Wednesday, August 19, 2015

Centrify's Value Proposition - Part 3: Privileged User/Identity Management with Least Priviliege

In the third part of this series, we'll discuss how Centrify provides solutions for privileged user/identity management and maintains these principles:
a) Eliminates identity silos
b) Implements strong access controls without interfering with the user experience
c) Use what you have: infrastructure, processes, knowledge (less IT fragmentation)
d) Promotes operational efficiency
e) Provides strategic value, rather than tactical solutions

Organizations come to Centrify for privileged identity management or privileged user management because of combinations of the following challenges or circumstances:
  •  Overall: They want to increase accountability and implement strong privileged user identity and access controls based on a common identity repository.
  • They have Active Directory and multiple platforms, but primarily for UNIX, Linux and Windows
  • They have a traditional (on-premise only) or hybrid (public/private cloud) enterprise
  • They want to eliminate the use of shared credentials or persistent administrative accounts (root, administrator, “-a”, etc)
  • Their existing solution does not provide flexibility on grouping systems based on a security governance model
  • They might have chosen to implement a password-centric approach as their unique strategy and they’ve come to realize that their users are less productive (or supportive), that they’ve duplicated identity silos and that ultimately, their systems (the main goal) aren’t protected by it.
  • On UNIX: They understand that using sudo/sudoers, although it’s mature may not be enough for high-risk, highly-regulated enterprises; they are tired of the complexities of managing a sudoers file and want more granularity and flexibility
  • They want a higher-degree of control on how their users access systems (beyond just granting/denying access) cross platform.
  • On Windows, they want to eliminate the problem of the Local Administrator, are conscious of the “pass the x” attacks and want to eliminate the “camping” issue with “-a” accounts.
  • They need to provide separation of duties (operational rights vs governance rights)
  • They need timely reporting of who has access to what system(s), what are their privileges, and what granted them access to do this.
  • They don’t want to deviate from existing processes or realized that by implementing point solutions or “best of breed” they ended-up fragmenting their IT in the context of processes.
  • They have regulatory requirements that they need to meet or exceed.  These may be SOx, PCI DSS, HIPAA, NERC, FERC, etc.
  • They want to solve the Shared Account Password issue, but they want a solution that reflects the state of modern trends (they hybrid datacenter, IaaS, mobile-first, etc)
  • They have high-security requirements like FIPS, solutions common-criteria certified, perhaps they rely heavily on Smart Cards.
  • They want log aggregation that is simple to their native tools (ARCSight, LogLogic, Splunk, etc)
  • They may need to go beyond the traditional security operations and provide session capture and replay from anywhere (remote or via console) because today they don't have that capability, are required to have it or simply, they might have gone the "jumpbox" route to realize that they are missing crucial sessions.
  • They hate having to invest in multiple solutions to enforce the same basic security principles.  Each time they do, this may mean:
    - Evaluate a product
    - Invest or procure new hardware or software
    - Add additional infrastructure
    - Train or hire specialist
    - Maintain the solution down the road
    - Manage the vendor relationship
Here's a technical demonstration on how Centrify delivers this value:


The key differentiation areas are:

  • AD Orientation - implemented in more of 90% of enterprises, users use a unique identity.
  • Centrify Zones - unique patented way to create groups of systems in Active Directory
  • Granularity of Access Controls - control HOW users log in to systems
  • Granularity of Privileges - no need to know the privileged account password.
  • Simple privilege elevation:  sudo-like tool in UNIX/Linux, shell and command line on Windows.
  • No proprietary magic on how events are stored: no need to have a central system just to know who did what and when - need to rely on a central system to correlate who had a privileged account.
  • Quick attestation and robust reporting - the data is in AD.
  • Separates the operational tasks versus the governance tasks - to enforce SoD
  • Works in multiple core platforms:  UNIX, Linux and Windows
  • Protects your systems: Provides end-to-end enforcement of the rules as well as session capture and replay.
Finally, the end user experience is not affected, no identity silos are created  and your AD infrastructure, processes and technology are reused.  We propose that the "least access/least privilege" approach to Privileged Identity/Super User Privilege Management should be used at least in 80% of the use cases.

In the next post we're going to talk about the next 20%, this includes Shared Account Password Management, Proxied/Brokered/JumpBox initiated sessions (what gartner calls Privilege Session Management).

A commentary on Privileged User Management

A commentary on Privileged User Management

When I visit customers and prospects, I see an amalgam of priorities, knowledge, organizational dynamics, but most commonly complexity and a feeling that most people don’t know where to start. Ultimately the decision is simple.  There’s no access controls without a consistent identity store.

I’m also surprised on how easy analysts are influenced by vendors. Let’s take for example the topic of passwords; I've  always conceded that shared account password management is needed in the enterprise, but that it only applies in break-glass scenarios, change control or network devices; however, vendors in their effort to expand have positioned their solutions as the “end-all-be-all” (regardless of the true need) which to me is a disservice to the customer or prospect.

My personal philosophy is clear, least privilege management is the right way to go because it applies in most of the cases (the cases would be larger if network devices had better AD integration); however, now that Centrify is in the SAPM business as well, I feel it’s my obligation to position it, but in its proper context and use cases.  This is validated by the fact that most data breaches have components of credential theft; threat agents are counting on somebody that has more power than they should have, to get to the sacred keys of the kingdom.

Here’s what I propose to readers of this post, (I will be the first to admit that I’m just reusing the 80/20 rule) but, I think that if 8 out of 10 privileged actions are part of my day-to-day job and they have been defined with a privileged elevation mechanism, I’m quite happy.  This is becoming increasingly important on Windows, where admin account (e.g. “-a”) accounts are no longer the best practice.  On UNIX/Linux privilege escalation has existed for years in the form of sudo.  What you’re trying to avoid here is that if you implement a password-centric system, users will naturally “camp” or will try to get around the proxy system (forcing the implementation of complex network rules).



This should settle the whole “what’s my goal post” question, and ultimately, it’s up to the organization dynamics to determine if this is a realistic and attainable goal.

Least Privilege Management - Where do I start?

Ultimately, the game it’s all about control.  Here’s a playbook that I often share with customers and prospects:
  • First, you have to start with a Common Identity (e.g. AD)
  • Then you have to be able to group systems based on a security governance model
    (e.g. web servers, database servers, PCI servers, Financial Systems)
  • Implement granular access controls:
  • Define where the user can log in as part of their job functions 
  • Define how the user can log in to systems (E.g. SSH but not console;  RDP but not console)
  • Define any time effectiveness of a role  (E.g. Backup guy should only run tar as root from 5PM to 6AM
  • Reuse Processes
  • Assign roles to AD groups
  • Manage memberships or requests via your ITSM or workflow tool.
  • This way you can use that tool for attestation as well.
With least privilege, where I see customers often think that the task will be very large because they must identify and catalog the tasks that users are performing with privilege; but the view is a bit myopic because those things are managed and it is after all a capability (people-process-technology) that should have its own road map.

At Centrify we suggest this:
  1. Start with a “broad scope” but with a simple goal:  Eliminate shared account usage.  Maintain status quo as it relates to super users.  Allow them to elevate as root/Administrator; but deny them the knowledge of the password.  
  2. As you are able to increase accountability, then start “narrowing the scope”; e.g. “What’s does a Database guy do, with privilege in their day-to-day?” 

As you move to this model, concede that there will be areas of improvement (hence the need for feedback and a road map). This is another area where customers and prospects have misaligned expectations;  you will have to work on privilege management all the time, this is not a "set it and forget it" type of deal.  There are governance and operations components, there's attestation

The other 20%, perhaps break/glass, or access to production systems, I’m happy with proper workflow/approvals and change control.  Otherwise I’m getting in the way of the user’s productivity and they will try to find ways around the “broker” system.

The ever-expanding definition of a Privileged Account

It's not just about root, Administrator, oracle, apache, jboss or xyz service/privileged account.  Your privileged users exist everywhere.   What about your social media accounts?  The embarrassment of losing control of these accounts is evident every day for corporations;  the same with SaaS applications.  Isn't the Sales Admin in Salesforce, or the Finance or CFO lead in Netsuite a privileged user?

In a hybrid enterprise, the rules have changed;  however, I believe that Centrify has you covered.  In the next post we'll continue this series and we'll talk about the Centrify value in the context of Privileged User Management.

Monday, August 17, 2015

Centrify's Value Proposition - Part 2: The hybrid and heterogeneous enterprise

Organizations with traditional (on-premise) and  hybrid (private/public cloud) with Active Directory, come to Centrify because:
  • They have diverse platforms (UNIX, Linux, Macs) in their enterprise (on-premise and in the cloud).
  •  They are looking to Centralize the administration (or implement effective controls) for user access in those different platforms.  Their reasons may be due to security, regulation, operational efficiency or simply because they are reacting to an audit or other event.
  •  They are also looking to leverage the secure authentication methods provided by Active Directory. 
  •  They are looking to find a way to effectively manage UNIX identities by using Active Directory, but preferably, they don’t want any schema extensions to AD or software loaded in Domain Controllers.
  • Some other organizations (and this is quite common on the Mac side) are looking for a more robust way to support AD integration and are also looking to use a common management framework (like Active Directory Group Policies) to enforce security policy or configuration management policies.
  • Other organizations are looking to focus on their core competencies because perhaps they invested a lot of engineering cycles using open source software (like Samba/Winbind, RedHat’s SSSD, OpenLDAP with MIT Kerberos) and realized that the speed of requirements and diversity of platforms does not align with their goals.  (E.g. a Financial organization spending hundreds of man hours on “manual” identity and access controls rather than portfolio analysis).  These types of organizations are ready for a solution that “just works”
  • Organizations want solutions that are friendly to private/public cloud scenarios; this means a toolset that promotes automation.
  • The organization may have high-security requirements like smartcard authentication, FIPS encryption or common-criteria certified solutions
  •  Finally, some organizations tried to wait as long as they can keeping the status quo; and a compelling event has made them change like:
  • Change of leadership
  •  A merger or an acquisition
  •  A new technology (like BigData)
  •  Acknowledgement that advanced persistent threats can’t be ignored
  •  Another solution isn’t providing timely updates, proper support or their future is uncertain
  • An audit or data-breach
  •  Perhaps there’s an old infrastructure (e.g. NIS, LDAP) that found fresh blood that isn’t afraid of “touching the server, who knows what will break”  <= yes, this sadly happens.
Everything I outlined above is core of what some analysts call “Active Directory Bridging” but when you look at it is much more; it is the basis for implementing critical access controls and a management framework that is based on reuse of existing infrastructure and processes rather than point solutions.  It’s also the foundation of making sure users can do their work, without interrupting their flow.

Here’s a technical demonstration on how Centrify provides value:


 A very unique capability that is exclusive to Centrify is the zones technology.  Nobody else can do what Centrify does to group systems in a hierarchical way while consolidating UNIX identities for Users, Groups and NIS Maps.

Note that also, a large number of "born-in-the-cloud" organizations are coming to Centrify for Web Application SSO and Enterprise Mobility.  We will cover that in other entry.

In the next post, we'll focus on how Centrify builds on their AD bridging capabilities to provide Privileged User Management on UNIX, Linux and Windows and how it uses it's Identity Platform for secure access and shared account password management.

Opinion: On Centrify's Value Proposition - Part I

My take on Centrify's value proposition

Non-IT people often ask me:  “What is it that Centrify does…?” the answer to that question is becoming increasingly broad, because the product portfolio is growing; what I typically like to say  is this:  “we provide Active Directory-centric Access Controls(*)”; however, in the past 3 years we have released capabilities that expand beyond the basic premise of a heterogeneous data center.  The overwhelming response to some of the briefings we have with prospects or customers is this:  "Wow, I didn't know you did that much?"

I've expanded the definition to:  “We help you with your existing access control challenges in the data center, in the cloud and with mobile devices” this is regardless of directory bias especially in the context of Cloud (IaaS, SaaS) we are dealing with extended borders where Active Directory may not exist. However, ultimately common sense dictates that organizations should be aiming to reduce identity stores, not increase them.  However, when I look at our customer successes, and I'm a bit more bullyish.  Perhaps the answer should be: "We allow you to implement strong access controls in your systems and apps, regardless of location while promoting usability and operational efficiency" 

In this long entry, I'm going to present Centrify’s value proposition in 3 major areas:
  • The diverse data center (using Active Directory to conquer AAA challenges with non-Windows platforms:  UNIX, Linux and Macs)
  • Privileged Identity Management (using Centrify software and Services and Active Directory) to conquer the Super User Privilege Management (SUPM), Shared Account Password Management (SAPM), and Privileged Session Management (PSM) for Windows, UNIX, Linux, Macs and Network Devices.
  • Web application and Software as a Service (SaaS) access controls, single sign-on (SSO), mobile access and mobility management

The subsequent posts will consist of “problem statements” or “challenges” that our customers and prospects provide us, and I will deliver a series of technical briefings (or demos) to cover each problem set.  As always, the intended audience is typically architects, security professionals, systems administrators and application owners.

In summary, and in business terms Centrify’s value proposition is around these principles:
  • Implementing Strong Access Controls to protect your systems regardless of location
  • Eliminate or consolidate identity stores
  • Use what you have:  de-duplicate processes and infrastructure 
  • Promote operational efficiency
  • Be strategic, rather than tactical - solve the problems of today and tomorrow.

The goal is not to go in depth in technical terminology but to look at problem sets and solution sets "a la Centrify" - If you're just a visitor, it's a great way to look at Centrify in a non-technical way, although the demos will be somewhat technical.


(*)Why not use “Identity Management”?   Centrify uses the term too.

I personally refrain from using the “Identity Management” term because years ago, the term was intimately linked with Gartner’s definition AND for too many IT professionals it is synonymous with software that was expensive, consultant-heavy and projects that showed very little results.  
I think Centrify is in the identity space, but our approach is much simpler and integrated (producing faster results), besides, prospects often have unrealistic expectations if they think a single solution can solve all their Identity-related problems.  What I’m willing to concede (and I’m BIASED) is that if an organization is committed to Active Directory as their main identity store, using Centrify will provide “pound-per-pound” the best capability return per dollar invested, however, I’m also able to recognize that not all organizations are the same; there are complexities, political battles, biases and the simple commitment to use Active Directory is a tough decision to get to.
I also don’t want to have to tell people what they don’t want to hear.  If you were to ask me “Can you synchronize between PeopleSoft and target “X” system” – my answer is basically “No. user provisioning happens upstream and we try to avoid synchronization at all costs”  - sometimes briefings become a contest of “what can you do?” vs. “what problems can you help me with?” and this is the most frustrating part of being in technical sales.


Wednesday, July 22, 2015

My favorite Centrify features for the last year (2014-2015)....

Background

With the release of Centrify Server Suite 2015.1 and Cloud (CIS/CPS) 15.6 we have wrapped up another great year of introducing great capabilities to keep our existing customers happy and to help them solve the challenges of today and tomorrow.

I am biased towards functionality that help existing customers optimize their existing deployments, and in this article I will outline my personal top 10 Centrify features that promote operational efficiency for existing Centrify Server Suite or Centrify Identity/Privilege Service customers.


Finally, this would not be possible without product management that listens attentively and tries to understand our use cases plus our amazing engineering team.  This is a very exciting time to be at Centrify.


1. UNIX/Linux/Mac Agent:  Enhancements to adjoin
Top10 - Enhancements to adjoin.jpg
Release date:  Apple Scheme (2014.1); ComputerRole (2015.1)
What is it:  Facilitate OS X Migrations and optimize your automation scripts
How does it improve Operational Efficiency:  When an existing OS X user moves from the Apple Directory Services plugin, extra steps eliminated.  Reduced size of provisioning scripts for servers (Chef recipes, Puppet scripts).
What do I need to do to get the benefits: Upgrade to 2015.1 (5.2.3.x).

2. Identity Service: Application Provisioning
Top10 - CIS App Provisioning.jpg
Release date:  Preview started in April 2014 for Box, GoogleApps, Office 365, Salesforce and ZenDesk
What is it:  Just add a user (or remove) to an AD group or CIS role, and the user will get provisioned (or deprovisioned), the proper license is applied and if supported, the proper role is assigned as well.
How does it improve Operational Efficiency:  Use the normal cadence of group management and extend it to be the hub for your App provisioning and effective controls to disable access timely and control costs.
What do I need to do to get the benefits: Use the App Catalog and find apps ready for provisioning.

3. DirectAudit: Performance and Scalability Improvements for Enteprise Edition
Top10 - DA Enhancements.jpg
Release date:  July 2015 (Server Suite Enterprise Edition 2015.1)
What is it:  Centrify invested significant development cycles to optimize all components of DirectAudit
How does it improve Operational Efficiency:  Scalability, right-sizing, better compression, better optimization, this all translates in less effort to maintain DirectAudit deployments.
What do I need to do to get the benefits: Upgrade to 2015.1 DirectAudit.

4. Manageability: PowerShell Management for Centrify DirectManage and DirectAudit
Top10 - PowerShell.jpg
Release date:  DirectManage (Server Suite 2014), DirectAudit (Server Suite 2015)
What is it:  Windows PowerShell to automate/orchestrate Access and Audit capabilities
How does it improve Operational Efficiency:  The tasks traditionally performed in the DirectControl and DirectAudit MMCs now can be scripted, automated and orchestrated by leveraging PowerShell.  All PowerShell commandlets leverage the DirectManage or DirectAudit APIs.
What do I need to do to get the benefits: Install the PowerShell Modules for your platform.

5. Windows PIM:  SmartCard Support for Windows Privilege Elevation
Top10 - DZWin Multifactor.jpg
Release:  Server Suite 2015
What is it:  In high-security environments, when a privileged AD user uses Centrify to perform Windows Privilege Elevation, the user can be prompted  for the smartcard PIN.
How does it improve Operational Efficiency:  By eliminating "-a" accounts and forcing Windows users to use privilege elevation, you are doing the proper due-diligence to limit the impact of advanced threats.
What do I need to do to get the benefits: Upgrade to Server Suite 2015 (3.2.x)

6. Kerberos:  Infinite Kerberos Ticket Renewal
Top10 - Infinite Kerberos Ticket.jpg
Release date:  Server Suite 2015.1 (July 2015)
What is it:  Kerberos tickets expire, but there are applications (e.g. Hadoop) that require jobs or credentials to be effective longer than the policy define din AD.  These parameters and GPOs allow the UNIX agent to trigger a renewal based on AD principal (user or group).
How does it improve Operational Efficiency:  Improves the supportability of these use cases.
What do I need to do to get the benefits: Upgrade to Server Suite 2015.1 (5.2.3.x)

7. LDAP Proxy:   Support for TLS and Startup Scripts
Top10 - TLS Support added to LDAPProxy.jpg
Release date:  Server Suite 2015 (March 2015)
What is it:  Secure communications for our very useful LDAP Proxy.
How does it improve Operational Efficiency:  Several apps and appliances only support LDAPS, in addition, now there's no need to do manual scripts to startup the slapd daemon.
What do I need to do to get the benefits: Upgrade to Server Suite 2015 (5.2.3.x)

8. Mac Agent:  AD + Identity Service Combo Join
Top 10 - OS X Combo Join.jpg
Release date:  Server Suite 2014.1 and CIS
What is it:  Macs in the enterprise are on the move and multiplying.  Not only they need to be managed from AD to get unified identity, but being able to provide Enterprise Manageability and Self-Service.
How does it improve Operational Efficiency:  Now you can empower your mobile Mac workforce with capabilities while decreasing calls to the help desk, this goes along with their existing iOS, Android or Windows devices.
What do I need to do to get the benefits: Enroll your Macs now using Identity Service.  Just go to the Devices tab.

9. Identity Service:  App Gateway  (Per-app VPN, Secure Access)
Top10 - CIS App Gateway.jpg
Release date:  Beta in 2014, live January 2015
What is it:  App gateway eliminates the need to establish a persistent VPN to access an application or a resource (server, appliance)
How does it improve Operational Efficiency:  Eliminate the need for VPN access for external users  (consultants, external partners) for both apps and servers.
What do I need to do to get the benefits: Get Centrify Identity Suite App Edition

10. Identity Platform:  Centrify Privilege Service
Station - Portal Mixed.JPG

CPS - Password Checkout.jpgMobile - Password Checkout.jpg
Release date:  May 2015
What is it:  Shared account password management (SAPM), secure remote access, privileged session monitoring (PSM), mobile-ready, deploy anywhere.
How does it improve Operational Efficiency:  Built on the Identity Platform, complements Server Suite by providing SAPM and PSM plus more!
What do I need to do to get the benefits: Request a trial now!

This is a copy of a featured article written in the Centrify Community.

Thursday, July 9, 2015

Implement strong access controls for Hadoop clusters using Centrify

This 15-minute video also features Centrify Privileged Service



Centrify can help challenges with Hadoop implementations for confidentiality and integration at the OS-level.  No need to stand-up independent MIT Kerberos infrastructure, plus the strongest Access Controls to meet or exceed any security or regulatory requirement.

Wednesday, July 8, 2015

Using Centrify with the Microsoft CA and the Autoenrollment GPO for your UNIX/Linux/Mac PKI Certificate needs

Background

Active Directory provides a Public Key Infrastructure (PKI) capability with the Microsoft Certificate Authority.  This is quite convenient to system administrators especially when combined with Group Policy since it allows for the automation of the Certificate lifecycle:  issue, renew, revoke, supersede templates, etc.



We've discussed this before, but Centrified clients can also take advantage of Certificate auto-enrollment.  This can happen automatically or manually using the adcert utility.

How it works?

The process works as follows:
  1. When a system is joined to AD using Centrify, as part of the join the system will read the domain controller's SYSVOL for Group Policies.  The system may download the trust chain (containing the trusted CAs or the local root CA) and any revocation information to the /var/centrify/net/certs folder.
  2. If the auto-enrollment policy that applies to the system points to a usable template, the agent will attempt to enroll automatically when the GPO refresh interval starts.
    Note: there are different auto-enrollment GPOs depending on the version of Active Directory.
  3. The agent will use the computer's credentials with the adcert utility and connect to the CA or Intermediate CA to obtain a certificate set for autoenrollment.
  4. adcert will issue pkcs10 request for each template, if an issuing CA is found for the templates in question and the certificates, chain and private key (if defined exportable by the template) will be placed in the /var/centrify/net/certs folder with this format:
    [name of template].cert
    [name of template].key
    [name of template].chain
Once the certificate is in your system, you may be able to use it as is, or you may have to change the encoding using OpenSSL tools.

Here are two video examples:

Using Auto-enrollment for your Apache HTTPS certs




Using Auto-enrollment with Mac OS X Systems