|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/forgerock-openam/
课程评论:没有评论
课程名称:ForgeRock OpenAM 课程概述:ForgeRock OpenAM 是一款用于身份验证和授权的访问管理工具,是 ForgeRock 堆栈中的一部分。OpenAM 提供多种用户身份验证方式,如身份验证模块、身份验证树、身份验证链、联合(SAML2)、OpenID Connect(OIDC)/OAuth2、多因素身份验证等。本课程将提供端到端的 OpenAM 安装指导,包括多个容器的配置、身份验证模块、链和树的配置、联合(SAML2)配置、OIDC 配置、OAuth2 配置及与 OpenAM 的示例应用程序集成、在 Postman 中配置 REST 接口等。 ForgeRock 主要提供以下产品:1. OpenAM 2. OpenDJ 3. OpenIDM 4. OpenIG。其中,ForgeRock 的各产品在 13.0 版本之前为开源项目,用户可以通过免费的订阅下载源代码并根据需求进行更改;而在 13.0 版本后,产品为商用,需付费订阅以下载源代码进行自定义。产品命名规则也发生改变,取消了 "Open" 前缀,新产品命名如下:1. AM(访问管理) 2. DS(目录服务) 3. IDM(身份管理) 4. IG(身份网关)。 OpenAM 的特点包括:自助注册、找回用户名、找回密码、身份验证模块、身份验证链、身份验证节点(树)、社交登录(如 Google、Facebook、LinkedIn 等)、OAuth2、OIDC、SAML2.0,以及审计日志、调试日志、复制(多个实例)、策略配置和 OpenAM REST API 等。 OpenIDM 是身份管理解决方案,可以整合多种身份数据源,进行基于策略和工作流的管理。其现代化界面使用户无需编写代码即可管理数据,并提供标准 RESTful 接口,方便定制和开发。 OpenDJ 是符合 LDAPv3 的目录服务,旨在提供高效、可用且安全的身份存储。其轻量级和可嵌入的特性可以在企业、云、社交和移动环境中实时共享用户、设备和身份数据,具有高性能和多主复制功能。 OpenIG 是一款高性能的反向代理服务器,能实现会话管理和凭证重放功能,与 OpenAM 协作,整合 web 应用程序而无需修改目标应用程序或其运行的容器,支持身份标准(OAuth 2.0、OpenID Connect、SAML 2.0)等。 本课程将全面涵盖 OpenAM 的主要功能和使用场景,帮助学员深入理解和应用 ForgeRock OpenAM。
ForgeRock OpenAM is an access management tool for authentication and authorization. It's one of the products in the ForgeRock stack. ForgeRock OpenAM provides different types of user authentications such as the Authentication module. Authentication tree, Authentication chains, Federation(SAML2), OpenID Connect(OIDC)/OAuth2, Multifactor Authentication etc.. In this course, we are providing end-to-end OpenAM installation with multiple containers, the configuration of authentication module, chains, and tree, Federation(SAML2) configuration, OIDC configuration, OAuth2 Configuration, sample applications integration with OpenAM, Rest-end points configuration in postman, etc...Forgerock mainly providing the following products.1. OpenAM 2. OpenDJ3. OpenIDM4. OpenIGForgeRock products are open source project till the version of 13.0 and the naming convention of each product start with Open and download the source code with free subscription and do the changes according to the requirement.After the 13.0 version, the products are commercial and need the paid subscription to download the source code to customize the source code. And also the product naming convention changed like removed the Open keyword. But we can download the software/binary file to practice in the lower environment or personally.The new product's name is as follows.1. AM (Access Management)2. DS (Directory Services)3. IDM (Identity Management)4. IG (Identity Gateway)OpenAM - (AM - Access Management)OpenAM originated as OpenSSO, it's created by Sun Microsystems and now owned by Oracle Corporation.OpenAM providing authentication and authorization in multiple ways. Here summarizing and sharing the OpenAM most important and frequently using the features.RealmSelf Service RegistrationForgot UsernameForgot PasswordAuthentication ModulesAuthentication ChainsAuthentication Nodes(Trees)Login with Social - Google, Facebook, Linked-In, etc...OAuth2OIDCSAML2.0OpenAM - IDPOpenAM - SPAgents (Java/Web)Dynamic Client RegistrationAudit LoggingDebug LoggingReplication (Multiple Instances)Policy ConfigurationOpenAM Rest APIOpenIDM - IDM(Identity Management)OpenIDM enables you to consolidate multiple identity sources for policy and workflow-based management. OpenIDM can consume, transform and feed data to external sources so that you maintain control over the identities of users, devices, and other objects.OpenIDM provides a modern UI experience that allows you to manage your data without writing a single line of code. The standard RESTful interfaces also offer ultimate flexibility so that you can customize and develop the product to fit the requirements of your deployment.OpenDJ - DS(Directory Services)OpenDJ is an LDAPv3 compliant directory service, which has been developed for the Java platform, providing a high performance, highly available, and secure store for the identities managed by your organization. Its easy installation process, combined with the power of the Java platform makes OpenDJ the simplest, fastest directory to deploy and manage.An open-source, lightweight, embeddable directory that can easily share real-time customer, device, and user identity data across enterprise, cloud, social, and mobile environments.Massive data scale and high availability providing developers with ultra-lightweight ways to access identity dataHigh Performance - ms response times & tens of thousands of w/r per secMulti-Master replication for high availabilityAs well as the expected LDAP access OpenDJ lets you access directory data as JSON resources over HTTP making it super convenient for web and phone apps.OpenIG - IG(Identity Gateway)The Open Identity Gateway (OpenIG) is a high-performance reverse proxy server with specialized session management and credential replay functionality.OpenIG is an independent policy enforcement point that reduces the proliferation of passwords and ensures consistent, secure access across multiple web apps and APIs. OpenIG can leverage any standards-compliant identity provider to integrate into your current architecture. Single sign-on and sign-off improves the user experience and will vastly improve adoption rates and consumption of services provided.Extend SSO to any ApplicationFederate Enabling ApplicationsImplement Standards-Based Policy EnforcementOpenIG works together with OpenAM to integrate Web applications without the need to modify the target application or the container that it runs in.Support for identity standards (OAuth 2.0, OpenID Connect, SAML 2.0)Application and API gateway conceptPrepackaged SAML 2.0-based federationPassword capture and replayWorks with any identity provider, including OpenAMSingle Sign-On and Single Log-Out100% open source