Chapter 14: Active Directory Federation Services Flashcards

(15 cards)

1
Q

Define a “Federation trust/service”

A

A web service that authenticates users from the Identity Provider (IdP) and provides access to claim-based applications from the Service Provider (SP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is another term for an Identity Provider (IdP)?

A

Claims Provider (CP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is another term for a Service Provider (SP)?

A

Relying Party (RP), in federation trust, this depends on the claims provided by the federation service to allow/deny access to the application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What ports are needed for a federation service?

A

LDAP/LDAPs (389/636), DNS/DNSSEC (53), HTTPS (443)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What level of access does federation allow for remote/eternal users?

A

Access can only be allowed to claims-aware applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Define a “claim” in terms of federation

A

A claim is simply a statement about a user that is used for the authorization purposes of claim-aware applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How do claims play a role in access to a federated service?

A

The federation service will request access from the SP based on the claims. If the SP’s application doesn’t understand claims, it cannot decide whether to allow or deny access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are commonly used claims?

A

Claim type Description
-UPN UPN of the user
-Email RFC 5322-type email address
-Given name Given name of the user
-CN CN value of the user account
-Name Name of the user
-Surname Surname of the user
-Windows account name Domain account in domain/user format
-Group Group the user belongs to
-Role Role of the user
-AD FS 1.x UPN UPN of the user when interacting with AD FS 1.x
-AD FS 1.x email address RFC 5322-type email address of the user when interacting with AD FS 1.x

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the role of Security Assertion Markup Language (SAML) in a federated environment?

A

The IdP and the SP need to exchange authentication
and authorization data; SAML is an XML-based open standard that is used to pass authorization credentials from IdP to SP.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How are claims requested/processed when implementing SAML?

A

The claim requesting and claim processing process is almost the same, with the only difference being the format of the token request and response; SAML uses a signed XML file as the token. In SAML terminology, the security tokens generated at the IdP end are called asserts, and the decryption and processing of asserts at the SP end is called assertion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does “WS-*” stand for?

A

“Web Services”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define “Security Token Service(STS)-Token Generation”

A

A web service that generates and issues security tokens; makes assertions based on evidence that it trusts; AD FS implements several federation frameworks and protocols because there are multiple ideas of federation and of what a security token is and how it is consumed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define “WS-Federation”

A

Provides the general language and mechanism to connect users and resources across security boundaries (IdP and SP); Fundamental goal of WS-Federation is to simplify the development of federated services through the cross-realm communication and management of federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define “WS-Trust”

A

WS-Trust defines the protocols used in requesting and issuing security tokens by WS-Security; Includes Security Token Service
(STS), used to convert locally issued security
tokens into other security token formats that can be processed by the application. It
can also convert incoming security tokens into supported token formats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly