首页

文章

SSO是什么?

发布网友 发布时间:2022-03-29 02:02

我来回答

4个回答

懂视网 时间:2022-03-29 06:23

SSO英文全称Single Sign On,单点登录。SSO是在多个应用系统中,用户只需要登录一次就可以访问所有相互信任的应用系统。它包括可以将这次主要的登录映射到其他应用中用于同一个用户的登录的机制。它是目前比较流行的企业业务整合的解决方案之一。

  

  统一的认证系统是SSO的前提之一。认证系统的主要功能是将用户的登录信息和用户信息库相比较,对用户进行登录认证;认证成功后,认证系统应该生成统一的认证标志(ticket),返还给用户。另外,认证系统还应该对ticket进行校验,判断其有效性。实现SSO的功能,让用户只登录一次,就必须让应用系统能够识别已经登录过的用户。应用系统应该能对ticket进行识别和提取,通过与认证系统的通讯,能自动判断当前用户是否登录过,从而完成单点登录的功能。

  

  

热心网友 时间:2022-03-29 03:31

微软已经推出了Office System,其中的SharePoint Portal Server 2003(以下简称SPS2003)可以用来快速地建立起一个门户网站,可以使企业内用户轻易地找到所需要的信息,协同工作,同时,也可以向Internet上的用户提供一个信息查询的门户网站。

如果用户的客户端和SPS2003服务器以及其他一些服务器(例如Exchange Server)在同一个域中,那么通过SPS2003的网站,访问其他的信息是一件轻而易举的事情,但在很多时候,可能会遇到下面的问题:

1. 客户端并没有加入到域中,或者客户端通过虚拟专用网(VPN)接入公司网络。此时,在访问所有的服务器时,都需要输入用户信息。

2. 用户会使用一些第三方的产品,无法将这些服务器加入到域中。此时,即使登录了SPS2003的网站,在访问其他服务器的时候,还是会出现需要用户信息的窗口。

正是基于以上的需求,在SPS2003中,有一项新的功能—Single Sign On(以下简称SSO)。SSO的基本思想就是:

建立一个加密的数据库,把用户的认证信息,存放到这个数据库中。当成功地验证了登录SPS2003网站的用户身份以后,就可以从加密的数据库中,获得用户的信息,从而用来访问其他的服务器或者一些第三方的服务器。

热心网友 时间:2022-03-29 04:49

Single sign-onFrom Wikipedia, the free encyclopediaSingle sign-on (SSO) is a property of access control of multiple, related, but independent software systems. With this property a user logs in once and gains access to all systems without being prompted to log in again at each of them. Single sign-off is the reverse property whereby a single action of signing out terminates access to multiple software systems.As different applications and resources support different authentication mechanisms, single sign-on has to internally translate to and store different credentials compared to what is used for initial authentication.Contents [hide]1 Benefits2 Criticisms3 Common Single Sign-On Configurations3.1 Kerberos based3.2 Smart card based3.3 OTP Token3.4 Integrated Windows Authentication4 Shared authentication schemes which are not single sign-on5 See also6 References7 External links[edit]BenefitsThis section does not cite any references or sources.
Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.(September 2010)Benefits include:Reces phishing success, because users are not trained to enter password everywhere without thinking.Recing password fatigue from different user name and password combinationsRecing time spent re-entering passwords for the same identityCan support conventional authentication such as Windows credentials (i.e., username/password)Recing IT costs e to lower number of IT help desk calls about passwordsSecurity on all levels of entry/exit/access to systems without the inconvenience of re-prompting usersCentralized reporting for compliance adherence.SSO uses centralized authentication servers that all other applications and systems utilize for authentication purposes, and combines this with techniques to ensure that users do not actively have to enter their credentials more than once.SSO users need not remember so many passwords to login to different systems or applications.[edit]CriticismsThis section does not cite any references or sources.
Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.(September 2010)The term enterprise reced sign-on is preferred by some authors[who?] who believe single sign-on to be impossible in real use cases.As single sign-on provides access to many resources once the user is initially authenticated ("keys to the castle"), it increases the negative impact in case the credentials are available to other persons and misused. Therefore, single sign-on requires an increased focus on the protection of the user credentials, and should ideally be combined with strong authentication methods like smart cards and one-time password tokens.Single sign-on also makes the authentication systems highly critical; a loss of their availability can result in denial of access to all systems unified under the SSO. SSO can thus be undesirable for systems to which access must be guaranteed at all times, such as security or plant-floor systems.[edit]Common Single Sign-On Configurations[edit]Kerberos basedInitial sign-on prompts the user for credentials, and gets a Kerberos ticket-granting ticket (TGT).Additional software applications requiring authentication, such as email clients, wikis, revision control systems, etc., use the ticket-granting ticket to acquire service tickets, proving the user's identity to the mailserver / wiki server / etc. without prompting the user to re-enter credentials.Windows environment - Windows login fetches TGT. Active Directory-aware apps fetch service tickets, so user is not prompted to re-authenticate.UNIX/Linux environment - Login via Kerberos PAM moles fetches TGT. Kerberized client applications such as Evolution, Firefox, and SVN use service tickets, so user is not prompted to re-authenticate.[edit]Smart card basedInitial sign on prompts the user for the smart card. Additional software applications also use the smart card, without prompting the user to re-enter credentials. Smart card-based single sign-on can either use certificates or passwords stored on the smart card.[edit]OTP TokenAlso referred to as one-time password token. Two-factor authentication with OTP tokens [1] follows instry best practices for authenticating users[2]. This OTP token method is more secure and effective at prohibiting unauthorized access than other authentication methods.[3][edit]Integrated Windows AuthenticationIntegrated Windows Authentication is a term associated with Microsoft procts and refers to the SPNEGO, Kerberos, and NTLMSSP authentication protocols with respect to SSPI functionality introced with Microsoft Windows 2000 and included with later Windows NT-based operating systems. The term is used more commonly for the automatically authenticated connections between Microsoft Internet Information Services and Internet Explorer. Cross-platform Active Directory integration vendors have extended the Integrated Windows Authentication paradigm to UNIX, Linux and Mac systems.[edit]Shared authentication schemes which are not single sign-onThis section does not cite any references or sources.
Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.(September 2010)Single sign on requires that users literally sign in once to establish their credentials. Systems which require the user to log in multiple times to the same identity are inherently not single sign on. For example, an environment where users are prompted to log in to their desktop, then log in to their email using the same credentials, is not single sign on.[edit]See alsoList of single sign-on implementationsRelated conceptsCentral Authentication ServiceIdentity managementPassword fatigueOpenID[edit]References^ Examples are tokens by RSA Data Security, Vasco, Actividentity or Aladdin^ OTP use meets the guidelines in DOE Order 205.1 as well^ FAQ on OTP Tokens - One Time Password Tokens[edit]External linksSingle Sign-on Intro with DiagramsSPNEGO Http Servlet Filter - Open Source SSO LibraryCampusEAI Consortium myCampus QuickLaunch Single Sign-On and Central Authentication ServiceCategories: Identity management systems | Password authentication

热心网友 时间:2022-03-29 06:40

不大清楚 我才开始学习数据库
八月中国最凉快的地方 八月份哪里最凉快,去哪旅游好?美丽的地方 乱字同韵字是什么意思 华硕笔记本电脑触摸板怎么开笔记本电脑触摸板怎么开启和关闭_百度知 ... 陕西职务侵占案立案准则 结婚后我的恋情维系了十年,怎么做到的? 玉米仁子饭产自哪里 中国期货交易所的交易品种有哪些? 历史要怎么读,有啥诀窍 高中历史诀窍 年终会活动策划方案 深度解析:第一财经回放,探索财经新风向 逆水寒手游庄园怎么邀请好友同住 逆水寒手游 逆水寒不同区可以一起组队吗? 逆水寒手游 逆水寒怎么进入好友世界? 逆水寒手游 逆水寒怎么去别人的庄园? 使用puppeteer实现将htmll转成pdf 内卷时代下的前端技术-使用JavaScript在浏览器中生成PDF文档 【译】将HTML转为PDF的几种实现方案 变形金刚08动画怎么样 变形金刚08动画的问题 变形金刚08动画日语版剧情介绍 高分!换显卡nvidia控制面板被我卸了,重新安装显卡驱动后没了nvidia控... 我的nvidia控制面板被卸载了 怎么找回啊 卸载后 这个画面看着很奇怪_百 ... 李卓彬工作简历 林少明工作简历 广东工业职业技术学院怎么样 郑德涛任职简历 唐新桂个人简历 土地入股的定义 ups快递客服电话24小时 贷款记录在征信保留几年? 安徽徽商城有限公司公司简介 安徽省徽商集团新能源股份有限公司基本情况 安徽省徽商集团有限公司经营理念 2019哈尔滨煤气费怎么有税? 快手删除的作品如何恢复 体育理念体育理念 有关体育的格言和理念 什么是体育理念 万里挑一算彩礼还是见面礼 绿萝扦插多少天后发芽 绿萝扦插多久发芽 扦插绿萝多久发芽 炖牛排骨的做法和配料 网络诈骗定罪标准揭秘 “流水不争先”是什么意思? mc中钻石装备怎么做 为什么我的MC里的钻石块是这样的?我想要那种。是不是版本的问题?如果是... 带“偷儿”的诗句 台式电脑机箱如何加电源指示灯 在主机上,电源指示灯旁边的是什么灯??? 电脑机箱哪个是硬盘指示灯哪个是电源灯 电脑主机指示灯一直亮 电脑主机指示灯 电脑主机按下开机键没反应,电源指示灯亮着 电脑关机后主机电源指示灯还在亮着_风扇也在转 电脑主机插上电源指示灯一直在亮开不了机是怎么回事 台式电脑电源的指示灯在主板上哪个地方 电脑主机上的绿色和红色指示灯分别代表什么意思? 电脑机箱上的电源指示灯一直在闪烁,什么问题 主机箱上的两个灯分别是什么灯啊? 关于电脑主机电源指示灯的问题 为什么我的电脑主机的电源灯一直都在闪? 主机电源指示灯一直在闪 电脑机箱电源灯在哪 台式电脑的电源接上但开不了机,主板的一个指示灯... 电脑的电源指示灯在哪里 SSO具体是什么意思 魅族5有单手操作模式和指纹识别解锁吗? 获得国妆特字的化妆品有哪些 国妆特字的化妆品可以长期使用吗 《重生之美人攻略》txt下载在线阅读全文,求百度网... 国妆特字G20202344是真的吗? 重生之美人攻略_by谷雨公子_txt全文阅读,百度网盘... 国妆特字20202600可靠吗 季谨言温乔顾耀川在哪可以看呀 国妆特字和3c认证一样的吗 温乔是那本小说的女主人公 国妆特字G20160939想查这家祛斑产品效果怎么样?是... 男主叫孟珩的小说,男主做梦到女主前世,女主是远... 一个霸道总裁类小说 备注温乔是什么意思 有人有红帽LINUX RHCE历年考试试题么 谢谢了 linux下部署模拟考试环境 RHCE6.0考试题,“配置ssh允许harry用户访问,拒绝t... 我会java可以做web开发了,也会php也可以做网站了... exam文件怎么打开 娃娃菜有几种 娃娃菜有哪些主要栽培品种?
声明声明:本网页内容为用户发布,旨在传播知识,不代表本网认同其观点,若有侵权等问题请及时与本网联系,我们将在第一时间删除处理。E-MAIL:11247931@qq.com