Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

711 total results found

Step 6.2. Create Password policy

PAM Implementation guide Step 6. Passwords rotation

How to define a new password policy for the previous user type created. Step-by-step 1. First of all, you must access the Password policies page, the path to access is the following: Main Menu > Administration > Configure Soffid > Security settings > Pass...

Soffid
3
PAM
PAM Implementation

Step 6.3. Assign password policy

PAM Implementation guide Step 6. Passwords rotation

You must assign a proper password policy to the critical accounts to keep them safe. Step-by-step 1. To access the accounts of a specific host or database (SQL Server or Oracle), you must click the "Accounts" button. The button is located close to the name...

PAM Implementation
Soffid
3
PAM

Step 6.4. Enable Task

PAM Implementation guide Step 6. Passwords rotation

To rotate the password it will be necessary to enable the task Expire untrusted passwords. The Expire untrusted passwords task is in charge to create a new password for the accounts: Critical accounts with the password type "Automatically generated", in ...

Soffid
3
PAM
PAM Implementation

Step 8.1. PAM Rules

PAM Implementation guide Step 8. Behavior analysis

Step-by-step 1. To create a new PAM Rule, you must access the PAM Rules page in the following path: Main Menu > Administration > Configure Soffid > Security settings > PAM rules 2. To add a new PAM rule, you must click the add button (+) and Soffid will di...

Soffid
3
PAM
PAM Implementation

Step 8.2. PAM Policies

PAM Implementation guide Step 8. Behavior analysis

Step-by-step 1. To create a new PAM Policy, you must access the PAM Rules page in the following path: Main Menu > Administration > Configure Soffid > Security settings > PAM policies 2. To create a new PAM policy, you must click the add button (+) and Soff...

Soffid
3
PAM
PAM Implementation

Step 8.3. Assign PAM policy

PAM Implementation guide Step 8. Behavior analysis

Assign PAM policy 1. To assign the PAM policy to a Password Vault folder, you must access the Password vault page in the following path: Main Menu > Administration > Resources > Password vault 2. Then you must select the folder by clicking on the record. S...

Soffid
3
PAM
PAM Implementation

Step 7.1. Define an approval workflow

PAM Implementation guide Step 7. Just in time privileges

Step-by-step 1. To define and configure an approval workflow, you can use the Soffid BPM editor. You must access the BPM editor page in the following path: Main Menu > Administration > Configure Soffid > Workflow settings > BPM editor 2. To add a new workfl...

Soffid
3
PAM
PAM Implementation

Step 7.2. Define XACML policy set to use a workflow

PAM Implementation guide Step 7. Just in time privileges

Step-by-step 1. To define policies, you must access the XACML Policy Management page in the following path: Main Menu > Administration > Configure Soffid > Security settings > XACML Policy Management 2. Once you have accessed the XACML Policy Management pag...

Soffid
3
PAM
PAM Implementation

Step 7.3. Configure XACML PEP

PAM Implementation guide Step 7. Just in time privileges

Step-by-step 1. To configure the XACML PEP  You must access the "XACML PEP configuration" page in the following path: Main Menu > Administration > Configure Soffid > Security settings > XACML PEP configuration 2. At the "XACML PEP configuration page you mus...

Soffid
3
PAM
PAM Implementation

Step 6. Passwords rotation

PAM Implementation guide Step 6. Passwords rotation

Introduction The password rotation reduces the vulnerability to password-based attacks. Soffid allows you to limit the password lifespan and force you to change it. Soffid defines a procedure for Password rotation to keep safe the critical accounts. It allow...

Soffid
3
PAM
PAM Implementation

Step 4.3. Reconcile (Optional)

PAM Implementation guide Step 4. Register additional resources (...

To request the accounts you must launch the reconciliation process. The main purpose of reconciling process is to provide a mechanism to ensure that all users are aligned on the specific roles and responsibilities. Step-by-step 1. First of all, you need to...

Soffid
3
PAM
PAM Implementation
Addon

How to deploy the identity & service provider

Federation How to deploy the identity & service pr...

Step-by-step 1. To deploy the identity provider is advisable to install a dedicated sync server. It can be configured as a proxy sync server as it does not need direct access to Soffid database. Instead, it will connect to main sync servers to get users and f...

Soffid
3
Addon
Federation

SAML architecture

Federation SAML

Introduction SAML is the most complete, secure, and mature solution to get identity federation. SAML defines three main kinds of servers: Federation metadata server. Publishes information about the federation members, its protocols, and capabilities. Any f...

Soffid
3
Addon
Federation
SAML
Architecture

OpenID-Connect architecture

Federation OpenID-Connect

Introduction OpenID is based on the well known protocol. It is easier to implement and deploy, as it does not require digital signature or  encryption. The drawback is that it is significantly less secure. For example, the single logout protocol is not finish...

Soffid
3
Addon
Federation
OpenId Connect
Architecture

SAML (Security Assertion Markup Language)

Federation SAML

Introduction Security Assertion Markup Language is an open standard for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider. It is an identity federation protocol, born in 2...

Soffid
3
Addon
Federation
SAML

OpenID-Connect

Federation OpenID-Connect

Introduction OpenID is an open standard and decentralized authentication protocol.  It allows users to be authenticated by cooperating sites (known as relying parties, or RP) using a third-party service, eliminating the need for webmasters to provide their ...

Soffid
3
Addon
Federation
OpenId Connect

Attribute definition

Federation Web SSO

Description The attribute definition page displays all the auto-generated user attributes. Those attributes will be the attributes to deliver from the identity providers to the service providers depending on the defined rules. Soffid has a default implementa...

Soffid
3
Addon
Federation

Attribute sharing policies

Federation Web SSO

Description After defining the attributes to publish, it’s required to write a policy that defines which attributes will be allowed to share with each service provider. Soffid allows you to define security rules that apply to any attribute that should be del...

Soffid
3
Addon
Federation

Identity & Service providers

Federation Web SSO

Description Soffid Identity Federation addon helps administrators to manage an Identity Federation. With Soffid you can manage the whole federation security configuration, increasing the security while reducing the federation management costs. Soffid can also...

Soffid
3
Addon
Federation

Entity Group

Federation Federation members

Description An entity group is just like a folder that allows you to manage different kinds of federation members. One of the most common ways to group federation members is by trust level. When you create an entity group, the Identity Providers and the Serv...

Soffid
3
Addon
Federation