pre-con ed: ca api gateway: developing custom policies to secure your enterprise apis

10
Developing Custom Policies to Secure Your Enterprise APIs Jamie Williams Senior Software Engineer CA Technologies DO3X47EV DEVOPS

Upload: ca-technologies

Post on 10-Jan-2017

84 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

Developing Custom Policies to Secure Your Enterprise APIsJamie WilliamsSenior Software EngineerCA Technologies

DO3X47EV

DEVOPS

Page 2: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

3 © 2016 CA. ALL RIGHTS RESERVED.@CAWORLD #CAWORLD

© 2016 CA. All rights reserved. All trademarks referenced herein belong to their respective companies.

The content provided in this CA World 2016 presentation is intended for informational purposes only and does not form any type of warranty. The information provided by a CA partner and/or CA customer has not been reviewed for accuracy by CA.

For Informational Purposes Only Terms of this Presentation

Page 3: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

4 © 2016 CA. ALL RIGHTS RESERVED.@CAWORLD #CAWORLD

Abstract

In this session on CA API Gateway we'll focus on basic policy creation and demonstrate the ease with which enterprise APIs can be secured.

We will also spend some time on policy performance factors, troubleshooting, and understanding points of failure when securing APIs.

Jamie WilliamsCA TechnologiesSenior Software Engineer

Page 4: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

5 © 2016 CA. ALL RIGHTS RESERVED.@CAWORLD #CAWORLD

Agenda

INTRODUCTION TO SERVICES, POLICIES, AND ASSERTIONS

SECURING YOUR API

PERFORMANCE CONSIDERATIONS

TROUBLESHOOTING

1

2

3

4

Page 5: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

6 © 2016 CA. ALL RIGHTS RESERVED.@CAWORLD #CAWORLD

Introduction to Services, Policies, and Assertions

A Service is a logical construct that represents the sum of the API calls the client side can call to access the service that the Gateway is protecting

Every service has a policy that implements an individual flow of data between the client and the back-end service

Assertions are the building blocks of policy that determine the authentication method, identity credentials, transport method, and routing method for the service

Page 6: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

7 © 2016 CA. ALL RIGHTS RESERVED.@CAWORLD #CAWORLD

Live Demo

Page 7: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

8 © 2016 CA. ALL RIGHTS RESERVED.@CAWORLD #CAWORLD

Recommended Sessions

SESSION # TITLE DATE/TIME

DO3X49E CA API Gateway: Managing and migrating Gateway policies with the Gateway Migration Utility 11/14/2016 at 11:00 am

DO3X52E CA Mobile App Services: Build the Powerful Mobile App Every Enterprise Needs in Under an Hour 11/14/2016 at 1:00 pm

DO3X51E Workshop on Policy Creation, Management and Support for OAuth and OIDC in CA Mobile API Gateway 11/14/2016 at 2:00 pm

Page 8: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

9 © 2016 CA. ALL RIGHTS RESERVED.@CAWORLD #CAWORLD

Questions?

Page 9: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

10 © 2016 CA. ALL RIGHTS RESERVED.@CAWORLD #CAWORLD

Thank you.

Stay connected at communities.ca.com

Page 10: Pre-Con Ed: CA API Gateway: Developing Custom Policies to Secure Your Enterprise APIs

@CAWORLD #CAWORLD © 2016 CA. All RIGHTS RESERVED.11 @CAWORLD #CAWORLD

DevOps – API Management and Application Development

For more information on DevOps – API Management and Application Development, please visit: http://cainc.to/DL8ozQ