FORUMS


Discussion about Intalio|BPP Community Edition.


Back to Documentation (0 viewing) 
Go to bottom Favoured: 0
TOPIC: Re:LDAP connector for single sign-on
Jun 27, 2007 3:56 pm
kclukey (User)
1 posts
Fresh Boarder

Karma: 0  
We would like to replace the intalio security module with LDAP. Rick mentioned a LDAP connector was available.

We are using OpenACS & AOLServer to handle logins, and would like to seamlessly integrate with Intalio. If there is a better method to do single sign-on, please let me know.

Thx.
 
  The administrator has disabled public write access.
Jun 27, 2007 4:27 pm
Antoine (Admin)
2754 posts
Admin

Karma: 56  
Hi,

paying customers should directly ask questions through the support interface, so they are answered quickly. Could you enter a new ticket there ?

Sorry for the inconvenience.
 
 
Intalio, The Enterprise Cloud Company
www.intalio.com
  The administrator has disabled public write access.
Jun 27, 2007 6:12 pm
arnaud (Admin)
329 posts
Admin

Karma: 13  
Hi,

The security module of Intalio|BPMS relies on RBAC and it entirely open source.
You can find it in the Tempo project.
We do provide an LDAP implementation that comes along an LDAP Visual Connector but it is offered as an option of the Entreprise Edition for our Gold and Platinum customers.

LDAP is definitely the best way to go to handle single sign on through the RBAC interface.

I hope this helps,

Arnaud
 
  The administrator has disabled public write access.
May 15, 2008 7:37 pm
2 posts
Fresh Boarder

Karma: 0  
I would also like to see a single sign-on implementation, but was thinking more in the lines of:

1. Implementing Kerberos for authentication. Most efficiently by delivering a PAM module for Tempo.
2. Implementing SPNEGO for dealing with negotiation. Both Firefox and Internet Explorer support this mechanism.
3. Using the existing LDAP implementation purely for the authorisation partition of Tempo, where administration of authorisation is delegated to the LDAP server. The Tempo service/daemon should of course be configured to run using an account that has read access on the LDAP server. Credentials in configuration files is bad practice imho.
 
  The administrator has disabled public write access.
Go to top Post Reply
get the latest posts directly to your desktop

Top Posters

Last 30 days

  • estebanf (39)
  • madhav.vodnala (21)
  • kevin.fernandez (14)
  • scott.hebden (10)
  • jaouhar.ahmed (10)
  • jigonzalez@vertice.es (8)
  • federico.baroni (8)
  • marcelr (8)
  • ianoboa (7)
  • spyridoula.markopoulou (7)

All time

  • Antoine (2754)
  • Shivanand (1194)
  • cshekhar (933)
  • psq (797)
  • metabyte (415)
  • jag (393)
  • dfrench (367)
  • arnaud (329)
  • jalateras (325)
  • talita.pezzi (254)

Show last 4 hrs - 12 hrs - 24 hrs

Copyright © Intalio, 1999-2010.