Blog
Articles, tutorials, and field notes on identity, integration, API management, and application security — spanning nearly two decades of hands-on work.
Articles, tutorials, and field notes on identity, integration, API management, and application security — spanning nearly two decades of hands-on work.
I’ve talked about authentication many times on ThinkMiddleware.com. It recently occurred to me that I have never devoted a blog post to defining authentication. I’ve had a section on the subject in a couple of different places, but I wanted to have an article to reference from other posts. So, here…
The primary administration automation mechanism on IBM WebSphere DataPower appliances is the XML Management Interface. The XMI interface allows one to make SOMA (SOAP Configuration Management, assuming SOMA = SOap MAnagement) calls to perform various administration tasks. How to perform these…
A few months ago I switched from using Cisco’s QuickVPN software to the ShrewSoft VPN Client for Windows. I’m not going to get into the issues that I had with QuickVPN-it wasn’t very reliable. I’ve had ShrewSoft VPN for Windows v2.1.7 connecting to a Cisco RV082 VPN router. ShrewSoft provides…
In a previous blog post, I listed a number of SOA Specs and Security Specs that I thought were important to be familiar with when working with DataPower and other SOA technologies. In this post, I made a quick (and dirty) Visio diagram that I tend to draw up on a whiteboard when I’m at a new client…
While working with DataPower and Active Directory (acting as the User Repository) I have often run into situation where AD returns an LDAP error code 49 plus a sub-code in the error string that is unique to AD. The sub-code can be very useful to troubleshooting, if you know what it means.
In the last post, we saw how an XML Firewall in loopback mode could be used to return a valid SOAP response to a service message. The stylesheet used simply returned a static SOAP response that was independent of the input parameters. The stylesheet returns a response containing the sum of two…
It is often the case that a DataPower developer will have work to do, but does not yet have a backend Service Provider to point the DataPower service at. In general, anything beyond trivial examples will need to point at something that returns a valid response. In order to satisfy this requirement,…
Another use-case that I touched on during my JBoss World 2012 presentation was using the PicketLink WS-Trust Client implementation to communicate with third-party Security Token Services. In particular, we discussed how the PicketLink SAML2STSIssuingLoginModule can communicate with the IBM Tivoli…
I’ve been at a couple of different client sites where there was a heavy IBM product presence, the use of IBM’s proprietary token format-LTPA2, and the need for a non-IBM technology such as JBoss EAP. Given the nature of the LTPA2 technology (IBM proprietary protocol), there isn’t any direct support…
Ever since I was first started working with IBM WebSphere DataPower I was looking around for someone that was offering access to a IBM WebSphere Datapower, I was looking around for someone that was offering access to an Internet-facing appliance that I could use for experimenting and learning. I…
It’s been a few weeks since I have posted any updates. I started a new project at the beginning of June; it always takes a few weeks to get up to speed on an extended project. Integrating the IBM Tivoli Security stack and JBoss EAP was the subject of my JBoss World 2012 presentation.
I was recently involved in a conversation where someone asked the question what is FGA (Fine Grained Authorization) versus Coarse Grained Authorization(CGA)? From their perspective, there was just authorization. Further distinction was not needed.