11 Mar 2010
Planet Identity
Daniel Raskin - Sun: Make Me a Sandwich!
10 Mar 2010
Planet Identity
Identity 360 - Imprivata: Infosecurity Europe Stand # H40
Join Imprivata at Infosecurity Europe. At this conference, information security professionals will meet for a 3 day event, addressing the challenges of today while preparing for those of tomorrow.
10 Mar 2010 10:09pm GMT
Dave Kearns' IdM Newsletter: Google heats up OpenID
OpenID and OAuth will work in tandem to provide single sign-on to third-party applications that are OpenID relying parties. In fact, the recommendation from Google is that application developers simply provide a button that says "Sign in using a Google Apps account" instead of presenting a log-in box.
10 Mar 2010 9:23pm GMT
Anil Saldhana - Red Hat: Oasis Identity In The Cloud Technical Committee
I am pleased to have ignited the establishment of a new Technical Committee called as "Oasis Identity In The Cloud" at the Oasis standards consortium. Prominent security experts in the industry were gracious to participate in the initial brainstorming group I created.
You can read more on the charter here: IDCloud Charter
Apart from Red Hat, the proposers of the TC include Microsoft, IBM, CA, Novell, Rackspace, SafeNet, Yaana Technologies along with a few prominent individuals in the security/identity space. I am sure the proposer list will grow in a few days.
If you are an Oasis member or your company is an Oasis member, you should definitely look at joining this effort.
More details and a call for participation will be announced by the Oasis consortium in a few days.
Keywords: Oasis Cloud Security.
10 Mar 2010 9:12pm GMT
Jackson Shaw - Quest: True story: After being away 2 years I wish I was de-provisioned!
I had lunch with my friend "Jason" from Universal Widgets last week. We hadn't talked for more than two years and Jason's first comment was "Did you know I left Universal to go work for Galactic Widgets but I've gone back to Universal Widgets?" I was surprised because I had missed out on what my friend was up to for more than two years. But, here we were back at the beginning again. Anyway, we had a good discussion about what each of us were up to but the most interesting part of Jason's story was his answer to this question: "How was your return to Universal?"
Jason answered that they hadn't allocated his desk to anyone else so it looked as if a "Jason shrine" had developed while he was gone. "But the worse part of my return was that I was able to logon with my old userid and password!" Where had I heard this before? However, rather than agreeing with me Jason's comment was: "The worse part was when I started Outlook and I had 25,000 unread messages!"
I guess there can be some things even worse than a security compromise with not being de-provisioned and that's coming back to two years worth of unread e-mails! I think Jason is still too busy deleting messages to answer his phone…
10 Mar 2010 8:30pm GMT
Neil Wilson - UnboundID: Large result sets in the LDAP SDK
One of the things that I think is particularly nice about the UnboundID LDAP SDK for Java is the way that it allows you to perform a search and have it collect the matching entries in a list that is available in the search result. However, this is really only well suited for cases in which you're sure that you won't get a huge number of entries returned because otherwise the need to hold all of the matching entries at once can cause significant memory problems.
However, if you are going to be dealing with large search result sets, then the LDAP SDK provides a couple of additional APIs that may be of use. The SearchResultListener interface defines methods that can be invoked whenever an entry or reference is returned by the server that allows you to act on that entry or reference as soon as it is received. I've had a number of people ask for an example of how to use this interface, so I've created a simple program, WriteAttrToFileUsingListener.java, that you can use to accomplish this. It's a pretty simple program that performs a search to retrieve all entries containing a specified attribute, and then writes all of the values for that attribute to a specified output file. It's a little more complex than it absolutely needs to be in order to demonstrate just the SearchResultListener interface, but it also serves as a nice example of the LDAPCommandLineTool API that you can use to easily write command-line utilities that need to talk to a directory server.
We also have another class, LDAPEntrySource, which can be used to make dealing with large result sets easier. This class provides an implementation of the EntrySource API (which makes it easy to iterate across entries in a common way regardless of how they were obtained, like returned as search results or read from an LDIF file), and you can treat it kind of like an iterator across search entries. I've created another version of the example program, WriteAttrToFileUsingEntrySource.java, that demonstrates how to use the LDAPEntrySource as an alternative to SearchResultListener to achieve the same result.
10 Mar 2010 6:37pm GMT
Chris Ceppi - Ping Identity: Google Apps Marketplace - Seamless is the Move
I walked out of the Google Apps Marketplace launch last night in Mountain View convinced of a couple of things. One, Google consistently gives out cool schwag, caters well, and runs some of the best lit PR events in the...
10 Mar 2010 3:34pm GMT
Ludovic Poitou - Sun: OpenDS Tab Sweep
It's been a while since I last posted an OpenDS tab sweep. So here's a list of news and pointers related to our open source LDAP directory server.
PCQuest Top Story this month is about the Top 10 Enterprise Open Source Apps, which include OpenDS and an article on Managing Identities with OpenDS.
The OpenDS project is starting to demonstrate its maturity. Several startups and software companies are now officially supporting OpenDS.
iConcur Software delivers new Axiom a Requirements management tool integrates by default with OpenDS.
Bonitasoft, the leader in open source Business Process Management (BPM) and a Grenoble based company, uses OpenDS for testing its support of LDAP repositories and praises it to its own customers, for its ease of use. Ask @rodrigue !
Symeos, another high profile French startup is building its Symeos Appliance Framework on open source projects including GlassFish, OpenSSO and OpenDS.
Janua, a French IT services company specialized in identity projects has included OpenDS in its product offering and has just launched a new site for its LDAPTools.
Sopera, a german company building open source SOA is integrating OpenDS in its development tools and offering, as shown on the screenshot below (courtesy of SpringSource)
Also in the recent days a couple of new LDAP browsers appeared.
- Symlabs announced a Free LDAP Browser, tested to work against many directory servers including Sun Directory Server Enterprise Edition, Oracle Internet Directory and OpenDS. The browser is currently available for Solaris, Linux and Windows.
- For the developers who are using NetBeans, Allan Lykke Christensen is rapidly developing a Maven-based NetBeans module for exploring LDAP services from within NetBeans. The plugin works well with OpenDS, but is currently only offering a read only view of the data.
Finally, in a introductory article titled Microsoft Azure for the Dummies, Ernest regrets the lack of flexibility in the PaaS plans from Microsoft and suggest that Java based OpenDS directory Server as a good alternative for running your own LDAP service on MS infrastructure.
Technorati Tags: directory-server, identity, ldap, opends, opensource, software
10 Mar 2010 3:12pm GMT
Phil Windley - Kynetx: The Power of Pull
This week on the Technometria podcast, Scott and I talk to David Siegel, the author of The Power of Pull. David talked to me one or two times quite a while back about identity as he was researching this...
10 Mar 2010 3:11pm GMT
Marc Canter - Broadband Mechanics: Spring break @ Case week
This is when everyone can get work done - when the students are away!
Congrats to John Slanina on a job - in Youngstown!
The year Open Data went worldwide
Jon Medved on Entrepreneurism b'Israel
5 reasons why your company should be distributed
Universities and Open Access - interview with David Weinberger
Dave is upset that they watered down Alice, made it more palatable for American/mainstream palettes. My daughters enjoyed it - regardless.
JayCut - white labeled on-line video editor with Open APIs
Penton Publishing is bankrupt - just walked away from $270M in debt
100 mbps coverage coming - en masse
Prezi, Reaktor 5, CrowdSpring, JayCut, the NYC Data mine, Open Clip Art Library, sfe
10 Mar 2010 6:29am GMT
09 Mar 2010
Planet Identity
Marc Canter - Broadband Mechanics: Case Connection Zone in the WSJ
The project we're working on here at CWRU was written up in the WSJ today. Unfortunately I can't link to the full article, as it's behind a paywall.
In it Lev Gonick (the CIO of CWRU) explains that we're working on figuring out the recipes for success of ultra high-speed connectivity.
"What do you DO with a 1G connection?"
That is the question.
Now for some answers.
What we launch in late May '10 won't be the final answer, but it'll be a beginning.
By combining advanced health, energy, education and safety services, a personalized News page and a social network, with blogging, activity streams, live-video help, groups with media sharing we hope to start to answer the question.
Now throw in some compelling local content and services and you've got yourself a full fledged ultra high-speed dashboard 2.0.
And that is what is required of every Digital City.
09 Mar 2010 10:11pm GMT
Dave Kearns' IdM Newsletter: Axiomatics, European Entitlement Management specialist, accelerates its US expansion by hiring top IAM analyst Gerry Gebel
Former VP and Service Director for Burton Group Identity and Privacy Strategies, Gerry Gebel, has joined leading entitlement management experts, Axiomatics. Gebel brings more than 25 years of relevant experience to the company both from the Burton Group and from his time in the financial services industry.
09 Mar 2010 7:02pm GMT
Dave Kearns' IdM Newsletter: The business of business is trust
The role of government, Jánszky says, is simple: Stop trying to build walls around the consumer and instead focus on passing laws that enable companies to use personal information, provided they do so in a responsible way and with the full content and oversight of the consumer.
09 Mar 2010 4:06pm GMT
Dave Kearns' IdM Newsletter: SAML vs. XACML for Authorization: VHS versus Betamax?
Who will win the war? I don't know but there's something to be said about the fact that progress is being made faster with SAML than XACML.
09 Mar 2010 3:44pm GMT
Jackson Shaw - Quest: SAML vs. XACML for Authorization: VHS versus Betamax?
Is SAML the right "thing" for authorization? Hmmm, I guess if I were a purist I'd say "No" but since I'm a pragmatist I'd say "If it works for your application then use it". In either case, this brings me to wonder about SAML and XACML from an authorization perspective. Will there be a Betamax versus VHS war in the authorization space? Hard to say. I know Microsoft will be support SAML tokens with the release of ADFS V2 later this quarter. They won't be supporting XACML.
Who will win the war? I don't know but there's something to be said about the fact that progress is being made faster with SAML than XACML. Draw your own conclusions…As they say, time will tell.
09 Mar 2010 1:56pm GMT
JISC Access Management Team: Can you solve this problem for me?
I have a bunch of spreadsheets. Each spreadsheet represents one institution. Each spreadsheet contains a list of resources that institution subscribes to. I want to turn this around so that I end up with one spreadsheet with each resource as column, and each institution that subscribes to that resource underneath it. [...]
09 Mar 2010 1:05pm GMT

