{"id":1048,"date":"2009-06-01T21:41:44","date_gmt":"2009-06-02T02:41:44","guid":{"rendered":"http:\/\/www.coresecuritypatterns.com\/blogs\/?p=1048"},"modified":"2020-08-08T04:04:51","modified_gmt":"2020-08-08T04:04:51","slug":"fortifying-sun-ray-desktops-with-biometric-authentication","status":"publish","type":"post","link":"https:\/\/websecuritypatterns.com\/blogs\/2009\/06\/01\/fortifying-sun-ray-desktops-with-biometric-authentication\/","title":{"rendered":"Fortifying Sun Ray Desktops with Biometric Authentication"},"content":{"rendered":"<p>Lately I&#8217;ve been franctically busy with couple of my ISVs and an SI helping them&nbsp;out on&nbsp;a <span style=\"#000000;\"><strong><em>Citizen-scale National Healthcare Identity Infrastructure <\/em><\/strong><\/span>solution pilot for one of the populous countries in the Atlantic region &#8211; Sorry&nbsp;I cannot&nbsp;disclose the country&#8217;s&nbsp;name to abide their privacy laws and to protect my job :-).&nbsp;The solution aims to deliver an Unified Desktop\/Voice Infrastructure via Sun Ray environment and fortified by Biometrics and Smartcard PKI based authentication to access the exposed services.&nbsp; Using Smartcard\/PKI and Biometrics for Sun Rays has been deployed in production (at few customers) and in practice&nbsp;for a while now&#8230; but in my current project the interesting thing is the complete Sun Ray solution will be hosted as a&nbsp;<a href=\"http:\/\/en.wikipedia.org\/wiki\/Software_as_a_service\">SaaS <\/a>environment (~Private Cloud) and other complexities are&nbsp;related to&nbsp;legal\/privacy issues with performing citizen&#8217;s&nbsp;biometric enrollment and storing the biometric information with a&nbsp;private organization&nbsp; (Especially, when the&nbsp;Country&#8217;s privacy laws&nbsp;forbids&nbsp;storing citizen&#8217;s biometric samples). Keeping those nail biting legal issues aside, the Govt folks are still very&nbsp;enthusiastic and excited about adopting to Biometric authentication for&nbsp;Sun Ray based&nbsp;desktops to access their SaaS hosted Web-based healthcare applications.<\/p>\n<div id=\"attachment_1049\" style=\"width: 510px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/www.websecuritypatterns.com\/blogs\/wp-content\/uploads\/2009\/06\/sunray-270-login.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1049\" class=\"size-full wp-image-1049 \" src=\"http:\/\/www.coresecuritypatterns.com\/blogs\/wp-content\/uploads\/2009\/06\/sunray-270-login.jpg\" alt=\"Biometric Authentication for Sun Rays\" width=\"500\" height=\"559\"><\/a><p id=\"caption-attachment-1049\" class=\"wp-caption-text\">Biometric Authentication on a Sun Ray environment<\/p><\/div>\n<p>Looks cool,&nbsp;Is&#8217;nt it.&nbsp; If you are curious to know the secret sauce of the Sun Ray biometric authentication solution, here is the bill of materials, to put together in place:<\/p>\n<ol>\n<li>Sun Ray Session Server 4.x or above<\/li>\n<li>Solaris 10 X64 or SPARC<\/li>\n<li>Sun OpenSSO (Biometric SSO for Web applications)<\/li>\n<li>Sun Identity Manager (Provisioning Biometric Samples during enrollment)<\/li>\n<li>Sun Directory Server<\/li>\n<li>Sun Secure Global Desktop (Support accessing Windows, Mac, Linux, Solaris Desktops)<\/li>\n<li>Oracle 11g or MySQL 5.x database<\/li>\n<li>BiObex Authentication Middleware (Advanced Biometric Controls)<\/li>\n<li>Hamster Plus &#8211; USB Biometric Scanner (SecuGen) &#8211; For supporting Desktop\/Web authentication<\/li>\n<li>CrossMatch Verifier E &#8211; Biometric Scanner for supporting Biometric enrollment<\/li>\n<\/ol>\n<p>Shortly, I will&nbsp;update this blog entry with a detailed architecture and deployment cheatsheet&#8230; as soon as I wrap up my current project deliverables.&nbsp; If you are a Sun Ray enthusiast,&nbsp; I&nbsp;know you will be having some burning questions ! Feel free to send them, I will try to answer them quick&#8230;. otherwise please <span style=\"underline;\">stay tuned<\/span> for my unofficial deployment guide.<\/p>\n<p>This stateless infrastructure could be your next generation client for <strong>securely<\/strong> accessing&nbsp;your virtual desktops hosted on the cloud \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lately I&#8217;ve been franctically busy with couple of my ISVs and an SI helping them&nbsp;out on&nbsp;a Citizen-scale National Healthcare Identity Infrastructure solution pilot for one of the populous countries in the Atlantic region &#8211; Sorry&nbsp;I cannot&nbsp;disclose the country&#8217;s&nbsp;name to abide their privacy laws and to protect my job :-).&nbsp;The solution aims to deliver an Unified Desktop\/Voice Infrastructure via Sun Ray&#8230; <a href=\"https:\/\/websecuritypatterns.com\/blogs\/2009\/06\/01\/fortifying-sun-ray-desktops-with-biometric-authentication\/\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[2,15,5,6,8,9],"tags":[24,27,57,62,64,70],"class_list":["post-1048","post","type-post","status-publish","format-standard","hentry","category-biometrics","category-cloud-security","category-identity-management","category-main","category-pki-main","category-security","tag-biometrics-main","tag-cloud","tag-pki-main","tag-security","tag-smartcards","tag-sunray"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/posts\/1048","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/comments?post=1048"}],"version-history":[{"count":1,"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/posts\/1048\/revisions"}],"predecessor-version":[{"id":2835,"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/posts\/1048\/revisions\/2835"}],"wp:attachment":[{"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/media?parent=1048"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/categories?post=1048"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/websecuritypatterns.com\/blogs\/wp-json\/wp\/v2\/tags?post=1048"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}