Well, JBoss Security is not just security specified by the Java EE specifications. With my active participation as the Red Hat representative on JSR-196 at the JCP and Oasis Technical Committees on SAML, XACML, PKI, EKMI and WS-Federation, I am always exploring new things that will make the users of JBoss security feel more secure and have confidence in adopting JBoss as the platform for secure computing.
Given this, I am always happy to interact with my users. You can always send me an email at anil (AT) saldhana (AT) redhat (dot) com. I may not answer immediately but will certainly get back to you, provided you are talking about some meaningful stuff. New features, new directions, new requirements will all be met with glee while RTFM type questions will be ignored.
I also represent on the Security Context Working Group at the W3C.
This blog is a personal book on Security/ IDM related thoughts/opinions. The blog posts are a personal opinion only and neither reflect the views of current/past employers nor any OTHER person living/dead on this planet.
Google Site Search
Saturday, May 12, 2007
Have you noticed JBoss4.2.0.GA?
If you have not noticed Rajesh's email on the JBoss.org development mailing list, then you should look at the new JBoss 4.2.0.GA release to the community.
You can download it from:
http://sourceforge.net/project/showfiles.php?group_id=22866&package_id=16942&release_id=507793
The release notes:
http://sourceforge.net/project/shownotes.php?release_id=507793&group_id=22866
For security, the following may be interesting:
[ JBAS-1824 ] JACC: * in web.xml should allow configurable authorization bypass
[ JBAS-2895 ] Extend SecureIdentityLoginModule to externalize the secret
[ JBAS-3400 ] JaasSecurityManagerService can show security provider/JCA algorithm information
[ JBAS-1537 ] When Tomcat error handler is invoked, JBossGenericPrincipal is returned instead of custom principal
[ JBAS-4158 ] JACC:WebUserDataPermission creation for unchecked policy should consider excluded constraints
[ JBAS-4149 ] Update Jacc Authorization to consider deployment level roles
There are other security related stuff in the release.
If you have an opportunity, just use it.
You can download it from:
http://sourceforge.net/project/showfiles.php?group_id=22866&package_id=16942&release_id=507793
The release notes:
http://sourceforge.net/project/shownotes.php?release_id=507793&group_id=22866
For security, the following may be interesting:
[ JBAS-1824 ] JACC: * in web.xml should allow configurable authorization bypass
[ JBAS-2895 ] Extend SecureIdentityLoginModule to externalize the secret
[ JBAS-3400 ] JaasSecurityManagerService can show security provider/JCA algorithm information
[ JBAS-1537 ] When Tomcat error handler is invoked, JBossGenericPrincipal is returned instead of custom principal
[ JBAS-4158 ] JACC:WebUserDataPermission creation for unchecked policy should consider excluded constraints
[ JBAS-4149 ] Update Jacc Authorization to consider deployment level roles
There are other security related stuff in the release.
If you have an opportunity, just use it.
Friday, May 4, 2007
ApacheCon Europe 2007 Presentation
Today I finished a very successful presentation at the ApacheCon Europe 2007 in Amsterdam. The presentation is titled 'Understanding Apache Tomcat Security'. It basically is a presentation on writing custom valves/authenticators and realms.
The presentation is available at:
Understanding Apache Tomcat Security
The presentation is available at:
Understanding Apache Tomcat Security
Subscribe to:
Posts (Atom)