Siteminder 替代方案
我们将设置一个新环境,建议使用 SiteMinder 来帮助内部用户和联合用户进行 Web 应用程序身份验证/授权。然而,我们在 Siteminder 方面没有获得良好的体验,因此希望避免使用它 - 您会建议什么替代方案?
编辑:我们目前计划成为 RP/SP,但有一天也可能成为 IdP。 OpenID 是我们计划的第一个 IdP,但将来会扩展到更多 IdP
We are going to be setting up a new environment and SiteMinder has been suggested to help with web app authentication/authorization for both internal users and federated users. However, we have not had good experiences with Siteminder and would like to avoid it - what alternatives would you suggest?
Edit: We are currently planning to be a RP/SP, but may one day be an IdP as well. OpenID is our first planned IdP, but will expand to additional ones in the future
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
如果内部用户位于 Active Directory 中,您可以使用 ADFS (v2)。您不需要 ADFS 的额外许可证,因为它是操作系统组件。对于外部用户,您可以使用支持 OpenID、LiveID、Yahoo!、Google(以及任何 WS-Federation IdP)的 ACS (*)。
从高层次来看,它看起来像这样:
您将使用 WIF 来“声明启用”您的应用程序。
(*) 截至 2015 年 2 月:MSFT 可能会停止或取消对 ACS 的投资。但它仍然可用。
If the internal users are in Active Directory, you could use ADFS (v2). You won't need additional licenses for ADFS as it is an OS component. For your external users, you can use ACS which supports OpenID, LiveID, Yahoo!, Google (and any WS-Federation IdP) (*).
At a high level it would look like this:
You would use WIF to "claims enable" your app.
(*) As of Feb 2015: ACS might be discontinued or de-invested by MSFT. It is still available though.
ADFS(Windows Server 2012 R2 及更高版本)可与任何 SAML 或 OpenID Connect 身份提供商配合使用,并且非常易于设置。 ADFS 服务器必须是域成员,但不必使用 Active Directory 来验证用户身份。
您可以将您的应用程序与 ADFS(作为依赖方)联合,然后将 ADFS 与外部身份提供商(作为声明提供商)联合。
ADFS (Windows Server 2012 R2 and newer) will work with any SAML or OpenID Connect Identity Provider, and is very easy to setup. The ADFS server has to be a Domain member but does not have to use Active Directory to authenticate users.
You can Federate your app(s) with ADFS (as a Relying Party), then Federate ADFS with external Identity Providers (as Claims Providers).