Superpatterns

Pat Patterson on Identity Management, Federation and Single Malt Scotch
         

accessmanager adfs authentication authorization bloggers blogwatch burtongroup cardspace catalyst donbowen extensions fam federation federationmanager fisl identity idwsf infocard java libertyalliance lightbulb links microsoft opends openid opensource opensso php planetidentity podcast roller saml sdn sso sun tokyo ubuntu video webservices wsfederation
 
Be an Identity Hero!
[ ]

It's Friday afternoon, time for some fun! We've put together a neat little game where you can protect your enterprise from the like of disgruntled former employees, Sarbox gremlins and the deadly auditors with the help of Sun's identity management products: Identity Hero! Here's a screenshot:

Go save your enterprise!

@ 02:16 PM PDT Comments [0]
 
 
 
OpenSSO at JavaOne
[ ]

Marina is covering JavaOne 2008 for the Sun Developer Network - she's written a review of our Monday OpenSSO session, which also appears in the today's 'JavaOne Today' newspaper. Lucas Jellema at AMIS Technology also wrote a nice review, even including a screenshot of OpenSSO.

If you're at JavaOne, come along to the Sun stand in the pavilion - we're on pod 181, just under the poster of an old geezer with a red pickup. I'll be here today (Wednesday) and tomorrow (Thursday) from 11am to 2pm, but feel free to stop by any time the pavilion is open for a demo and a chat.

@ 11:25 AM PDT Comments [0]
 
 
 
The Fedlet Lives!!!
[ ]

If you're following OpenSSO at all, you can't have failed to notice the recent buzz around the Fedlet - from Daniel (complete with screencast), Eve Mark D, Mark H, Tatsuo, Derrick, Marina and Daniel at Sun to Coté at RedMonk and Enrico at Tenthline.

Briefly, the 'Fedlet' is a package that a SAML 2.0 identity provider can create to quickly federation-enable a small service provider. The idea is that, if you're running a single web application, you're not going to want to deploy a whole 'nother server to run a standalone service provider. What you want is a little package of code and configuration to federation-enable your web app. You want the Fedlet.

I've been wrapped up in demos and travel for the past month or so, so I haven't had much of a chance to play with the Fedlet. Since I'm planning to demo it in my session at CommunityOne on Monday, I thought I'd better do so - I set aside this afternoon to get it working. Turns out I was a little pessimistic there - here's what I did, in less than an hour:

  • Update from OpenSSO CVS (cvs -q update -dP)
  • Cleaned out previous build detritus and built the WAR file (ant clean && ant server-war)
  • Deployed onto Glassfish (don't forget to change GF's -client JVM option to -server, as detailed in the release notes!)
  • Pointed Flock (my preferred web browser du jour) at the newly deployed OpenSSO at http://demo.example.com:8000/opensso (I alias demo.example.com to 127.0.0.1 in /etc/hosts), configured OpenSSO to use the embedded OpenDS instance for its configuration and user stores.
  • Logged in as amadmin, created a SAML 2.0 identity provider and a Fedlet.
  • Unzipped the Fedlet, deployed it into Glassfish.
  • Ran the Federation validator to check that SSO is operational.
  • And...

When you spend your time in the weeds of a project, you always half expect any given step to fail due to some issue or another. Perhaps some recent fix destabilized something; perhaps some errant process has eaten my laptop's memory; whatever. So it was extremely gratifying when all of the above passed off without a hitch. I won't tell you what I muttered under my breath as the federation validator completed and gave me the thumbs up, but the second word was "cool!"

@ 03:19 PM PDT Comments [2]
 
links for 2008-05-01
[ ]
@ 07:31 AM PDT Comments [0]
 
 
 
links for 2008-04-30
[ ]
@ 07:32 AM PDT Comments [0]
 
 
 
CommunityOne OpenSSO Session - Monday May 5, 4pm, E135
[ ]

I mentioned our upcoming CommunityOne session back when I posted my Spring/Summer schedule; now I have a time and place, since the CommunityOne schedule was just published. We'll be presenting "OpenSSO Workshop: Creating Federated Relationships with Software as a Service, Social Networking, and Web 2.0 Applications" on Monday May 5 at 4pm in Hall E 135.

By the way, CommunityOne is free of charge to attend, though you do need to register. See you there!

@ 02:38 PM PDT Comments [1]
 
OpenSSO @ FISL 9.0
[ ]

Nice pic of me kicking off my OpenSSO preso at FISL - thanks, boaglio!

@ 10:06 AM PDT Comments [0]
 
 
 
FISL 9.0 Pictures from Ken D
[ ]

Fellow blogger and Glassfish marketeer Ken Drachnik took this appealing (appalling?) photo of me doing a Steve Ballmer impression at a post-FISL dinner... More FISL photos from Ken.

@ 12:28 PM PDT Comments [0]
 
 
 
Slides from OpenSSO Presentation at FISL 9.0 - April 19 2008
[ ]

As promised, here are the slides to my presentation this evening at FISL 9.0. I've had a great time here in Brazil - wonderful people, fabulous food and kicking cachaça. I'll definitely be back sometime in the future.

@ 03:29 PM PDT Comments [0]
 
 
 
Fetching User Attributes With Identity Services
[ ]

As I just blogged over at The Aquarium, Aravindan, Lakshman and Marina just published part 3 of their series on the new identity services functionality available now in OpenSSO and coming soon in Sun Federated Access Manager 8.0: Securing Applications With Identity Services, Part 3: User Attributes.

User attributes are key for delivering personalized services, and are often the main reason for authenticating the user in the first place. Go read the article - whether you're a RESTafarian or on the SOAPy side - you can quickly and easily put OpenSSO's identity services to work.

@ 07:31 PM PDT Comments [0]
 
Sala Radia Perlman
[ ]

Had to get a shot of this - Radia was my SEED mentor a little while ago - now she's been commemorated in the naming of the press room here at FISL. Kind of appropriate for a pioneer in communications

@ 02:31 PM PDT Comments [0]
 
OLPC Brasil
[ ]

Wandering around FISL, I keep seeing gaggles of schoolkids with XO Laptops. Then I stumbled on the LEC booth:

Some very satisfied customers there!

@ 11:52 AM PDT Comments [0]
 
Living with Sun Open-Source - OpenSSO
[ ]

This will only be useful if you know MUCH more Japanese than I do, but here's Yasushi Iwakata introducing OpenSSO at a Java Hot-Topic Seminar in Tokyo, as blogged by Takayuki Okazaki:

You'll be able to download the slides soon - I'll update this entry with the link.

As he mentions in the video, Iwakata-san has also been working on an OpenSSO Extension for Hitachi Finger Vein Authentication. You can find the code in the OpenSSO CVS at opensso/extensions/authnhfvb, or browse it online. I'll write more about this extension when I get back home from Brazil.

@ 07:45 AM PDT Comments [0]
 
links for 2008-04-18
[ ]
@ 07:31 AM PDT Comments [0]
 
 
 
Blogging from 35,000ft
[ ]

I'm sitting in seat 20A of Delta flight 101 from Atlanta to Buenos Aires, catching up with the blogging backlog that built up during the RSA Conference. I usually compose my blog entries directly in Roller's web UI, but, since there bain't be no Interweb up here, I'm using Flock's built-in blog editor, and a very comfortable experience it is. I can type up the bulk of the text in the 'Editor' view, tweak formatting in 'Source' view and get a pretty good idea of how it will look in 'Preview', fiipping back and forth as I go.

While this is very convenient, what is really cool is that I have Flock in 'offline' mode, but it allows me to load pages from its cache, so, since most everything I've looked at lately is cached, I can just go to a URL, and I see it exactly as if I was connected. This lets me look up links, check references, even view source to remind myself of the formatting I use when posting over at The Aquarium. In fact, it's probably more productive than being connected, since there's no email to distract me

@ 12:46 PM PDT Comments [1]
 
 
 
 
    Identity Management Buzz Podcast
    Stay connected to news, show notes and leave your feedback.
visits since 9/21/2005
    Listening To
    Listen to Radio Pat
    www.flickr.com
    superpat7's photos More of superpat7's photos
    Technorati
Valid XHTML or CSS?
[This is a Roller site]
Original theme by Rowell Sotto. Heavily modified by Pat Patterson.