Skip to content

Government Open Code Collaborative

Sections
Personal tools
You are here: Home » Members » timothybennett's Home » weblog_storage » Safehaus Identity Management

Safehaus Identity Management

Like my organization, I imagine some of you have been looking for a robust and enterprise Identity Management solution without the invasiveness, complexity, and expense of most of the more popular solutions. For our organization, we were looking for a solution that could provide authentication and authorization services based on standards like Kerberos, LDAP, and OATH. We needed a solution that could aggregate user repositories across different domains like Microsoft AD, databases, LDAP directories -- providing us with a single view of all these disparate stores. Furthermore, we didn't want to spend alot of $$$ or be burdened with a heavy licensing fee, and have the technology wrap its tentacles around every aspect of our back-end. While there's no silver bullet in most complex environments, we think we've found a solution that comes a close as we've found. I thought maybe I'd take a minute or two to post what we've discovered for some of you that might be looking for a similar identity management solution. It's called Safehaus and the techology is based on the standards listed above, and is the effort of open source initiatives at the Apache Software Foundation and the Codehaus. Feel free to contact Alex Karasulu or myself for more information.

About Safehaus


Safehaus.org is the first ecosystem of IT, ISV and open source developers providing high quality open-source software components related to directory and security infrastructure. By commoditizing directory and security related software, safehaus.org allows innovation to move up to the next layer of higher functionality, which further fuels, the innovation of enterprise security software.

Safehaus Triplesec Server - http://triplesec.safehaus.org


The Triplesec Server is a non-invasive strong authentication and policy server designed to meet enterprise identity management needs. Triplesec is a composite server that can serve requests for multiple protocols to achive this end result: LDAP, Kerberos, NTP and Changepw. It is based on the Apache Directory Server from the Apache Software Foundation. Coupled with the HausKeys application (http://hauskeys.safehaus.org) it enables users of the system to authenticate into their (*NIX, Windows, MacOS) workstations or to intra and internet applications using One Time Passwords generated from mobile devices. HausKeys is a J2ME application that generates HOTP values specified by OATH (http://openauthentication.org) the Organization for Open Authentication as an RFC Draft here: http://www.ietf.org/internet-drafts/draft-mraihi-oath-hmac-otp-04.txt. This is all done non-invasively using the LDAP and Kerberos protocols. Any operating system or application independent of the programing language or platform can be enabled with strong authentication. No hardware key fobs are needed reducing the chances of loosing yet another device to carry. One's cell phone is all that is needed for multiple accounts. Both Single Sign On and authorization policies can be managed by Triplesec to identify and control access to applications, systems and resources.


Features:

  • Open-source
  • 100% Java
  • Non-Invasive interoperability with most operating systems, languages, and platforms
  • Unlike proprietary auth protocols Kerberos is proven, secure, and open
  • 2-factor auth with Kerberos enables immediate interop with existing Kerberos infrastructure (2-factor auth is free)
  • Proprietary protocols do not interop without invasive changes: i.e. RSAs SecureID
  • Passwords are not transmitted on the wire
  • SSO is supported out of the box
  • Trusts also supported between servers and realms
  • Pluggable SAM types leverage existing investments in FOB hardware
  • Run embedded in your application
  • No time synchronization required
  • Resynchronization is automatic
  • Tunable: security parameters can be altered in response to attempted attacks
  • Forgiving: it operates even when servers are disconnected from a replicated cluster

Safehaus Penrose Server - http://penrose.safehaus.org


Penrose is a virtual directory server based on Apache Directory project (http://directory.apache.org). A Virtual Directory does not store any information itself, unlike other LDAP implementations. Requests received from LDAP client applications are processed by Penrose and passed on to the data source hosting the desired data. Penrose currently supports Active Directory, LDAP and JDBC back-ends. Penrose is a phenomenal tool for Directory integration of disparate resources. In conjunction with Triplesec it can centralize access to security information across databasess making it appear as a single corporate LDAP directory.


Features:

  • Open-source
  • 100% Java
  • Run stand-alone as a backend for ApacheDS and OpenLDAP
  • Run embedded in your application
  • Object transformation via BeanShell scripting
  • High performance join and cache engine
  • Data encryption using Bouncy Castle
  • Supports resource connectors for JDBC/SQL, JNDI/LDAP, Active Directory
  • Remote management via JMX
  • Extensible via plug-ins
#permalink   Aug 10, 2005 2:29 pm  

Radiant technology

Posted by Anonymous User at 2007-04-25 12:58 AM

RadiantOne Functionality - Authenticate using Multiple Password Repositories

Usage Scenario: Application uses LDAP for authentication, but there is more than one directory or database with password data.

Summary: If your application authenticates to a directory service, such as a portal or a web access management package, it often expects that there is a single directory with all passwords. It is not equipped to handle multiple directories, or data sources that do not have LDAP interfaces, such as a database.

Triplesec

Posted by Anonymous User at 2007-04-29 01:08 PM

The Triplesec Server is a non-invasive strong authentication and policy server designed to meet enterprise identity management needs. Triplesec is a composite server that can serve requests for multiple protocols to achive this end result: LDAP, Kerberos, NTP and Changepw. It is based on the Apache Directory Server from the Apache Software Foundation. Cheers, Ernest Musial You are welcome to visit our SEO Directory to submit your site. You might also visit Free SEO Directory if you want to submit your sites for free. You can also visit free Polish directory Darmowy Katalog Stron

Triplesec

Posted by Anonymous User at 2007-05-25 06:11 AM

Java open-sources are always on top of the game. Great post. Regards Free web directory SEO services

Great info

Posted by Anonymous User at 2007-06-21 11:20 AM

Yes I agree! - Quotes and - Cell Phones
and here are roommate information at Rooms and Roommates and Bible Verses

looks good

Posted by Anonymous User at 2007-06-21 05:47 PM

good info casino online uk

re

Posted by Anonymous User at 2007-06-26 09:06 AM

Thanks for very interesting Article. Keep up the good work. Greetings Pozycjonowanie

Martial Art Safehaus Identity Management Microsoft AD, databases, LDAP

Posted by Anonymous User at 2007-06-28 03:16 PM

Safehaus Identity Management Microsoft AD, databases, LDAP with martial arts sports: Martial Arts Connection Dojo Earth and Martial Arts Videos

great job man

Posted by Anonymous User at 2007-07-08 11:26 AM

this for thise information for free visit jave category in my Business Directory or the Directory of Directories

Open Source Software Industry

Posted by Anonymous User at 2007-07-08 04:04 PM

Link Building Services and Directory Submission Services are one of the main internet advertising strategists in the market. SEO company gives you the lowdown on how to get the best strategy that suits all your needs.

Open Source

Posted by Anonymous User at 2007-07-08 04:08 PM

Open source is well known as disruptive software industry force in the guise of operating systems (Linux, Solaris), servers (Apache, TomCat, JBoss)and other categories, ranging from business intelligence (JasperSoft, Pentaho) to system management (Qlusters, GroundWork) Bidding Web Directory For SEO Resources visit SEO Directory

Resources

Posted by Anonymous User at 2007-07-08 04:16 PM

Thank you

Posted by Anonymous User at 2007-07-09 04:48 AM

I have an internet business blog for stuff related to internet marketing, online business, SEO, copywriting, etc.

great post

Posted by Anonymous User at 2007-07-10 01:55 PM

Very informative

Cams

Yes, nice way

Posted by Anonymous User at 2007-07-18 06:15 PM

I agree, it's nice. The post too but the site address it's even better. So I couldn't miss the oportunity to give you another resource: Free Directory and Link Directory are other easy to use sources of information.

Good Post

Posted by Anonymous User at 2007-07-22 01:10 PM

Very Informative

Kendall

Quality Deep Link Directory

.

Posted by Anonymous User at 2007-07-31 10:41 PM

nice

Posted by Anonymous User at 2007-08-04 05:21 AM

thanks for info.

Felsefe Edebiyat Forum

Great article.

Posted by Anonymous User at 2007-08-11 01:36 AM

Great article about enterprise Identity Management solution. Thank you. Leading Web Directory

Nice ideas

Posted by Anonymous User at 2007-08-11 01:40 AM

Thank you for sharing! Maldives

Thanks

Posted by Anonymous User at 2007-08-25 03:00 PM

Really good article!

-------------------------------------- Free Business Card Templates