Thursday, March 22, 2018
Post of the Week: SAML IdP and SP on One BIG-IP
Posted Question on DevCentral: https://devcentral.f5.com/questions/apm-ltm-121-saml-idp-and-sp-possible-in-one-ve-58114
If you got an answer you'd like lit up on the Lightboard, let us know in the comments!
ps
Friday, January 26, 2018
Post of the Week: Two-Factor Auth and SSO with BIG-IP
Posted Question on DevCentral: https://devcentral.f5.com/questions/2fa-authentication-with-sso-on-apm-57581
ps
Tuesday, November 14, 2017
VDI Gateway Federation with BIG-IP
On the BIG-IP we’ve set up three VDI environments. Microsoft RDS/RDP with a broker authentication server, VMware Horizon and Citrix ZenApp. With only a corporate account, a user can authenticate to all of them as needed and access all available desktop content.
In this example, we connect to the BIG-IP APM. This is the default view.
And here we’ve put some advanced security fields like OTP or multifactor authentication for instance.
With a single, multifactor authentication we’re able to gain access to our federated BIG-IP Webtop and select the specific VDI resource we need.
Tuesday, October 10, 2017
Legacy Application SSO with BIG-IP and Okta
Today we’ll take you through BIG-IP APM’s integration with Okta, a cloud-based identity-as-a-service provider.
The primary use case for this scenario is providing the user authentication through Okta and then Okta providing BIG-IP APM a SAML assertion so that BIG-IP can perform legacy SSO using either Kerberos Constrained Delegation (KCD) or Header Authentication. BIG-IP is the Service Provider (SP) in this SAML transaction.
As we log on to a BIG-IP, you’ll see that we have two policies/application examples.
First, we’ll log into Okta and in the portal, we see two applications – the Header Auth and Kerberos Auth.
BIG-IP is able to consume that SAML assertion from Okta and then use SSO capabilities via Header or Kerberos for legacy applications. Watch Cody Green’s excellent demo of this integration.
ps
Tuesday, March 14, 2017
Social Login to Enterprise Apps using BIG-IP & OAuth 2.0
With v13, BIG-IP APM offers a rich set of OAuth capabilities allowing organizations to implement OAuth Client, OAuth Resource Server and OAuth Authorization Server roles to implement social logins.
Let's look at BIG-IP’s capabilities (from the user's perspective) as an OAuth Client, OAuth Resource Server. We’ll navigate to our BIG-IP login screen and immediately you’ll notice it looks slightly different than your typical APM login.
Here, you now have a choice and can authenticate using any one of the 4 external resources. Azure AD Enterprise and AD B2C along with Google and Facebook. Google and Facebook are very popular social login choices - as shown in the initial image above - where organizations are looking to authenticate the users and allow them to authorize the sharing of information that Google and Facebook already have, with the application.
In this case, we have an application behind BIG-IP that is relying on getting such information from an external third party. For this, we’ll select Facebook. When we click logon, BIG-IP will redirect to the Facebook log into screen.
Now we’ll need to log into Facebook using our own personal information. And with that, Facebook has authenticated us and has sent BIG-IP critical info like name, email and other parameters.
BIG-IP has accepted the OAuth token passed to it from Facebook, extracted the info from the OAuth scope and now the application knows my identity and what resources I’m authorized to access.
We can do the same with Google. Select the option, click logon and here we’re redirected to the Google authentication page. Here again, we enter our personal credentials and arrive at the same work top.
Like Facebook, Google sent an authorization code to BIG-IP, BIG-IP validated it, extracted the username from the OAuth scope, passed it to the backend application so the application knows who I am and what I can access.
Let's look at Microsoft. For Microsoft, we can authenticate using a couple editions of Azure AD – Enterprise and B2C. Let’s see how Enterprise works. Like the others, we get redirected to Microsoftonline.com to enter our MS Enterprise credentials.
In this instance, we’re using an account that’s been Federated to Azure AD from another BIG-IP and we’ll authenticate to that BIG-IP. At this point that BIG-IP will issue a SAML assertion to Azure AD to authenticate me to Azure AD. After that, Azure AD will issue an OAuth token to that BIG-IP. BIG-IP will accept it, extract the user information and pass it to the application.
Finally, let’s see how Azure AD B2C works. B2C is something that companies can use to store their non-corporate user base. Folks like partners, suppliers, contractors, etc. B2C allows users to maintain their own accounts and personal information. In addition, they can login using a typical Microsoft account or a Google account. In this case, we’ll simply use a Microsoft account and are directed to the Microsoft authentication page.
We’ll enter our personal info, the servers communicate and we’re dropped into our WebTop of resources.
Social logins can not only help enterprises offer access to certain resources, it also improves the overall customer experience with speed and convenience and allows organizations to capture essential information about their online customers.
ps
Related:
Wednesday, December 14, 2016
Lightboard Lessons: SSO to Legacy Web Applications
In this Lightboard Lesson, I draw out how VMware and F5 helps remove these complexities and enable productive, any-device app access. By enabling secure SSO to Kerberos constrained delegation (KCD) and header-based authentication apps, VMware Workspace ONE and F5 BIG-IP APM help workers securely access all the apps they need—mobile, cloud and legacy—on any device anywhere.
ps
Related:
Tuesday, February 23, 2016
Would You Put Corporate Applications in the Cloud?
This growth is to support our on-demand, always connected lifestyle, where content and information must be accessible/available anytime, anywhere, and on any screen. Mobility is the new normal, and the cloud is the platform to deliver this content. No wonder enterprises are scrambling to add cloud components to their existing infrastructure to provide agility, flexibility, and secure access to support the overall business strategy. Applications that used to take months to launch now take minutes, and organizations can take advantage of innovations quickly. But most IT organizations want the cloud benefits without the risks. They want the economics and speed of the cloud without worrying about the security and integration challenges.
Use of the corporate network itself has become insecure, even with firewalls in place. Gone are the days of “trusted” and “untrusted,” as the internal network is now dangerous. It'll only get worse once all those IoT wearables hit the office. Even connecting to the corporate network via VPN can be risky due to the network challenges. Today, almost anything can pose a potential security risk, and unauthorized access is a top data security concern.
Going against the current trend, some organizations are now placing critical applications in the cloud and facing the challenge of providing secure user access. This authentication is typically handled by the application itself, so user credentials are often stored and managed in the cloud by the provider. Organizations, however, need to keep close control over user credentials, and for global organizations, the number of identity systems can be in the thousands, scattered across geographies, markets, brands, or acquisitions. It becomes a significant challenge for IT to properly authenticate the person (whether located inside or outside the corporate network) to a highly available identity provider (such as Active Directory) and then direct them to the proper resources. The goal is to allow access to corporate data from anywhere with the right device and credentials. Speed and productivity are key.
Authentication, authorization, and encryption help provide the fine-grained access, regardless of the user’s location and network. Employee access is treated the same whether the user is at a corporate office, at home, or connected to an open, unsecured Wi-Fi network at a bookstore. This eliminates the traditional VPN connection to the corporate network and also encrypts all connections to corporate information, even from the internal network.
In this scenario, an organization can deploy the BIG-IP platform, especially virtual editions, in both the primary and cloud data centers. BIG-IP intelligently manages all traffic across the servers. One pair of BIG-IP devices sits in front of the servers in the core network; another pair sits in front of the directory servers in the perimeter network. By managing traffic to and from both the primary and directory servers, the F5 devices ensure the availability and security of cloud resources—for both internal and external (federated) employees. In addition, directory services can stay put as the BIG-IP will simply query those to determine appropriate access.
While there are some skeptics, organizations like GE and Google are already transitioning their corporate applications to cloud deployments and more are following. As Jamie Miller, President & CEO at GE Transportation, says, 'Start Small, Start Now.'
ps
Related:
- CIOs Face Cloud Computing Challenges, Pitfalls
- Google Moves Its Corporate Applications to the Internet
- GE's Transformation... Start Small, Start Now
- Ask the Expert Why Identity and Access Management?
| Connect with Peter: | Connect with F5: |
| |
Tuesday, April 21, 2015
RSA2015 Partner Spotlight - RSA Risk Based Authentication
RSA Technology Consultant Josh Waterloo talks about the evolution of two-factor authentication and how risk based auth is starting to take hold. He also shows us a demo of the integration between RSA SecurID and BIG-IP APM to provide risk based, strong authentication for corporate access to sensitive information.
ps
Related
| Connect with Peter: | Connect with F5: |
| |
Friday, November 15, 2013
AWS re:Invent 2013 – Cloud Federation Reference Architecture (feat. Pearce)
Nathan Pearce and I yuck it up on camera again, this time commiserating about Cloud Federation and the challenges associated with identity and access management in the cloud.
ps
Related:
- AWS re:Invent 2013 – Find F5
- AWS re:Invent 2013 - Cloud Bursting Reference Architecture (feat. Pearce)
- AWS re:Invent 2013 – Cloud Migration Reference Architecture (feat. Pearce)
- AWS re:Invent 2013 – F5 AWS Solutions (feat. Pearce & Huang)
- F5 Adds Pay-Per-Use Billing and New Solutions for Amazon Web Services
- F5 and Amazon Web Services | Partnership Overview [PDF]
- F5 and Amazon Web Services (Video)
- Deploying a BIG-IP Virtual Edition HA Pair into AWS (Video)
- Now Playing on Amazon AWS - BIG-IP
- F5 BIG-IP Virtual Edition for AWS (BYOL)
- F5 BIG-IQ Virtual Edition for AWS (BYOL)
- F5 Synthesis: The Reference Architectures
| Connect with Peter: | Connect with F5: |
| |
Thursday, January 31, 2013
Inside Look - SAML Federation with BIG-IP APM
I get an Inside Look at BIG-IP's new #SAML #Federation functionality in v11.3 with Sr Security Solution Architect, Gary Zaleski. We cover BIG-IP as a SAML Service Provider (SP) and as a SAML Identity Provider (IdP). Watch how users can easily connect to Salesforce, SharePoint, Office365 and Google. Solving Substantiation with SAML.
ps
Related:
- Solving Substantiation with SAML – White Paper (pdf)
- In 5 Minutes or Less: BIG-IP Advanced Firewall Manager
- Inside Look - BIG-IP Advanced Firewall Manager
- BIG-IP Access Policy Manager Overview (pdf)
- F5 Enhances Application Delivery Security with the World’s Fastest Firewall
- F5's YouTube Channel
- In 5 Minutes or Less Series (23 videos – over 2 hours of In 5 Fun)
- Inside Look Series
- Life@F5
| Connect with Peter: | Connect with F5: |
| |



