security P8 Authentication and Single Sign-On
Agenda
Single Sign-On Support (SSO)
Authentication for
– Content Engine
– Process Engine
– Application Engine
EJB Container
EJB Layer
EJB Container
EJB Layer
EJB Container
EJB Layer
Limitations of JAAS
Requires a trust mechanism between client and server.
– Mechanics of this trust mechanism are non-standard or are
proprietary
No interoperability between J2EE application server
vendors
Support for stand-alone Java client applications is lacking
Perimeter Authentication
Real authentication occurs at a “network perimeter”
Authentication credentials are passed to the J2EE container
Servlet container intercepts credentials and verifies
Content Engine
(20) Response Proxy Server AE/Web Server
Server
(9) Request
with session (16) EJB
(1) Request Web Container EJB Container
Proxy Server call
JSP/servlet CE EJB(s)
(19) Response
(18) EJB
(2) Prompt for credentials return
(10) Login (15) Subject Content Engine Core
(8) Request with session
Client with session
(11) Authenticate
JAAS
(3) Credentials
Netegrity SiteMinder Authn Providers
(7) Session cookie Web Agent (14) Subject
SiteMinder ASA
Identity Asserter
(12) Validate
(6) SMSession session
token (13) Credentials
Active
Directory
(KDC)
Tivoli
Access Manager
Policy Server
WS-Security Profiles
Supported Out-Of-The-Box in P8 4.0
– Username Profile
– Kerberos Profile
Support for other WS-Security profile available through
custom development
(1) Logon to
Windows Domain
EJB Container
Content Engine EJB(s)
WorkPlace Client
Reverse Proxy
Server & SSO Agent
WebDAV Client
Application Engine
Application
Integration Client BPM Process
Orchestration Client
Knowledge Checkpoint
All IBM ECM course materials, whether delivered as printed or electronic files, are protected by copyright. No part of this publication
may be reproduced in any form by any means without prior written authorization of IBM. This publication is provided for educational
purposes only. Any product specifications are subject to change without notice. ©Copyright 2007 IBM. All Rights Reserved.