Blog
Articles, tutorials, and field notes on identity, integration, API management, and application security — spanning nearly two decades of hands-on work.
Articles, tutorials, and field notes on identity, integration, API management, and application security — spanning nearly two decades of hands-on work.
I generally recommend to clients that DataPower RBM (Role-Based Management) be configured to perform authentication and authorization of DataPower administrators and developers with LDAP. In particular, whatever respository serves as the central repository of user information should be used (of…
I’ve been in a couple of shops that have used the HSM module option of DataPower for FIPS 140-2 v2 or v3 compliance. An HSM is a Hardware Security Module. My understanding is that there is a short list of IBM customers that are using this technology. I thought collecting all the information and…
I will be presenting at JBoss World 2012 in Boston the last week of June. I’ll be presenting with Anil Saldana on JBoss Security, PicketLink, and Identity Management, JBoss Security Architect. A link to the description can be found here. The original abstract:
I was recently presented with an opportunity to be clever while promoting DataPower objects from a development environment to a testing environment. The WS-Proxy object’s policy rules had a Transform Action that ran a custom stylesheet. The stylesheet referenced a configuration file that was kept…
Anyone who has worked with DataPower for a while has gotten into a situation where they need to rename a service object (XML Firewall, WS-Proxy, Multi-Protocol Gateway, etc). There isn’t a rename button that I have ever found. This tutorial will describe two ways of renaming such objects.
I listed several of Thomas Erl’s books in my SOA Recommended reading list. A full list of Thomas Erl’s series of SOA books can be found here. Anyone working in the SOA space, regardless of vendor or technology stack, should read these books.
The definition of the word ownership has varying meanings across organizations, but there is always a group that retains control of the technology. It’s typically the group that sponsored the adoption of the technology and owns day-to-day support of it. But, sometimes, the technology initiative…
DataPower has a serial port console that is used during initial bootstrap of the appliance, recovering from problems, and certain configuration changes. Having access to the serial console is the only feasible approach to resolving certain issues that arise with any appliance (or piece of network…
DataPower is a weird (but, wonderful) beast. It has a tendency to break some of the traditional IT silos that develop within infrastructure groups. That can lead to a lot of friction and amusing arguments in which everyone is simply talking past one another. In this post, I want to describe the…
I have been in several different shops that are either deploying DataPower or are a few years after deploying DataPower. I’ve also had opportunities to talk to numerous different DataPower technical resources about how they have utilized DataPower. In the post, I want to describe what I’ve seen as…
I’ve been playing with Cisco switches and routers recently at home to get a handle on VLANs-more about VLANs later. Some people I know who have gotten involved in DataPower started out in system administration or networking and worked their way up the technology stack to SOA Appliances (WebSphere…
A couple of weeks ago I wrote a brief post about how to generate symmetric keys that can be used with DataPower. It demonstrates how to generate shared keys of various lengths using the Unix dd command. Today, someone asked how a shared key (or symmetric key) can be generated using the openssl…