Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > Best practices for deploying enterprise single sign-on (SSO)
Ask The Security Expert: Questions & Answers
EMAIL THIS

Best practices for deploying enterprise single sign-on (SSO)

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 23 September 2007
I am trying to deploy single sign-on within our bank. What are some common obstacles to such deployments? What are some best practices for deploying SSO in an enterprise, on the Web, or in a federated or transactional system?


BROWSE BY TAG
Identity Management and Access Control,   Enterprise Single Sign-On (SSO),   Enterprise Identity and Access Management,   User Authentication Services,   Expert Archive: Identity Management and Access Control,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Identity Management and Access Control
Learn about enterprise strategy for server virtualization single sign-on
Employee information security awareness training for new IAM systems
Can you combine RFID tag technology with GPS to track stolen goods?
Is there a free enterprise-caliber password-management tool?
Cryptosystem attacks that do not involve obtaining the decryption key
Can any firm or organization get a digital signature certificate?
Should the CTO have domain administrator access?
Does password sharing in international branches violate SOX?
What are best practices for secure password distribution after a data breach?
Is it possible to encrypt CDs and DVDs as well as SD cards?

Enterprise Single Sign-On (SSO)
Changing times for identity management
Kerberos configuration as an authentication system for single sign-on
How to use single sign-on for Web access control to prevent malware
Learn about enterprise strategy for server virtualization single sign-on
Enterprise single sign-on: Easing the authentication process
Exploring authentication methods: How to develop secure systems
User provisioning and SSO for PeopleSoft- and Unix-based products
Sun launches open source OpenSSO for identity management
Pre-requisites for implementing enterprise single sign-on (SSO)
Startup Symplified delivers SSO in the cloud
Enterprise Single Sign-On (SSO) Research

Expert Archive: Identity Management and Access Control
Enterprise password management policy: Finding the balance
How to conduct a periodic user access review for account privileges
Options for a mechanical door security system on a server room door
Comparing access control mechanisms and identity management techniques
User provisioning and SSO for PeopleSoft- and Unix-based products
Could someone place a rootkit on an internal network through a router?
Should a new user have to confirm an email address to gain access?
Can home PCs provide a way for viruses and spyware to enter a corporate LAN?
What should an enterprise look for in a password token and a vendor?
Using batch files for temporary user access to the local admin group

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
single sign-on  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


The most important part of single sign-on (SSO) deployments is planning. There are a number of options available, depending on the size of your company and the scope of your implementation. Banks should also consider compliance with regulations, such as SOX and the FFIEC.

Since your SSO deployment will probably span multiple and diverse systems and platforms, you should first determine which systems to enroll. The choice should be based on the systems your employees use most, like email or the corporate Intranet--if it requires a logon. Second, decide the type of product that best fits your organization's IT architecture and infrastructure.

The biggest obstacle is planning which systems to include in the installation and how to simultaneously synch them up with the SSO technology. SSO is rarely a simple deployment that can be done quickly. It should be carefully planned and implemented in stages with different groups of enterprise users.

It's also important to ensure that the SSO system meshes with your organization's existing IT infrastructure. SSO can be implemented in hardware or software; in either case, a gateway authenticates to the member applications. In other words, the user authenticates to the SSO gateway, which turns around and then authenticates on behalf of the user, employing the stored credentials for each member application. The SSO system is the master store for the applications' log-on credentials.

Software SSO systems consist of modules, which usually sit on a dedicated server. The modules require quite a bit of configuration and tuning, and there may be additional development effort when connecting them to home-grown applications. Products in this space include IBM's Tivoli Access Manager, Citrix Password Manager and Entrust GetAccess. Because of the requirement for dedicated hardware and the configuration involved, these systems are geared toward larger enterprises.

On the hardware side, a product that requires fewer configurations is Imprivata's OneSign Single Sign On. The appliance has a Web-based front end for easy enrollment of member applications. Imprivata is geared toward mid-market companies and organizations that may not have the staff or expertise for extensive software configurations. And, since it's self-contained in its own server, a smaller company doesn't have to make the investment in a dedicated one, as might be required for a software SSO module.

For a Web-based SSO product, the Microsoft Passport Network allows a user to register once for multiple Web site access. In this case, Passport acts as an online SSO gateway.

Since SSO can be a single point of authentication failure, all components of the SSO system need to be secured within the enterprise. If a malicious user gets hold of the SSO log-on credentials, all applications registered with the system will be at risk.

Since SSO provides a centralized point of access, it can be used to more closely monitor user access; regulations like the Sarbanes-Oxley Act require such careful observation. In addition, because SSO installations are complex, they call for extensive documentation about authentication. That's something else that your auditors and regulators may want to look at.

For more information:

  • Security expert Joel Dubin discusses the impact that enterprise single sign-on (SSO) can have on a security program.
  • Learn how to properly test an enterprise single sign-on (SSO) login.




  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts