Read up on the latest ideas and technologies from companies that sell hardware, software and services. Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
Email Archiving 101—Customer Case Study
How to Beef Up Your Sales Pipeline
Web Security SaaS: The Next Generation of Web Security
Solve Exchange Mailbox Storage Issues Once and for All
Delivering the Power of Choice with Microsoft Dynamics CRM
Email Archiving Technical Overview
Strategies for Eliminating .PST Files
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Just when I thought we had solved one set of IT security problems by getting the human resources department to properly train new hires, another has cropped up with our IT team and a new single sign-on system it has deployed. The system was designed without input from the IT security team and at least one other department that will be affected. Now we're dealing with the issues after the fact.
The single sign-on project addresses a significant problem. There are several ways for employees to log into different parts of our IT infrastructure, and each requires entering a separate set of credentials.
The single sign-on system will make life easier for users, giving them access to a broad set of applications and services with just one user ID and password.
The IT group has been talking about this for some time, but several obstacles have kept the project sidelined until now. The biggest was the fact that we bought Novell Inc.'s eDirectory directory services and iChain identity management software to handle the authentication of our PeopleSoft system.
But we also deployed Windows 2000, which uses Active Directory for authentication, and our Exchange server uses yet another directory structure.
Unfortunately, these infrastructures were designed separately, with no common vision, so there's a lot of duplication. To make matters worse, none of these directories were mirrored in anticipation of a catastrophe. Sure, we backed up the data, but we didn't have another system on standby to take over the authentication process in the event of a hardware failure.
This week, the IT group and I finally began migrating users to a single authentication system based on eDirectory that's fully mirrored, clustered and load-balanced.
We mirror the data to another data center, so in the event of a fire, malicious damage or other event, the alternate data center will automatically begin accepting authentication requests.
The no-name log-in
This new system makes logging in very convenient, except for one problem. Instead of logging in with our traditional usernames (we used a naming convention that closely matches each employee's actual name), we're using employee ID numbers.
Personally, I didn't even recall that I had an employee ID, much less remember the number itself. Until now, our IDs had been used only by the HR and finance departments for personnel tracking, so I was surprised when I received an e-mail stating that I must start using mine. Like other employees, I was given a week's advance notice and informed that I would also have to change my password.
The decision to use our employee ID numbers in this way has implications for the IT security team. It will end up creating more work for my group and some other groups, such as the IT help desk. Here's why: In our case, most of the audit and security software we use lets us view users by name. Because our log-in names are based on the users' real names, we can quickly match the person to the event when there's a problem.
With the new system, all we see is a number. Identifying the users requires the extra step of matching the IDs to the users' names. Given the frequency with which we'll need to do that, it will be an annoyance and take a lot of time.
Neither the IT security group nor the IT help desk was included in the decision-making during the design of the single sign-on system. Had we been involved, both groups would have voiced strong arguments against using employee IDs for this purpose.
While I don't yet know why the decision was made, I would certainly agree that there is a sense of anonymity in using numbers. Perhaps that was the driving factor.
So far, the problem isn't so bad, because only a few hundred people have been converted to the new system. But soon the entire company will be using it.
Not-so-single sign-on
There's another problem with the new system: It's not inclusive of all our applications. For example, our software developers use a content versioning application that tracks changes in software under development. There are also a dozen or so external development sites, several of which are outside of the U.S., that use this system. To configure this application to use single sign-on would be a nightmare.
Also, the sales department uses CRM tools. Since the information this system contains is highly confidential, the IT team decided not to incorporate the sign-on for it in the enterprise directory.
Within the security department, we have RSA SecurID servers configured to authenticate systems and network administrators to resources within the infrastructure. It would be nice if we could tie that whole system into the enterprise single sign-on application, but we would have too much to lose if there was a security breach.
We use SecurID for access to our most critical systems, which are responsible for our revenue and corporate image. But for now, we are going to keep all of these specialized environments separate from the environment that caters to the mass employee populace.
So, what's the lesson learned here? It's that even as my company and others throw around the term single sign-on, it's rare that an organization of our size can institute a true single sign-on environment that works for all applications enterprisewide.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
IOGEAR Gears Up in Australia 2008-10-09 20:18:00+10
Internet Service Providers offer new unlimited Online Backup from F-Secure 2008-10-09 19:42:00+10
Choices in Storage Architecture for Oracle Environments
Database systems have always been at the core of the IT landscape. Not only is storage an increasingly large cost component of database investments, but storage architecture can significantly and directly impact the performance, availability, and recovery of data. Read on to explore the interaction between Oracle databases and EMC and Network Appliance storage architectures.










