Extranet   Home | Legal & Privacy Notice | Search | Sitemap
flash
highlights
  • Easy access with single sign-on & identity federation

ssl_vpn_authSingle Sign-On

During a session, users typically interact with multiple back-end application and data resources.

Technologies like single Sign-On and next generation identity federation simplify the user experience. Disparate application and data resources can appear to the user as one homogenous group.
  • Single Sign-On – Access to resources without the need to re-authenticate improves the user experience. Once you have signed in to the Stonegate SSL VPN Authentication Service, it takes care of the rest.
  • Identity Federation – A single digital identity can now be used to access multiple departments or even businesses without the need for extra and costly user enrollment. This is ideal for sharing identities in business-to-business partnerships, or when companies or departments are merged.



Single Sign-On

Single Sign-On (SSO) permits users to enter their credentials once, which then gives them access to several resources without the need to re-authenticate when accessing each resource. All resources available with the same user credentials can be defined in a SSO domain. When the user credentials are modified, the changes apply to all resources in the SSO domain.

When using the system for the first time, users are prompted for SSO credentials (user ID and password). The SSO credentials are stored per user account and retrieved whenever the user accesses resources registered in a SSO domain. If credentials are changed, the user will be prompted for authentication.

Identity federation

Stonesoft SSL VPN provides standards-based identity federation. By using the latest SAML 2.0 and ADFS standards, the StoneGate SSL VPN solution is compliant with any existing third-party identity federation deployments.

Next generation sign-on provides trusted authentication between directories for securing B2B, B2C and easing the merging of organizations' IT infrastructure.

By using the SAML 2.0  or ADFS standard, one digital identity can be used to access multiple domains without the need for costly user enrollment. This is ideal for business-to-business partnerships, mergers and acquisitions.