当前位置:网站首页>What can LDAP and SSO integration achieve?
What can LDAP and SSO integration achieve?
2022-06-12 12:19:00 【nington01】
For single sign on (SSO) Of SAML Protocol and lightweight directory access for enterprise directories (LDAP) There was no overlap in the agreement , The integration of the two is interesting . The end user only needs to log in once to access whatever they need IT resources , But the reality is that this effect cannot be really realized in the short term .
therefore , Rather than LDAP and Single sign on (SSO) Integrate , In fact, it is more like realizing the identity and access to the unified management platform using multiple protocols , Support administrators to use in a single tool at the same time LDAP and SAML agreement . This article will discuss LDAP Protocol and identity and access management (IAM) The connection of ,IAM How is the industry because SAML The agreement has changed , Finally, this paper will also introduce how to implement the multi protocol identity management platform LDAP and SSO Integration of .
1. LDAP and IAM
In identity and access management (IAM) field ,LDAP It is arguably the most important kind of agreement . Since its creation ,LDAP Has been widely used as a core element of directory services , Typical examples include Microsoft local directory service Active Directory (AD). For a while ,LDAP Almost IAM The pronoun of , Microsoft AD And so on LDAP Protocols connect end users to the enterprise IT resources .
The rise of cloud computing makes IAM The market has undergone earth shaking changes . The most obvious one is Web application , This new application is hosted on the Internet and widely used . The problems that follow are Web Applications cannot be federated by local directory services like other resources . So , Manufacturers have proposed a new solution to meet the growing demand for Web Application access requirements , That's single sign on (SSO) Tools .
2. Get into SAML Time
With single sign on (SSO), Administrators can take advantage of SAML Protocol to bridge local AD Instances and cloud services , And this tool and in IAM Use in LDAP The agreement is irrelevant . On the other hand , Enterprises also need to implement single sign on (SSO) The solution complements Microsoft AD The function of , It is hoped that by combining single sign on (SSO) Tools and LDAP Agreement to perfect IAM Experience , Similar to the early AD. However , These two independent protocols not only increase the workload and cost , Also for administrators IAM The program adds pressure .
For the disconnection between local directory and cloud identity platform , Single sign on has been introduced in the industry (SSO) and LDAP The integration concept of the protocol : Administrator use LDAP Will single sign on (SSO) The scheme is connected to the local AD. But at that time, there was no centralized solution in the market that could fully combine identity management with the two .
3. Integrate LDAP and SAML A unified platform for protocols
In recent years ,IAM The industry is developing rapidly , In the twinkling of an eye, a general was born SAML、LDAP And other protocols integrated into a single directory —— Directory as a service (Directory-as-a-Service,DaaS) Or cloud directory platform . The cloud directory platform will centralize user management 、 fictitious LDAP、 Cloud based RADIUS authentication 、 Multifactor certification (MFA)、 System management, etc. are integrated into one solution , Through integration LDAP and SAML SSO, Provide a truly seamless single sign on experience for administrators and end users .
—————— This paper is written by Shanghai ningdun Information Technology Co., Ltd Nington original , Do not reprint without authorization ———————
边栏推荐
- 关于报文
- 安装canvas遇到的问题和运行项目遇到的报错
- Load/store instruction addressing mode of arm instruction set (1)
- LeetCode_ Binary search_ Medium_ 162. looking for peaks
- Jump instruction of arm instruction set
- Stress - system pressure simulation tool
- JS pre parsing, object, new keyword
- The difference between bind, call and apply, and the encapsulation of bind()
- Pre order, middle order and post order traversal of tree
- 无重复字符的最长字符串(LeetCode 3)
猜你喜欢

Point cloud registration -- GICP principle and its application in PCL

A. Prefix range

Performance comparison test of channel and condition variables of golang in single production and single consumption scenarios

LeetCode 1037. Effective boomerang (vector cross product)

Beyondcompare 4 uses PJ

无重复字符的最长字符串(LeetCode 3)

Chaîne la plus longue sans caractères dupliqués (leetcode 3)

LeetCode 890. Find and replace mode (analog + double hash table)

Dom and BOM in JS

元宇宙是短炒,还是未来趋势?
随机推荐
拿来就能用的网页动画特效,不来看看?
The second day of QML study
Data processing instruction addressing method of arm instruction set
bind、call、apply三者的区别,还有bind()的封装
【Leetcode】79. Word search
Difference between Definition and Declaration
[转]placement new
Congratulations to splashtop for winning the 2022 it Europa "vertical application solution of the year" award
QT添加QObject类(想使用信号和槽)遇到的问题汇总,亲测解决有效error: undefined reference to `vtable for xxxxxx(你的类名)‘
What is modularity? Benefits of modularity
什么是模块化?模块化的好处
System. IO. Fileloadexception exception
JS将DOM导出为图片的方法
关于报文
JS pre parsing, object, new keyword
必杀技--使用FFmpeg命令快速精准剪切视频
Beyondcompare 4 uses PJ
LeetCode 890. Find and replace mode (analog + double hash table)
Traditional DOM rendering?
ACE配置IPv6, VS静态编译ACE库