๐ฆ๐ฆ๐ข (๐ฆ๐ถ๐ป๐ด๐น๐ฒ ๐ฆ๐ถ๐ด๐ป-๐ข๐ป) ๐ฒ๐
๐ฝ๐น๐ฎ๐ถ๐ป๐ฒ๐ฑ
SSO is an authentication process that allows users to access multiple apps with a single master key.
This is accomplished using a central authentication server that stores the user's credentials and verifies them for each application.
Here are ๐๐ต๐ฒ ๐๐๐ฒ๐ฝ๐ that happen if you want to access the Trello web app by using your Google account:
1. Use the Trello login web page and select Google account as a login method
2. Trello redirects the user to the Google login page
3. User is served with the Google login page
4. The user enters their Google credentials
5. Google sends authentication info to the SSO Authorization server
6. If credentials are valid, the Authorization server returns the auth token (SAML)
7. Google sends the auth token to the Trello
8. In the last step, Trello sends the token to the Google Authentication server to validate its
9. If the token is valid, Trello will allow access to the user and store the session for future interactions
โ
The ๐ฏ๐ฒ๐ป๐ฒ๐ณ๐ถ๐๐ of SSO are:
๐น Improved user experience. Users do not need to remember multiple usernames and passwords.
๐น Increased security. Users are less likely to reuse passwords across applications.
โ The ๐ฑ๐ถ๐๐ฎ๐ฑ๐๐ฎ๐ป๐๐ฎ๐ด๐ฒ๐ are:
๐ธ Single point of failure. One of the most notable disadvantages is that SSO creates a single point of failure. If the SSO system is compromised, the attacker could access all connected applications and services.
๐ธSecurity risks. If credentials are compromised, the security of all connected applications could be at risk.
Some ๐ฐ๐ผ๐บ๐บ๐ผ๐ป ๐๐๐ฝ๐ฒ๐ ๐ผ๐ณ ๐ฆ๐ฆ๐ข are:
๐น ๐ฆ๐๐ ๐-๐ฏ๐ฎ๐๐ฒ๐ฑ ๐ฆ๐ฆ๐ข. This is the most common type of SSO. It uses the SAML protocol to exchange authentication information between the SSO server and applications.
๐น ๐ข๐ฝ๐ฒ๐ป๐๐ ๐๐ผ๐ป๐ป๐ฒ๐ฐ๐. This is a newer SSO type based on OAuth 2.0. It is a more straightforward protocol than SAML and is easier to integrate with web applications.
And ๐ฝ๐ผ๐ฝ๐๐น๐ฎ๐ฟ ๐ฆ๐ฆ๐ข ๐๐ผ๐น๐๐๐ถ๐ผ๐ป๐ are:
โก๏ธ Azure Active Directory
โก๏ธ Okta
โก๏ธ Ping Identity
โก๏ธ OneLogin
โก๏ธ Google Cloud Identity Platform