Project

General

Profile

Actions

Task #155

closed

Ensure ORE authentication services are interoperable with cloud authentication services as required by Flank Speed

Added by Doug Fraser over 2 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Start date:
10/10/2022
Due date:
08/02/2023
% Done:

100%

Estimated time:

Description

PWS 3.3.7 Ensure ORE authentication services are interoperable with cloud authentication services as required by Flank Speed


Files

PIVCAC login screenshot.png (484 KB) PIVCAC login screenshot.png Jacob Halle, 05/01/2023 08:17 PM
Actions #1

Updated by Doug Fraser over 2 years ago

  • Status changed from New to In Progress
Actions #2

Updated by Lloyd Osafo about 2 years ago

  • Due date changed from 02/27/2023 to 05/17/2023
  • % Done changed from 30 to 70

Microsoft services (Government white labeled SaaS "Flankspeed)- The ORE is interoperable with AD services for authentication and supports the protocols for the Azure authentication services.

Actions #3

Updated by Tom Eden about 2 years ago

If this is a service that is available and we've ensured it's interoperable with Flank Speed cloud authentication services, recommend closing.

Actions #4

Updated by Jacob Halle about 2 years ago

We want to keep this open in case the government want us to actually tie into their services in Microsoft's environment with their environment variables so it can be captured for production once the ORE goes to the colocation. Functionally the ORE is interoperable and meets the AD authentication for ORE ID broker.

Actions #5

Updated by Jacob Halle almost 2 years ago

  • Tracker changed from Feature to Task
Actions #6

Updated by Jacob Halle almost 2 years ago

  • Due date changed from 05/17/2023 to 08/02/2023
Actions #7

Updated by Jacob Halle almost 2 years ago

  • % Done changed from 70 to 100

We are not able to use any authentication from NIS/flankspeed because that request to proceed was blocked. However, Our authentication services support SAML and OIDC protocol standards which is the same as is supported by Flankspeed (Azure AD - OIDC) and NIS (Ping Identity - SAML & OIDC), so this satisfies the requirement of interoperability with cloud authentication services required by Flankspeed.
Our supportability of hspd 12 piv also satisfies that requirement for authentication simulation.

Actions #8

Updated by Oscar Robertson almost 2 years ago

RE: "We are not able to use any authentication from NIS/flankspeed because that request to proceed was blocked. However, Our authentication services support SAML and OIDC protocol standards which is the same as is supported by Flankspeed (Azure AD - OIDC) and NIS (Ping Identity - SAML & OIDC), so this satisfies the requirement of interoperability with cloud authentication services required by Flankspeed.
Our supportability of hspd 12 piv also satisfies that requirement for authentication simulation."

Gerald and Brent are interested in learning who blocked the request to proceed to make this go from 70 to 100% complete?

Actions #9

Updated by Jacob Halle almost 2 years ago

Hi Oscar,
See the attached screenshot demonstrating the consumable CAC/PIV login functionality.

Christina LaRussa, the previous PM, stopped the request to proceed.

Actions #10

Updated by Oscar Robertson over 1 year ago

The government doesn't believe utilizing Azure or NDP is blocked at this time. We are exploring options to reconstitute ORE on one of those environments.

Actions #11

Updated by Jacob Halle over 1 year ago

Great. The ORE is ready to support the environmental variables with open standard and open architecture for those platforms and environments.

Actions #12

Updated by Jacob Halle over 1 year ago

  • Status changed from In Progress to Closed
Actions

Also available in: Atom PDF