Introduction

Sun OpenSSO prevents unauthorized access to web service applications and web content. OpenSSO integrates authentication and authorization services, policy agents, and identity federation to provide a comprehensive solution for protecting your network resources.

Many enterprises grant access to information on a per-application basis. For example, an employee might have to set up a user name and password to access the company's health benefits administration website. The same employee must use a different user name and password to access the Accounting Department online forms. Within the same enterprise, a customer sets up a user name and password to access the public branch of the company website. For each website or service, an administrator must convert the enterprise user's input into a data format that the service can recognize. Each service added to the enterprise must be provisioned and maintained separately.

OpenSSO reduces the administrative costs and eliminates the redundant user information associated with per-application solutions. OpenSSO enables an administrator to assign specific rules or policies governing which information or services each user can access. Policy agents are deployed on application or web servers to process HTTP requests and to enforce active policies. Together, a user's information and associated access policies comprise the user's enterprise identity. OpenSSO makes it possible for a user to access many resources in the enterprise with just one identity.