Token issuer manager for management and dynamic changing of token issuers
In general, certain embodiments described herein relate to a method for managing token issuers for a system. One or more embodiments are directed to changing the token issuer after a factory configuration, a disaster situation, and the current token issuer being compromised or down. The method for managing token issuers includes restoring a system on to a virtual machine environment based on a backup image of the system, identifying available token issuers on the virtual machine environment, determining that a currently configured token issuer on the system is not one of the available token issuers, and selecting, in response to the determining, a token issuer of the available token issuers. Finally, the method includes updating, by a token issuer manager executing on the system, a common IAM service of the system to use the token issuer to grant access to an application executing on the system.
1 . A method for managing token issuers, comprising:
initiating use of an approved external token issuer on a system after a factory configuration;
updating, in response to the initiating and by a token issuer manager, a common identity access manager (IAM) service to use the approved external token issuer;
after the updating of the token issuer manager to use the approved external token issuer:
receiving, by the common IAM service, an authentication request from an application executing on the system;
obtaining, by the token issuer manager and from the common IAM, the authentication request;
forwarding the authentication request to the approved external token issuer;
receiving a token from the approved external token issuer, wherein the token is used to service the authentication request;
after servicing the authentication request and in a disaster situation of the system:
restoring the system on a virtual machine environment based on a backup image of the system;
after the restoring:
identifying available token issuers on the virtual machine environment;
determining that a currently configured token issuer on the system is not one of the available token issuers, wherein the currently configured token issuer is the approved external token issuer;
selecting, in response to the determining, a token issuer of the available token issuers;
updating, by the token issuer manager executing on the system, the common AM service of the system to use the token issuer; and
after the updating, using the token issuer by the common IAM service to grant access to the application executing on the system.
2 . The method of claim 1 , wherein the factory configuration specifies the approved external token issuer and that the common IAM service uses a native token issuer.
3 . The method of claim 2 , wherein the approved external token issuer is not available on the system when the factory configuration is generated.
4 . The method of claim 1 , wherein the currently configured token issuer is the approved external token issuer.
5 . The method of claim 1 , wherein the token issuer is a second external token issuer.
6 . The method of claim 1 , wherein the token issuer is a native token issuer executing on the virtual machine environment and the currently configured token issuer is an external token issuer.
7 . The method of claim 1 , wherein the currently configured token issuer is an external token issuer and wherein the token issuer is a second external token issuer.
8 . A method for managing token issuers, comprising:
initiating use of an approved external token issuer on a system after a factory configuration;
updating, in response to the initiating and by a token issuer manager, a common identity access manager (IAM) service to use the approved external token issuer;
after the updating of the token issuer manager to use the approved external token issuer:
receiving, by the common IAM service, an authentication request from an application executing on the system;
obtaining, by the token issuer manager and from the common IAM, the authentication request;
forwarding the authentication request to the approved external token issuer;
receiving a token from the approved external token issuer, wherein the token is used to service the authentication request;
after servicing the authentication request:
determining that a currently configured token issuer executing on the system has been compromised, wherein the currently configured token issuer is the approved external token issuer;
in response to the determination:
halting use of the currently configured token issuer;
identifying available token issuers accessible by the system;
selecting, in response to the identification, a token issuer of the available token issuers;
updating, by the token issuer manager executing on the system, the common IAM service of the system to use the token issuer; and
after the updating,
invalidating tokens previously issued by the currently configured token issuer; and
using the token issuer by the common IAM service to grant access to the application executing on the system.
9 . The method of claim 8 , wherein the factory configuration specifies the approved external token issuer and that the common IAM service uses a native token issuer.
10 . The method of claim 9 , wherein the approved external token issuer is not available on the system when the factory configuration is generated.
11 . The method of claim 8 , wherein the currently configured token issuer is the approved external token issuer.
12 . The method of claim 8 , wherein the token issuer is a second external token issuer.
13 . The method of claim 8 , wherein the token issuer is a native token issuer executing on the system and the currently configured token issuer is an external token issuer.
14 . The method of claim 8 , wherein the currently configured token issuer is an external token issuer and wherein the token issuer is a second external token issuer.
15 . A method for managing token issuers, comprising:
initiating use of an approved external token issuer on a system after a factory configuration;
updating, in response to the initiating and by a token issuer manager, a common identity access manager (IAM) service to use the approved external token issuer;
after the updating of the token issuer manager to use the approved external token issuer:
receiving, by the common IAM service, an authentication request from an application executing on the system;
obtaining, by the token issuer manager and from the common IAM, the authentication request;
forwarding the authentication request to the approved external token issuer;
receiving a token from the approved external token issuer, wherein the token is used to service the authentication request;
after servicing the authentication request:
determining that a currently configured token issuer executing on the system is unavailable, wherein the currently configured token issuer is the approved external token issuer;
in response to the determination:
identifying available token issuers accessible by the system;
selecting, in response to the identification, a token issuer of the available token issuers;
updating, by the token issuer manager executing on the system, the common IAM service of the system to use the token issuer; and
after the updating,
using the token issuer by the common IAM service to grant access to the application executing on the system.
16 . The method of claim 15 , wherein the factory configuration specifies the approved external token issuer and that the common IAM service uses a native token issuer.
17 . The method of claim 16 , wherein the approved external token issuer is not available on the system when the factory configuration is generated.