BitKoo Keystone

Download PDF
Challenge

BitKOO KeystoneBiTKOO Keystone is an authorization management engine for enterprise policy administration, decision and enforcement. It allows fine-grain authorization and web access control. Keystone provides an abstracted layer of security web services, unifying silos of authentication and authorization sources throughout an enterprise.

However, Keystone only provides a Web Service interface for its usage. This limitation prevents it from interfacing easily with commonly used identity tools, which often make use of an LDAP interface. Many enterprise environments seek a means to further integrate BiTKOO Keystone with existing infrastructure, and the option of extending its interfaces to include support for LDAP would massively extend the capabilities of the Keystone software.

Solution
BitKOO Keystoner SolutionSymlabs provides the "Keystone LDAP Adapter" (also known as KLA) to extend Keystone interfaces to support LDAP protocol. The Keystone LDAP Adapter has been developed on top of Symlabs Virtual Directory Server as an out-of-the-box feature, and allows an instance of the Keystone Auth Web Service to expose an LDAP interface to applications that support this protocol.

Keystone LDAP Adapter is an extension mechanism for Keystone that opens business opportunities and allows more customers to use Keystone for their authentication and authorization processes without needing to build a Web Service Layer.

Using Keystone LDAP Adapter in combination with other Symlabs Virtual Directory Server features, can further extend the possible uses of Keystone. Among its many included features, Symlabs Virtual Directory Server includes functionality to allow you to connect to multiple data repositories, to enable cross domain authentication and authorization, and to perform attribute mapping across data repositories.

KLA is the first of a set of adaptors that will be set up with Symlabs Virtual Directory Server to enable other protocols such as Radius and Diameter for use with Keystone authentication and authorization services.

Benefits
  • Resolve authentication via LDAP enabled clients.
  • Retrieve one or more attribute values based on attribute names, given a DN and attributes names.
  • Determine whether a user is in a Keystone role.
  • Keystone services enhancement via out of the box capabilities of Symlabs Virtual Directory Server.

About BiTKOO
BiTKOO is pioneering new technologies in the area of identity and access management (IAM). BiTKOO's mission is to provide access to data and systems across secured boundaries, with the highest degree of security and flexibility.

BiTKOO has enjoyed tremendous growth since it was co-founded in 2006 by the development team who developed and implemented Keystone, which originated as The Walt Disney Company's authentication and authorization engine.

Symlabs is now part of Quest Software. A leader in simplifying and reducing the cost of IT management, Quest’s innovative solutions make solving the toughest IT management problems easier, enabling more than 100,000 customers worldwide to save time and money across physical, virtual and cloud environments. The addition of Symlabs virtual directory and federation technology will enhance the overall architecture of the Quest® One Identity Solution and Quest migration products. Learn more at www.quest.com/symlabs.