The app for independent voices

๐—ฆ๐—ฆ๐—ข (๐—ฆ๐—ถ๐—ป๐—ด๐—น๐—ฒ ๐—ฆ๐—ถ๐—ด๐—ป-๐—ข๐—ป) ๐—ฒ๐˜…๐—ฝ๐—น๐—ฎ๐—ถ๐—ป๐—ฒ๐—ฑ

SSO is an authentication process that allows users to access multiple apps with a single master key.

This is accomplished using a central authentication server that stores the user's credentials and verifies them for each application.

Here are ๐˜๐—ต๐—ฒ ๐˜€๐˜๐—ฒ๐—ฝ๐˜€ that happen if you want to access the Trello web app by using your Google account:

1. Use the Trello login web page and select Google account as a login method

2. Trello redirects the user to the Google login page

3. User is served with the Google login page

4. The user enters their Google credentials

5. Google sends authentication info to the SSO Authorization server

6. If credentials are valid, the Authorization server returns the auth token (SAML)

7. Google sends the auth token to the Trello

8. In the last step, Trello sends the token to the Google Authentication server to validate its

9. If the token is valid, Trello will allow access to the user and store the session for future interactions

โœ… The ๐—ฏ๐—ฒ๐—ป๐—ฒ๐—ณ๐—ถ๐˜๐˜€ of SSO are:

๐Ÿ”น Improved user experience. Users do not need to remember multiple usernames and passwords.

๐Ÿ”น Increased security. Users are less likely to reuse passwords across applications.

โŒ The ๐—ฑ๐—ถ๐˜€๐—ฎ๐—ฑ๐˜ƒ๐—ฎ๐—ป๐˜๐—ฎ๐—ด๐—ฒ๐˜€ are:

๐Ÿ”ธ Single point of failure. One of the most notable disadvantages is that SSO creates a single point of failure. If the SSO system is compromised, the attacker could access all connected applications and services.

๐Ÿ”ธSecurity risks. If credentials are compromised, the security of all connected applications could be at risk.

Some ๐—ฐ๐—ผ๐—บ๐—บ๐—ผ๐—ป ๐˜๐˜†๐—ฝ๐—ฒ๐˜€ ๐—ผ๐—ณ ๐—ฆ๐—ฆ๐—ข are:

๐Ÿ”น ๐—ฆ๐—”๐— ๐—Ÿ-๐—ฏ๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—ฆ๐—ฆ๐—ข. This is the most common type of SSO. It uses the SAML protocol to exchange authentication information between the SSO server and applications.

๐Ÿ”น ๐—ข๐—ฝ๐—ฒ๐—ป๐—œ๐—— ๐—–๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜. This is a newer SSO type based on OAuth 2.0. It is a more straightforward protocol than SAML and is easier to integrate with web applications.

And ๐—ฝ๐—ผ๐—ฝ๐˜‚๐—น๐—ฎ๐—ฟ ๐—ฆ๐—ฆ๐—ข ๐˜€๐—ผ๐—น๐˜‚๐˜๐—ถ๐—ผ๐—ป๐˜€ are:

โžก๏ธ Azure Active Directory

โžก๏ธ Okta

โžก๏ธ Ping Identity

โžก๏ธ OneLogin

โžก๏ธ Google Cloud Identity Platform

Apr 8
at
7:03 AM
Relevant people

Log in or sign up

Join the most interesting and insightful discussions.