Training
The following course will help you acquire the knowledge
and skills required to integrate and customize Cams in your environment.
Cams Integration
This course is a 3 hour online, interactive class that gives students
practical reinforcement of environmental conditions by taking them
through the installation, configuration, customization, and troubleshooting
of a Cams integration. All principals are taught from a web security
best practices perspective.
Audience
Web masters, network administrators, web developers, or anyone
else wishing to develop skills for successfully installing and integrating
Cams to protect web resources.
Prerequisites
Students should download and review the Cams Tour prior to class.
Students should also have a Cams policy server on their desktop
with an active evaluation license obtained from Cafésoft.
Student PC must have access to a high-bandwidth Internet connection
and a browser that is compatible with Citrix GoToMeeting.
Content
Introduction to Web Security
- Web resources
- Web security best practices
- HTTP and web security
- Internet infrastructure
- HTTP
- SSL
- Cookies
- User directories
- LDAP servers
- Active Directory
- Database
- Heterogeneous systems
- Web servers
- Application servers
Cams Security Concepts
- Terminology
- What is Cams
- Web servers with and without Cams
- Cams policy server
- Cams security domains
- Service oriented architecture
- Authentication
- Access control
- Cams users
- Cams web agents
- Web single sign-on
- Personalization
Deployment Considerations
- Topology overview
- Sample topologies
- Integration methodologies
- Firewall considerations
- Scaling the load
- Cams policy server clustering
- Authentication
- Web application integration
Installing Cams
- Installation assumptions
- Installation process
- Cams web agent installation
- Testing
Configuring Cams
- Cams policy server
- cams.conf
- cams-reg-default.conf
- Cams web agents
- Authentication agent issues
- Login, denied, error pages
- Use of SSL
- Cookie management
- cams-webagent.conf
Configuring Authentication
- How authentication works
- Login configuration
- login-config.xml
- Directory schema mapping
- Login modules
- Configuration
- Stacking
- Password digests
- Security domain services
- Callback handers
- Parameters
- Login exception messages
- Login configuration tag reference
- End user interaction pages
- Cams authentication APIs
Configuring a Security Policy
- How Cams access control works
- Cams permissions
- Access control policy rules
- Security policy management tips
Hardening a Cams Installation
- Cams policy server do's
- Cams web agent do's
- Hardening considerations
- Hardening don'ts
- Hardening miscellaneous
Webapp Programming with Cams
- Cams session information
- Fine-grained access control
- Personalization
- Cams secure request headers
- Java Servlet security API
Troubleshooting Cams
- Troubleshooting Cams policy server
- Troubleshooting Cams web agents
- Cams web agent debugging tips
- Submitting support requests
|