Key Features
- J2EE Application Server Support - AssureAccess
provides a variety of security solutions for the J2EE/Java
environment. The Universal Java Plug-In and Servlet Filter
provide Bolt-On security that does not require application
modifications. For application developers that want to build
security-aware applications, the JSP Tag Library and Java
API allows security to be customized in applications while
still enabling central administration.
- Architecture - In testing done by an independent
performance lab, AssureAccess was shown to scale linearly
as additional servers were added because policy decisions
and policy enforcement are co-located at the server. Additionally,
AssureAccess is optimized for authorizations, which occur
far more frequently than authentications, by packaging all
user credentials/entitlements in an Attribute Certificate
that travels through the system with the user.
- Policy Model - Out of the box, AssureAccess provides
16 standard rules covering identity, group membership, role,
client and server machine identification, client connection
encryption strength, client authentication strength, time,
and day. Custom rules can be easily added, enabling data
in legacy systems to be included real-time in policy decisions.
- Standards Support- Entegrity Solutions is committed
to delivering standards based solutions, and is an active
participant in a number of standards activities. Entegrity
is a founding member of the SAML group and maintains the
issues list. Entegrity is also a co-chair of XACML, another
OASIS activity. In the Java Community Process, Entegrity
submitted JSR 85, and is actively involved in JSR 115 and
JSR 155. AssureAccess internally uses X.509 Attribute Certificates
for user credentials, X.509 Public Key Certificates to encrypt
communications, writes audit as XML, and implements the
Java standard for internationalization.
Entegrity Solutions has been named an Approved E-Authentication Technology Provider for the Federal government’s E-Authentication Initiative.
Platforms and Other Software Supported
AssureAccess Authentication, Audit and Management Servers
run in all environments that support JDK 1.3.1 and higher,
and are verified on the following platforms:
- Windows 2000 and NT 4.0 sp6a, Windows 2003
- Solaris 7, 8, and 9
- Red Hat Linux 7.3, 8.0, and 9
While the following platforms have not been included in formal
testing at Entegrity, since the product is Java-based, it
should operate correctly on any platform running version 1.3.1
or later of the Java Runtime Environment (JRE). We have exercised
the product, or customers have reported running the product,
on the following systems:
The Management Console client, providing full system administration
capabilities in a Java Swing based GUI, is supported on all
JDK 1.3 supported platforms, and verified on the following
platforms:
- Windows 2000 and NT 4.0 sp6a, Windows 2003
- Solaris 7, 8, and 9
- Red Hat Linux 7.3, 8.0, and 9
Information Stores
AssureAccess uses LDAP as a Policy Store for configuration
and security information.
The following LDAP directories are supported as Policy Stores:
- iPlanet Directory Server 4.1.x and 5.x
- OctetString
- OpenLDAP 2.0.23
- Oracle Internet Directory
- Siemens DirX 6.0 Meta Directory
- Microsoft Active Directory
- Critical Path
AssureAccess can retrieve user identification, authentication,
and authorization data from many sources, including the following:
- Any LDAP V3-compliant LDAP server (including all those
listed above)
- Windows NT 4 Security Service
- Windows 2000 Security Service
- Any JDBC/ODBC-accessible database
- PKI (Supports client certificates for Web and J2EE platforms
and
Distinguished Name as a user attribute)
- DCE Security Security Server (separately orderable extension)
- Developers can use the AssureAccess API to plug additional
authentication providers into the system as required
Application, Portal, and Web Servers
Bolt-On security using AssureAccess Adapters allows administrators
to enable Single Sign-On and secure resources without modifying
applications on the following platforms:
- BEA WebLogic 6.1 and 7.0
- iPlanet Enterprise Server 4.1 and 6.0 (Solaris, and Windows
only)
- Microsoft IIS 4, 5, and 6 (Windows only)
- Apache 1.3.x and 2.0 Web Server (Linux and Solaris Only)
- All J2EE compliant Application and Portal Servers supporting
the Servlet 2.3 Specification
- All J2EE-compliant Application and Portal Servers supporting
the Servlet 2.3 Specification (for example, Apache Tomcat)
Fine-grained security, protecting individual page elements
in J2EE and Web Applications, is supported through the Universal
Java Plug-In, JSP Tags, Java Security Toolkit, and COM Interface
on the following server platforms:
- BEA WebLogic 5.x, 6.x and 7.0
- IBM WebSphere 3.x and 4.0
- Borland Application Server
- iPlanet Enterprise Server 4.1 and 6.0 (Windows and Solaris)
- Microsoft IIS 4, 5, and 6 (Windows only)
- All J2EE compliant Applications and Portal Servers
The following web servers are supported:
- Microsoft Internet Information Server 6.0 on Windows 2003
- Microsoft Internet Information Server 5.0 on Windows
2000
- Microsoft Internet Information Server 4.0 on Windows NT
- iPlanet Web Server, Enterprise Edition 4.1 SP6 and higher,
and version 6.0
- Apache 1.3.x and 2.0 Web Server (Linux and Solaris Only)
|