Sunday, March 22, 2015

Single Sign On (SSO) for Windchill PLM

IDEA

Single Sign-On for Windchill PLM provides simplified access using Integrated Windows Authentication and SAML based web browser exchanges. It is First to Market to integrate PingFederate WS-Federation with Windchill PLM. Single Sign-On provides highly secure user authentication with seamless switch between different applications and reduced IT administration costs.






CLIENT


It is diversified health and Well-being Company, focused on improving people’s lives through meaningful innovation in the areas of Healthcare, Consumer Lifestyle and Lighting. It is listed in Fortune 500 company which sales and services in more than 100 countries





BUSINESS SITUATION




Client wanted to standardize on authentication to applications using industry standards for achieving single sign on (SSO) for Windchill PLM. This included building a federation capability and removal of usage/storage of user names and passwords in Windchill.




HOW WE HELPED




The highlights of this solution being,
·         Recommended Shibboleth as SAML based middleware between Apache and PingFederate since Windchill uses Apache for the authentication.
·         Configured PingFederate 7.1.3 as Identity Provider (IdP) and Shibboleth as Service Provider (SP).
·         Shibboleth-Apache integration for Windchill PLM authentication.
·         Arcot AOK integration for internet based user authentication requests.
·         Form based authentication for non-person user IDs especially since the required solution was Integrated Windows Authentication.
·         Advanced Configurations for specific Windchill modules :
*        PTC Workgroup Manager
*        Windchill Product Analytics.
*        Desktop Integration(DTI)
*        PTC System Monitor
·         Developed a solution for integration of IBM Cognos and Windchill PLM with Amazon Cloud, SSL, SSO, and Reverse Proxy.
·         Deployed SSO Solution on reverse proxy Apache for bi-layered security.
·         Corporate LDAP integration for additional enterprise-wide user attributes like Digital Signatures for Change Tasks.









BUSINESS IMPACT



PTC's Windchill PLM SSO Solution resulted in various key benefits such as:

First to Market - Windchill PLM SSO Solution team delivered challenging goal of client to integrate PTC’s Windchill PLM enterprise application with Ping Federate using Shibboleth SAML-based Middleware.


Productivity Boost - We helped client users to move between services securely and uninterrupted without specifying their credentials each time. Having to remember and key-in only one password significantly cuts down login time and reduces the chances of a failed login. Thus, SSO can enable users to buckle down to work right away.

Secured Windchill over Internet - The users’ credentials are provided directly to the central SSO server, not the actual service that the user is trying to access, and therefore the credentials cannot be cached by the service.  The central authentication point – Implemented SSO service – limits the possibility of phishing.

Windchill Administration Cost Reduction - Windchill administrators can save their time and resources by utilizing the central web access management service. Also SSO will allow users to remember just one password, reduce the chances of forgotten passwords, and consequently bring down Help Desk costs.


Disclosure: I’m responsible for Infrastructure Solutions as service.



Wednesday, March 18, 2015

Windchill PLM on Amazon Cloud

IDEA

Cloud Computing for Windchill PLM which provides a simple way to access servers, storage, databases and a broad set of application services in isolated network. It is First to Market to host internet facing enterprise application Windchill PLM over Amazon Cloud. It should also serve multi-site requirement of Security, High availability, Application Performance.

CLIENT
It is diversified health and Well-being Company, focused on improving people’s lives through meaningful innovation.

BUSINESS SITUATION
Client wanted to use Cloud Computing for Windchill PLM which provides a simple way to access servers, storage, databases and a broad set of application services in isolated network. It is First to Market to host internet facing enterprise application Windchill PLM over Amazon Cloud. It should also serve multi-site requirement of Security, High availability, Application Performance.



HOW WE HELPED
We Infrastructure services expertise to achieve the application hosting over Amazon Cloud. The highlights of this solution being,


·         Architecture Design and deployment of Load Balanced Windchill PLM Cluster.
·          Deployed and managed Amazon Elastic Compute Cloud (Amazon EC2) instances using Amazon Control Tower.
·          Recommended Hardware Sizing for Amazon EC2 Instances for Windchill Cluster.
·          Recommended and deployed High Availability solution using multiple availability zone and Elastic Load Balancer (ELB).
·          Deployed APM – Application Performance Management tool Compuware dynaTrace and user experience management module.
·          Windchill PLM and IBM Cognos integration deployment in Amazon VPC.
·          Recommended and configured Amazon Relational Database Service (Amazon RDS) with Windchill PLM
·          Configured to use Amazon Virtual Private Cloud (Amazon VPC) for advanced security features such as security groups and network access control for Windchill PLM


BUSINESS IMPACT
Windchill PLM Infrastructure Solution for Amazon Cloud resulted in various key benefits such as:

 First to Market - Windchill PLM Infrastructure Solution team delivered challenging goal of client to deploy PTC’s Windchill PLM enterprise application in Amazon Cloud.


Flexible, On-Demand and tailor Made Enterprise application hosting in Cloud - We helped client to select Flexible, On-Demand and Tailor Made instances for better utilization memory, CPU, instance storage, operating system and database.


Secured Windchill website over Internet - We deployed Amazon VPC (Virtual Private Cloud) behind WAF (Web Application Firewall) of Akamai and isolated network with security groups.


Minimal and restricted corporate network interaction with Amazon cloud - Deployed Secured Corporate LDAP integration with Windchill PLM in Amazon Cloud.

 

Cost Reduction - Wedelivered financial benefits to client, client paid a very low rate for the compute capacity they actually consumed.

Disclosure: I’m responsible for Infrastructure Solutions as service.