Home > Security News > Review: Affordable IdentityBridge lets partners plug in
Security News:
EMAIL THIS

Review: Affordable IdentityBridge lets partners plug in

By Peter Giannacopoulos, Contributor
03 Aug 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

IdentityBridge Standard Edition
Trustgenix, www.trustgenix.com
Price: Starting at $5,000

As more enterprises deploy extensive extranets, the need for each partner to control its local user data while sharing appropriate account information is paramount. But implementing federated identity and single sign-on (SSO) deployments requires significant effort, expertise and expense. Trustgenix's affordable and easy-to-implement IdentityBridge Standard Edition addresses this problem, allowing small organizations to plug in to an enterprise extranet.

The product is aimed at smaller organizations participating in a "hub-and-spoke"-style extranet hosted by a larger enterprise (for example, a small auto parts distributor federating with an auto manufacturer's OEM channel extranet). The product allows the smaller company to use its local directory services for user authentication/account management and selectively publish a user's information to the federated resource. The partners can participate in the extranet without forcing the users to remember a different set of credentials, and can still maintain a firm control over user accounts. The Standard Edition isn't intended to run solo and assumes that the hub organization is running Trustgenix IdentityBridge Enterprise Edition or some other Liberty/SAML compliant directory services application. But it relieves the cost and effort that would otherwise be required to implement an enterprise-caliber product at a small organization.

IdentityBridge Standard Edition is a more or less "fire-and-forget" solution. The security manager simply navigates the Web-based console to generate and exchange metadata with the core site, create a URL for the federated application and decide which user properties (name, title, etc.) will be published to the federated site. The manager then creates an SSO URL through which users authenticate to federated resources. After users authenticate locally, they have seamless access to all federated resources. Multiple applications can be set up quickly, so it's pretty easy to keep up with new applications as they are developed. IdentityBridge fully supports SAML 1.x and Liberty 1.x, so the product can implement federation with just about any directory service (AD, Novell eDirectory, etc.).

Installation was relatively straightforward, but needs to be improved, especially since the product is intended for SMB customers. The entire process of setting up the application sites, exchanging metadata and creating an SSO URL isn't terribly intuitive and begs for a setup wizard. Additionally, there are some minor, but annoying, setup bugs that need to be addressed. For example, if the company name used during setup contains a comma, the install fails to generate the cryptographic key store for the site and will prevent successful federation with the extranet.

Even with the relatively minor installation glitches and lack of setup wizards, IdentityBridge Standard Edition is a solid product that delivers what it promises. If you're setting up a large-scale extranet, it's worth considering as an option to tie in smaller partner sites with minimal hassle.

Peter Giannacopoulos wrote this review for the August 2005 issue of Information Security magazine, where this first appeared.

Tags: Enterprise Single Sign-On (SSO)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Enterprise Single Sign-On (SSO)
How to log in to multiple servers with federated single sign-on (SSO)
Security on a budget: How to make the most of authentication tools
Best Identity and Access Management Products
Changing times for identity management
Kerberos configuration as an authentication system for single sign-on
How to use single sign-on for Web access control to prevent malware
Learn about enterprise strategy for server virtualization single sign-on
Enterprise single sign-on: Easing the authentication process
Exploring authentication methods: How to develop secure systems
User provisioning and SSO for PeopleSoft- and Unix-based products
Enterprise Single Sign-On (SSO) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
onboarding and offboarding  (SearchSecurity.com)
single sign-on  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts