The following sections describe some of the major differences between iChain and Access Manager:
With iChain, you have a single machine that provides authentication and authorization for single sign-on to protected resources. Administration is done through multiple applications: the Web application, ConsoleOne®, and sometimes an LDAP browser. The embedded operation system is NetWare®, and at the NetWare console, you use command line options to configure the system.
With Access Manager, you have multiple components. Each component can be installed on its own machine, some can be installed on the same machine, and some can be installed on different operations systems: Linux, Windows, and NetWare. Access Manager has the following components:
Administration Console: Installed on Linux and provides a single point of administration. It stores the configuration for all Access Manager components and uses a modified iManager interface. It can be installed on the same machine as the Identity Server.
Identity Server: Installed on Linux and provides single sign-on authentication, federation with other identity providers, and role and policy distribution. Roles are assigned at authentication time and filter though all components, thus simplifying the definition of authorization policies.
Access Gateway: Installed on Linux or NetWare as a soft appliance and provides single sign-on to Web servers and access control through policies to the resources on the Web servers. You can require SSL connections between the browsers and the Access Gateway, but require only HTTP connections between the Access Gateway and the Web servers, thus reducing the need for certificates on the Web servers.
SSL VPN Server: Installed on Linux and provides single sign-on to private networks with non-HTTP applications.
J2EE Agent: Installed on a J2EE sever to proved fine-grained authorization for J2EE applications and single sign-on. Currently Access Manager has agents for WebSphere, WebLogic, and JBoss* servers installed on Linux or Windows.
One of the first decisions you’ll need to make is which Access Manager components you need (an Administration Console, Identity Server, and Access Gateway are required, the others are optional) and which components you are going to install on separate machines, which ones you are going to combine on a single machine, and what operating systems you want to support.
For a more thorough description of these components, see Section 1.0, Introduction to Novell Access Manager.
The following table lists some of the major features of Access Manager and indicates support levels for both iChain and Access Manager.
Table 10-1 iChain and Access Manager Feature Comparison