<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:planet="http://planet.intertwingly.net/" xmlns:indexing="urn:atom-extension:indexing" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" indexing:index="no"><access:restriction xmlns:access="http://www.bloglines.com/about/specs/fac-1.0" relationship="deny" />
  <title>Planet Identity</title>
  <updated>2010-09-02T22:34:26Z</updated>
  <generator uri="http://intertwingly.net/code/venus/">Venus</generator>
  <author>
    <name>Pat Patterson</name>
    <email>pat@superpat.com</email>
  </author>
  <id>http://planetidentity.org/atom.xml</id>
  
  <link href="http://planetidentity.org" rel="alternate" />

  <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/PlanetIdentity" /><feedburner:info uri="planetidentity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry>
    <id>tag:blogger.com,1999:blog-3200930.post-7409949046922872255</id>
    <link href="http://epeus.blogspot.com/feeds/7409949046922872255/comments/default" rel="replies" type="application/atom+xml" />
    <link href="https://www.blogger.com/comment.g?blogID=3200930&amp;postID=7409949046922872255" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/3200930/posts/default/7409949046922872255" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/3200930/posts/default/7409949046922872255" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/QKQ1T2z5ksE/welcome-apple-seriously.html" rel="alternate" type="text/html" />
    <title>Kevin Marks: Welcome Apple, seriously</title>
    <content type="html">&lt;p&gt;Yesterday's update of iTunes added &lt;a href="http://www.apple.com/itunes/ping/"&gt;Ping&lt;/a&gt;, a music-focused social network. When I tried it out early in the evening, it had Facebook Connect enabled, and both imported friends from Facebook, and notified me when new ones joined. Shortly afterwards, &lt;a href="http://c.itunes.apple.com/WebObjects/MZConnections.woa/wa/viewProfile?userId=172394997"&gt;Mark Zuckerberg joined&lt;/a&gt;, and shortly after that the Facebook connection was missing.&lt;br&gt;This morning, neither company is talking on the record, though &lt;a href="http://kara.allthingsd.com/20100902/facebook-blocked-api-access-to-ping-after-failure-to-strike-agreement-so-apple-removed-feature-after-launch/"&gt;Kara Swisher reports&lt;/a&gt; that Steve Jobs complained about 'onerous terms' from Facebook.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.flickr.com/photos/psd/2592742563/" title="Supernova by psd, on Flickr"&gt;&lt;img alt="Supernova" height="188" src="http://farm4.static.flickr.com/3101/2592742563_5e96da5494_m.jpg" style="float: right;" width="240"&gt;&lt;/img&gt;&lt;/a&gt; This naturally reminds me of the problems we had with &lt;a href="http://googlecode.blogspot.com/2008/05/how-google-friend-connect-works.html"&gt;Google Friend Connect&lt;/a&gt;, where Facebook's accusation of a ToS violation was never backed up by an explanation of what would not violate the terms, leading to the &lt;a href="http://techcrunch.com/2008/06/17/not-so-social-google-and-facebook-face-off-at-supernova/"&gt;"Data Roach Motel" accusations at Supernova&lt;/a&gt;. The underlying issue is whether you should give another company veto power over your application. Last time I wrote on this, it was &lt;a href="http://epeus.blogspot.com/2010/06/steve-jobs-and-curates-egg.html"&gt;Apple's veto&lt;/a&gt; I was warning about, though at the same time Apple was trying to avoid giving Adobe veto power over their platform again.&lt;/p&gt;&lt;p&gt; The thing is, we have been round this &lt;a href="http://epeus.blogspot.com/2008/12/cycling-to-new-layers-of-freedom.html"&gt;cycle&lt;/a&gt; before, and the answer is known too - the way to interoperate with another company without having to have a business agreement with them is to use &lt;a href="http://epeus.blogspot.com/2008/05/api-is-bespoke-suit-standard-is-t-shirt.html"&gt;open standards, not proprietary APIs&lt;/a&gt;.&lt;/p&gt;&lt;p&gt; Apple knows this - they have helped lead development of HTML5 and WebKit, along with many other standards in the past, including podcasting and MPEG4. Facebook knows this too, and they have been strong supporters of OAuth and Activity Streams, and even of Portable Contacts, when it's them doing the importing.&lt;/p&gt;&lt;p&gt; Clearly it good for us as users to be able to delegate our contact lists to an existing source - this weeks launch of conference sharing site &lt;a href="http://lanyrd.com"&gt;Lanyrd&lt;/a&gt; shows that. It's also in our interests to be able to propagate the actions of playing, liking and purchasing music, videos and anything else between sites of our choosing, so that we can share with our friends, and so we can get more useful recommendations for the future (at minimum, not suggesting things we already have).&lt;/p&gt;&lt;p&gt; This was the core of the discussion at the &lt;a href="http://cyber.law.harvard.edu/projectvrm/VRM_CRM_2010"&gt;VRM Workshop&lt;/a&gt; last week in Boston - that we should control over who sees what about us, and I think that with these common standards we can solve both problems - the individuals get to save having to re-enter their information everywhere, and control what flows to where, and the companies get the ability to interoperate without bizdev and single source lock-in. &lt;a href="http://activitystrea.ms/"&gt;Activity Streams&lt;/a&gt; (and the &lt;a href="http://prezi.com/c2hwhoqdmlfj/social-web-standards/"&gt;associated standards they build on&lt;/a&gt;) are our best hope for this.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/3200930-7409949046922872255?l=epeus.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=QKQ1T2z5ksE:B9q2iBhoF0k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=QKQ1T2z5ksE:B9q2iBhoF0k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=QKQ1T2z5ksE:B9q2iBhoF0k:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=QKQ1T2z5ksE:B9q2iBhoF0k:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/QKQ1T2z5ksE" height="1" width="1"/&gt;</content>
    <updated>2010-09-02T21:32:46Z</updated>
    <published>2010-09-02T19:46:00Z</published>
    <category scheme="http://www.blogger.com/atom/ns#" term="Steve Jobs" />
    <category scheme="http://www.blogger.com/atom/ns#" term="standards" />
    <category scheme="http://www.blogger.com/atom/ns#" term="Activity Streams" />
    <author>
      <name>Kevin Marks</name>
      <email>noreply@blogger.com</email>
      <uri>http://www.blogger.com/profile/18338939297948690534</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-3200930</id>
      <author>
        <name>Kevin Marks</name>
        <email>noreply@blogger.com</email>
        <uri>http://www.blogger.com/profile/18338939297948690534</uri>
      </author>
      <link href="http://epeus.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://www.blogger.com/feeds/3200930/posts/default" rel="self" type="application/atom+xml" />
      <link href="http://epeus.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <link href="http://www.blogger.com/feeds/3200930/posts/default?start-index=26&amp;max-results=25" rel="next" type="application/atom+xml" />
      <subtitle>Edifying exquisite equine entrapments</subtitle>
      <title>Epeus' epigone</title>
      <updated>2010-09-02T21:32:45Z</updated>
    </source>
  <feedburner:origLink>http://epeus.blogspot.com/2010/09/welcome-apple-seriously.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/clinical_workflows_september</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/ihM6SNXuByU/clinical_workflows_september" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: Webcast: Give Clinicians a Jump Start for EMR Adoption</title>
    
    <updated>2010-09-02T20:53:38Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">This interactive webcast will explore how healthcare organizations are bridging the gap between clinician productivity and security. A few of the topics include the introduction of one-touch follow-me desktop and securing unattended desktops.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ihM6SNXuByU:7dTC4c2lpp4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ihM6SNXuByU:7dTC4c2lpp4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ihM6SNXuByU:7dTC4c2lpp4:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=ihM6SNXuByU:7dTC4c2lpp4:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/ihM6SNXuByU" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/clinical_workflows_september</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content53077.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/5o6ArD_NjTU/content53077.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: HealthTechnica - Why You Should Consider a Single Sign On Product in Health Care</title>
    
    <updated>2010-09-02T18:12:11Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://www.healthtechnica.com/blogsphere/2010/09/01/why-you-should-consider-a-single-sign-on-product-in-health-care/&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5o6ArD_NjTU:L7dYkmz0FCA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5o6ArD_NjTU:L7dYkmz0FCA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5o6ArD_NjTU:L7dYkmz0FCA:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=5o6ArD_NjTU:L7dYkmz0FCA:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/5o6ArD_NjTU" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content53077.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.windley.com/archives/2010/09/twitter_and_the_oauthalypse_a_restful_misfire.shtml</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/RYXH7LRZlzE/twitter_and_the_oauthalypse_a_restful_misfire.shtml" rel="alternate" type="application/xhtml+xml" />
    <title xml:lang="en">Phil Windley - Kynetx: Twitter and the OAuthalypse: A RESTful Misfire</title>
    <summary xml:lang="en" type="html">Yesterday was the OAuthalypse--the day when Twitter stopped accepting HTTP Basic authorizations on theis API. I had a few apps break--like almost everything I've done with Twitter. To get them back working I'll have to spend some time on...</summary>
    <content type="html" xml:lang="en">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;img align="right" alt="Fail Whale" border="0" hspace="3" src="http://farm4.static.flickr.com/3611/3323389892_18cd79c369_m.jpg" style="margin-top: 10px;" title="Fail Whale" vspace="3" width="150px"&gt;&lt;/img&gt;&#xD;
&lt;p&gt;&#xD;
&lt;a href="http://dev.twitter.com/announcements"&gt;Yesterday was the OAuthalypse&lt;/a&gt;--the day when Twitter stopped accepting HTTP Basic authorizations on theis API.  I had a few apps break--like almost everything I've done with Twitter.  To get them back working I'll have to spend some time on each moving them over to OAuth.  For some that won't be hard--they're already using a library that supports OAuth.  For others it will be more work.  All of them are single user apps (like the &lt;a href="http://www.utahpolitics.org"&gt;UtahPolitics retweeter&lt;/a&gt; and so will use the &lt;a href="http://dev.twitter.com/pages/oauth_single_token"&gt;OAuth single token&lt;/a&gt; pattern.  &#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
The reason for moving to OAuth is so that apps won't need to ask users for their Twitter password or store it anymore.  Twitter had a bad experience with this and that led to the decision to go nuclear on usernames and passwords on their API.  This is a clear win for delegated authorization protocols like OAuth and the more capable ones that are surely to follow.  What's more it trains users to use a delegated authorization scheme.  I love it.  &#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
But what's curious about the move is that in everycase (except the retweeter) my apps are not updating information.  These are read-only apps that simply read a &lt;a href="http://dev.twitter.com/doc/get/statuses/friends_timeline"&gt;friend timeline&lt;/a&gt; for a partcular user.  I can't figure out why any authorization is needed at all.  Since who I follow is public information, it would be simple enough to reconstruct my friend timeline from available information.  My theory is that Twitter uses authentication on read-only data as a substitute for a poorly designed API.  That is, they use the authentication as a substitute for merely allowing me to specify &lt;em&gt;whose&lt;/em&gt; timeline I want to see.  &#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
This is classic REST stuff and it seems that Twitter got it wrong.  Thousands of apps are failing today because Twitter requires them to authorize when they don't really need to.  Am I wrong?  &#xD;
&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=RYXH7LRZlzE:fXjU-ei3guA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=RYXH7LRZlzE:fXjU-ei3guA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=RYXH7LRZlzE:fXjU-ei3guA:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=RYXH7LRZlzE:fXjU-ei3guA:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/RYXH7LRZlzE" height="1" width="1"/&gt;</content>
    <updated>2010-09-02T15:57:10Z</updated>
    <published>2010-09-02T15:55:05Z</published>
    <category term="twitter, oauth, identity, rest," />
    <source>
      <id>http://www.windley.com/</id>
      <icon>http://www.windley.com/favicon.ico</icon>
      <logo>http://www.niallkennedy.com/alive.gif</logo>
      <author>
        <name>windley</name>
        <email>phil@windley.org</email>
        <uri>http://www.windley.com</uri>
      </author>
      <link href="http://www.windley.com/" rel="alternate" type="application/xhtml+xml" />
      <link href="http://www.windley.com/atom.xml" rel="self" type="application/atom+xml" />
      <rights xml:lang="en">Creative Commons Attribution 2.5</rights>
      <subtitle xml:lang="en">Organizations Get the IT They Deserve</subtitle>
      <title xml:lang="en">Phil Windley's Technometria</title>
      <updated>2010-09-02T15:57:10Z</updated>
    </source>
  <feedburner:origLink>http://www.windley.com/archives/2010/09/twitter_and_the_oauthalypse_a_restful_misfire.shtml</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content53068.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/OIqtXFWIjro/content53068.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: SC Magazine UK - VMware launches new virtualised technology, as Imprivata and F5 confirm support</title>
    
    <updated>2010-09-02T15:49:06Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://www.scmagazineuk.com/vmware-launches-new-virtualised-technology-as-imprivata-and-f5-confirm-support/article/178125/&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=OIqtXFWIjro:cAoA9YeoBWw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=OIqtXFWIjro:cAoA9YeoBWw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=OIqtXFWIjro:cAoA9YeoBWw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=OIqtXFWIjro:cAoA9YeoBWw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/OIqtXFWIjro" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content53068.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content53067.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/RPrBh6ZCzFc/content53067.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: Medical News Today - Imprivata Delivers Fast And Secure Access To Applications For VMware View 4.5 Users</title>
    
    <updated>2010-09-02T15:48:27Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://www.medicalnewstoday.com/articles/199516.php&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=RPrBh6ZCzFc:tI1h6RWUXnw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=RPrBh6ZCzFc:tI1h6RWUXnw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=RPrBh6ZCzFc:tI1h6RWUXnw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=RPrBh6ZCzFc:tI1h6RWUXnw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/RPrBh6ZCzFc" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content53067.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blog.broadbandmechanics.com/?p=7236</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/SXuL1LtSPbA/" rel="alternate" type="text/html" />
    <title>Marc Canter - Broadband Mechanics: the final FYI video</title>
    <summary type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;This is what I’m showing tomorrow to Chancellor Fingerhut. This is what I did on my summer vacation.&#xD;
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;This is what I’m showing tomorrow to Chancellor Fingerhut. This is what I did on my summer vacation.&#xD;
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=SXuL1LtSPbA:tCPHGb6DsSA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=SXuL1LtSPbA:tCPHGb6DsSA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=SXuL1LtSPbA:tCPHGb6DsSA:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=SXuL1LtSPbA:tCPHGb6DsSA:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/SXuL1LtSPbA" height="1" width="1"/&gt;</content>
    <updated>2010-09-02T03:57:02Z</updated>
    <category term="Blog" />
    <category term="Open Guru" />
    <author>
      <name>marc</name>
    </author>
    <source>
      <id>http://blog.broadbandmechanics.com</id>
      <link href="http://blog.broadbandmechanics.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://blog.broadbandmechanics.com" rel="alternate" type="text/html" />
      <subtitle>building the open web one bit at a time</subtitle>
      <title>Marc's Voice</title>
      <updated>2010-09-02T04:00:25Z</updated>
    </source>
  <feedburner:origLink>http://blog.broadbandmechanics.com/2010/09/01/the-final-fyi-video/</feedburner:origLink></entry>

  <entry>
    <id>tag:blogs.oracle.com,2010:/mwilcox//68.21846</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/HVirKzcCOFQ/another_helpful_hint_for_insta.html" rel="alternate" type="text/html" />
    <title>Mark Wilcox - Oracle: Another helpful hint for installing Oracle Fusion Middleware Components on Oracle Enterprise Linux</title>
    <summary type="html">I'm helping a colleague get OVD 11g up and running for an upcoming demo. We're running on OEL 5 and I forgot to remind him to make sure to put the Oracle Validated package during install. If you don't do...</summary>
    <content type="html" xml:lang="en">&lt;div class="posterous_autopost"&gt;I'm helping a colleague get OVD 11g up and running for an upcoming demo. We're running on OEL 5 and I forgot to remind him to make sure to put the Oracle Validated package during install. &lt;br&gt;If you don't do this - you'll most likely be missing some packages. &lt;p&gt;&lt;/p&gt; An easy way to resolve this is to either run: &lt;p&gt;&lt;/p&gt; up2date oracle-validated (if you are a OEL support subscriber) &lt;br&gt;Or you have configured OEL to connect to the public YUM server: &lt;br&gt;yum install oracle-validated      &lt;p style="font-size: 10px;"&gt;  &lt;a href="http://posterous.com"&gt;Posted via email&lt;/a&gt;   from &lt;a href="http://mewldap.posterous.com/another-helpful-hint-for-installing-oracle-fu"&gt;Virtual Identity Dialogue&lt;/a&gt;  &lt;/p&gt;  &lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=HVirKzcCOFQ:B83-PNjnKJE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=HVirKzcCOFQ:B83-PNjnKJE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=HVirKzcCOFQ:B83-PNjnKJE:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=HVirKzcCOFQ:B83-PNjnKJE:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/HVirKzcCOFQ" height="1" width="1"/&gt;</content>
    <updated>2010-09-02T03:44:47Z</updated>
    <published>2010-09-02T03:44:47Z</published>
    <author>
      <name>mark.wilcox</name>
    </author>
    <source>
      <id>tag:blogs.oracle.com,2010:/mwilcox//68</id>
      <link href="http://blogs.oracle.com/mwilcox/" rel="alternate" type="text/html" />
      <link href="http://blogs.oracle.com/mwilcox/xml/rss.xml" rel="self" type="application/atom+xml" />
      <title>Virtual Identity Dialogue</title>
      <updated>2010-09-02T03:44:47Z</updated>
    </source>
  <feedburner:origLink>http://blogs.oracle.com/mwilcox/2010/09/another_helpful_hint_for_insta.html</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-12447072.post-6631780477386910122</id>
    <link href="http://connectid.blogspot.com/feeds/6631780477386910122/comments/default" rel="replies" type="application/atom+xml" />
    <link href="https://www.blogger.com/comment.g?blogID=12447072&amp;postID=6631780477386910122" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/6631780477386910122?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/6631780477386910122?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/ZVZji5Xf6w8/new-line-of-greeting-cards.html" rel="alternate" type="text/html" />
    <title>Paul Madsen: New line of greeting cards</title>
    <content type="html">&lt;div class="posterous_autopost"&gt;&lt;img height="293" src="http://posterous.com/getfile/files.posterous.com/paulmadsen/eJZaIbxIwQBpNRc3HkCkZcLSXBrtQKldTEWkzdC9FFPp02hcHZxWjBsVc0j2/Screen_00020.jpg" width="422"&gt;&lt;/img&gt; &lt;p style="font-size: 10px;"&gt;  &lt;a href="http://posterous.com"&gt;Posted via email&lt;/a&gt;   from &lt;a href="http://paulmadsen.posterous.com/new-line-of-greeting-cards-60"&gt;Pre(posterous)&lt;/a&gt;  &lt;/p&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/12447072-6631780477386910122?l=connectid.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/blogspot/gMwy/~4/ZVZji5Xf6w8" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ZVZji5Xf6w8:i21CMTj6bHI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ZVZji5Xf6w8:i21CMTj6bHI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ZVZji5Xf6w8:i21CMTj6bHI:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=ZVZji5Xf6w8:i21CMTj6bHI:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/ZVZji5Xf6w8" height="1" width="1"/&gt;</content>
    <updated>2010-09-01T22:30:26Z</updated>
    <published>2010-09-01T22:30:00Z</published>
    <author>
      <name>Paul Madsen</name>
      <email>noreply@blogger.com</email>
      <uri>http://www.blogger.com/profile/08489111023182783403</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-12447072</id>
      <author>
        <name>Paul Madsen</name>
        <email>noreply@blogger.com</email>
        <uri>http://www.blogger.com/profile/08489111023182783403</uri>
      </author>
      <link href="http://connectid.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://connectid.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/12447072/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/blogspot/gMwy" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>When you don't have anything nice to say, consider blogging it. or a tweet if you're rushed for time.</subtitle>
      <title>ConnectID</title>
      <updated>2010-09-01T22:30:26Z</updated>
    </source>
  <feedburner:origLink>http://connectid.blogspot.com/2010/09/new-line-of-greeting-cards.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blog.tumy-tech.com/?p=284</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/pj9w-yqs7bc/" rel="alternate" type="text/html" />
    <title>Brad Tumy - Oracle: Identity Mgmt Publication Survey #IDM #Survey</title>
    <summary type="html">I am trying to gather more information to help provide a better source of information for the IDM community.  I have put together a simple survey to give you the opportunity to provide feedback and to help steer the direction of this new publication.  We are targeting the first part of November for the initial [...]&lt;img alt="" border="0" height="1" src="http://stats.wordpress.com/b.gif?host=blog.tumy-tech.com&amp;amp;blog=6745476&amp;amp;post=284&amp;amp;subd=bradtumy&amp;amp;ref=&amp;amp;feed=1" width="1"&gt;&lt;/img&gt;</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;I am trying to gather more information to help provide a better source of information for the IDM community.  I have put together a simple&lt;a href="http://www.tumy-tech.com/idm-publication-survey" target="_self" title="IDM Publication Survey"&gt; survey&lt;/a&gt; to give you the opportunity to provide feedback and to help steer the direction of this new publication.  We are targeting the first part of November for the initial release and would love to have your feedback to help shape this great resource.   The survey should take about 10 minutes of your time and as a thank-you I am giving a way a free year (1 year) subscription to everyone that completes the survey (be sure to include your email address).&lt;/p&gt;&#xD;
&lt;p&gt;Please let me know if you have any questions or comments!&lt;/p&gt;&#xD;
&lt;p&gt;Survey (&lt;a href="http://www.tumy-tech.com/idm-publication-survey"&gt;http://www.tumy-tech.com/idm-publication-survey&lt;/a&gt;)&lt;/p&gt;&#xD;
&lt;p&gt;Thanks,&lt;/p&gt;&#xD;
&lt;p&gt;Brad Tumy&lt;/p&gt;&#xD;
&lt;br&gt;Filed under: &lt;a href="http://blog.tumy-tech.com/category/idm/"&gt;IdM&lt;/a&gt;  &lt;a href="http://feeds.wordpress.com/1.0/gocomments/bradtumy.wordpress.com/284/" rel="nofollow"&gt;&lt;img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bradtumy.wordpress.com/284/"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.wordpress.com/1.0/godelicious/bradtumy.wordpress.com/284/" rel="nofollow"&gt;&lt;img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bradtumy.wordpress.com/284/"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.wordpress.com/1.0/gofacebook/bradtumy.wordpress.com/284/" rel="nofollow"&gt;&lt;img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bradtumy.wordpress.com/284/"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.wordpress.com/1.0/gotwitter/bradtumy.wordpress.com/284/" rel="nofollow"&gt;&lt;img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bradtumy.wordpress.com/284/"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.wordpress.com/1.0/gostumble/bradtumy.wordpress.com/284/" rel="nofollow"&gt;&lt;img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bradtumy.wordpress.com/284/"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.wordpress.com/1.0/godigg/bradtumy.wordpress.com/284/" rel="nofollow"&gt;&lt;img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bradtumy.wordpress.com/284/"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.wordpress.com/1.0/goreddit/bradtumy.wordpress.com/284/" rel="nofollow"&gt;&lt;img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bradtumy.wordpress.com/284/"&gt;&lt;/img&gt;&lt;/a&gt; &lt;img alt="" border="0" height="1" src="http://stats.wordpress.com/b.gif?host=blog.tumy-tech.com&amp;amp;blog=6745476&amp;amp;post=284&amp;amp;subd=bradtumy&amp;amp;ref=&amp;amp;feed=1" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=pj9w-yqs7bc:Y3p0GxAmulM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=pj9w-yqs7bc:Y3p0GxAmulM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=pj9w-yqs7bc:Y3p0GxAmulM:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=pj9w-yqs7bc:Y3p0GxAmulM:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/pj9w-yqs7bc" height="1" width="1"/&gt;</content>
    <updated>2010-09-01T19:32:50Z</updated>
    <category term="IdM" />
    <author>
      <name>Brad Tumy</name>
    </author>
    <source>
      <id>http://blog.tumy-tech.com</id>
      <logo>http://0.gravatar.com/blavatar/657de124e59f46ae881d9fd13af69999?s=96&amp;d=http://s2.wp.com/i/buttonw-com.png</logo>
      <link href="http://blog.tumy-tech.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://blog.tumy-tech.com" rel="alternate" type="text/html" />
      <link href="http://blog.tumy-tech.com/osd.xml" rel="search" type="application/opensearchdescription+xml" />
      <link href="http://blog.tumy-tech.com/?pushpress=hub" rel="hub" type="text/html" />
      <subtitle>Implementing Identity Management and Information Security</subtitle>
      <title>Deploying Identity Solutions</title>
      <updated>2010-09-02T22:32:49Z</updated>
    </source>
  <feedburner:origLink>http://blog.tumy-tech.com/2010/09/01/identity-mgmt-publication-survey-idm-survey/</feedburner:origLink></entry>

  <entry>
    <id>f1397696-738c-4295-afcd-943feb885714:41144</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/jX8yfopwMxA/Identropy-Adds-New-Advisory-Offering-the-Identropy-IAM-Primer-Series" rel="alternate" type="text/html" />
    <title>Identropy: Identropy Adds New Advisory Offering: the Identropy IAM Primer Series</title>
    
    <updated>2010-09-01T17:07:00Z</updated>
    <author>
      <name>Ash Motiwala</name>
    </author>
    <source>
      <id>http://www.identropy.com/blog/</id>
      <link href="http://www.identropy.com/blog/" rel="alternate" type="text/html" />
      <link href="http://www.identropy.com/CMS/UI/Modules/BizBlogger/rss.aspx?tabid=85591&amp;moduleid=85510&amp;maxcount=25" rel="self" type="application/rss+xml" />
      <subtitle>RSS feeds for</subtitle>
      <title>Blog</title>
      <updated>2010-09-02T22:32:03Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Identropy adds a new offering as part of its well-known Advisory Services: the Identropy &lt;a href="http://www.identropy.com/iam-primer-series/" target="_blank" title="IAM Primer Series"&gt;IAM Primer Series&lt;/a&gt;.  This offering not only provides access to Identropy's IAM best practices library, but also provides direct access to an Identropy IAM professional.&lt;/p&gt;&#xD;
&lt;p&gt;Our seasoned Identity and Access Management (IAM) professionals, each with over 10 years of experience in IAM, have created IAM best practices reference documents that capture practical and empirical knowledge in various aspects of the identity and access management landscape, spanning business processes and technologies. They are intended to educate IAM initiative stakeholders of industry best practices and facilitate their adoption in a cost-effective, self-paced manner, thus helping organizations improve their business processes by making optimal use of IAM.&lt;/p&gt;&#xD;
&lt;p&gt;In addition to the best practice documents, the offering includes five hours of direct access to an Identropy IAM professional.  Rather than read a static document, customers can also engage in a live conversation regarding the practical aspects of an IAM initiative. This approach will help organizations get started with a specific IAM topic with the practical hands-on guidance that is often missing in IAM initiatives, thereby leading to a more effective approach to adopting and implementing the solution specific to the customer's environment.For more information on this Identropy's IAM Primer Series, click here: &lt;a href="http://www.identropy.com/iam-primer-series/" target="_self" title="http://www.identropy.com/iam-primer-series/"&gt;http://www.identropy.com/iam-primer-series/&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=jX8yfopwMxA:JOrPvILVsBI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=jX8yfopwMxA:JOrPvILVsBI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=jX8yfopwMxA:JOrPvILVsBI:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=jX8yfopwMxA:JOrPvILVsBI:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/jX8yfopwMxA" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.identropy.com/blog/bid/41144/Identropy-Adds-New-Advisory-Offering-the-Identropy-IAM-Primer-Series</feedburner:origLink></entry>

  <entry xml:lang="en-us">
    <id>http://zetetic.net/blog/2010/09/01/tempo-maintenance-tonight-sept-1st-11pm-edt/</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/6ZWsuRW58uE/" rel="alternate" type="text/html" />
    <title>Identicentric: Tempo Maintenance Tonight, Sept 1st 11PM EDT</title>
    
    <updated>2010-09-01T14:00:32Z</updated>
    <source>
      <id>http://zetetic.net/rss/</id>
      <author>
        <name>Identicentric</name>
      </author>
      <link href="http://zetetic.net/rss/" rel="alternate" type="text/html" />
      <link href="http://blog.identicentric.com/feed/atom" rel="self" type="application/rss+xml" />
      <subtitle>Zetetic Software Design and Development Blog</subtitle>
      <title>Zetetic Blog</title>
      <updated>2010-09-01T18:02:27Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;For customers of our time-tracking system, &lt;a href="http://keeptempo.com"&gt;Tempo&lt;/a&gt;, the web interface will be temporarily unavailable starting at &lt;a href="http://www.timeanddate.com/worldclock/fixedtime.html?month=9&amp;amp;day=1&amp;amp;year=2010&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=179"&gt;11PM &lt;span class="caps"&gt;EDT&lt;/span&gt; tonight&lt;/a&gt;, Wednesday September 1st.&lt;/p&gt;&#xD;
&lt;p&gt;Just a couple of small fixes, service should only be offline for a few minutes while we make sure nothing’s amiss. Reporting time entries via Twitter and Email will continue to function without interruption.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=6ZWsuRW58uE:C33yaK6AC40:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=6ZWsuRW58uE:C33yaK6AC40:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=6ZWsuRW58uE:C33yaK6AC40:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=6ZWsuRW58uE:C33yaK6AC40:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/6ZWsuRW58uE" height="1" width="1"/&gt;</content><feedburner:origLink>http://zetetic.net/blog/2010/09/01/tempo-maintenance-tonight-sept-1st-11pm-edt/</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blogs.gartner.com/mark-diodati/?p=60</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/zbdRkWtVaTA/" rel="alternate" type="text/html" />
    <title>Mark Diodati - Gartner: VMware’s Purchase of TriCipher</title>
    <summary type="html">When it rains, it pours. Yesterday, CA Technologies announced its purchase of Arcot Systems. My blog post about the purchase can be found here.  Today, VMware announced its purchase of TriCipher. Arcot Systems and TriCipher are eerily similar. Both companies started with innovative technology which protects the user’s private PKI key in software (in TriCipher’s [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;When it rains, it pours. Yesterday, CA Technologies announced its purchase of Arcot Systems. My blog post about the purchase can be found &lt;a href="http://blogs.gartner.com/mark-diodati/2010/08/30/ca-technologies-to-purchase-arcot/"&gt;here&lt;/a&gt;.  Today, VMware announced its purchase of TriCipher. Arcot Systems and TriCipher are eerily similar. Both companies started with innovative technology which protects the user’s private PKI key in software (in TriCipher’s case, the private key is split). Both expanded into the cloud identity management market. Cloud identity management products are SaaS-based. They provide authentication and provisioning services for cloud-based applications. As discussed in my blog post yesterday, these products provide relatively simple solutions for enterprises as they reach out to cloud-based applications. With the Arcot Systems and TriCipher acquisitions, it is safe to say that the emerging market for cloud identity management products has been validated.&lt;/p&gt;&#xD;
&lt;p&gt;VMware (a subsidiary of EMC) has good reasons for the purchase, including building out its cloud portfolio. But I wonder if TriCipher belongs with RSA (another subsidiary of EMC). Its products are security- and identity-based, and are complimentary to RSA’s enterprise authentication, consumer authentication, and web access management offerings. As with CA Technologies’ purchase of Arcot Systems, TriCipher products would extend RSA’s enterprise offerings into the cloud without wholesale development effort. There’s no product conflict between the authentication products of both companies; TriCipher’s authentication technology would be a great compliment to RSA’s SecurID, consumer authentication, and PKI products.&lt;/p&gt;&#xD;
&lt;p&gt;One of RSA’s core marketing messages is that it is “The Security Division of EMC”. Perhaps we’ll learn more about RSA’s role in all of this as the dust settles on the purchase. For more information on TriCipher, please see our published research documents (subscription required). Also, we are close to publishing our “Federation, Directory Services, and Cloud” research document, which focuses squarely on Arcot and TriCipher. Stay tuned.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=1856"&gt;Burton Group Catalyst 2009: Cloud SSO Interoperability Summary&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=1730"&gt;New Directions in Federation&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=1990"&gt;Market Profile: Identity Management 2010&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zbdRkWtVaTA:07HHWKh7564:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zbdRkWtVaTA:07HHWKh7564:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zbdRkWtVaTA:07HHWKh7564:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=zbdRkWtVaTA:07HHWKh7564:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/zbdRkWtVaTA" height="1" width="1"/&gt;</content>
    <updated>2010-09-01T01:31:45Z</updated>
    <category term="Uncategorized" />
    <author>
      <name>Mark Diodati</name>
    </author>
    <source>
      <id>http://blogs.gartner.com/mark-diodati</id>
      <link href="http://blogs.gartner.com/mark-diodati/feed/" rel="self" type="application/atom+xml" />
      <link href="http://blogs.gartner.com/mark-diodati" rel="alternate" type="text/html" />
      <subtitle>A Member of The Gartner Blog Network</subtitle>
      <title>Mark Diodati</title>
      <updated>2010-09-01T01:32:50Z</updated>
    </source>
  <feedburner:origLink>http://blogs.gartner.com/mark-diodati/2010/08/31/vmware%e2%80%99s-purchase-of-tricipher/</feedburner:origLink></entry>

  <entry xml:lang="en-us">
    <id>http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/31/Twitter-OAuth-a-vote-for-APIs</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/x3Jvtiqv7Dk/Twitter-OAuth-a-vote-for-APIs" rel="alternate" type="text/html" />
    <title>Ping Talk - Ping Identity: Twitter OAuth: Keep your eye on the API</title>
    
    <updated>2010-09-01T01:21:00Z</updated>
    <category term="IdM" />
    <category term="Cloud" />
    <source>
      <id>http://www.pingidentity.com/blogs/pingtalk/index.cfm</id>
      <category scheme="http://www.itunes.com/" term="Technology" />
      <category scheme="http://www.itunes.com/" term="Podcasting" />
      <category scheme="http://www.itunes.com/" term="Tech News" />
      <author>
        <name>Ping Talk - Ping Identity</name>
        <email>pingtalkblog@pingidentity.com</email>
      </author>
      <link href="http://www.pingidentity.com/blogs/pingtalk/index.cfm" rel="alternate" type="text/html" />
      <link href="http://www.pingidentity.com/blogs/pingtalk/rss.cfm?mode=full" rel="self" type="application/rss+xml" />
      <title>Ping Talk Blog</title>
      <updated>2010-09-03T00:23:13Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;So Twitter cut over to &lt;a href="http://www.pingidentity.com/knowledge-center/CardSpace-OpenID.cfm"&gt;OAuth&lt;/a&gt; today and as far as I can tell the Earth is still spinning on its axis.&lt;/p&gt;&#xD;
&lt;div&gt;But it is a watershed event for the microblogging service, or in plain language; Twitter-based  apps won’t store your password anymore.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;I've said here before that OAuth's development bears watching as more services cut over to the emerging protocol, which will eventually intersect with current enterprise identity systems – mostly because &lt;a href="http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/5/27/The-OpenAPI-flirts-with-developers"&gt;API access to application components &lt;/a&gt;will demand it.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Here is how Twitter explains its OAuth moment to application developers:&lt;/div&gt;&#xD;
&lt;div&gt;“You, as the application developer:&lt;/div&gt;&#xD;
&lt;ul style="margin-top: 0in;" type="disc"&gt;&#xD;
    &lt;li&gt;don't      have to worry about exposing the credentials for your users whether      through a bug or other means (especially considering that a lot of people      use the same password for multiple services);&lt;/li&gt;&#xD;
    &lt;li&gt;don't      have to worry about the user changing their password — a user can change      his or her password and the OAuth "connection" to your app will      still work;&lt;/li&gt;&#xD;
    &lt;li&gt;don't      have to worry about other applications masquerading as your application -      only you can set the byline with your application name;&lt;/li&gt;&#xD;
    &lt;li&gt;will      eventually have access to more APIs from Twitter that will only be      available to "trusted" OAuth-enabled applications; and&lt;/li&gt;&#xD;
    &lt;li&gt;give the @twitterapi team more      visibility into the network — you help us plan for capacity, and you help      us squash spam and you help us identify bugs."&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;div style="margin-left: 0.5in;"&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Twitter is on the right track, but not a pioneer. They are adopting version 1.0 and still working on support of version 2.0, which is a more secure version but won’t be finalized until the end of the year. But others such as Facebook and Gowalla are already using 2.0.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;The bottom line here is securing the API. Why? Google and Facebook handle five billion API calls per day. Twitter handles three billion, which is 75% of all its traffic. And more than 50% of SalesForce.com’s traffic is via API.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;APIs will help users integrate features or data from their SaaS apps with their on-premise systems.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Ping is working on OAuth support that our end-users are likely to see by the end of the year to help make such possibilities comes true.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;In addition, Ping’s principal engineer Brian Campbell is &lt;a href="http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/5/IETF-working-on-SAML-OAuth-20-bridge"&gt;already working through the IETF&lt;/a&gt; on a bridge between SAML and OAuth 2.0 that will allow a specifically structured SAML token to be exchanged for OAuth.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;From what I am hearing, some of what you should be thinking about in terms of OAuth is how systems manage it.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;One expert I know told me that concerns may center on making sure the cryptography, negotiation, management of OAuth peer servers, the establishment/honoring/caching of tokens, etc. can be separated from the applications themselves, so it all can be centrally managed/logged/audited.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Follow John on &lt;a href="http://twitter.com/JohnFontana"&gt;Twitter&lt;/a&gt;  and check out                                           our Identity-Conversation &lt;a href="http://twitter.com/JohnFontana/identity-conversation"&gt;Tweet                                            list&lt;/a&gt;&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;   &lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=x3Jvtiqv7Dk:PDv9GIXTXc0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=x3Jvtiqv7Dk:PDv9GIXTXc0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=x3Jvtiqv7Dk:PDv9GIXTXc0:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=x3Jvtiqv7Dk:PDv9GIXTXc0:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/x3Jvtiqv7Dk" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/31/Twitter-OAuth-a-vote-for-APIs</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://self-issued.info/?p=337</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/0H4-_dJt3h8/" rel="alternate" type="text/html" />
    <link href="http://self-issued.info/?p=337#comments" rel="replies" type="text/html" />
    <link href="http://self-issued.info/?feed=atom&amp;p=337" rel="replies" type="application/atom+xml" />
    <title xml:lang="en">Mike Jones - Microsoft: Information Card SAML Token Profile Committee Specifications</title>
    <summary xml:lang="en" type="html">As editor of the OASIS IMI TC, I wanted to bring to your attention that the committee specifications for the SAML V1.1 Information Card Token Profile Version 1.0 and the SAML V2.0 Information Card Token Profile Version 1.0 specifications have been posted by OASIS. These specs are standard profiles for SAML 1.1 and SAML 2.0 [...]</summary>
    <content type="html" xml:lang="en">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;span class="plain"&gt;&lt;img align="right" alt="Information Card Icon" hspace="2" src="http://self-issued.info/infocard_icon/images/infocard_114x80.png"&gt;&lt;/img&gt;&lt;img align="right" alt="OASIS logo" hspace="10" src="http://self-issued.info/images/oasis.png"&gt;&lt;/img&gt;&lt;/span&gt;As editor of the OASIS IMI TC, I wanted to bring to your attention that the committee specifications for the &lt;a href="http://docs.oasis-open.org/imi/identity/cs/imi-saml1.1-profile-cs-01.html"&gt;SAML V1.1 Information Card Token Profile Version 1.0&lt;/a&gt; and the &lt;a href="http://docs.oasis-open.org/imi/identity/cs/imi-saml2.0-profile-cs-01.html"&gt;SAML V2.0 Information Card Token Profile Version 1.0&lt;/a&gt; specifications have been posted by OASIS. These specs are standard profiles for SAML 1.1 and SAML 2.0 tokens when used with the &lt;a href="http://docs.oasis-open.org/imi/identity/v1.0/identity.html"&gt;Identity Metasystem Interoperability Version 1.0&lt;/a&gt; (IMI 1.0) specification for &lt;a href="http://informationcard.net/"&gt;Information Cards&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;p&gt;Thanks again to Scott Cantor and the &lt;a href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security"&gt;OASIS Security Services (SAML) TC&lt;/a&gt; for driving the creation of these profiles.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0H4-_dJt3h8:NZGtmhCL-Xo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0H4-_dJt3h8:NZGtmhCL-Xo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0H4-_dJt3h8:NZGtmhCL-Xo:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=0H4-_dJt3h8:NZGtmhCL-Xo:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/0H4-_dJt3h8" height="1" width="1"/&gt;</content>
    <updated>2010-09-01T00:29:50Z</updated>
    <published>2010-09-01T00:29:50Z</published>
    <category scheme="http://self-issued.info" term="Information Cards" />
    <category scheme="http://self-issued.info" term="Interoperability" />
    <author>
      <name>Mike Jones</name>
      <uri>http://self-issued.info/</uri>
    </author>
    <source>
      <id>http://self-issued.info/?feed=atom</id>
      <link href="http://self-issued.info" rel="alternate" type="text/html" />
      <link href="http://self-issued.info/?feed=atom" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en">Musings on Digital Identity</subtitle>
      <title xml:lang="en">Mike Jones: self-issued</title>
      <updated>2010-09-01T00:29:50Z</updated>
    </source>
  <feedburner:origLink>http://self-issued.info/?p=337</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.internetidentityworkshop.com/?p=389</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/xkimERqqE4s/" rel="alternate" type="text/html" />
    <title>Internet Identity Workshop: Our DC Location</title>
    <summary type="html">We thought we would share with you some more information about our venue. It is 0verlooking Meridian Hill Park, and is a 18,000 sq ft, 40-room Renaissance-revival style mansion. It has been quite fascinating to find over the course of organizing the event that several people we know have gotten married here.

The Center has undergone a landmark restoration [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;We thought we would share with you some more information about our venue. It is 0verlooking Meridian Hill Park, and is a 18,000 sq ft, 40-room Renaissance-revival style mansion. It has been quite fascinating to find over the course of organizing the event that several people we know have gotten married here.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;img alt="" class="alignleft" height="171" src="http://www.washingtonparks.net/Images/JBPC_Watercolor_large.jpg" title="Josephine Buttler Parks Center" width="230"&gt;&lt;/img&gt;&lt;/p&gt;&#xD;
&lt;p&gt;The Center has undergone a landmark restoration to its former glory of the 1927 Renaissance Revival design, with adaptations to serve a broad range of modern needs and environmental retrofitting.  The special event space is where we are hosting the Internet Identity Workshop.&lt;/p&gt;&#xD;
&lt;p&gt;We are making sure there is going to be adequate wifi for the event with Jump Labs sponsoring that aspect of the conference.   Just as we do in our regular IIW we will be having a barista for most of the 2 days.&lt;/p&gt;&#xD;
&lt;p&gt;Dinner Thursday evening will be hosted thanks to Booz Allen Hamilton who is sponsoring AND we will be having a bus transport people from the venue to our dinner location that will be even closer to a metro then IIW.&lt;/p&gt;&#xD;
&lt;p&gt;We know it is quite different then our usual home on the west coast at the Computer History Museum however we think it will prove to be a great starting point for future events on the East Coast.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=xkimERqqE4s:Ni-tVGqArbo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=xkimERqqE4s:Ni-tVGqArbo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=xkimERqqE4s:Ni-tVGqArbo:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=xkimERqqE4s:Ni-tVGqArbo:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/xkimERqqE4s" height="1" width="1"/&gt;</content>
    <updated>2010-08-31T23:21:49Z</updated>
    <category term="Uncategorized" />
    <author>
      <name>Kaliya</name>
    </author>
    <source>
      <id>http://www.internetidentityworkshop.com</id>
      <link href="http://www.internetidentityworkshop.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.internetidentityworkshop.com" rel="alternate" type="text/html" />
      <subtitle>Just another WordPress weblog</subtitle>
      <title>Internet Identity Workshop</title>
      <updated>2010-08-31T23:33:16Z</updated>
    </source>
  <feedburner:origLink>http://www.internetidentityworkshop.com/our-dc-location/</feedburner:origLink></entry>

  <entry xml:lang="en-gb">
    <id>http://simonwillison.net/2010/Aug/31/rasterweb/</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/IjuhvU2pwmQ/" rel="alternate" type="text/html" />
    <title>Simon Willison: RasterWeb: Lanyrd</title>
    
    <updated>2010-08-31T20:49:35Z</updated>
    <category term="identity" />
    <category term="oauth" />
    <category term="openid" />
    <category term="peteprodoehl" />
    <category term="twitter" />
    <source>
      <id>http://simonwillison.net/tags/openid/</id>
      <author>
        <name>Simon Willison</name>
        <email>noemail@noemail.org</email>
      </author>
      <link href="http://simonwillison.net/tags/openid/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/SimonWillisonsItemsTaggedOpenid" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <title>Simon Willison's items tagged openid</title>
      <updated>2010-08-31T20:03:49Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;div class="blogmark segment"&gt;&lt;p&gt;&lt;a href="http://rasterweb.net/raster/2010/08/31/lanyrd/"&gt;RasterWeb: Lanyrd&lt;/a&gt;. Pete Prodoehl calls me out on Lanyrd’s integration with the Twitter auth API at the expense of OpenID. I’ve posted a comment with my justification—essentially, tying to Twitter’s ecosystem means I can actually implement the features I’ve been talking about building on top of OpenID for years, with far less engineering effort.&lt;/p&gt;&#xD;
&lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=IjuhvU2pwmQ:MxZA4MLoaTY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=IjuhvU2pwmQ:MxZA4MLoaTY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=IjuhvU2pwmQ:MxZA4MLoaTY:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=IjuhvU2pwmQ:MxZA4MLoaTY:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/IjuhvU2pwmQ" height="1" width="1"/&gt;</content><feedburner:origLink>http://simonwillison.net/2010/Aug/31/rasterweb/</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://eternallyoptimistic.com/?p=1672</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/hYU4eL0_S7U/" rel="alternate" type="text/html" />
    <title>Pamela Dingle - Ping Identity: This Woman in Tech says: Thank you</title>
    <summary type="html">I’ve been reading the various recent articles about women in tech bubbling around the interwebs with mixed feelings.  I’ve seen a lot of these debates go by, and although I have strong opinions (I know, you’re surprised, right?), I usually choose not to comment here. There is only one thing that I find myself wanting [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://eternallyoptimistic.com/wp-content/uploads/2010/08/cascading.jpg"&gt;&lt;img alt="" class="alignright size-medium wp-image-1696" height="300" src="http://eternallyoptimistic.com/wp-content/uploads/2010/08/cascading-240x300.jpg" style="margin: 4px;" title="Balanced Foundations" width="240"&gt;&lt;/img&gt;&lt;/a&gt;I’ve been reading the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://blogs.wsj.com/venturecapital/2010/08/27/addressing-the-lack-of-women-leading-tech-start-ups/" target="_blank"&gt;various&lt;/a&gt;&lt;/span&gt; &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wimnonline.org/WIMNsVoicesBlog/2010/08/29/to-techcrunchs-battle-of-the-sexes-no-ones-blaming-anyone/" target="_blank"&gt;recent&lt;/a&gt;&lt;/span&gt; &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://broadstuff.com/archives/2291-Where-are-the-Women-in-Tech.html"&gt;articles&lt;/a&gt;&lt;/span&gt; about women in tech bubbling around the interwebs with mixed feelings.  I’ve seen a lot of these debates go by, and although I have strong opinions (I know, you’re surprised, right?), I usually choose not to comment here.&lt;/p&gt;&#xD;
&lt;p&gt;There is only one thing that I find myself wanting to say publicly in this week’s resurgence of the debate, and that is: Thank you.   I have had the incredible blessing of being surrounded by group after group of intelligent, thoughtful men and women who have not only treated me equally and fairly, but have encouraged my abilities and helped me to reach greater and greater heights.  &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://techcrunch.com/2010/08/28/women-in-tech-stop-blaming-me/" target="_blank"&gt;I have nobody to blame&lt;/a&gt;&lt;/span&gt;, but many to acknowledge – and why should the jerks get all the press time?&lt;/p&gt;&#xD;
&lt;p&gt;I may not be on anyone’s top 30 women in tech, and I may never be the CxO that people seem to so desperately need all women in tech to be, but I have a fulfilling and challenging job and I have achieved my primary goal in my career, which is to work with people who make me smarter every day. By the only standards that count (mine), I have it all.&lt;/p&gt;&#xD;
&lt;p&gt;I believe that a lot of women have fought difficult fights over the years so that I could have this kind of positive experience, and I know that not all women in tech have been so fortunate.  To those women who take on the establishment in this area – You have my support, gratitude and thanks.  You take the heat today so that the next generation of girls can simply accomplish and wonder what all the fuss is about.&lt;/p&gt;&#xD;
&lt;p&gt;Why am I writing this?  I don’t know. I suppose, it seems wrong for the unhappy examples to be the only examples out there. What I do know, is that I am one of the luckiest women in tech; the people who stand out in my life are not the ones who tried to hold me back, but the ones who have helped me fly.  Thank you, to some of these exceptional people: Darcy, John, Cliff, Don, Cullen, Alan, Tammy, Tim, Pete, Doug, Brian, Dave, Janelle, Kaliya, Gordon, Derek, Barb, Bob, Kim, Craig, Mike, Vittorio, Ben, Sydney, Dale, Patrick, Julie, Sean, Andrew, Gil, Laura, Andre, and so many more.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=hYU4eL0_S7U:HpqTKmuYGAY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=hYU4eL0_S7U:HpqTKmuYGAY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=hYU4eL0_S7U:HpqTKmuYGAY:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=hYU4eL0_S7U:HpqTKmuYGAY:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/hYU4eL0_S7U" height="1" width="1"/&gt;</content>
    <updated>2010-08-31T19:53:53Z</updated>
    <category term="Grrrlgeeks" />
    <category term="Me, my life, and I" />
    <category term="The Plain ol' Truth" />
    <author>
      <name>Pamela</name>
    </author>
    <source>
      <id>http://eternallyoptimistic.com</id>
      <link href="http://eternallyoptimistic.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://eternallyoptimistic.com" rel="alternate" type="text/html" />
      <title>Adventures of an Eternal Optimist</title>
      <updated>2010-09-01T02:02:54Z</updated>
    </source>
  <feedburner:origLink>http://eternallyoptimistic.com/2010/08/31/this-woman-in-tech-says-thanks/</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-6940728126479075612.post-2213442891000860658</id>
    <link href="http://anil-identity.blogspot.com/feeds/2213442891000860658/comments/default" rel="replies" type="application/atom+xml" />
    <link href="https://www.blogger.com/comment.g?blogID=6940728126479075612&amp;postID=2213442891000860658" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/6940728126479075612/posts/default/2213442891000860658?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/6940728126479075612/posts/default/2213442891000860658?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/_1HTrAcykYk/picketbox-xacml-v205final-from-jboss.html" rel="alternate" type="text/html" />
    <title>Anil Saldhana - Red Hat: PicketBox XACML v2.0.5.final from JBoss released</title>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;It took some extra time (other priorities took precedence). In the end, it all worked out fine.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
LGPL licensed free open source project, PicketBox has released the XACML component v2.0.5.final.   Please download it from PicketBox &lt;a href="http://jboss.org/picketbox/downloads.html"&gt;downloads&lt;/a&gt;. &lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;&lt;br&gt;&#xD;
&lt;/span&gt;&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;Main Wiki Page&lt;/span&gt;&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;&lt;br&gt;&#xD;
&lt;/span&gt;&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;&lt;a href="http://community.jboss.org/wiki/PicketBoxXACMLJBossXACML"&gt;&lt;span style="font-size: small;"&gt;PicketBox XACML Dashboard Wiki Page&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;&lt;br&gt;&#xD;
&lt;/span&gt;&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;Main Features Added (compared to v2.0.4)&lt;/span&gt;&lt;br&gt;&#xD;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://community.jboss.org/wiki/XACMLPolicyLocatorusingLDAP"&gt;LDAP Based Policy Locator&lt;/a&gt;. &lt;/li&gt;&#xD;
&lt;li&gt;&lt;a href="http://community.jboss.org/wiki/XACMLAttributeLocatorusingLDAP"&gt;LDAP Based Attribute Locator&lt;/a&gt;.&lt;/li&gt;&#xD;
&lt;li&gt;&lt;a href="http://community.jboss.org/wiki/XACMLAttributeLocatorusingtheDatabase"&gt;Database Based Attribute Locator&lt;/a&gt;.&lt;/li&gt;&#xD;
&lt;li&gt;&lt;a href="https://community.jboss.org/wiki/XACMLCachingforPerformance"&gt;Decision Cache for performance&lt;/a&gt;.&lt;/li&gt;&#xD;
&lt;/ul&gt;&lt;span style="font-size: large;"&gt;&lt;br&gt;&#xD;
&lt;/span&gt;&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;JIRA&lt;/span&gt;&lt;br&gt;&#xD;
&lt;a href="https://jira.jboss.org/browse/SECURITY"&gt;PicketBox JIRA&lt;/a&gt;&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;&lt;br&gt;&#xD;
&lt;/span&gt;&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;&lt;br&gt;&#xD;
&lt;/span&gt;&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;JBoss Integration&lt;/span&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
PicketBox XACML is integrated into JBoss Application Server v5.0 and beyond.  Additionally, it is available as part of the JBoss Enterprise Application Platform (EAP) v5.0 and beyond and JBoss SOA Platform v5.0 and beyond.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;Release Notes&lt;/span&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
** Bug&lt;br&gt;&#xD;
&lt;ul&gt;&lt;li&gt;    * [SECURITY-452] - Don't use Xalan classes directly. Use Java API instead&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-461] - AttributeFinder:findAttribute method can throw an NPE if any of the attribute finder modules return null&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-462] - JBossRequestContext should throw IllegalArgumentException for null inputstream&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-507] - JBossXACML: anyURI mismatch&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-518] - JBossPDP should be serializable&lt;/li&gt;&#xD;
&lt;/ul&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
** Feature Request&lt;br&gt;&#xD;
&lt;ul&gt;&lt;li&gt;    * [SECURITY-454] - Database Attribute Locator&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-463] - AttributeValue.getValue abstract method * [SECURITY-455] - LDAP based attribute locator&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-456] - File based Attribute Locator&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-492] - JBossPolicySetLocator should gracefully handle policies&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-516] - Create a LDAP policy provider for JBoss XACML&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-521] - Decision Cache for constant XACML Requests&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-522] - XACML add hashcode and equals to RequestCtx, Attribute&lt;/li&gt;&#xD;
&lt;li&gt;    * [SECURITY-525] - XACML Attribute Locator should support comma separated list of attributeSupportedIds                                                                                                         &lt;/li&gt;&#xD;
&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/6940728126479075612-2213442891000860658?l=anil-identity.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&#xD;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/hv96y_ZuHGLKm4dKuZ1qg1obuxA/0/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/hv96y_ZuHGLKm4dKuZ1qg1obuxA/0/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a href="http://feedads.g.doubleclick.net/~a/hv96y_ZuHGLKm4dKuZ1qg1obuxA/1/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/hv96y_ZuHGLKm4dKuZ1qg1obuxA/1/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_1HTrAcykYk:Iv7Cg2f7mqw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_1HTrAcykYk:Iv7Cg2f7mqw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_1HTrAcykYk:Iv7Cg2f7mqw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=_1HTrAcykYk:Iv7Cg2f7mqw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/_1HTrAcykYk" height="1" width="1"/&gt;</content>
    <updated>2010-08-31T19:03:08Z</updated>
    <published>2010-08-31T19:01:00Z</published>
    <category scheme="http://www.blogger.com/atom/ns#" term="picketbox" />
    <category scheme="http://www.blogger.com/atom/ns#" term="JBossXACML" />
    <category scheme="http://www.blogger.com/atom/ns#" term="XACML" />
    <category scheme="http://www.blogger.com/atom/ns#" term="picketlink" /><feedburner:origlink>http://anil-identity.blogspot.com/2010/08/picketbox-xacml-v205final-from-jboss.html</feedburner:origlink>
    <author>
      <name>Anil Saldhana</name>
      <email>noreply@blogger.com</email>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-6940728126479075612</id>
      <author>
        <name>Anil Saldhana</name>
        <email>noreply@blogger.com</email>
      </author>
      <link href="http://anil-identity.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://anil-identity.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/6940728126479075612/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/AnilsSecurityAndIdentityManagementBlog" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>This blog is a personal online diary of Security/ IDM related thoughts, muses, stories and rumors. The blog posts are a personal opinion only and neither reflect the views of current/past employers nor any OTHER person living/dead on this planet.

I am the Lead Security Architect at JBoss (Middleware for Red Hat Inc). I strive to make JBoss secure for users and customers alike.</subtitle>
      <title>Anil's Security and Identity Management Blog</title>
      <updated>2010-08-31T19:03:08Z</updated>
    </source>
  <feedburner:origLink>http://feedproxy.google.com/~r/AnilsSecurityAndIdentityManagementBlog/~3/ycoXU1MDajI/picketbox-xacml-v205final-from-jboss.html</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://blogs.msdn.com/b/vbertocci/archive/2010/08/31/wif-amp-yours-truly-the-knowledge-chamber.aspx</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/e4BslvTQ9Hs/wif-amp-yours-truly-the-knowledge-chamber.aspx" rel="alternate" type="text/html" />
    <title xml:lang="en-US">Vittorio Bertocci - Microsoft: WIF &amp; Yours Truly @ the Knowledge Chamber</title>
    <content type="html" xml:lang="en-US">&lt;p&gt;&lt;a href="http://bit.ly/8YuXUf"&gt;&lt;img alt="image" border="0" height="387" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/0160.image_5F00_6965FB16.png" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px;" title="image" width="500"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Last week &lt;a href="http://channel9.msdn.com/Niners/Robert%20Hess/"&gt;Robert Hess&lt;/a&gt;, host extraordinaire, invited me to his &lt;a href="http://bit.ly/8YuXUf"&gt;The Knowledge Chamber show&lt;/a&gt;. The casus belli was the release of &lt;a href="http://bit.ly/9mjSIi"&gt;Programming Windows Identity Foundation&lt;/a&gt;, but we ended up having a nice chat about all things claims-based identity. I even had the chance of showing a super-quick demo using WIF, ACS, the &lt;a href="http://bit.ly/bGc4n8"&gt;security token visualizer control&lt;/a&gt; and &lt;a href="http://bit.ly/9YE2X5"&gt;SelfSTS&lt;/a&gt;. Check out the video &lt;a href="http://bit.ly/8YuXUf"&gt;&lt;strong&gt;here&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The chat was so nice that we ended up going on for almost 40 minutes, which is practically twice the length of the typical Knowledge Chamber episode. Thank you Robert for having me over!&lt;/p&gt;&lt;div style="clear: both;"&gt;&lt;/div&gt;&lt;img height="1" src="http://blogs.msdn.com/aggbug.aspx?PostID=10056420" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=e4BslvTQ9Hs:M0vu7jIp6-4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=e4BslvTQ9Hs:M0vu7jIp6-4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=e4BslvTQ9Hs:M0vu7jIp6-4:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=e4BslvTQ9Hs:M0vu7jIp6-4:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/e4BslvTQ9Hs" height="1" width="1"/&gt;</content>
    <updated>2010-08-31T16:43:34Z</updated>
    <published>2010-08-31T16:43:34Z</published>
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Identity/" term="Identity" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Book/" term="Book" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Windows+Identity+Foundation/" term="Windows Identity Foundation" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/WIF/" term="WIF" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Access+Control+Service/" term="Access Control Service" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/ACS/" term="ACS" />
    <author>
      <name>vibro</name>
      <uri>http://blogs.msdn.com/members/vibro/</uri>
    </author>
    <source>
      <id>http://blogs.msdn.com/b/vbertocci/atom.aspx</id>
      <link href="http://blogs.msdn.com/b/vbertocci/" rel="alternate" type="text/html" />
      <link href="http://blogs.msdn.com/b/vbertocci/atom.aspx" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Scatter thoughts</subtitle>
      <title xml:lang="en-US">Vibro.NET</title>
      <updated>2010-05-11T17:27:14Z</updated>
    </source>
  <feedburner:origLink>http://blogs.msdn.com/b/vbertocci/archive/2010/08/31/wif-amp-yours-truly-the-knowledge-chamber.aspx</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content52908.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/yYinRg782zc/content52908.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: E-Health Insider - EHI's industry round up 31.08.2010</title>
    
    <updated>2010-08-31T14:47:14Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://www.e-health-insider.com/news/6198/ehi%27s_industry_round_up_31.08.2010&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yYinRg782zc:7Wiyk6ZHsko:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yYinRg782zc:7Wiyk6ZHsko:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yYinRg782zc:7Wiyk6ZHsko:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=yYinRg782zc:7Wiyk6ZHsko:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/yYinRg782zc" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content52908.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/integrated_solution_secures_data_and_improves_productivity_with_vmware_view___imprivata</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/J5ad11NiR5Y/integrated_solution_secures_data_and_improves_productivity_with_vmware_view___imprivata" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: Imprivata Delivers Fast and Secure Access to Applications for VMware View 4.5 Users</title>
    
    <updated>2010-08-31T13:23:51Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">Integrated Solution Secures Data and Improves Productivity via One-Touch “Follow me” Desktops with Single Sign-on and Extended Strong Authentication&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=J5ad11NiR5Y:4CiA4cZFmKY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=J5ad11NiR5Y:4CiA4cZFmKY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=J5ad11NiR5Y:4CiA4cZFmKY:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=J5ad11NiR5Y:4CiA4cZFmKY:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/J5ad11NiR5Y" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/integrated_solution_secures_data_and_improves_productivity_with_vmware_view___imprivata</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-12447072.post-5721110888957474556</id>
    <link href="http://connectid.blogspot.com/feeds/5721110888957474556/comments/default" rel="replies" type="application/atom+xml" />
    <link href="https://www.blogger.com/comment.g?blogID=12447072&amp;postID=5721110888957474556" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/5721110888957474556?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/5721110888957474556?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/yUH4Ch-R_Ck/new-line-of-greeting-cards_31.html" rel="alternate" type="text/html" />
    <title>Paul Madsen: New line of greeting cards</title>
    <content type="html">&lt;div class="posterous_autopost"&gt;&lt;img height="298" src="http://posterous.com/getfile/files.posterous.com/paulmadsen/2iY3KbnMUkw69PKXjxa7047TqVSVAqaDGsrBa3OSOMhQtapzlztQRtSIFYir/Screen_00019.jpg" width="356"&gt;&lt;/img&gt; &lt;p style="font-size: 10px;"&gt;  &lt;a href="http://posterous.com"&gt;Posted via email&lt;/a&gt;   from &lt;a href="http://paulmadsen.posterous.com/new-line-of-greeting-cards-51"&gt;Pre(posterous)&lt;/a&gt;  &lt;/p&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/12447072-5721110888957474556?l=connectid.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/blogspot/gMwy/~4/yUH4Ch-R_Ck" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yUH4Ch-R_Ck:IkOBu8V3gmI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yUH4Ch-R_Ck:IkOBu8V3gmI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yUH4Ch-R_Ck:IkOBu8V3gmI:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=yUH4Ch-R_Ck:IkOBu8V3gmI:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/yUH4Ch-R_Ck" height="1" width="1"/&gt;</content>
    <updated>2010-08-31T13:00:14Z</updated>
    <published>2010-08-31T13:00:00Z</published>
    <author>
      <name>Paul Madsen</name>
      <email>noreply@blogger.com</email>
      <uri>http://www.blogger.com/profile/08489111023182783403</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-12447072</id>
      <author>
        <name>Paul Madsen</name>
        <email>noreply@blogger.com</email>
        <uri>http://www.blogger.com/profile/08489111023182783403</uri>
      </author>
      <link href="http://connectid.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://connectid.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/12447072/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/blogspot/gMwy" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>When you don't have anything nice to say, consider blogging it. or a tweet if you're rushed for time.</subtitle>
      <title>ConnectID</title>
      <updated>2010-09-01T22:30:26Z</updated>
    </source>
  <feedburner:origLink>http://connectid.blogspot.com/2010/08/new-line-of-greeting-cards_31.html</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-6940728126479075612.post-4885569784115540187</id>
    <link href="http://anil-identity.blogspot.com/feeds/4885569784115540187/comments/default" rel="replies" type="application/atom+xml" />
    <link href="https://www.blogger.com/comment.g?blogID=6940728126479075612&amp;postID=4885569784115540187" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/6940728126479075612/posts/default/4885569784115540187?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/6940728126479075612/posts/default/4885569784115540187?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/3clJ2ykITas/xacml-design-considerations-and.html" rel="alternate" type="text/html" />
    <title>Anil Saldhana - Red Hat: XACML Design Considerations and Pointers</title>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;One of the challenges with XACML has been the deep knowledge/expertise required in understanding the XACML vocabulary. It can send shivers down anybody's spine when they come across a bunch of XACML policies. While the language is extremely powerful, lack of editors has been the bane.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
While it is difficult to design a general purpose xacml editor without requiring the user to have extensive xacml knowledge, it should definitely be possible to create context based editors for XACML rules.  Suppose you are creating XACML policies for your web application, then you can have an editor that is specific to the web application domain.  This domain based editor approach will avoid the requirement of xacml knowledge. The policies can be designed in the domain semantics.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
If you have some free time to kill and want to understand XACML better, I certainly recommend taking a peak at the &lt;a href="http://www.fedora-commons.org/download/2.2/userdocs/server/security/XACMLPolicyGuide.htm"&gt;Fedora XACML document&lt;/a&gt; ( &lt;i&gt;&lt;b&gt;I did not write it or was associated with the project&lt;/b&gt;&lt;/i&gt;).&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;span style="font-size: large;"&gt;&lt;br&gt;&#xD;
Design Consideration&lt;/span&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
One of the favorite topics broached by XACML designers is the concept of date/time as part of the environment attributes. &lt;br&gt;&#xD;
&lt;br&gt;&#xD;
You should be able to create XACML policies with rules such as:&lt;br&gt;&#xD;
&lt;ul&gt;&lt;li&gt;Deny requests to web applications between 5pm and 8am CDT.&lt;/li&gt;&#xD;
&lt;/ul&gt;One point you need to note here is that if you are setting up automated tests to validate your policies, then the time at which the PDP is running your tests, can affect the outcome of the test result.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
You should embed the current time as part of your XACML request during tests such that they simulate a request occurring at a particular time - rather than when the test is run. :) &lt;br&gt;&#xD;
&lt;br&gt;&#xD;
You should definitely take a look at the XML Date and Time functions including Timezone configuration as listed &lt;a href="http://www.w3schools.com/Schema/schema_dtypes_date.asp"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/6940728126479075612-4885569784115540187?l=anil-identity.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&#xD;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/91fCGeeOFvK0CnYOvORZYdqVYdI/0/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/91fCGeeOFvK0CnYOvORZYdqVYdI/0/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a href="http://feedads.g.doubleclick.net/~a/91fCGeeOFvK0CnYOvORZYdqVYdI/1/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/91fCGeeOFvK0CnYOvORZYdqVYdI/1/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3clJ2ykITas:bIcgpSKDmuI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3clJ2ykITas:bIcgpSKDmuI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3clJ2ykITas:bIcgpSKDmuI:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=3clJ2ykITas:bIcgpSKDmuI:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/3clJ2ykITas" height="1" width="1"/&gt;</content>
    <updated>2010-08-31T04:14:58Z</updated>
    <published>2010-08-31T04:14:00Z</published>
    <category scheme="http://www.blogger.com/atom/ns#" term="XACML" /><feedburner:origlink>http://anil-identity.blogspot.com/2010/08/xacml-design-considerations-and.html</feedburner:origlink>
    <author>
      <name>Anil Saldhana</name>
      <email>noreply@blogger.com</email>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-6940728126479075612</id>
      <author>
        <name>Anil Saldhana</name>
        <email>noreply@blogger.com</email>
      </author>
      <link href="http://anil-identity.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://anil-identity.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/6940728126479075612/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/AnilsSecurityAndIdentityManagementBlog" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>This blog is a personal online diary of Security/ IDM related thoughts, muses, stories and rumors. The blog posts are a personal opinion only and neither reflect the views of current/past employers nor any OTHER person living/dead on this planet.

I am the Lead Security Architect at JBoss (Middleware for Red Hat Inc). I strive to make JBoss secure for users and customers alike.</subtitle>
      <title>Anil's Security and Identity Management Blog</title>
      <updated>2010-08-31T19:03:08Z</updated>
    </source>
  <feedburner:origLink>http://feedproxy.google.com/~r/AnilsSecurityAndIdentityManagementBlog/~3/S4T9yYr8F9c/xacml-design-considerations-and.html</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://blogs.msdn.com/b/vbertocci/archive/2010/08/30/just-out-the-ebook-version-of-programming-windows-identity-foundation.aspx</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/X0KkNYzHG6w/just-out-the-ebook-version-of-programming-windows-identity-foundation.aspx" rel="alternate" type="text/html" />
    <title xml:lang="en-US">Vittorio Bertocci - Microsoft: Just Out: The eBook Version of “Programming Windows Identity Foundation”</title>
    <content type="html" xml:lang="en-US">&lt;p&gt;&lt;a href="http://www.amazon.com/gp/product/0735627185?ie=UTF8&amp;amp;tag=wwwcloudident-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0735627185"&gt;&lt;img alt="image" border="0" height="140" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/0336.image_5F00_3.png" style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px;" title="image" width="240"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;strong&gt;[UPDATE: I eventually got it too, see at the end of the post]&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Yes, you get to see the &lt;a href="http://bit.ly/aejn0m"&gt;eBook version&lt;/a&gt; of &lt;a href="http://oreil.ly/9FcbvB"&gt;my book&lt;/a&gt; even before I do :-)&lt;/p&gt;  &lt;p&gt;&lt;a href="http://oreil.ly/9FcbvB"&gt;O’Reilly&lt;/a&gt; just made available today the &lt;a href="http://oreil.ly/9FcbvB"&gt;eBook option&lt;/a&gt; for &lt;a href="http://oreil.ly/9FcbvB"&gt;Programming Windows Identity Foundation&lt;/a&gt;. Thanks to &lt;a href="http://twitter.com/mgerickson"&gt;Mike Erickson&lt;/a&gt;’s &lt;a href="http://twitter.com/mgerickson/status/22549718648"&gt;tweet&lt;/a&gt; we also know that the download now works (thanks Mike!).&lt;/p&gt;  &lt;p&gt;I admit my general ignorance in terms of {&amp;lt;format,device&amp;gt;} well-formed pairs, but from a quick search I learned that&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;strong&gt;Mobi&lt;/strong&gt; is for Kindle &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;ePub&lt;/strong&gt; is for Sony Reader, iPad, iPhone, Android, various mobile devices &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;PDF&lt;/strong&gt; is, well, PDF. I’m sure you’ll figure it out :-) &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;It’s true, I haven’t seen &lt;a href="http://oreil.ly/9FcbvB"&gt;the book in a single file&lt;/a&gt; just yet. Will I buy this one? Weeell, I am still a big fan of the paper versions. Besides, I already know how this particular book ends… but &lt;a href="http://oreil.ly/9FcbvB"&gt;if digital books are your thing&lt;/a&gt;, by all means :-)&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;[Updated: PS, here it is!]&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/0552.image_5F00_62BA3081.png"&gt;&lt;img alt="image" border="0" height="348" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/5466.image_5F00_thumb_5F00_172ADCFD.png" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px;" title="image" width="628"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear: both;"&gt;&lt;/div&gt;&lt;img height="1" src="http://blogs.msdn.com/aggbug.aspx?PostID=10056109" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=X0KkNYzHG6w:panFqrqlSIc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=X0KkNYzHG6w:panFqrqlSIc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=X0KkNYzHG6w:panFqrqlSIc:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=X0KkNYzHG6w:panFqrqlSIc:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/X0KkNYzHG6w" height="1" width="1"/&gt;</content>
    <updated>2010-08-31T04:10:31Z</updated>
    <published>2010-08-31T04:10:31Z</published>
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Identity/" term="Identity" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Book/" term="Book" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Windows+Identity+Foundation/" term="Windows Identity Foundation" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/WIF/" term="WIF" />
    <author>
      <name>vibro</name>
      <uri>http://blogs.msdn.com/members/vibro/</uri>
    </author>
    <source>
      <id>http://blogs.msdn.com/b/vbertocci/atom.aspx</id>
      <link href="http://blogs.msdn.com/b/vbertocci/" rel="alternate" type="text/html" />
      <link href="http://blogs.msdn.com/b/vbertocci/atom.aspx" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Scatter thoughts</subtitle>
      <title xml:lang="en-US">Vibro.NET</title>
      <updated>2010-05-11T17:27:14Z</updated>
    </source>
  <feedburner:origLink>http://blogs.msdn.com/b/vbertocci/archive/2010/08/30/just-out-the-ebook-version-of-programming-windows-identity-foundation.aspx</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.links.org/?p=985</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/WKHCFH-CTBY/" rel="alternate" type="text/html" />
    <title>Ben Laurie - Apache / The Bunker: Cod Chowder</title>
    <summary type="html">Chowder isn’t exactly rocket science, but this went pretty well, so documenting it here…
I actually made this almost entirely from frozen ingredients and it was just fine. Fresh might be better.
Finely chopped leek
Smoked bacon, sliced (I used some lardons I had in the freezer)
Cubed potatoes
Chicken stock (maybe fish stock would be better, I didn’t have [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Chowder isn’t exactly rocket science, but this went pretty well, so documenting it here…&lt;/p&gt;&#xD;
&lt;p&gt;I actually made this almost entirely from frozen ingredients and it was just fine. Fresh might be better.&lt;/p&gt;&#xD;
&lt;p&gt;Finely chopped leek&lt;br&gt;&#xD;
Smoked bacon, sliced (I used some lardons I had in the freezer)&lt;br&gt;&#xD;
Cubed potatoes&lt;br&gt;&#xD;
Chicken stock (maybe fish stock would be better, I didn’t have any) or water&lt;br&gt;&#xD;
Milk (about half as much as stock)&lt;br&gt;&#xD;
Pepper&lt;br&gt;&#xD;
Mace&lt;br&gt;&#xD;
Cod&lt;br&gt;&#xD;
King prawns&lt;br&gt;&#xD;
Sweetcorn&lt;br&gt;&#xD;
Cream&lt;/p&gt;&#xD;
&lt;p&gt;Fry the leeks and bacon in a little butter/olive oil (I used both) until pretty soft – I didn’t crisp the bacon for a change. I think it is better for chowder not to. Add cubed potatoes and fry for a bit longer, then add chicken stock (or water or fish stock) and bring to the boil. Simmer until the potatoes have softened, then zap half the mixture with a blender (I just did this in situ). Season (I didn’t need salt, there was enough in the bacon). Add milk, fish, prawns and bring back up to a simmer, cook for a few minutes, making sure the fish falls apart. Add cooked sweetcorn and bring back up to temperature. Finally, add some cream.&lt;/p&gt;&#xD;
&lt;p&gt;Quantities should be chosen so that the final result is good and thick.&lt;/p&gt;&#xD;
&lt;p&gt;Serve with warm, crusty bread and butter. Works as a whole meal.&lt;/p&gt;&#xD;
&lt;p class="akst_link"&gt;&lt;a class="akst_share_link" href="http://www.links.org/?p=985&amp;amp;akst_action=share-this" id="akst_link_985" rel="nofollow" title="E-mail this, post to del.icio.us, etc."&gt;Share This&lt;/a&gt;&#xD;
&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/lLvq41BwNEPfkO3h3boLCtEdTN0/0/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/lLvq41BwNEPfkO3h3boLCtEdTN0/0/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a href="http://feedads.g.doubleclick.net/~a/lLvq41BwNEPfkO3h3boLCtEdTN0/1/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/lLvq41BwNEPfkO3h3boLCtEdTN0/1/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/links/ZvUZ/~4/Iq7_WiHA2rY" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=WKHCFH-CTBY:Iq7_WiHA2rY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=WKHCFH-CTBY:Iq7_WiHA2rY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=WKHCFH-CTBY:Iq7_WiHA2rY:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=WKHCFH-CTBY:Iq7_WiHA2rY:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/WKHCFH-CTBY" height="1" width="1"/&gt;</content>
    <updated>2010-08-31T04:05:11Z</updated>
    <category term="Food" />
    <category term="Recipes" /><feedburner:origlink>http://www.links.org/?p=985</feedburner:origlink>
    <author>
      <name>Ben</name>
    </author>
    <source>
      <id>http://www.links.org</id>
      <link href="http://www.links.org" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/links/ZvUZ" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Ben Laurie blathering</subtitle>
      <title>Links</title>
      <updated>2010-08-31T04:32:29Z</updated>
    </source>
  <feedburner:origLink>http://feedproxy.google.com/~r/links/ZvUZ/~3/Iq7_WiHA2rY/</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.windley.com/archives/2010/08/come_to_kynetx_developer_day.shtml</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/xJF509gIrgQ/come_to_kynetx_developer_day.shtml" rel="alternate" type="application/xhtml+xml" />
    <title xml:lang="en">Phil Windley - Kynetx: Come to Kynetx Developer Day</title>
    <summary xml:lang="en" type="html">In the past Kynetx has held two Kynetx Impact conferences, one last fall and one last spring. Kynetx Impact exceeded my expectations both times with lots of people and energy. But holding a conference of that size is, frankly,...</summary>
    <content type="html" xml:lang="en">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;a href="http://www.kynetx.com"&gt;&lt;img align="right" alt="Kynetx" border="0" hspace="3" src="http://www.windley.com/images/kynetx_logo.jpg" style="margin-top: 10px;" title="Kynetx" vspace="3"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
&lt;p&gt;&#xD;
In the past Kynetx has held two Kynetx Impact conferences, one last fall and one last spring. Kynetx Impact exceeded my expectations both times with lots of people and energy. But holding a conference of that size is, frankly, a lot of work for a small team.  Consequently, we've decided to move to an annual schedule with Kynetx Impact, holding the conference once a year in the spring.  At the same time, we didn't want to lose the ability to contact and work with developers, so we've created Kynetx Developer Days.  The first Kynetx Developer Day will be held in our &lt;a href="http://www.eventbrite.com/googlemap?eid=767164610"&gt;Utah office&lt;/a&gt; on September 18, 2010.  (&lt;a href="http://kynetxdevday.eventbrite.com/"&gt;Register here...it's free!&lt;/a&gt;)&#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
At Kynetx Dev Day, you'll find tracks for beginning KRL programmers as well as more advanced topics for experienced KRL developers.  The &lt;a href="http://kynetxdevday.eventbrite.com/"&gt;full agenda is available online&lt;/a&gt;.  We'll be announcing and teaching people how to use some cool new features, including how to use Kynetx with email and telephony services like &lt;a href="http://www.twilio.com/?gclid=CL_25_v24aMCFRxEgwodDGB70g"&gt;Twilleo&lt;/a&gt; via &lt;a href="http://www.webhooks.org/"&gt;webhooks&lt;/a&gt;.  But there's more...&#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
Last Friday we gave a demonstration of the power of Kynetx to orchestrate multiple services (Web, email, telephony, and so on) in pursuit of the end-user's purpose.  In this case we showed how an email from a person's radiologist suggesting they need neck surgery based on their MRI results could kick-off a whole series of interactions and tasks.  Our demo showed how a dozen individual, small, simple cooperating KRL applications could automate the interactions to significantly reduce the user's cognitive load.  &#xD;
&lt;/p&gt;&#xD;
&#xD;
&#xD;
&lt;p&gt;&#xD;
Not only will we be showing the latest version of that demo at the Sept 18th Dev Day, but we'll be teaching about the techniques necessary to build those kind of compelling experiences.  You don't want to miss it.  &#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
And for those who can't be in Utah on Sept 18th, one of the reasons for moving to the simpler format for our fall event was to be able to spread them around more.  We plan on conducting similar Kynetx Dev Days in other locations in the coming months.  Stay tuned for more information...&#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
In the meantime, &lt;a href="http://kynetxdevday.eventbrite.com/"&gt;register for the Sept 18th event&lt;/a&gt; if you'd like to come.  It's free. We'd love to have you.  &#xD;
&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=xJF509gIrgQ:ycToQV9MSD0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=xJF509gIrgQ:ycToQV9MSD0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=xJF509gIrgQ:ycToQV9MSD0:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=xJF509gIrgQ:ycToQV9MSD0:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/xJF509gIrgQ" height="1" width="1"/&gt;</content>
    <updated>2010-08-30T22:30:23Z</updated>
    <published>2010-08-30T19:47:40Z</published>
    <category term="kynetx, developers, krl," />
    <source>
      <id>http://www.windley.com/</id>
      <icon>http://www.windley.com/favicon.ico</icon>
      <logo>http://www.niallkennedy.com/alive.gif</logo>
      <author>
        <name>windley</name>
        <email>phil@windley.org</email>
        <uri>http://www.windley.com</uri>
      </author>
      <link href="http://www.windley.com/" rel="alternate" type="application/xhtml+xml" />
      <link href="http://www.windley.com/atom.xml" rel="self" type="application/atom+xml" />
      <rights xml:lang="en">Creative Commons Attribution 2.5</rights>
      <subtitle xml:lang="en">Organizations Get the IT They Deserve</subtitle>
      <title xml:lang="en">Phil Windley's Technometria</title>
      <updated>2010-09-02T15:57:10Z</updated>
    </source>
  <feedburner:origLink>http://www.windley.com/archives/2010/08/come_to_kynetx_developer_day.shtml</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content52862.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/n9AVifaEoAc/content52862.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: Healthcare Info Security - Survey: Spending on Security Up</title>
    
    <updated>2010-08-30T19:41:11Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://blogs.healthcareinfosecurity.com/posts.php?postID=686&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=n9AVifaEoAc:HbZ-NTgw2GU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=n9AVifaEoAc:HbZ-NTgw2GU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=n9AVifaEoAc:HbZ-NTgw2GU:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=n9AVifaEoAc:HbZ-NTgw2GU:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/n9AVifaEoAc" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content52862.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content52861.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/GRYnHgQZdto/content52861.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: HealthTechnica - Imprivata Announces Healthcare Advisory Board</title>
    
    <updated>2010-08-30T19:40:39Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://www.healthtechnica.com/blogsphere/2010/08/27/imprivata-announces-healthcare-advisory-board/&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=GRYnHgQZdto:5RK9qCrOHvE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=GRYnHgQZdto:5RK9qCrOHvE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=GRYnHgQZdto:5RK9qCrOHvE:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=GRYnHgQZdto:5RK9qCrOHvE:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/GRYnHgQZdto" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content52861.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content52860.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/iXZBA8ZJtI0/content52860.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: InternetNews.com - Security, EMRs Top Healthcare IT Priorities</title>
    
    <updated>2010-08-30T19:37:57Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://www.internetnews.com/security/article.php/3900416/Security+EMRs+Top+Healthcare+IT+Priorities.htm&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=iXZBA8ZJtI0:4OInpY8ZoEQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=iXZBA8ZJtI0:4OInpY8ZoEQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=iXZBA8ZJtI0:4OInpY8ZoEQ:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=iXZBA8ZJtI0:4OInpY8ZoEQ:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/iXZBA8ZJtI0" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content52860.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.windley.com/archives/2010/08/come_to_internet_identity_workshop_east_next_week.shtml</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/KMeUIy3LHsI/come_to_internet_identity_workshop_east_next_week.shtml" rel="alternate" type="application/xhtml+xml" />
    <title xml:lang="en">Phil Windley - Kynetx: Come to Internet Identity Workshop East Next Week</title>
    <summary xml:lang="en" type="html">The East Coast edition of the Internet Identity Workshop (IIW) will happen next week on Thursday and Friday (Sept 9-10) at the Josaphine Butler Parks Center in Washington DC. The theme for this edition of IIW is Open Identity...</summary>
    <content type="html" xml:lang="en">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;a href="http://iiweast.eventbrite.com/"&gt;&lt;img align="right" alt="IIW" border="0" hspace="3" src="http://www.internetidentityworkshop.com/wp-content/uploads/2010/08/MVFall2010.jpg" style="margin-top: 10px;" title="IIW" vspace="3" width="150px"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
&lt;p&gt;&#xD;
The East Coast edition of the Internet Identity Workshop (IIW) will happen next week on Thursday and Friday (Sept 9-10) at the &lt;a href="http://www.washingtonparks.net/parkscenter.html"&gt;Josaphine Butler Parks Center&lt;/a&gt; in Washington DC.  The theme for this edition of IIW is &lt;em&gt;Open Identity for Open Government&lt;/em&gt;. You can &lt;a href="http://iiweast.eventbrite.com/"&gt;register online&lt;/a&gt;. Late registration fees kick in after Friday, so register now.  &#xD;
&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=KMeUIy3LHsI:BaX_5chBFhk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=KMeUIy3LHsI:BaX_5chBFhk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=KMeUIy3LHsI:BaX_5chBFhk:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=KMeUIy3LHsI:BaX_5chBFhk:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/KMeUIy3LHsI" height="1" width="1"/&gt;</content>
    <updated>2010-08-30T19:16:16Z</updated>
    <published>2010-08-30T19:15:05Z</published>
    <category term="identity, events, iiw," />
    <source>
      <id>http://www.windley.com/</id>
      <icon>http://www.windley.com/favicon.ico</icon>
      <logo>http://www.niallkennedy.com/alive.gif</logo>
      <author>
        <name>windley</name>
        <email>phil@windley.org</email>
        <uri>http://www.windley.com</uri>
      </author>
      <link href="http://www.windley.com/" rel="alternate" type="application/xhtml+xml" />
      <link href="http://www.windley.com/atom.xml" rel="self" type="application/atom+xml" />
      <rights xml:lang="en">Creative Commons Attribution 2.5</rights>
      <subtitle xml:lang="en">Organizations Get the IT They Deserve</subtitle>
      <title xml:lang="en">Phil Windley's Technometria</title>
      <updated>2010-09-02T15:57:10Z</updated>
    </source>
  <feedburner:origLink>http://www.windley.com/archives/2010/08/come_to_internet_identity_workshop_east_next_week.shtml</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blogs.gartner.com/mark-diodati/?p=55</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/UryJBHcB6I4/" rel="alternate" type="text/html" />
    <title>Mark Diodati - Gartner: CA Technologies to Purchase Arcot Systems</title>
    <summary type="html">I’ve been following the evolution of Arcot Systems for twelve years. I became aware of them as a potential competitor (and acquisition target) while working at RSA, and I’ve kept up with them in my role at Burton/Gartner. I’ve seen the evolution of its products beginning with its innovative “Camouflage” technology, which provided enhanced protection [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;I’ve been following the evolution of Arcot Systems for twelve years. I became aware of them as a potential competitor (and acquisition target) while working at RSA, and I’ve kept up with them in my role at Burton/Gartner. I’ve seen the evolution of its products beginning with its innovative “Camouflage” technology, which provided enhanced protection of the PKI private key in software.&lt;/p&gt;&#xD;
&lt;p&gt;Arcot has since expanded in three important product classes: consumer authentication (RiskFort and WebFort), the Verified by Visa program, and cloud identity management (A-OK On Demand). A-OK On Demand is SaaS-based. It provides SSO, authentication, and provisioning services to cloud applications. Cloud identity management products provide a relatively simple solution for complex enterprise needs. Along the way, Arcot has also picked up the expertise of hosting large-scale applications, including multi-tenancy. This expertise will come in handy as CA Technologies crafts its go-to-market cloud identity management strategy.&lt;/p&gt;&#xD;
&lt;p&gt;The purchase of Arcot provides good benefits for CA Technologies, without much (if any) downside. Over time, the synergies between Arcot’s cloud identity management offerings and CA Technologies’ enterprise-based identity management products will grow. For this to happen, CA Technologies must integrate its provisioning and web access management products with the Arcot products. If CA Technologies executes correctly, it can provide “desktop to cloud” identity management using existing products, without wholesale development effort. From a roadmap conflict perspective, the only capability overlap is federation.&lt;/p&gt;&#xD;
&lt;p&gt;CA Technologies has worked with Arcot for several years, including integrating its SiteMinder web access management product with Arcot’s consumer authentication solution. CA Technologies’ competition, Oracle, has offered a converged web access management/consumer authentication solution, which began with its acquisitions of Oblix (2005) and Bharosa (2007). The Arcot purchase will position CA Technologies to compete with Oracle, with the additional capability of a SaaS option.&lt;/p&gt;&#xD;
&lt;p&gt;For more information on Arcot and CA Technologies, please see our research documents (subscription required):&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=1990"&gt;Market Profile: Identity Management 2010&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=1728"&gt;Burton Group More, More, More: The Challenge of Extended Enterprise Authentication Mobility&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=1856"&gt;Burton Group Catalyst 2009: Cloud SSO Interoperability Summary&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=UryJBHcB6I4:eGcuOTJqSvs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=UryJBHcB6I4:eGcuOTJqSvs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=UryJBHcB6I4:eGcuOTJqSvs:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=UryJBHcB6I4:eGcuOTJqSvs:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/UryJBHcB6I4" height="1" width="1"/&gt;</content>
    <updated>2010-08-30T17:34:05Z</updated>
    <category term="Applications" />
    <category term="IAM" />
    <author>
      <name>Mark Diodati</name>
    </author>
    <source>
      <id>http://blogs.gartner.com/mark-diodati</id>
      <link href="http://blogs.gartner.com/mark-diodati/feed/" rel="self" type="application/atom+xml" />
      <link href="http://blogs.gartner.com/mark-diodati" rel="alternate" type="text/html" />
      <subtitle>A Member of The Gartner Blog Network</subtitle>
      <title>Mark Diodati</title>
      <updated>2010-09-01T01:32:50Z</updated>
    </source>
  <feedburner:origLink>http://blogs.gartner.com/mark-diodati/2010/08/30/ca-technologies-to-purchase-arcot/</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.identityblog.com/?p=1155</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/lJuqMD21iQ0/" rel="alternate" type="text/html" />
    <title>Kim Cameron - Microsoft: Kim Komando on location services</title>
    <summary type="html">Both of these stories are true. And they're very unnerving. There is also a common thread.</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://content.usatoday.com/topics/topic/Kim+Komando"&gt;Kim Komando&lt;/a&gt; has a &lt;a href="http://www.usatoday.com/tech/columnist/kimkomando/2010-08-26-location-services_N.htm?csp=usat.me"&gt;great piece&lt;/a&gt; at &lt;a href="http://www.usatoday.com/"&gt;USA Today &lt;/a&gt;where she explains geotagging through the experiences of two women who also happened to be using the &lt;a href="http://www.foursquare.com"&gt;foursquare location service&lt;/a&gt;.  This article is one of the first of what I expect will become a torrent as the media learns the implications of geolocation:&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Sylvia was dining out with a friend. The restaurant manager interrupted her dinner to tell her she had a phone call. It was from a complete stranger who tracked her online. He had described her to the manager.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Louise was at a bar with colleagues. A stranger began talking to her. He knew a lot about her personal interests. Then, he pulled out his phone and showed her a photo. It was a picture of Louise that he found online.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Both of these stories are true. And they’re very unnerving. There is also a common thread. The women were tracked by something known as “geotagging.”&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Geotagging adds GPS coordinates to your online posts or photos. You may be exposing this information without even knowing it. Geotagging is particularly popular with photos; many smartphones automatically geotag photos.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Photos can be plotted on a map for easy organization and viewing. But if you post photos online, and you could reveal your home address or child’s school. You’ve given a criminal a treasure map.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Layers of information&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;A geotagged photo is the most obvious threat to your privacy and safety. But, in Louise’s and Sylvia’s cases, there was more going on. Both used the location-based social-networking service Foursquare.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Location-based social-networking services are designed to help you meet up with family and friends. When you’re out and about, you check in with the site. At the coffee shop? Check in so friends nearby can find you.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Unless you have a stalker, these services aren’t particularly dangerous on their own. You need to think about the layers of information you leave online. As you use more services, it’s easier for criminals to track you.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Let’s say you post a photo of your new house to a photo site. The photo is geotagged. You’ve linked your photo account to Facebook. And you use Foursquare or Twitter on the go; updates are sent to your Facebook account.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;One night you go to the movies. You send a tweet as you wait in line. When you get home, you discover you’ve been robbed. The burglar used your photo to find your address. He learned more about you on Facebook. Your tweet tipped him off to your location.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Thanks to a movie site, he knew exactly how long the movie ran. He scoped out your house and neighborhood on Google Street View. He devised a plan to get in and out fast and undetected.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Protecting yourself&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;If you use these services, protect yourself. Use a little common sense. First, don’t geotag photos of your house or your children. In fact, it’s best to disable geotagging until you specifically need it.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;On the iPhone 4, tap Settings, then General, and then Location Services. You can select which applications can access GPS data. These options aren’t available in older iPhone software, so tap Settings, then General, then Reset. Tap Reset Location Warnings. You’ll be prompted if an application wants to access GPS data. You can then disallow it.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;In Android, start the Camera app and open the menu at the left. Go into the settings and turn off geotagging or location storage, depending on which version of Android is on your phone. On a BlackBerry, click the Camera icon. Press the Menu button and select Options. Set the Geotagging option to Disabled. Save your settings.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;You can also use an EXIF editor to remove location information from photos. EXIF data is information about a photo embedded in the file. Visit&lt;a href="http://www.komando.com/news"&gt; www.komando.com/news &lt;/a&gt;for free EXIF editors.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;Don’t check in on Foursquare or similar sites from home. And make sure your Twitter program is not including GPS coordinates in your tweets.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;For many people, Facebook ties everything together. Reconsider linking other accounts to Facebook. Pay close attention to your privacy settings. Only trusted friends should know when you are or aren’t at home. Finally, if you have contacts you don’t fully trust, it’s time to do a purge.&lt;/p&gt;&#xD;
&lt;p style="padding-left: 30px;"&gt;[&lt;a href="http://content.usatoday.com/topics/topic/Kim+Komando"&gt;Kim Komando&lt;/a&gt; hosts the nation's largest talk radio show about computers and the Internet. To get the podcast or find the station nearest you, visit www.komando.com/listen. To subscribe to Kim's free e-mail newsletters, sign up at &lt;a href="http://www.identityblog.com/www.komando.com/listen."&gt;www.komando.com/listen.&lt;/a&gt;. Contact her at &lt;a href="mailto:C1Tech@gannett.com"&gt;C1Tech@gannett.com&lt;/a&gt;. ]&lt;/p&gt;&#xD;
&lt;p&gt;It is well worth reading &lt;a href="http://foursquare.com/privacy/"&gt;Foursquare’s privacy policy&lt;/a&gt; - which is well thought out and makes Foursquare a paragon of virtue when compared to the &lt;a href="http://www.identityblog.com/?p=1154"&gt;contract with the devil&lt;/a&gt; you sign when you install iTunes, for example.  I’ll explore this more going forward.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=lJuqMD21iQ0:exPfB258b4Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=lJuqMD21iQ0:exPfB258b4Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=lJuqMD21iQ0:exPfB258b4Q:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=lJuqMD21iQ0:exPfB258b4Q:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/lJuqMD21iQ0" height="1" width="1"/&gt;</content>
    <updated>2010-08-30T15:06:42Z</updated>
    <category term="Linkage" />
    <category term="Location" />
    <category term="Mobile" />
    <category term="Privacy" />
    <author>
      <name>Kim Cameron</name>
    </author>
    <source>
      <id>http://www.identityblog.com</id>
      <link href="http://www.identityblog.com/wp-rss2.php" rel="self" type="application/atom+xml" />
      <link href="http://www.identityblog.com" rel="alternate" type="text/html" />
      <subtitle>Digital Identity And Our Future</subtitle>
      <title>Kim Cameron's Identity Weblog</title>
      <updated>2010-08-30T15:12:39Z</updated>
    </source>
  <feedburner:origLink>http://www.identityblog.com/?p=1155</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>8d07cc69-a460-48f1-844d-25b05ba87317:5917</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/DPh-55tCOAw/delivering-the-enterprise-ready-cloud-the-acquisition-of-arcot-systems-inc.aspx" rel="alternate" type="text/html" />
    <title>CA on Security Management: Delivering the Enterprise-Ready Cloud – The Acquisition of Arcot Systems, Inc.</title>
    
    <updated>2010-08-30T14:08:00Z</updated>
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/authentication/default.aspx" term="authentication" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Cloud+Security/default.aspx" term="Cloud Security" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/fraud/default.aspx" term="fraud" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Identity+and+Access+Management/default.aspx" term="Identity and Access Management" /><feedburner:origlink>http://community.ca.com/blogs/iam/archive/2010/08/30/delivering-the-enterprise-ready-cloud-the-acquisition-of-arcot-systems-inc.aspx</feedburner:origlink>
    <author>
      <name>Matthew Gardiner</name>
    </author>
    <source>
      <id>http://community.ca.com/blogs/iam/default.aspx</id>
      <logo>http://www.ca.com/images/global/logo_172900.gif</logo>
      <link href="http://community.ca.com/blogs/iam/default.aspx" rel="alternate" type="text/html" />
      <link href="http://feeds.ca.com/CS_CAIAMBlog" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Insight and opinion on the world of security management. This is the place for commentary on industry issues, articles and reports on topics such as managing identities and their lifecycles; securing access to data and resources; securing Web business applications and services; and managing security logs and information.</subtitle>
      <title>CA on Security Management</title>
      <updated>2010-08-31T03:02:26Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Today CA Technologies announced an agreement to acquire Arcot Systems, Inc. This transaction will result in several immediate and longer term benefits for our customers.  Current on-premise IAM customers, particularly customers of CA SiteMinder, will gain immediate benefits by using Arcot's strong authentication and fraud prevention capabilities to complement their well established...&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
 &lt;img height="1" src="http://feeds.feedburner.com/~r/CS_CAIAMBlog/~4/Y0yuFHG3FBQ" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=DPh-55tCOAw:OqYEvao7EgU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=DPh-55tCOAw:OqYEvao7EgU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=DPh-55tCOAw:OqYEvao7EgU:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=DPh-55tCOAw:OqYEvao7EgU:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/DPh-55tCOAw" height="1" width="1"/&gt;</content><feedburner:origLink>http://feeds.ca.com/~r/CS_CAIAMBlog/~3/Y0yuFHG3FBQ/delivering-the-enterprise-ready-cloud-the-acquisition-of-arcot-systems-inc.aspx</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://blogs.msdn.com/b/vbertocci/archive/2010/08/29/simon-says.aspx</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/_XDab_mwnU0/simon-says.aspx" rel="alternate" type="text/html" />
    <title xml:lang="en-US">Vittorio Bertocci - Microsoft: Simon Says</title>
    <content type="html" xml:lang="en-US">&lt;p&gt;[No technical content in this uncharacteristically brief post, be warned]&lt;/p&gt;  &lt;p&gt;This morning I was leafing through the September issue of Wired, when I got to an interview with &lt;a href="http://en.wikipedia.org/wiki/Simon_Singh"&gt;Simon Singh&lt;/a&gt; (no links to it, &lt;a href="http://www.wired.com/"&gt;Wired’s Web site&lt;/a&gt; does not appear to have the September issue up yet).&lt;/p&gt;  &lt;p&gt;Mr. Singh is a great science writer. A decade ago his &lt;a href="http://www.amazon.com/Code-Book-Science-Secrecy-Cryptography/dp/0385495323/ref=sr_1_1?s=books&amp;amp;ie=UTF8&amp;amp;qid=1283110281&amp;amp;sr=1-1"&gt;The Code Book&lt;/a&gt; (Codici &amp;amp; Segreti nella versione italiana) was one of the reasons for which I got an interest in security and protocols (one other being &lt;a href="http://www.amazon.com/Cryptonomicon-Neal-Stephenson/dp/0060512806/ref=sr_1_1?s=books&amp;amp;ie=UTF8&amp;amp;qid=1283110392&amp;amp;sr=1-1#_"&gt;Cryptonomicon&lt;/a&gt;, of course); more recently, I indirectly referenced his work on &lt;a href="http://www.amazon.com/Fermats-Enigma-Greatest-Mathematical-Problem/dp/0385493622/ref=sr_1_1?s=books&amp;amp;ie=UTF8&amp;amp;qid=1283110574&amp;amp;sr=1-1"&gt;Fermat’s Enigma&lt;/a&gt; from my &lt;a href="http://www.amazon.com/gp/product/0735627185?ie=UTF8&amp;amp;tag=wwwcloudident-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0735627185"&gt;Programming Windows Identity Foundation&lt;/a&gt; (doesn’t that titillate your curiosity? ;-)). &lt;/p&gt;  &lt;p&gt;I won’t get in the details of the article I was reading here, but just highlight a quote from it: &lt;/p&gt;  &lt;p align="center"&gt;&lt;em&gt;“You have to decide who you trust before you decide what to believe”&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Taken alone that may be a tad out of context, however I could not resist putting it out here: because that, folks, is such a beautifully concise enunciation of the very essence of claims-based identity that I may just start putting it everywhere.&lt;/p&gt;&lt;div style="clear: both;"&gt;&lt;/div&gt;&lt;img height="1" src="http://blogs.msdn.com/aggbug.aspx?PostID=10055564" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_XDab_mwnU0:Tlb12156pNw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_XDab_mwnU0:Tlb12156pNw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_XDab_mwnU0:Tlb12156pNw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=_XDab_mwnU0:Tlb12156pNw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/_XDab_mwnU0" height="1" width="1"/&gt;</content>
    <updated>2010-08-29T19:48:43Z</updated>
    <published>2010-08-29T19:48:43Z</published>
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Wild+Ideas/" term="Wild Ideas" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Identity/" term="Identity" />
    <author>
      <name>vibro</name>
      <uri>http://blogs.msdn.com/members/vibro/</uri>
    </author>
    <source>
      <id>http://blogs.msdn.com/b/vbertocci/atom.aspx</id>
      <link href="http://blogs.msdn.com/b/vbertocci/" rel="alternate" type="text/html" />
      <link href="http://blogs.msdn.com/b/vbertocci/atom.aspx" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Scatter thoughts</subtitle>
      <title xml:lang="en-US">Vibro.NET</title>
      <updated>2010-05-11T17:27:14Z</updated>
    </source>
  <feedburner:origLink>http://blogs.msdn.com/b/vbertocci/archive/2010/08/29/simon-says.aspx</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-11222552.post-8194284948952687422</id>
    <link href="http://jacksonshaw.blogspot.com/feeds/8194284948952687422/comments/default" rel="replies" type="application/atom+xml" />
    <link href="https://www.blogger.com/comment.g?blogID=11222552&amp;postID=8194284948952687422&amp;isPopup=true" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/11222552/posts/default/8194284948952687422?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/11222552/posts/default/8194284948952687422?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/5lzFjxqJJx0/location-services-pose-huge-security.html" rel="alternate" type="text/html" />
    <title>Jackson Shaw - Quest: Location services pose huge security risks</title>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Interesting &lt;a href="http://www.usatoday.com/tech/columnist/kimkomando/2010-08-26-location-services_N.htm?csp=usat.me" target="_blank"&gt;article in USA Today&lt;/a&gt; regarding this topic. What interested me about the article was the two real-life stories associated with the story:&lt;br&gt;&#xD;
&lt;blockquote&gt;&lt;i&gt;Sylvia was dining out with a friend. The restaurant manager interrupted her dinner to tell her she had a phone call. It was from a complete stranger who tracked her online. He had described her to the manager.&lt;/i&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;i&gt;Louise was at a bar with colleagues. A stranger began talking to her. He knew a lot about her personal interests. Then, he pulled out his phone and showed her a photo. It was a picture of Louise that he found online.&lt;/i&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;i&gt;Both of these stories are true. And they're very unnerving. There is also a common thread. The women were tracked by something known as "geotagging."&lt;/i&gt;&lt;/blockquote&gt;&lt;a href="http://identityblog.com/" target="_blank"&gt;Kim Cameron&lt;/a&gt; and others have been blogging about the &lt;a href="http://www.identityblog.com/?p=1140" target="_blank"&gt;privacy of location information&lt;/a&gt; – especially in light of the revelations about the Google street view service. This article brings to Earth exactly what the ramifications of the abuse of this information can lead to.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7de10747-0661-4bc1-8565-fcff5aaeffe3" style="display: inline; float: none; margin: 0px; padding: 0px;"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/privacy" rel="tag"&gt;privacy&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Kim+Cameron" rel="tag"&gt;Kim Cameron&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/11222552-8194284948952687422?l=jacksonshaw.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&#xD;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DqYJfA99MS5qtU8TxyEMPLwNn0Q/0/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/DqYJfA99MS5qtU8TxyEMPLwNn0Q/0/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a href="http://feedads.g.doubleclick.net/~a/DqYJfA99MS5qtU8TxyEMPLwNn0Q/1/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/DqYJfA99MS5qtU8TxyEMPLwNn0Q/1/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/JacksonsIdentityManagementActiveDirectoryRealityTourTravelblog/~4/f7j35Gual6w" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5lzFjxqJJx0:iuhuobBDNvE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5lzFjxqJJx0:iuhuobBDNvE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5lzFjxqJJx0:iuhuobBDNvE:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=5lzFjxqJJx0:iuhuobBDNvE:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/5lzFjxqJJx0" height="1" width="1"/&gt;</content>
    <updated>2010-08-28T14:46:59Z</updated>
    <published>2010-08-28T14:46:00Z</published><feedburner:origlink>http://jacksonshaw.blogspot.com/2010/08/location-services-pose-huge-security.html</feedburner:origlink>
    <author>
      <name>Jackson Shaw</name>
      <email>jackson.shaw@gmail.com</email>
      <uri>http://www.blogger.com/profile/00014140177974348471</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-11222552</id>
      <author>
        <name>Jackson Shaw</name>
        <email>jackson.shaw@gmail.com</email>
        <uri>http://www.blogger.com/profile/00014140177974348471</uri>
      </author>
      <link href="http://jacksonshaw.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://jacksonshaw.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/11222552/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/JacksonsIdentityManagementActiveDirectoryRealityTourTravelblog" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><em>Jackson's comments, commiserations, confabulations and simplifications on identity management and Microsoft's Active Directory all based on his continuous "reality tour" of meetings with customers, ISVs and Microsoft.</em></div>
      </subtitle>
      <title>Jackson's Identity Management &amp; Active Directory Reality Tour Travelblog</title>
      <updated>2010-09-02T09:53:38Z</updated>
    </source>
  <feedburner:origLink>http://feedproxy.google.com/~r/JacksonsIdentityManagementActiveDirectoryRealityTourTravelblog/~3/f7j35Gual6w/location-services-pose-huge-security.html</feedburner:origLink></entry>

  <entry>
    <id>http://blogs.kuppingercole.com/cole/2010/08/28/not-just-any-port-in-a-storm/</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/n5pqUpyyyjc/" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Not Just Any Port in a Storm</title>
    
    <updated>2010-08-28T09:53:54Z</updated>
    <source>
      <id>http://blogs.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://blogs.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole-blogs" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Kuppinger Cole Blogs</subtitle>
      <title>Kuppinger Cole Blogs</title>
      <updated>2010-08-28T22:02:59Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;As anyone in the identity industry knows, more lies between America and Europe that just an ocean. In fact, when it comes to privacy and data protection, a wide gulf separates the old and new worlds.&lt;/p&gt;&#xD;
&lt;p&gt;Germany in particular is often perceived as hidebound, not to say paranoid, when it comes to companies collecting personal data about their customers. People are signing up by the thousands to have their houses deleted from Google StreetView, with the mass-circulation “Bild Zeitung” running panic-inducing headlines like “StreetView snoops private data” and warning their readers about“Google’s next attack: Now they’re using bikes to film us!” The German minister of consumer affairs, Ilse Aigner, has publicly urged her fellow citizens to follow her example and cancel their Facebook accounts.&lt;/p&gt;&#xD;
&lt;p&gt;Most Americans I know simply shake their heads and grumble about “unhinged eurocrats run amok”. But unfortunately, it isn’t that simple. For better or worse, American companies need to realize that these are genuine concerns by genuine people. And no matter how lackadaisical US consumers may be when it comes to handing out personal information, the reality is that Europeans are not.&lt;/p&gt;&#xD;
&lt;p&gt;“But isn’t that what Safe Harbor is all about?”, one American identity expert (who shall remain nameless) exclaimed recently when I asked him how he thinks the problem should be addressed. True – but apparently, safe harbors in the US are anything but. That at least is what the so-called “Duesseldorf Circle”, a group of data privacy officials from all German states, stated in a report released last April. They accuse US companies of cheating on the agreement which was reached way back in 2000 between the United States and the EU.&lt;span id="more-162"&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p&gt;This essentially confirms results of a study conducted in 2008 by the Australian consulting firm &lt;a href="http://www.galexia.com/public/research/assets/safe_harbor_fact_or_fiction_2008/safe_harbor_fact_or_fiction-Introduc.html"&gt;Galexia&lt;/a&gt;, in which they concluded that most companies that purport to be certified members of the Safe Harbour Framework actually aren’t. Their findings are a shock to anyone believing in self-regulation:&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
&lt;li&gt;Only 348 of 1,597 enterprises and organizations on the official Safe Harbor List, which is jointly kept by the European Commission and the U.S. Department of Commerce, meet even the most basic requirements. Many do not have a privacy policy, and most fail to comply with Principle 7 of the agreement which stipulates that signees must identify an independent dispute resolution process for consumers.&lt;/li&gt;&#xD;
&lt;li&gt;209 organizations selected a dispute resolution provider that was not affordable (including the infamous &lt;a href="http://en.wikipedia.org/wiki/American_Arbitration_Association"&gt;American Arbitrations Association&lt;/a&gt;, AAA, that charged up to $1,200 an hour with a four-hour minimum charge plus a hefty $950 administration fee!).&lt;/li&gt;&#xD;
&lt;li&gt;206 companies claimed on their public websites to be members of the Safe Harbor, but aren’t.73 companies falsely claimed to be members of a Privacy Trustmark Scheme such as eTrust, or the BBB Online Privacy program which ceased to operate in June of 2008.&lt;/li&gt;&#xD;
&lt;li&gt;20 organizations displayed a fictional Department of Commerce Safe Harbor “seal” on their website.&lt;/li&gt;&#xD;
&lt;li&gt;24 claimed to have been certified by the Department of Commerce or the Euroepan Commission, which is obviously impossible: The program is based on self-certification.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;In a recent article in “&lt;a href="http://www.oekotest.de/cgi/index.cgi?artnr=95230;bernr=01;co="&gt;Öko-Test&lt;/a&gt;”, a magazine published by the prestigious German foundation “Stiftung Warentest”, the privacy policies of U.S.-based companies such as Google, Facebook, Twitter and YouTube were graded. They all failed.&lt;/p&gt;&#xD;
&lt;p&gt;Facebook, the article states, is in open breach of German law, while Google introduces the concept of “sensitive personal information” (which implies that some personal data are somehow “insensitive” and therefore free to be put to any use Google might think of). Twitter blandly informs visitors to their website that they “collect and use your information to provide our services and improve them over time”, but fail to mention which information they are referring to and what specifically they do with it, blatantly ignoring the four guiding principles of German privacy laws, namely allocation of purpose, necessity, transparency and minimal disclosure.&lt;/p&gt;&#xD;
&lt;p&gt;While Facebook and Google at least pay lip service to the Safe Harbor Agreement, Twitter hasn’t even bothered to sign, Öko-Test maintains. And anyway, why bother: “These contracts aren’t worth the paper they were signed on or the e-mails they were sent with”, the magazine writes.&lt;/p&gt;&#xD;
&lt;p&gt;Rainer Erd, a well-known expert on privacy and data protection with the law firm Schmalz in Frankfurt/Main, recently weighed in with a comment in the “Sueddeutsche Zeitung” in which he accuses U.S. companies such as Google and Facebook of duping European consumers by making them believe that they follow the provisions of the Safe Harbor Agreement, when actually they routinely store personal data on “secret servers” in the United States.&lt;/p&gt;&#xD;
&lt;p&gt;So why should U.S. companies be worried? After all, German policemen won’t be turning up anytime soon in corporate headquarters in Silicon Valley, and writs issued by German courts aren’t likely to be enforced by authorities on the other side of the Atlantic.&lt;/p&gt;&#xD;
&lt;p&gt;The real cause for concern is the growing uneasiness of European consumers with the high-handed manner with which U.S. companies treat their data. If Google seriously thinks it can make StreetView fly in Germany, they will need to launch a whole-hearted goodwill campaign including ironclad guarantees that they will follow not just the letter but the spirit of local privacy laws. As of even date, there is no sign that this has been really understood, either in Mountain View or in the headquarters of other U.S. companies seeking growth in Europe as the domestic U.S. market continues to sag.&lt;/p&gt;&#xD;
&lt;p&gt;Above all, governments and companies on both sides of the Atlantic need to strengthen and enforce the Safe Harbor Agreement so that it does in fact become a secure port for business – and not another murky swamp into which data disappears.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=n5pqUpyyyjc:5_eW9bF2o3k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=n5pqUpyyyjc:5_eW9bF2o3k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=n5pqUpyyyjc:5_eW9bF2o3k:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=n5pqUpyyyjc:5_eW9bF2o3k:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/n5pqUpyyyjc" height="1" width="1"/&gt;</content><feedburner:origLink>http://blogs.kuppingercole.com/cole/2010/08/28/not-just-any-port-in-a-storm/</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blog.broadbandmechanics.com/?p=7228</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/bmoS5r9_Jt4/" rel="alternate" type="text/html" />
    <title>Marc Canter - Broadband Mechanics: End of August 2010 blogging</title>
    <summary type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Getting lots of things done.  We have a &lt;a href="http://blog.broadbandmechanics.com/2010/08/25/fyi-book-v3/"&gt;killer book from our Futuristic Young Ideas STEM student summer internship program&lt;/a&gt;.  The Civic Commons is rocking - running towards an end of Sept ship date.&lt;/p&gt;&#xD;
&lt;p&gt;There are a lot of really basic person-&amp;gt;many communication tools which Facebook doesn’t have - let alone how shitty their messages tool is.  &lt;a href="http://googlesystem.blogspot.com/2010/08/orkut-lets-you-communicate-with-groups.html"&gt;Looks like Orkut sees this as a hole - and they’re right&lt;/a&gt;.  Now all they (Orkut) need are the 500M people.&lt;/p&gt;&#xD;
&lt;p&gt;Now that &lt;a href="http://www.readwriteweb.com/archives/new_version_of_googles_orkut_separates_business_fr.php?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+readwriteweb+%28ReadWriteWeb%29"&gt;Orkut is pitching multiple personae&lt;/a&gt;, how long until we need &lt;a href="http://www.youtube.com/watch?v=AtRoRMzE8Uc"&gt;Persona Editors&lt;/a&gt;?&lt;/p&gt;&#xD;
&lt;p&gt;Hmmmm - I wonder if I could &lt;a href="http://blogs.wsj.com/digits/2010/08/27/the-paul-allen-suit-a-look-at-the-patents/"&gt;help invalidate these Paul Allen patent claims from Interval research&lt;/a&gt;. I knew a lot of people who worked there - and I specifically recall showing similar interfaces to Brenda Laurel when she visited my MediaBar in 1996.  Hmmmmm - I’d just LOVE to fuck Paul Allen and ALL those interval people!&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.scvngr.com/"&gt;SCVNGR&lt;/a&gt; rocks - &lt;a href="http://techcrunch.com/2010/08/27/scvngr-facebook/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29"&gt;I love this stuff&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://windowsteamblog.com/windows_live/b/developer/archive/2010/08/25/windows-live-and-activity-streams.aspx"&gt;the Activity Streams standard is growing&lt;/a&gt;&lt;a href="http://mashable.com/2010/08/27/angstro-google-me/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+Mashable+%28Mashable%29"&gt;&lt;br&gt;&#xD;
&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://mashable.com/2010/08/27/angstro-google-me/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+Mashable+%28Mashable%29"&gt;Congrats to Rohit Khare and Adam Rifkin!&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://shoutyoungstown.blogspot.com/2010/08/how-gardens-stitch-together.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+blogspot%2FewZs+%28i+will+shout+youngstown%29"&gt;How gardens stitch together communities&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://jwz.livejournal.com/1280129.html"&gt;Killer Scott Pilgrim/Matrix mashup&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://civiccommons.digitalcitymechanics.com/content/cid=8"&gt;Whiplash fatigue&lt;/a&gt;,&lt;/p&gt;&lt;/div&gt;</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Getting lots of things done.  We have a &lt;a href="http://blog.broadbandmechanics.com/2010/08/25/fyi-book-v3/"&gt;killer book from our Futuristic Young Ideas STEM student summer internship program&lt;/a&gt;.  The Civic Commons is rocking - running towards an end of Sept ship date.&lt;/p&gt;&#xD;
&lt;p&gt;There are a lot of really basic person-&amp;gt;many communication tools which Facebook doesn’t have - let alone how shitty their messages tool is.  &lt;a href="http://googlesystem.blogspot.com/2010/08/orkut-lets-you-communicate-with-groups.html"&gt;Looks like Orkut sees this as a hole - and they’re right&lt;/a&gt;.  Now all they (Orkut) need are the 500M people.&lt;/p&gt;&#xD;
&lt;p&gt;Now that &lt;a href="http://www.readwriteweb.com/archives/new_version_of_googles_orkut_separates_business_fr.php?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+readwriteweb+%28ReadWriteWeb%29"&gt;Orkut is pitching multiple personae&lt;/a&gt;, how long until we need &lt;a href="http://www.youtube.com/watch?v=AtRoRMzE8Uc"&gt;Persona Editors&lt;/a&gt;?&lt;/p&gt;&#xD;
&lt;p&gt;Hmmmm - I wonder if I could &lt;a href="http://blogs.wsj.com/digits/2010/08/27/the-paul-allen-suit-a-look-at-the-patents/"&gt;help invalidate these Paul Allen patent claims from Interval research&lt;/a&gt;. I knew a lot of people who worked there - and I specifically recall showing similar interfaces to Brenda Laurel when she visited my MediaBar in 1996.  Hmmmmm - I’d just LOVE to fuck Paul Allen and ALL those interval people!&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.scvngr.com/"&gt;SCVNGR&lt;/a&gt; rocks - &lt;a href="http://techcrunch.com/2010/08/27/scvngr-facebook/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29"&gt;I love this stuff&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://windowsteamblog.com/windows_live/b/developer/archive/2010/08/25/windows-live-and-activity-streams.aspx"&gt;the Activity Streams standard is growing&lt;/a&gt;&lt;a href="http://mashable.com/2010/08/27/angstro-google-me/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+Mashable+%28Mashable%29"&gt;&lt;br&gt;&#xD;
&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://mashable.com/2010/08/27/angstro-google-me/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+Mashable+%28Mashable%29"&gt;Congrats to Rohit Khare and Adam Rifkin!&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://shoutyoungstown.blogspot.com/2010/08/how-gardens-stitch-together.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+blogspot%2FewZs+%28i+will+shout+youngstown%29"&gt;How gardens stitch together communities&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://jwz.livejournal.com/1280129.html"&gt;Killer Scott Pilgrim/Matrix mashup&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://civiccommons.digitalcitymechanics.com/content/cid=8"&gt;Whiplash fatigue&lt;/a&gt;,&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=bmoS5r9_Jt4:RoInCd9yOmo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=bmoS5r9_Jt4:RoInCd9yOmo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=bmoS5r9_Jt4:RoInCd9yOmo:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=bmoS5r9_Jt4:RoInCd9yOmo:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/bmoS5r9_Jt4" height="1" width="1"/&gt;</content>
    <updated>2010-08-27T22:51:18Z</updated>
    <category term="Blog" />
    <author>
      <name>marc</name>
    </author>
    <source>
      <id>http://blog.broadbandmechanics.com</id>
      <link href="http://blog.broadbandmechanics.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://blog.broadbandmechanics.com" rel="alternate" type="text/html" />
      <subtitle>building the open web one bit at a time</subtitle>
      <title>Marc's Voice</title>
      <updated>2010-09-02T04:00:25Z</updated>
    </source>
  <feedburner:origLink>http://blog.broadbandmechanics.com/2010/08/27/end-of-august-2010-blogging/</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content52770.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/VqdaQLgDYwc/content52770.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: NextGov - Doctors cry, 'Enough!'</title>
    
    <updated>2010-08-27T15:06:02Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://healthitupdate.nextgov.com/2010/08/password_please.php?oref=latest_posts&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VqdaQLgDYwc:igDct8VPPtg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VqdaQLgDYwc:igDct8VPPtg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VqdaQLgDYwc:igDct8VPPtg:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=VqdaQLgDYwc:igDct8VPPtg:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/VqdaQLgDYwc" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content52770.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content52769.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/yycdPB-gSn4/content52769.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: SC Magazine UK - Avoiding the loss that leads to the fine</title>
    
    <updated>2010-08-27T15:04:31Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://www.scmagazineuk.com/avoiding-the-loss-that-leads-to-the-fine/article/177567/&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yycdPB-gSn4:dYshQOV1G4w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yycdPB-gSn4:dYshQOV1G4w:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yycdPB-gSn4:dYshQOV1G4w:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=yycdPB-gSn4:dYshQOV1G4w:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/yycdPB-gSn4" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content52769.html</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/articles/virtualization2010</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/0QGnprDABuM/virtualization2010" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: New Survey</title>
    
    <updated>2010-08-27T11:10:21Z</updated>
    <source>
      <id>http://blogs.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://blogs.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole-blogs" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Kuppinger Cole Blogs</subtitle>
      <title>Kuppinger Cole Blogs</title>
      <updated>2010-08-28T22:02:59Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p align="justify"&gt;And even in private environments, either on-premise or in dedicated environments of service providers, things are changing. In this survey, we'd like to understand your views and experiences on security in virtualized environments and the developments happening in this space. How do you secure your virtual environments today? And how does your future roadmap look like? &lt;/p&gt;&lt;p align="justify"&gt;Kuppinger Cole have launched a &lt;strong&gt;&lt;a href="https://www.kuppingercole.com/survey/27" target="_blank"&gt;survey on these questions&lt;/a&gt;&lt;/strong&gt; and based on the results of this survey, a report and analysis will be produced. If you participate in the study, you will receive a complimentary copy of that report and analysis. Of course, you may respond anonymously to the questions within the survey. However, you must provide your e-mail address to receive a copy of the study when it is released. Participating in the survey, you will also have a great chance to win one of 3 tickets for the European Identity Conference (EIC) 2011, or an iPad. &lt;/p&gt;&lt;p align="justify"&gt;At no time will any individual's name, any company or university name, your participation, or individually identifiable response be released to any third party. The survey and analysis is being conducted by Kuppinger Cole and is sponsored by CA. You will also be invited to a KuppingerCole webinar where results of this survey will be presented and advice for actions will be provided. This survey should take you only around 20 minutes to complete. &lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0QGnprDABuM:7hRl_0ezZnc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0QGnprDABuM:7hRl_0ezZnc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0QGnprDABuM:7hRl_0ezZnc:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=0QGnprDABuM:7hRl_0ezZnc:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/0QGnprDABuM" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/articles/virtualization2010</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blogs.oracle.com/clayton/2010/08/facebook_lists_and_the_enterpr.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/P2OljXg7tOM/facebook_lists_and_the_enterpr.html" rel="alternate" type="text/html" />
    <title>Clayton Donley - Oracle: Facebook Lists and the Enterprise</title>
    
    <updated>2010-08-27T04:38:44Z</updated>
    <category scheme="http://www.sixapart.com/ns/types#category" term="Directories" />
    <category scheme="http://www.sixapart.com/ns/types#category" term="Identity Management" />
    <category scheme="http://www.sixapart.com/ns/types#category" term="Virtual Directory" /><feedburner:origlink>http://blogs.oracle.com/clayton/2010/08/facebook_lists_and_the_enterpr.html</feedburner:origlink>
    <source>
      <id>http://blogs.oracle.com/clayton/</id>
      <author>
        <name>Clayton Donley - Oracle</name>
      </author>
      <link href="http://blogs.oracle.com/clayton/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/cdonley" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <rights>Copyright 2010</rights>
      <title>Clayton Donley's Blog</title>
      <updated>2010-08-27T05:03:42Z</updated>
    </source>
  <content type="html">&lt;p&gt;&lt;a href="http://feedproxy.google.com/~r/Techcrunch/~3/iHeEme-pOTc/" target="_blank"&gt;This article&lt;/a&gt; on TechCrunch reminds me of how much I dislike enterprise systems that require you to recreate many of the relationships that are inherent in an organization using constructs that are available and remain unused in many popular consumer social sites.&lt;br&gt;&lt;br&gt;&lt;/p&gt;&lt;blockquote&gt;Tonight at a Facebook Developer's Garage meeting at Facebook's headquarters in Palo Alto, Zuckerberg fielded a question about the service's privacy controls. He said that the ideal solution for sharing different things with different people is to make a friend list. "But guess what? Nobody wants to make lists," Zuckerberg admitted.&lt;/blockquote&gt;&lt;br&gt;&lt;br&gt;Yes, nobody wants to make lists.&lt;br&gt;&lt;br&gt;The TechCrunch proposal is excellent for Internet-facing applications, as differentiation between "friends" and "followers" is usually a good first cutoff in a relationship. Enterprises have these relationship distinctions too...hence why you're likely to see a broadcast from your CEO, but your CEO probably isn't seeing broadcasts from each individual employee.&lt;br&gt;&lt;br&gt;In the enterprise, your peers, managers, reports, approvers, and so forth are already grouped in meaningful ways as part of business applications. Since these systems need to be accurate for payroll, promotions, mailing lists, and a number of other processes to work, there is significant incentive for the specific relationships to be accurate.&lt;br&gt;&lt;br&gt;Contrast this with single-purpose lists used by a single platform that need self-management. Such lists are maintained manually, are not going to be corrected by others if incorrect, and are unlikely to stay meaningful.&lt;br&gt;&lt;br&gt;We've long said in the directory space that the directory is a place for identity information that has utility in the broadest number of places. Similarly, many of these existing relationships are already modeled in the directory. With virtual directories, even those relationships found in external business systems can be brought into the scope of your applications via a single, simple LDAP request.&lt;br&gt;&lt;br&gt;I'd like to see mor enterprise applications become more social by simply using the "lists" and relationship granularity that is already defined rather than try to mimic Facebook and other Internet sites that require me to maintain these on my own.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;&lt;/p&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/cdonley/~4/TcxePeIu1To" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=P2OljXg7tOM:TcxePeIu1To:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=P2OljXg7tOM:TcxePeIu1To:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=P2OljXg7tOM:TcxePeIu1To:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=P2OljXg7tOM:TcxePeIu1To:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/P2OljXg7tOM" height="1" width="1"/&gt;</content><feedburner:origLink>http://feedproxy.google.com/~r/cdonley/~3/TcxePeIu1To/facebook_lists_and_the_enterpr.html</feedburner:origLink></entry>

  <entry>
    <id>http://www.id-conf.com/blog/2010/08/27/google-authentication-support/</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/RE9cLMCSAiI/" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Google authentication support</title>
    
    <updated>2010-08-27T02:45:35Z</updated>
    <source>
      <id>http://blogs.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://blogs.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole-blogs" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Kuppinger Cole Blogs</subtitle>
      <title>Kuppinger Cole Blogs</title>
      <updated>2010-08-28T22:02:57Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;In addition to Facebook authentication, which we have added last month, you’re now able to &lt;a href="https://www.kuppingercole.com/login" target="_blank"&gt;log in to our website&lt;/a&gt; with your Google account.&lt;/p&gt;&#xD;
&lt;p&gt;Don’t forget to check out your &lt;a href="https://www.kuppingercole.com/account" target="_blank"&gt;account page&lt;/a&gt; after signing up to edit your personal information  and subscribe to our newsletters!&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=RE9cLMCSAiI:5FYwaoizvPk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=RE9cLMCSAiI:5FYwaoizvPk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=RE9cLMCSAiI:5FYwaoizvPk:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=RE9cLMCSAiI:5FYwaoizvPk:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/RE9cLMCSAiI" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.id-conf.com/blog/2010/08/27/google-authentication-support/</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.discoveringidentity.com/2010/08/26/identity-management-for-zombies/</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/Du39EHuRQbY/" rel="alternate" type="text/html" />
    <title>Mark Dixon - Sun: Identity Management for Zombies?</title>
    <summary type="html">Note: This little post chronicles my favorite social media exchange in a long time.  You need to see the embedded images to get the gist of an intriguing conversation.
 
The intrigue began Wednesday afternoon when I was waiting in the Chicago O’Hare airport for a flight to Central Wisconsin Airport, near Wausau, WI.  I tweeted my [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Note: This little post chronicles my favorite social media exchange in a long time.  You need to see the embedded images to get the gist of an intriguing conversation.&lt;/p&gt;&#xD;
&lt;p&gt; &lt;/p&gt;&#xD;
&lt;p&gt;The intrigue began Wednesday afternoon when I was waiting in the Chicago O’Hare airport for a flight to Central Wisconsin Airport, near &lt;a href="http://www.ci.wausau.wi.us/" target="_blank"&gt;Wausau, WI&lt;/a&gt;.  I tweeted my intentions:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image25.png"&gt;&lt;img alt="image" border="0" height="104" src="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image_thumb9.png" style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto;" title="image" width="465"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;&#xD;
&lt;p&gt;Within a few minutes, I was being followed on Twitter by &lt;a href="http://twitter.com/WausauLoner" target="_blank"&gt;Wausau Loner&lt;/a&gt;:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://twitter.com/WausauLoner" target="_blank"&gt;&lt;img alt="image" border="0" height="194" src="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image26.png" style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto;" title="image" width="464"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;I had never heard of the &lt;a href="http://en.wikipedia.org/wiki/Zombie_apocalypse" target="_blank"&gt;Zombie Apocalypse&lt;/a&gt;, so I started poking around the web.  I thought, “Do Zombies need Identity Management?”&lt;/p&gt;&#xD;
&lt;p&gt;I found that my tweet was listed on the Wausau Wisconsin Best Blogs and Tweets … &lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.americantowns.com/wi/wausau/blogs" target="_blank"&gt;&lt;img alt="image" border="0" height="240" src="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image27.png" style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto;" title="image" width="464"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;&#xD;
&lt;p&gt;… along with my new follower, the Zombie Apocalypse expert, Wausau Loner.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image28.png"&gt;&lt;img alt="image" border="0" height="283" src="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image_thumb10.png" style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto;" title="image" width="465"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;&#xD;
&lt;p&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;/p&gt;&#xD;
&lt;p&gt;This morning (Thursday), I received a nice thank you note from Wausau Loner:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image29.png"&gt;&lt;img alt="image" border="0" height="149" src="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image_thumb11.png" style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto;" title="image" width="464"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;&#xD;
&lt;p&gt;I pinged him back and got this reply:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image30.png"&gt;&lt;img alt="image" border="0" height="142" src="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image_thumb12.png" style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto;" title="image" width="464"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;&#xD;
&lt;p&gt;I posed the big question:  Do zombies have unique Identities?  Do they need Identity Management?&lt;/p&gt;&#xD;
&lt;p&gt;Sadly, the answer was negative:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image31.png"&gt;&lt;img alt="image" border="0" height="142" src="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image_thumb13.png" style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px;" title="image" width="464"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image32.png"&gt;&lt;img alt="image" border="0" height="142" src="http://www.discoveringidentity.com/wp-content/uploads/2010/08/image_thumb14.png" style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px;" title="image" width="464"&gt;&lt;/img&gt;&lt;/a&gt;Well, there are still many unanswered questions.  May be next time I visit Wausau, I’ll get together with Wausau Loner and get more details!   I’ll let you know.&lt;/p&gt;&#xD;
&lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:cb23f035-5c5d-4922-b1da-8851accd1810" style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px;"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Wausau" rel="tag"&gt;Wausau&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Zombie+Apocalypse" rel="tag"&gt;Zombie Apocalypse&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Social+Media" rel="tag"&gt;Social Media&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Twitter" rel="tag"&gt;Twitter&lt;/a&gt;,&lt;a href="http://technorati.com/tags/IdentityManagement" rel="tag"&gt;IdentityManagement&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Du39EHuRQbY:TZBr95A_GzM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Du39EHuRQbY:TZBr95A_GzM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Du39EHuRQbY:TZBr95A_GzM:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=Du39EHuRQbY:TZBr95A_GzM:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/Du39EHuRQbY" height="1" width="1"/&gt;</content>
    <updated>2010-08-26T21:36:19Z</updated>
    <category term="Humor" />
    <category term="Social Media" />
    <category term="IdentityManagement" />
    <category term="Twitter" />
    <category term="Wausau" />
    <category term="Zombie Apocalypse" />
    <author>
      <name>Mark Dixon</name>
    </author>
    <source>
      <id>http://www.discoveringidentity.com</id>
      <link href="http://www.discoveringidentity.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.discoveringidentity.com" rel="alternate" type="text/html" />
      <subtitle>Just another WordPress weblog</subtitle>
      <title>Discovering Identity</title>
      <updated>2010-08-26T22:02:24Z</updated>
    </source>
  <feedburner:origLink>http://www.discoveringidentity.com/2010/08/26/identity-management-for-zombies/</feedburner:origLink></entry>

  <entry>
    <id>http://www.dirmgr.com/blog/2010/8/26/ldap-password-changes-in-active-directory.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/_vnZYAc-yrE/ldap-password-changes-in-active-directory.html" rel="alternate" type="text/html" />
    <title>Neil Wilson - UnboundID: LDAP Password Changes in Active Directory</title>
    <content type="html" xml:lang="en-US">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&#xD;
  I've never really been a big fan of Active Directory.  Microsoft tends to treat standards more like suggestions than rules, and Active Directory has some good examples of that.  I was recently asked a question about how you can change a password in Active Directory over LDAP.  In most directory servers, you would either use the LDAP password modify extended operation (as described in &lt;a href="http://www.ietf.org/rfc/rfc3062.txt"&gt;RFC 3062&lt;/a&gt;), or you would perform a simple modify operation to replace the &lt;tt&gt;userPassword&lt;/tt&gt; attribute with the clear-text password (and the server would automatically perform any necessary encoding to obscure the value).  However, Active Directory has a number of very unusual requirements, so it's probably worth making a note of them.  They include:&#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;ul&gt;&#xD;
  &lt;li&gt;&#xD;
    Active Directory doesn't appear to support the password modify extended operation, so you must change passwords using a normal LDAP modify operation.&#xD;
    &lt;br&gt;&lt;br&gt;&#xD;
  &lt;/li&gt;&#xD;
&#xD;
  &lt;li&gt;&#xD;
    Active Directory stores passwords in the &lt;tt&gt;unicodePwd&lt;/tt&gt; attribute, rather than &lt;tt&gt;userPassword&lt;/tt&gt;.&#xD;
    &lt;br&gt;&lt;br&gt;&#xD;
  &lt;/li&gt;&#xD;
&#xD;
  &lt;li&gt;&#xD;
    Active Directory will only accept password changes over secure connections.  I have only ever used SSL.  It may be that you can also use StartTLS, or perhaps SASL with confidentiality, but I'm not sure about that.&#xD;
    &lt;br&gt;&lt;br&gt;&#xD;
  &lt;/li&gt;&#xD;
&#xD;
  &lt;li&gt;&#xD;
    The new password must be enclosed in quotation marks, and it must use a UTF-16 little-endian encoding.&#xD;
    &lt;br&gt;&lt;br&gt;&#xD;
  &lt;/li&gt;&#xD;
&#xD;
  &lt;li&gt;&#xD;
    Active Directory may impose some strength requirements on the password, although exactly what those requirements are may vary from one instance to another.&#xD;
    &lt;br&gt;&lt;br&gt;&#xD;
  &lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
  Knowing these requirements, you should be able to write code using any LDAP API that will allow you to perform password changes in Active Directory.  The following code demonstrates how to do it using the UnboundID LDAP SDK for Java:&#xD;
&#xD;
  &lt;/p&gt;&lt;pre&gt;import java.io.UnsupportedEncodingException;&#xD;
import javax.net.ssl.SSLSocketFactory;&#xD;
&#xD;
import com.unboundid.ldap.sdk.LDAPConnection;&#xD;
import com.unboundid.ldap.sdk.LDAPException;&#xD;
import com.unboundid.ldap.sdk.Modification;&#xD;
import com.unboundid.ldap.sdk.ModificationType;&#xD;
import com.unboundid.ldap.sdk.ResultCode;&#xD;
import com.unboundid.util.StaticUtils;&#xD;
import com.unboundid.util.ssl.SSLUtil;&#xD;
import com.unboundid.util.ssl.TrustAllTrustManager;&#xD;
&#xD;
&#xD;
&#xD;
/**&#xD;
 * This class provides a simple utility method that may be used to change the&#xD;
 * password of a user stored in an Active Directory server instance.&#xD;
 */&#xD;
public class ADPasswordChange&#xD;
{&#xD;
  /**&#xD;
   * Perform the complete set of processing required to change a user's&#xD;
   * password in an Active Directory server.&#xD;
   *&#xD;
   * @param  adHost        The address of the Active Directory server.&#xD;
   * @param  adSSLPort     The SSL-based port of the Active Directory server&#xD;
   *                       (typically 636).&#xD;
   * @param  bindDN        The DN to use when binding to the Active Directory&#xD;
   *                       server instance.  It must have sufficient permission&#xD;
   *                       to change user passwords.&#xD;
   * @param  bindPassword  The clear-text password to use when binding to the&#xD;
   *                       Active Directory server instance.&#xD;
   * @param  userDN        The DN of the user whose password should be changed.&#xD;
   * @param  newPassword   The clear-text new password to assign to the user.&#xD;
   *&#xD;
   * @throws  LDAPException  If a problem is encountered while performing any&#xD;
   *                         of the required processing.&#xD;
   */&#xD;
  public static void changePasswordInAD(final String adHost,&#xD;
                                        final int adSSLPort,&#xD;
                                        final String bindDN,&#xD;
                                        final String bindPassword,&#xD;
                                        final String userDN,&#xD;
                                        final String newPassword)&#xD;
         throws LDAPException&#xD;
  {&#xD;
    // Properly encode the password.  It must be enclosed in quotation marks,&#xD;
    // and it must use a UTF-16LE encoding.&#xD;
    System.out.println("Going to encode the password.");&#xD;
    final byte[] quotedPasswordBytes;&#xD;
    try&#xD;
    {&#xD;
      final String quotedPassword = '"' + newPassword + '"';&#xD;
      quotedPasswordBytes = quotedPassword.getBytes("UTF-16LE");&#xD;
    }&#xD;
    catch (final UnsupportedEncodingException uee)&#xD;
    {&#xD;
      throw new LDAPException(ResultCode.LOCAL_ERROR,&#xD;
           "Unable to encode the quoted password in UTF-16LE:  " +&#xD;
                StaticUtils.getExceptionMessage(uee),&#xD;
           uee);&#xD;
    }&#xD;
&#xD;
&#xD;
    // Create an SSL socket factory to use during the course of establishing&#xD;
    // an SSL-based connection to the server.  For simplicity, we'll cheat and&#xD;
    // use a trust manager that will trust any certificate that the server&#xD;
    // presents, but in production environments you should validate the&#xD;
    // certificate more carefully.&#xD;
    System.out.println("Going to create the SSL socket factory.");&#xD;
    final SSLSocketFactory socketFactory;&#xD;
    final SSLUtil sslUtil = new SSLUtil(new TrustAllTrustManager());&#xD;
    try&#xD;
    {&#xD;
      socketFactory = sslUtil.createSSLSocketFactory();&#xD;
    }&#xD;
    catch (final Exception e)&#xD;
    {&#xD;
      throw new LDAPException(ResultCode.LOCAL_ERROR,&#xD;
           "Unable to create an SSL socket factory to use for establishing " +&#xD;
                "a secure connection:  " + StaticUtils.getExceptionMessage(e),&#xD;
           e);&#xD;
    }&#xD;
&#xD;
    // Create a secure connection to the Active Directory server.&#xD;
    System.out.println("Going to establish the secure connection.");&#xD;
    final LDAPConnection connection = new LDAPConnection(socketFactory, adHost,&#xD;
         adSSLPort, bindDN, bindPassword);&#xD;
&#xD;
    try&#xD;
    {&#xD;
      // Attempt to modify the user password.&#xD;
      System.out.println("Going to replace the user's password.");&#xD;
      final Modification mod = new Modification(ModificationType.REPLACE,&#xD;
           "unicodePwd", quotedPasswordBytes);&#xD;
      connection.modify(userDN, mod);&#xD;
    }&#xD;
    finally&#xD;
    {&#xD;
      System.out.println("Closing the connection.");&#xD;
      connection.close();&#xD;
    }&#xD;
  }&#xD;
}&#xD;
&lt;/pre&gt;&#xD;
&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_vnZYAc-yrE:oKZgVAm3XEg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_vnZYAc-yrE:oKZgVAm3XEg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_vnZYAc-yrE:oKZgVAm3XEg:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=_vnZYAc-yrE:oKZgVAm3XEg:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/_vnZYAc-yrE" height="1" width="1"/&gt;</content>
    <updated>2010-08-26T15:10:31Z</updated>
    <published>2010-08-26T15:10:31Z</published>
    <category term="Directory/Identity" />
    <category term="Java" />
    <category term="LDAP" />
    <category term="UnboundID" />
    <author>
      <name>Neil A. Wilson (dirmgr)</name>
    </author>
    <source>
      <id>http://www.dirmgr.com/blog/</id>
      <link href="http://www.dirmgr.com/blog/" rel="alternate" type="application/xhtml+xml" />
      <link href="http://www.dirmgr.com/blog/atom.xml" rel="self" type="application/atom+xml" />
      <subtitle>Blog</subtitle>
      <title>cn=Directory Manager Blog</title>
      <updated>2010-08-26T16:21:35Z</updated>
    </source>
  <feedburner:origLink>http://www.dirmgr.com/blog/2010/8/26/ldap-password-changes-in-active-directory.html</feedburner:origLink></entry>

  <entry>
    <id>http://blogs.sun.com/nickwooler/entry/free_webinar_today_simplify_access</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/GJrUnXhuNGU/free_webinar_today_simplify_access" rel="alternate" type="text/html" />
    <title>Nick Wooler - Sun: Free Webinar Today:  Simplify Access Management with F5 &amp; Oracle</title>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://www.eseminarslive.com/c/a/Security/F5082610/?partnerref=CL082610F5ORACLE"&gt;&lt;img align="left" src="http://www.eseminarslive.com/images/authors/1687.jpg"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt; &#xD;
  &lt;p&gt;On Thursday, August 26.  We are hosting a webcast that will take you through the solution and talk about why we believe this will simplify Access Management.  Please join us as F5 and Oracle product experts explain this simple solution.&lt;/p&gt; &#xD;
  &lt;p&gt; &lt;/p&gt; &#xD;
  &lt;p&gt;&lt;b&gt;Title:&lt;/b&gt; &lt;font face="Arial, Helvetica, sans-serif" size="2"&gt;&lt;b&gt;Live Webcast: Streamline Access Management with F5 &amp;amp; Oracle &#xD;
                &lt;/b&gt;&lt;/font&gt; &lt;/p&gt; &#xD;
  &lt;p&gt;&lt;b&gt;When&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-weight: bold;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;font color="#000000" face="Arial, Helvetica, sans-serif" size="2"&gt;&lt;b&gt;  Thursday, &#xD;
                            August 26, 2010, &lt;/b&gt;&lt;b&gt;10:00 a.m. PT or 1:00 p.m. ET&lt;/b&gt;&lt;/font&gt;&lt;/p&gt; &#xD;
  &lt;p&gt;&lt;b&gt;Where:&lt;/b&gt; &lt;b&gt;Register for this live webcast here:&lt;/b&gt; &lt;font color="#000000" face="Arial, Helvetica, sans-serif" size="2"&gt;&lt;a href="http://www.eseminarslive.com/c/a/Security/F5082610/?partnerref=CL082610F5ORACLE" target="_blank"&gt;&lt;font color="#ff0000"&gt;&lt;i&gt;Streamline Access Management with F5 &amp;amp; Oracle &lt;/i&gt;&lt;/font&gt;&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &#xD;
  &lt;p&gt; &lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=GJrUnXhuNGU:MogVFSabyJ0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=GJrUnXhuNGU:MogVFSabyJ0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=GJrUnXhuNGU:MogVFSabyJ0:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=GJrUnXhuNGU:MogVFSabyJ0:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/GJrUnXhuNGU" height="1" width="1"/&gt;</content>
    <updated>2010-08-26T14:51:15Z</updated>
    <published>2010-08-26T14:51:15Z</published>
    <category label="Sun" term="/Sun" />
    <category scheme="http://roller.apache.org/ns/tags/" term="accessmanagement" />
    <category scheme="http://roller.apache.org/ns/tags/" term="directoryservices" />
    <author>
      <name>nwooler</name>
    </author>
    <source>
      <id>http://blogs.sun.com/nickwooler/feed/entries/atom</id>
      <link href="http://blogs.sun.com/nickwooler/feed/entries/atom" rel="self" type="application/atom+xml" />
      <link href="http://blogs.sun.com/nickwooler/" rel="alternate" type="text/html" />
      <subtitle>Virtual Nick Wooler</subtitle>
      <title>Virtual Nick Wooler</title>
      <updated>2010-08-26T14:51:15Z</updated>
    </source>
  <feedburner:origLink>http://blogs.sun.com/nickwooler/entry/free_webinar_today_simplify_access</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/imprivata_demonstrates_secure_and_convenient_application_access_vmworld_2010___imprivata</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/9w4iqK5GYOo/imprivata_demonstrates_secure_and_convenient_application_access_vmworld_2010___imprivata" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: Imprivata Demonstrates Secure and Convenient Application Access and Roaming Desktops Throughout VMWORLD 2010 Conference</title>
    
    <updated>2010-08-26T13:05:14Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">Imprivata Founder and CTO to Join Expert Panel Discussing the Impact of Virtualization on the Delivery of Healthcare IT&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=9w4iqK5GYOo:Yazzk0rS5ZQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=9w4iqK5GYOo:Yazzk0rS5ZQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=9w4iqK5GYOo:Yazzk0rS5ZQ:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=9w4iqK5GYOo:Yazzk0rS5ZQ:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/9w4iqK5GYOo" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/imprivata_demonstrates_secure_and_convenient_application_access_vmworld_2010___imprivata</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blog.superpat.com/2010/08/26/bookmarks-for-august-25th-2010/</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/ozGGejONgg0/" rel="alternate" type="text/html" />
    <title>Pat Patterson - Huawei: Bookmarks for August 25th 2010</title>
    <summary type="html">These are my links for August 25th 2010: 500 Internal Server Error – 500 Internal Server Error</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;These are my links for August 25th 2010:&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
&lt;li&gt;&lt;a href="http://feeds.delicious.com/v2/rss/superpat"&gt;500 Internal Server Error&lt;/a&gt; – 500 Internal Server Error&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&#xD;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/stN87RtfgagoQZyTB9S3w4DiUXw/0/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/stN87RtfgagoQZyTB9S3w4DiUXw/0/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a href="http://feedads.g.doubleclick.net/~a/stN87RtfgagoQZyTB9S3w4DiUXw/1/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/stN87RtfgagoQZyTB9S3w4DiUXw/1/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/superpat/~4/73Ioy8kZrDs" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ozGGejONgg0:73Ioy8kZrDs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ozGGejONgg0:73Ioy8kZrDs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ozGGejONgg0:73Ioy8kZrDs:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=ozGGejONgg0:73Ioy8kZrDs:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/ozGGejONgg0" height="1" width="1"/&gt;</content>
    <updated>2010-08-26T13:00:00Z</updated>
    <category term="Links" />
    <category term="Uncategorized" /><feedburner:origlink>http://blog.superpat.com/2010/08/26/bookmarks-for-august-25th-2010/</feedburner:origlink>
    <author>
      <name>Pat Patterson</name>
    </author>
    <source>
      <id>http://blog.superpat.com</id>
      <link href="http://blog.superpat.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/superpat" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Pat Patterson on Identity Management, Federation and Single Malt Scotch</subtitle>
      <title>Superpatterns</title>
      <updated>2010-08-26T13:32:35Z</updated>
    </source>
  <feedburner:origLink>http://feedproxy.google.com/~r/superpat/~3/73Ioy8kZrDs/</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-12447072.post-911441893448222171</id>
    <link href="http://connectid.blogspot.com/feeds/911441893448222171/comments/default" rel="replies" type="application/atom+xml" />
    <link href="https://www.blogger.com/comment.g?blogID=12447072&amp;postID=911441893448222171" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/911441893448222171?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/911441893448222171?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/6BHxVg-18D0/new-line-of-greeting-cards_26.html" rel="alternate" type="text/html" />
    <title>Paul Madsen: New line of greeting cards</title>
    <content type="html">&lt;div class="posterous_autopost"&gt;&lt;img height="551" src="http://posterous.com/getfile/files.posterous.com/paulmadsen/h8v50WiqYXZxu9DvXPEk9uAFh1bdH9A9B4iDWSemwl3pnO0CENaKiAb0kg0o/Capture.jpg" width="490"&gt;&lt;/img&gt; &lt;p style="font-size: 10px;"&gt;  &lt;a href="http://posterous.com"&gt;Posted via email&lt;/a&gt;   from &lt;a href="http://paulmadsen.posterous.com/new-line-of-greeting-cards-45"&gt;Pre(posterous)&lt;/a&gt;  &lt;/p&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/12447072-911441893448222171?l=connectid.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/blogspot/gMwy/~4/6BHxVg-18D0" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=6BHxVg-18D0:vDFq_4E6pGE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=6BHxVg-18D0:vDFq_4E6pGE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=6BHxVg-18D0:vDFq_4E6pGE:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=6BHxVg-18D0:vDFq_4E6pGE:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/6BHxVg-18D0" height="1" width="1"/&gt;</content>
    <updated>2010-08-26T11:31:30Z</updated>
    <published>2010-08-26T11:31:00Z</published>
    <author>
      <name>Paul Madsen</name>
      <email>noreply@blogger.com</email>
      <uri>http://www.blogger.com/profile/08489111023182783403</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-12447072</id>
      <author>
        <name>Paul Madsen</name>
        <email>noreply@blogger.com</email>
        <uri>http://www.blogger.com/profile/08489111023182783403</uri>
      </author>
      <link href="http://connectid.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://connectid.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/12447072/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/blogspot/gMwy" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>When you don't have anything nice to say, consider blogging it. or a tweet if you're rushed for time.</subtitle>
      <title>ConnectID</title>
      <updated>2010-09-01T22:30:26Z</updated>
    </source>
  <feedburner:origLink>http://connectid.blogspot.com/2010/08/new-line-of-greeting-cards_26.html</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/articles/fg_sec_cloud_entwicklung26082010</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/p2jdCE3OpY8/fg_sec_cloud_entwicklung26082010" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Felix Gaehtgens: Security bei der Entwicklung für die Cloud</title>
    
    <updated>2010-08-26T09:47:18Z</updated>
    <source>
      <id>http://blogs.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://blogs.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole-blogs" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Kuppinger Cole Blogs</subtitle>
      <title>Kuppinger Cole Blogs</title>
      <updated>2010-08-28T22:02:58Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Einer der Gründe (wenn auch nicht der einzige) für das Cloud Computing ist eine hohe Skalierbarkeit, die man durch die Verteilung von Ressourcen in der Cloud erreicht. Das lässt sich beim Programmieren durch ähnliche Ansätze erreichen, etwa bei der Programmierung auf einem Multiprozessor-System und/oder bei der Entwicklung von Multithreaded-Programmen. Es ist wichtig, Prozesse in kleine, modulare Teile zu gliedern – Atomizität, Statuslosigkeit sowie Synchronisierung sind wichtige Konzepte und haben bei der Entwicklung von Cloud-Applikationen ebenfalls ihre Geltung.&lt;/p&gt;&lt;p&gt;Ein guter Vergleich ist der mit der Entwicklung innerhalb einer serviceorientierten Architektur (SOA). Hier spielen die genannten Faktoren eine wichtige Rolle, doch es kommt noch ein zusätzlicher Punkt hinzu: eine Sicherheitskomponente, die Authentisierung und Autorisierung innerhalb einer SOA bereitstellt. Dort finden sich mehrere verbreitete Standards, etwa WS-Security bei SOAs auf Basis von SOAP oder Spring Security.&lt;br&gt;&lt;br&gt;Beim Cloud Computing kann es jedoch viel komplexer zugehen: Oftmals werden einzelne Module komplett aus der Kontrolle eines Unternehmens ausgegliedert. So fließen Daten zwischen Unternehmen und Applikationsprovidern hin und her. Das ist einerseits vorteilhaft, da sich Firmen mehr auf ihr Kerngeschäft fokussieren und somit Anwendungen und Prozesse auslagern können. Andererseits ist das problematisch, da es wesentlich schwieriger ist, die Kontrolle zu behalten über das, was mit den Daten geschieht und wer Zugriff auf die Prozesse hat.&lt;br&gt;&lt;br&gt;In der heutigen IT-Landschaft ist es immer noch üblich, auf Benutzer und Rollenkonzepte zu setzen. Daher liegt es auf der Hand, sie auch im Cloud-Umfeld zu verwenden. Das führt jedoch langfristig zu Problemen, gerade wenn die Komplexität der Cloud-Infrastruktur zunimmt, was durchaus bei einer positiven Bilanz einer Cloud-Initiative eines Unternehmens zu erwarten ist. Benutzer-IDs, Passwörter und Rollen sind meist stark an einen Kontext gebunden und haben in einem verteilten Cloud-Konzept keine eindeutige Gültigkeit. Dafür sind Richtlinien notwendig, die den Umgang mit Daten oder Prozessen regeln.&lt;br&gt;&lt;br&gt;Es gibt dazu mehrere Ansätze, die sich mit dem Thema beschäftigen. Das von Microsoft spezifizierte Identity Metasystem realisiert es beispielsweise, Informationen zu Benutzern in sogenannten "Claims" mitzuliefern und sie im gesamten Prozess mitzutragen. Die Claims können nicht nur Informationen über den Benutzer enthalten, sondern auch weitere Datenfelder, die für den Prozessablauf wichtig sind. Somit lässt sich von der herkömmlichen, aber unsicheren Praxis absehen, Teile von Prozessen als privilegierter Benutzer auszuführen – das war (und ist) leider oft der Fall.&lt;br&gt;&lt;br&gt;Der XACML-Standard (eXtensible Access Control Markup Language) erfährt zunehmend Beachtung und findet mittlerweile selbst in komplexen Umgebungen Anwendung. Er definiert sowohl eine XML-Sprache zur Zugriffskontrolle als auch eine standardisierte verteilte Architektur. Letztere besteht aus mehreren Teilen:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Policy Enforcemente Point (PEP)&lt;/li&gt;&lt;li&gt;Policy Decision Point (PDP)&lt;/li&gt;&lt;li&gt;Policy Information Point (PIP) &lt;/li&gt;&lt;li&gt;Policy Administration Point (PAP) &lt;/li&gt;&lt;/ul&gt;Der Policy Enforcemente Point sitzt überall dort, wo ein Zugang überprüft werden muss und sich entweder einteilen oder abweisen lässt. Er führt jedoch keine Entscheidung durch, sondern fragt sie beim Policy Decision Point ab. Der kann wiederum (wenn notwendig) zusätzliche Informationen bei Policy Information Points abfragen. Die lassen sich – wie ihr Name verrät – zum Verwalten der einzelnen Policies verwenden. Die XACML-Sprache lässt sich gut innerhalb der definierten XACML-Architektur einsetzen, sie ist aber unabhängig von der Architektur – demnach eignet sie sich auch gut zum Austausch von Policies.&lt;br&gt;&lt;br&gt;Interessant ist die Verknüpfung des Identity Metasystem mit XACML. Dadurch dass Ersteres in den Claims beliebige Daten mitliefern kann, ließe sich auch eine XACML-Policy mit übergeben, und diese könnte man dann dazu benutzen, um in feiner Auflösung den Zugang zu kontrollieren. In dem Zusammenhang bedeutet "feine Auflösung", den Zugang bis ins kleinste Detail zu regeln – beispielsweise den Zugriff auf bestimmte Datenfelder. Das steht im Gegensatz zu einer groben Auflösung, die lediglich den Zugang zum kompletten Prozess bewilligt, mit allem, was er enthalten mag.&lt;br&gt;&lt;br&gt;Es ist jedoch noch einiges zu tun, bevor sich ein solcher Ansatz auch konsequent einsetzen lässt. Zum einen gibt es noch wenig Erfahrung beim Einsatz, zum anderen sind noch einige Fragen offen, insbesondere zur Skalierung: Wie lässt sich etwa ein solches Konzept effizient einsetzen, wenn Transaktionen immer feiner und modularer werden, über traditionelle Unternehmensgrenzen hinaus verteilt sind und drastisch in der Zahl zunehmen?&lt;br&gt;&lt;br&gt;Letztlich geht es aber besonders um das Vertrauen (Trust). In einer verteilten Umgebung ist es sicherlich von Vorteil, mit einem Datensatz gleich noch eine Policy mitzuliefern, die den Umgang mit den Daten regelt. Man muss sich jedoch darauf verlassen können, dass die Regeln auch eingehalten werden. Das gilt ebenso beim Einsatz von Policy Decision Points, die Anfragen zur Zugriffserteilung von Policy Enforcement Points beantworten. Man muss sich darauf verlassen können, dass die Enforcement Points die Entscheidungen von den Decision Points korrekt umsetzen.&lt;br&gt;&lt;br&gt;Das verwandte Rights Managements erreicht das durch sogenannte "Trusted Clients": Man verlässt sich auf die Softwareanbieter von Client-Software (wie die DRM-Media-Player), die ihre Software angeblich ordnungsgemäß absichern. Doch für eine verteilte Umgebung, in der viele unterschiedliche Module innerhalb und außerhalb eines Unternehmens verteilt sind, gibt es zwar gute Ansätze, aber noch keine komplette und offene Lösung. Eines ist aber sicher: Daran wird fieberhaft gearbeitet.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=p2jdCE3OpY8:p-YNS1PUk1s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=p2jdCE3OpY8:p-YNS1PUk1s:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=p2jdCE3OpY8:p-YNS1PUk1s:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=p2jdCE3OpY8:p-YNS1PUk1s:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/p2jdCE3OpY8" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/articles/fg_sec_cloud_entwicklung26082010</feedburner:origLink></entry>

  <entry xml:lang="en-us">
    <id>http://del.icio.us/beuchelt#2010-08-25</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/VoyCouvfsdA/beuchelt" rel="alternate" type="text/html" />
    <title>Gerry Beuchelt - MITRE: Links for 2010-08-25 [del.icio.us]</title>
    
    <updated>2010-08-26T07:00:00Z</updated><feedburner:origlink>http://del.icio.us/beuchelt#2010-08-25</feedburner:origlink>
    <source>
      <id>http://blog.beuchelt.org/</id>
      <logo>http://clustrmaps.com/counter/index2.php?url=http://blog.beuchelt.com</logo>
      <author>
        <name>Gerry Beuchelt - MITRE</name>
        <email>work@beuchelt.com</email>
      </author>
      <link href="http://blog.beuchelt.org/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/WebServicesContraptions" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <rights>Gerald Beuchelt</rights>
      <title>Web Services Contraptions</title>
      <updated>2010-08-30T19:32:56Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;ul&gt;&#xD;
&lt;li&gt;&lt;a href="http://blogs.computerworlduk.com/simon-says/2010/08/cause-and-effect/index.htm"&gt;Blogs - Technology Blog and Community from IT Experts - ComputerworldUK.com&lt;/a&gt;&lt;br&gt;&#xD;
"Which Open Source Licence" Is The Wrong Question&lt;br&gt;&#xD;
The debate over the demise of "Open Core" has led to a reprise of "which open source license is best" arguments again. But the real driving force is not the licence; it's the equality of participants.&lt;/li&gt;&#xD;
&lt;/ul&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/WebServicesContraptions/~4/XmyndEVT26c" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VoyCouvfsdA:XmyndEVT26c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VoyCouvfsdA:XmyndEVT26c:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VoyCouvfsdA:XmyndEVT26c:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=VoyCouvfsdA:XmyndEVT26c:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/VoyCouvfsdA" height="1" width="1"/&gt;</content><feedburner:origLink>http://feedproxy.google.com/~r/WebServicesContraptions/~3/XmyndEVT26c/beuchelt</feedburner:origLink></entry>

  <entry xml:lang="en-us">
    <id>http://blog.beuchelt.org/PermaLink,guid,be6491ae-5bb0-4507-b007-eacd31aa8e47.aspx</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/lNA1Wi6gV3I/Preparing+Some+Paper.aspx" rel="alternate" type="text/html" />
    <link href="http://creativecommons.org/licenses/by/2.5/" rel="license" />
    <title>Gerry Beuchelt - MITRE: Preparing some paper</title>
    
    <updated>2010-08-26T03:24:57Z</updated>
    <category term="General" />
    <category term="Identity" />
    <category term="Web Services" /><feedburner:origlink>http://blog.beuchelt.org/2010/08/26/Preparing+Some+Paper.aspx</feedburner:origlink>
    <author>
      <name>Gerald Beuchelt</name>
    </author>
    <source>
      <id>http://blog.beuchelt.org/</id>
      <logo>http://clustrmaps.com/counter/index2.php?url=http://blog.beuchelt.com</logo>
      <author>
        <name>Gerry Beuchelt - MITRE</name>
        <email>work@beuchelt.com</email>
      </author>
      <link href="http://blog.beuchelt.org/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/WebServicesContraptions" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <rights>Gerald Beuchelt</rights>
      <title>Web Services Contraptions</title>
      <updated>2010-08-30T19:32:56Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Here is a couple of questions I'd love&#xD;
to put out - if you have the time, please let me know since I am genuinely curious: &#xD;
&lt;br&gt;&lt;ul&gt;&lt;li&gt;&#xD;
Who has implemented a successfully chained service, with some propagation of identity? &#xD;
&lt;br&gt;&lt;/li&gt;&lt;li&gt;&#xD;
If you have, what architectural approach/technology stack have you used?&lt;br&gt;&lt;/li&gt;&lt;li&gt;&#xD;
How are you propagating identity - "sender vouches", "holder of key", "just trust&#xD;
me"?&lt;/li&gt;&lt;li&gt;&#xD;
How complex is the chain? Single step, multiple steps, complex orchestration?&lt;/li&gt;&lt;/ul&gt;&#xD;
There are really very few actual success stories I can find on this subject ... I&#xD;
have a sense why this could be, but I'd love to verify my suspicion. &#xD;
&lt;br&gt;&lt;p&gt;&lt;/p&gt;&lt;img height="0" src="http://blog.beuchelt.org/aggbug.ashx?id=be6491ae-5bb0-4507-b007-eacd31aa8e47" width="0"&gt;&lt;/img&gt;&#xD;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/aA-_BYuoR0Hsr0PtBIXW2STE8hQ/0/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/aA-_BYuoR0Hsr0PtBIXW2STE8hQ/0/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a href="http://feedads.g.doubleclick.net/~a/aA-_BYuoR0Hsr0PtBIXW2STE8hQ/1/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/aA-_BYuoR0Hsr0PtBIXW2STE8hQ/1/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/WebServicesContraptions/~4/qn1JZ1Vbe9E" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=lNA1Wi6gV3I:dk4dzqOmys8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=lNA1Wi6gV3I:dk4dzqOmys8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=lNA1Wi6gV3I:dk4dzqOmys8:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=lNA1Wi6gV3I:dk4dzqOmys8:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/lNA1Wi6gV3I" height="1" width="1"/&gt;</content><feedburner:origLink>http://feedproxy.google.com/~r/WebServicesContraptions/~3/qn1JZ1Vbe9E/Preparing+Some+Paper.aspx</feedburner:origLink></entry>

  <entry xml:lang="en-us">
    <id>http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/25/Came-Saw-Conquered</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/W_c6dc0KU4E/Came-Saw-Conquered" rel="alternate" type="text/html" />
    <title>Ping Talk - Ping Identity: Came. Saw. Conquered.</title>
    
    <updated>2010-08-25T18:26:00Z</updated>
    <category term="Customers" />
    <source>
      <id>http://www.pingidentity.com/blogs/pingtalk/index.cfm</id>
      <category scheme="http://www.itunes.com/" term="Technology" />
      <category scheme="http://www.itunes.com/" term="Podcasting" />
      <category scheme="http://www.itunes.com/" term="Tech News" />
      <author>
        <name>Ping Talk - Ping Identity</name>
        <email>pingtalkblog@pingidentity.com</email>
      </author>
      <link href="http://www.pingidentity.com/blogs/pingtalk/index.cfm" rel="alternate" type="text/html" />
      <link href="http://www.pingidentity.com/blogs/pingtalk/rss.cfm?mode=full" rel="self" type="application/rss+xml" />
      <title>Ping Talk Blog</title>
      <updated>2010-09-03T00:23:13Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;One thing I love about technology is getting to talk to people who get dirty up to their elbows in the stuff. I enjoy writing about end-users because once warmed up they usually have some great stories and unique anecdotes to share.&lt;/p&gt;&#xD;
&lt;div&gt;Internally, we have been juicing our efforts to get more customer stories into the flow. So today’s post is as much highlighting one of those end-users – Australian telecom provider AAPT – as it is a kickoff to some customer case studies you’ll see pass through these virtual pages.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Specifically regarding AAPT, it is shooting for the cloud, literally, and aiming at being strongest out of the gate with a range of business services from authentication, to storage, to reselling Google Apps&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;The company is cutting its services teeth on internal adoption of Google Apps and Gmail.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Internally, the company spent five days rolling out Google Apps to 1,200 user and is in the process of rolling out 1,700 Google Gmail inboxes. User access to those services is secured with a hosted Single Sign-On service run off Ping Connect, a hosted service from Ping Identity.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Last year, however, AAPT nearly hit a nasty and potentially embarrassing roadblock. As part of a partnership with Google, AAPT was set to record a television commercial detailing how they rolled out Google Apps and secured it via Single Sign-On.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;The problem was the IT architects might have been the last to know, according to David Tarrant, AAPT IT architect and a consultant on the company’s cloud build out and Google adoption.Ten days before the commercial, IT was informed of the SSO requirement and had to not only roll out software but pick a product.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Parent company Telecom New Zealand had an identity platform built on Sun Microsystems products, said Tarrant, but the estimated time to federate it with the Google platform was 2-3 months.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;“So I found Ping and we had it done in 3-4 days,” he said. “As soon as I found Ping had a hosted service [PingConnect] that is what I wanted.”&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;But Tarrant acknowledges it was a means to an end. “We didn’t care about SSO, what is important is the same password. You don’t have to learn new passwords. And all of it falls under compliance.” And Tarrant says the Google/Ping strategy saves the IT department $252,000 per year.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Now Tarrant is eyeing the Salesforce.com users within the organization as the next project.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;In parallel, the third-largest telecom provider in the country also is actively building out a commercial offering designed to provide virtual private clouds to customers. The company plans to ramp up services like desktops, applications and email. Tarrant says that should be in full swing in the next 18 months to two years.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;AAPT owns and operates its own national voice and data network. It provides residential, business, government and wholesale customers with local and long distance voice, mobile, data and internet solutions.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt; “We don’t want to build our own authentication service we want to use somebody else’s, we don’t want to build our own Google services we want to use somebody else’s, we don’t want to build storage services we want to use somebody else’s,” said Tarrant. “We want to build relationships with cloud providers all over the world.”&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;And how is the cloud services build-out going?&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;In May, Paul Broad, CEO of AAPT made a presentation at the company’s investor briefing day and singled out content delivery and cloud computing as areas targeted to grow, highlighted Q3 as the launch of Google Apps for business users, and named Specialty Fashion Group, Rio Tinto, Austar and WPP Holdings as key new customers.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Follow John on &lt;a href="http://twitter.com/JohnFontana"&gt;Twitter&lt;/a&gt;  and check out                                          our Identity-Conversation &lt;a href="http://twitter.com/JohnFontana/identity-conversation"&gt;Tweet                                           list&lt;/a&gt;&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=W_c6dc0KU4E:-UvTznASkzY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=W_c6dc0KU4E:-UvTznASkzY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=W_c6dc0KU4E:-UvTznASkzY:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=W_c6dc0KU4E:-UvTznASkzY:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/W_c6dc0KU4E" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/25/Came-Saw-Conquered</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blog.broadbandmechanics.com/?p=7226</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/nehCq1CXRqU/" rel="alternate" type="text/html" />
    <title>Marc Canter - Broadband Mechanics: FYI book v3</title>
    <summary type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;All the chapters have been reordered - it’s much more comprehensible now!&lt;/p&gt;&#xD;
&lt;p&gt;We’re doing a dress rehearsal tonight at the WOW (Wade Oval Weds) at 7:15&lt;/p&gt;&#xD;
&lt;div style="text-align: left; width: 450px;"&gt;&lt;a href="http://www.blurb.com/books/preview/1552607?ce=blurb_ew&amp;amp;utm_source=widget" target="_new"&gt;&lt;img src="http://bookshow.blurb.com/bookshow/cache/P2171413/md/wcover_2.png"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
&lt;div style="display: block;"&gt;&lt;a href="http://www.blurb.com/bookstore/detail/1552607?ce=blurb_ew&amp;amp;utm_source=widget" style="margin: 12px 3px;" target="_blank"&gt;FYI by Marc Canter and Christian Nieves&lt;/a&gt; | &lt;a href="http://www.blurb.com/landing_pages/bookshow?ce=blurb_ew&amp;amp;utm_source=widget" style="margin: 12px 3px;" target="_blank"&gt;Make Your Own Book&lt;/a&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&lt;/div&gt;</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;All the chapters have been reordered - it’s much more comprehensible now!&lt;/p&gt;&#xD;
&lt;p&gt;We’re doing a dress rehearsal tonight at the WOW (Wade Oval Weds) at 7:15&lt;/p&gt;&#xD;
&lt;div style="text-align: left; width: 450px;"&gt;&lt;a href="http://www.blurb.com/books/preview/1552607?ce=blurb_ew&amp;amp;utm_source=widget" target="_new"&gt;&lt;img src="http://bookshow.blurb.com/bookshow/cache/P2171413/md/wcover_2.png"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
&lt;div style="display: block;"&gt;&lt;a href="http://www.blurb.com/bookstore/detail/1552607?ce=blurb_ew&amp;amp;utm_source=widget" style="margin: 12px 3px;" target="_blank"&gt;FYI by Marc Canter and Christian Nieves&lt;/a&gt; | &lt;a href="http://www.blurb.com/landing_pages/bookshow?ce=blurb_ew&amp;amp;utm_source=widget" style="margin: 12px 3px;" target="_blank"&gt;Make Your Own Book&lt;/a&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=nehCq1CXRqU:tY_Xja2APx4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=nehCq1CXRqU:tY_Xja2APx4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=nehCq1CXRqU:tY_Xja2APx4:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=nehCq1CXRqU:tY_Xja2APx4:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/nehCq1CXRqU" height="1" width="1"/&gt;</content>
    <updated>2010-08-25T15:49:38Z</updated>
    <category term="Blog" />
    <author>
      <name>marc</name>
    </author>
    <source>
      <id>http://blog.broadbandmechanics.com</id>
      <link href="http://blog.broadbandmechanics.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://blog.broadbandmechanics.com" rel="alternate" type="text/html" />
      <subtitle>building the open web one bit at a time</subtitle>
      <title>Marc's Voice</title>
      <updated>2010-09-02T04:00:25Z</updated>
    </source>
  <feedburner:origLink>http://blog.broadbandmechanics.com/2010/08/25/fyi-book-v3/</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content52588</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/1mVraH0KZWI/content52588" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: Imprivata Announces Healthcare Advisory Board</title>
    
    <updated>2010-08-25T13:02:58Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">Healthcare Executives, Industry Experts and Thought Leaders Address Healthcare IT Challenges, Trends and Priorities for Improving Clinician Workflow and Securing Patient Data&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=1mVraH0KZWI:ZGL29RtG34Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=1mVraH0KZWI:ZGL29RtG34Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=1mVraH0KZWI:ZGL29RtG34Q:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=1mVraH0KZWI:ZGL29RtG34Q:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/1mVraH0KZWI" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content52588</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://blogs.msdn.com/b/vbertocci/archive/2010/08/25/infographic-ips-protocols-amp-token-flavours-in-the-august-labs-release-of-acs.aspx</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/2zzSWxvwTKw/infographic-ips-protocols-amp-token-flavours-in-the-august-labs-release-of-acs.aspx" rel="alternate" type="text/html" />
    <title xml:lang="en-US">Vittorio Bertocci - Microsoft: Infographic: IPs, Protocols &amp; Token Flavours in the August Labs release of ACS</title>
    <content type="html" xml:lang="en-US">&lt;p&gt;The newest lab release of ACS shows some serious protocol muscle, covering (to my knowledge) more ground than anything else to date. ACS also does an excellent job in simplifying many scenarios that would traditionally require much more thinking &amp;amp; effort: as a result, it is very tempting to just think that any scenario falling in the Cartesian product of possible IPs, protocols, token types and application types can be easily tackled. Although that is true in principle, in reality there are uses and scenarios that are more natural and easier to implement. Discussions about this, in a form or another, are blossoming all over the place both internally and externally: as a visual person I think that a visual summary of the current situation can help to scope the problem and use the service more effectively. Here there’s my first attempt (click for bigger version).&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/0385.ACS2Diagram1.0_5F00_21281B02.png"&gt;&lt;img alt="ACS2Diagram1.0" border="0" height="480" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/2110.ACS2Diagram1.0_5F00_thumb_5F00_04AB2922.png" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px;" title="ACS2Diagram1.0" width="613"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;I am fairly confident that this should be correct, I discussed it with Hervey, Todd and Erin, but there’s always the possibility that I misunderstood something.    &lt;br&gt;There’s quite a lot of stuff in there, let me walk you through the various parts of the diagram.&lt;/p&gt;  &lt;p&gt;The diagram is partitioned in 3 vertical disjointed regions: on the left there are all the identity providers you can use with ACS, on the right the applications that can trust ACS; and between them, there is ACS itself. On the borderline between ACS and your applications there are the three issuing endpoints offered by ACS: the WS-Federation endpoint, the WS-Trust endpoint and the OAuth WRAP one. Here I didn’t draw any of the ACS machinery, from the claim transformation engine to the list of RP endpoints; it’s enough to know that something happens to the claims in their journey from the IP to the ACS issuers.&lt;/p&gt;  &lt;p&gt;The diagram is also subdivided in 3 horizontal regions, which represent the kind of apps that are best implemented using a given set of identity providers and/or protocols. The WS-Federation issuer is best suited for applications which are meant to be consumed via web browser; WS-Trust, and the OAuth WRAP profiles that ACS implements, are ideal for server to server communications; finally, WS-Trust is also suitable for cases in which the user is taking advantage of rich clients. This classification is one of the areas of maximum confusion, and likely source of controversy. Of course you can use WS-Federation without a browser (that’s what I do in &lt;a href="http://bit.ly/9YE2X5"&gt;SelfSTS&lt;/a&gt;), of course you can embed WS-Federation in a rich client and use a browser control to obtain tokens; however those require writing custom code, a very good grasp of what you are doing and the will to stretch things beyond intended usage, hence I am not covering those here.&lt;/p&gt;  &lt;p&gt;Let’s backtrack through the diagram starting from the ACS issuer endpoints.&lt;/p&gt;  &lt;p&gt;The WS-Federation endpoint is probably the one you are most familiar with; it’s the one you take advantage of in order to sign in your application by leveraging multiple identity providers. It’s also the one which allow you a no-code experience for the most common cases, thanks to the WIF SDK’s Add STS Reference wizard.   &lt;br&gt;You can configure that endpoint to issue SAML1.1, SAML2 and SWT tokens. The latter can be useful for protocol transition scenarios, however remember that there’s no OOB support for the format.    &lt;br&gt;The sources here are the ones you can see on the portal, and the ones that the ACS-generated home realm discovery page will offer you (if you opted in). Every IP will use its own protocol for authentication (Google and Yahoo use OpenID, Facebook uses Facebook Connect, ADFS2 uses whatever authentication system is active) but in the end your application will get a WS-Federation wresult with a transformed token. It should be noted that “ADFS2” does not strictly indicates an ADFS2 instance, anything that can do WS-Federation should be able to be used here.&lt;/p&gt;  &lt;p&gt;The WS-Trust endpoint will issue tokens when presented with a token from a WS-Trust identity provider, that is to say an ADFS2 instance (or equivalent, per the earlier discussion). It will also issue tokens when invoked with username and password associated to a service identity, static credentials maintained directly in ACS. &lt;/p&gt;  &lt;p&gt;The OAuth WRAP endpoint will issue SWT tokens when invoked with a service identity credential; it will also accept SAML assertions from a trusted WS-Trust IP, pretty much the ADFS2 integration scenario from V1. Note that the profiles supported by ACS are server to server: the username &amp;amp; password of a service identity are not user credentials, but the means through which a service authenticates with another (including cases in which the user does not even have a session in place).&lt;/p&gt;  &lt;p&gt;That’s it, that should give you a feeling of the scope of what you can do with this release. I’ll probably add to this as things more forward. Have fun!&lt;/p&gt;&lt;div style="clear: both;"&gt;&lt;/div&gt;&lt;img height="1" src="http://blogs.msdn.com/aggbug.aspx?PostID=10053982" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=2zzSWxvwTKw:84G_2Vyuvyg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=2zzSWxvwTKw:84G_2Vyuvyg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=2zzSWxvwTKw:84G_2Vyuvyg:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=2zzSWxvwTKw:84G_2Vyuvyg:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/2zzSWxvwTKw" height="1" width="1"/&gt;</content>
    <updated>2010-08-25T08:10:31Z</updated>
    <published>2010-08-25T08:10:31Z</published>
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Identity/" term="Identity" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Windows+Identity+Foundation/" term="Windows Identity Foundation" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/WIF/" term="WIF" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Access+Control+Service/" term="Access Control Service" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/AppFabric/" term="AppFabric" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/ACS/" term="ACS" />
    <author>
      <name>vibro</name>
      <uri>http://blogs.msdn.com/members/vibro/</uri>
    </author>
    <source>
      <id>http://blogs.msdn.com/b/vbertocci/atom.aspx</id>
      <link href="http://blogs.msdn.com/b/vbertocci/" rel="alternate" type="text/html" />
      <link href="http://blogs.msdn.com/b/vbertocci/atom.aspx" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Scatter thoughts</subtitle>
      <title xml:lang="en-US">Vibro.NET</title>
      <updated>2010-05-11T17:27:14Z</updated>
    </source>
  <feedburner:origLink>http://blogs.msdn.com/b/vbertocci/archive/2010/08/25/infographic-ips-protocols-amp-token-flavours-in-the-august-labs-release-of-acs.aspx</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/articles/mk_virtuel_nutz25082010</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/pZ-GyrwUol8/mk_virtuel_nutz25082010" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Martin Kuppinger: Virtualisierung: Nicht immer nützlich</title>
    
    <updated>2010-08-25T07:38:18Z</updated>
    <source>
      <id>http://blogs.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://blogs.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole-blogs" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Kuppinger Cole Blogs</subtitle>
      <title>Kuppinger Cole Blogs</title>
      <updated>2010-08-28T22:02:59Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Das Konzept der Server-Virtualisierung hat sich durchgesetzt. Zu Recht, wenn man eine ausreichende Zahl von Servern hat. Denn damit lassen sich die physischen Server besser und flexibler auslasten. Dass sich auch unterschiedliche Betriebssysteme einfacher nebeneinander betreiben lassen und dazu noch die Betriebssysteme von der physischen Hardware entkoppelt werden und damit die Hardware einfacher gewechselt werden kann, ist ebenso ein feiner Nebeneffekt wie die Vorteile für die Verfügbarkeit durch den Wechsel auf andere Hardware.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#333333"&gt;Storage-, Desktop- und Application-Virtualisierung&lt;/font&gt;&lt;/strong&gt;&lt;br&gt;Inzwischen gewinnen auch die Storage-, Desktop- und Application-Virtualisierung immer mehr an Bedeutung. Nur: Machen diese Ansätze genauso viel Sinn? Gerade bei der Desktop- und Anwendungsvirtualisierung muss man sich diese Frage stellen, denn hier gibt es berechtigte Zweifel. Die Storage-Virtualisierung – wie beim Server am Backend – ist dagegen im Grundsatz durchaus sinnvoll.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#333333"&gt;Kein klarer Nutzen bei der Desktop-Virtualisierung&lt;/font&gt;&lt;/strong&gt;&lt;br&gt;Ganz anders stellt sich die Situation bei der Desktop-Virtualisierung dar. Desktop-Virtualisierung ist zum aktuellen Zeitpunkt vor allem auf die Bereitstellung weniger Varianten von relativ einheitlichen Systemumgebungen ausgerichtet. Das bekommt man aber mit Terminaldiensten und auch mit klassischem Client Lifecycle Management gut in den Griff. &lt;/p&gt;&lt;p&gt;Die Variantenvielfalt bei den Benutzern, die sich nicht in das Standard-Raster pressen lassen, ist aber damit nicht effizient beherrschbar – und für mobile Benutzer steckt die Technologie auch noch in den Kinderschuhen. Desktop-Virtualisierung bringt durchaus einige Vorteile. Aber so klar wie auf der Server-Seite ist der Nutzen nicht. Deshalb sollte man Desktop-Virtualisierung auch eher als eine Deployment-Option für Client-Systeme sehen und nicht als die perfekte Lösung.&lt;/p&gt;&lt;p&gt;&lt;font color="#333333"&gt;&lt;strong&gt;Hoher Aufwand für Anwendungsvirtualisierung &lt;br&gt;&lt;/strong&gt;&lt;/font&gt;Auch bei der Anwendungsvirtualisierung ist eine kritische Distanz sicher kein Fehler. Wenn Unternehmen darüber nachdenken, gerade die Standard-Anwendungen wie Office-Anwendungen zu virtualisieren, stellt sich doch sehr deutlich die Frage nach dem Warum.&lt;/p&gt;&lt;p&gt;Denn diese Anwendungen lassen sich einfach in virtualisierten Desktops oder über die Software-Verteilungsfunktionen auf physische Desktops verteilen. Interessant wird es eigentlich erst mit Anwendungen, die nur Teile der Benutzer benötigen – und das nicht dauernd.&lt;/p&gt;&lt;p&gt;Diese Anwendungen bereitzustellen und auch zu deinstallieren ist die eigentliche Herausforderung. Gerade bei solchen Anwendungen darf man aber auch den Bereitstellungsaufwand bei der Anwendungsvirtualisierung nicht unterschätzen. Und gerade bei spezialisierten Anwendungen kann man auch eher auf Kompatibilitätsprobleme stoßen.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#333333"&gt;Die Marketing-Versprechen der Hersteller&lt;/font&gt;&lt;/strong&gt;&lt;br&gt;Letztlich empfiehlt sich gerade am Frontend eine gewisse Skepsis gegenüber den Marketing-Versprechen der Hersteller. Denn nicht alles, was am Backend Sinn macht, stiftet auch beim Client einen vergleichbaren Nutzen. Zudem ist die Variantenvielfalt beim Client auch schwieriger zu beherrschen. Hier geht es eher um ein Sowohl-als-auch als um ein Entweder-oder.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=pZ-GyrwUol8:9_I1HgcOdR4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=pZ-GyrwUol8:9_I1HgcOdR4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=pZ-GyrwUol8:9_I1HgcOdR4:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=pZ-GyrwUol8:9_I1HgcOdR4:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/pZ-GyrwUol8" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/articles/mk_virtuel_nutz25082010</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.equalsdrummond.name/?p=318</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/gpg6CfUItE4/" rel="alternate" type="text/html" />
    <link href="http://www.equalsdrummond.name/?p=318#comments" rel="replies" type="text/html" />
    <link href="http://www.equalsdrummond.name/?feed=atom&amp;p=318" rel="replies" type="application/atom+xml" />
    <title xml:lang="en">Drummond Reed - Cordance: Finally Taking Off a Hat</title>
    <summary xml:lang="en" type="html">When the Information Card Foundation (ICF) and OpenID Foundation (OIDF) launched the Open Identity Exchange (OIX) at RSA on March 2, I temporarily added the hat of OIX Executive Director. ICF agreed to loan me half time to OIX to work through the startup stages of establishing the industry’s first open trust framework platform provider. [...]</summary>
    <content type="html" xml:lang="en">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;img alt="oix_logo" class="alignleft size-full wp-image-319" height="48" src="http://www.equalsdrummond.name/wp-content/uploads/oix_logo.jpg" title="oix_logo" width="251"&gt;&lt;/img&gt;When the &lt;a href="http://www.informationcard.net/"&gt;Information Card Foundation&lt;/a&gt; (ICF) and &lt;a href="http://www.openid.net/"&gt;OpenID Foundation&lt;/a&gt; (OIDF) launched the &lt;a href="file://%5Bhttp/::www.openidentityexchange.org:"&gt;Open Identity Exchange&lt;/a&gt; (OIX) at RSA on March 2, I temporarily added the hat of OIX Executive Director. ICF agreed to loan me half time to OIX to work through the startup stages of establishing the industry’s first &lt;a href="http://www.openidentityexchange.org/sites/default/files/the-open-identity-trust-framework-model-2010-03.pdf"&gt;open trust framework platform provider&lt;/a&gt;. For its part, OIDF contributed the time of OIDF Executive Director Don Thibeau to serve as OIX President and board chair, and it has been a tremendous pleasure working with Don, OIX counsel Scott David, and Global Inventures program manager John Ehrig to lay the foundation for OIX.&lt;/p&gt;&#xD;
&lt;p&gt;Now, with the announcement at last month’s Burton Catalyst conference that &lt;a href="http://openidentityexchange.org/press-releases/att-joins-oix-board"&gt;AT&amp;amp;T has joined OIX&lt;/a&gt;, that &lt;a href="http://openidentityexchange.org/news"&gt;several new OIX Working Groups are starting up&lt;/a&gt;, and that &lt;a href="http://openidentityexchange.org/press-releases/oix-kantara-collaboration"&gt;OIX and Kantara have begun collaborating on trust framework infrastructure&lt;/a&gt;, the startup phase of OIX is over, and I can finally take off the OIX ED hat.&lt;/p&gt;&#xD;
&lt;p&gt;This does not mean I will be any less involved with OIX, however. On the contrary, as I have been blogging throughout this year, the need for a particular trust framework—one governing data exchange with &lt;a href="http://www.equalsdrummond.name/../../../../../?cat=93"&gt;personal data stores&lt;/a&gt; (PDX)—is becoming acute. That need also intersects directly with the work I’ve been doing on the &lt;a href="http://en.wikipedia.org/wiki/XDI"&gt;XDI data sharing protocol&lt;/a&gt; at OASIS since 2004.&lt;/p&gt;&#xD;
&lt;p&gt;So as fast as I’m taking off the OIX ED hat, I’m preparing to take on another one spearheading the development of a PDX trust framework at OIX. This will be one of the key topics both at the &lt;a href="http://vrmcrm2010.eventbrite.com/"&gt;VRM+CRM conference in Boston&lt;/a&gt; this coming Thursday and Friday, and also at the &lt;a href="http://www.internetidentityworkshop.com/iiw-east-in-dc-open-identity-for-open-government/"&gt;Internet Identity Workshop East&lt;/a&gt; on September 9 and 10 in D.C. following Gov 2.0.&lt;/p&gt;&#xD;
&lt;p&gt;If you are attending either event and want to know more about PDX and the PDX trust framework, please come to the open space sessions we’ll be holding.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=gpg6CfUItE4:zD-a2oG5QKA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=gpg6CfUItE4:zD-a2oG5QKA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=gpg6CfUItE4:zD-a2oG5QKA:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=gpg6CfUItE4:zD-a2oG5QKA:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/gpg6CfUItE4" height="1" width="1"/&gt;</content>
    <updated>2010-08-25T05:27:15Z</updated>
    <published>2010-08-25T05:27:15Z</published>
    <category scheme="http://www.equalsdrummond.name" term="Open Identity Exchange" />
    <category scheme="http://www.equalsdrummond.name" term="Personal Data Store" />
    <category scheme="http://www.equalsdrummond.name" term="VRM" />
    <author>
      <name>Drummond Reed</name>
      <uri>http://xri.net/=drummond</uri>
    </author>
    <source>
      <id>http://www.equalsdrummond.name/?feed=atom</id>
      <link href="http://www.equalsdrummond.name" rel="alternate" type="text/html" />
      <link href="http://www.equalsdrummond.name/?feed=atom" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en">It's all about naming...</subtitle>
      <title xml:lang="en">Equals Drummond</title>
      <updated>2010-08-25T05:27:15Z</updated>
    </source>
  <feedburner:origLink>http://www.equalsdrummond.name/?p=318</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-12447072.post-8534612530461323354</id>
    <link href="http://connectid.blogspot.com/feeds/8534612530461323354/comments/default" rel="replies" type="application/atom+xml" />
    <link href="https://www.blogger.com/comment.g?blogID=12447072&amp;postID=8534612530461323354" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/8534612530461323354?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/8534612530461323354?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/0OpGKn-exeY/new-line-of-greeting-cards_24.html" rel="alternate" type="text/html" />
    <title>Paul Madsen: New line of greeting cards</title>
    <content type="html">&lt;div class="posterous_autopost"&gt;&lt;img height="321" src="http://posterous.com/getfile/files.posterous.com/paulmadsen/yH0OIYttMXg1SlAQDkDwWDPVEATiqkhe4mZWv6xywvwYRojnoVJLsCCAgDr3/Screen_00017.jpg" width="437"&gt;&lt;/img&gt; &lt;p style="font-size: 10px;"&gt;  &lt;a href="http://posterous.com"&gt;Posted via email&lt;/a&gt;   from &lt;a href="http://paulmadsen.posterous.com/new-line-of-greeting-cards-23"&gt;Pre(posterous)&lt;/a&gt;  &lt;/p&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/12447072-8534612530461323354?l=connectid.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/blogspot/gMwy/~4/0OpGKn-exeY" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0OpGKn-exeY:kMjwLGAQvg8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0OpGKn-exeY:kMjwLGAQvg8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0OpGKn-exeY:kMjwLGAQvg8:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=0OpGKn-exeY:kMjwLGAQvg8:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/0OpGKn-exeY" height="1" width="1"/&gt;</content>
    <updated>2010-08-24T22:56:27Z</updated>
    <published>2010-08-24T22:56:00Z</published>
    <author>
      <name>Paul Madsen</name>
      <email>noreply@blogger.com</email>
      <uri>http://www.blogger.com/profile/08489111023182783403</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-12447072</id>
      <author>
        <name>Paul Madsen</name>
        <email>noreply@blogger.com</email>
        <uri>http://www.blogger.com/profile/08489111023182783403</uri>
      </author>
      <link href="http://connectid.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://connectid.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/12447072/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/blogspot/gMwy" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>When you don't have anything nice to say, consider blogging it. or a tweet if you're rushed for time.</subtitle>
      <title>ConnectID</title>
      <updated>2010-09-01T22:30:26Z</updated>
    </source>
  <feedburner:origLink>http://connectid.blogspot.com/2010/08/new-line-of-greeting-cards_24.html</feedburner:origLink></entry>

  <entry xml:lang="en-us">
    <id>http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/24/Got-trust</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/WDB6DPkUbTE/Got-trust" rel="alternate" type="text/html" />
    <title>Ping Talk - Ping Identity: Got trust?</title>
    
    <updated>2010-08-24T21:03:00Z</updated>
    <category term="Cloud" />
    <category term="Internet" />
    <source>
      <id>http://www.pingidentity.com/blogs/pingtalk/index.cfm</id>
      <category scheme="http://www.itunes.com/" term="Technology" />
      <category scheme="http://www.itunes.com/" term="Podcasting" />
      <category scheme="http://www.itunes.com/" term="Tech News" />
      <author>
        <name>Ping Talk - Ping Identity</name>
        <email>pingtalkblog@pingidentity.com</email>
      </author>
      <link href="http://www.pingidentity.com/blogs/pingtalk/index.cfm" rel="alternate" type="text/html" />
      <link href="http://www.pingidentity.com/blogs/pingtalk/rss.cfm?mode=full" rel="self" type="application/rss+xml" />
      <title>Ping Talk Blog</title>
      <updated>2010-09-03T00:23:13Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;This morning I got a reminder why trust is such an important part of the identity architecture that is being constructed as corporations begin to understand concepts from federation to cloud computing.&lt;/p&gt;&#xD;
&lt;div&gt;In fact, why trust is an indispensable tool for any architecture, organization or society.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Here in Denver, the city’s &lt;a href="http://www.denverpost.com/news/ci_15873109"&gt;safety manager Ron Perea resigned&lt;/a&gt; last night after being engulfed in a controversy over the discipline he handed police officers involved in abuse cases involving citizens.&lt;img align="right" alt="" height="231" src="http://www.pingidentity.com/blogs/pingtalk/images/image/circle%20of%20trust.jpg" width="250"&gt;&lt;/img&gt;&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Perea told his boss, Mayor John Hickenlooper, that he didn’t think he could rebuild trust with the public after his decision not to fire two police officers caught on video tape beating a young man.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;"Once he put it in that context, it was hard to argue with," Hickenlooper told the Denver Post. "It would be very difficult to rebuild after all the events of the last four or five days. It would be very hard to rebuild that trust."&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Three months on the job and Perea, the former head of the Los Angeles office of the U.S. Secret Service, knew that a public that distrusted him made impossible his job of ensuring safety.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Without trust, all is lost.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;The same is true whether you’re protecting the streets of a city or the virtual pipes of a global distributed network.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;&lt;a href="http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/7/6/CIS-Series-Andrew-Nash-Trust-broker-a-linchpin"&gt;PayPal’s Andrew Nash described&lt;/a&gt; to me a few months ago how a collection of trust brokers on the Internet were needed to create any sort of relevant connections online. In other words, without trust between parties, between machines, nothing of significance gets done.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;A few days ago, a panel of experts on a &lt;a href="http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/13/Trust--the-discussion-continues-Part-II"&gt;Webinar on Federal News Radio&lt;/a&gt; concluded that trust was indeed the next killer app. They talked about integrity, policies, transparency and just the plain fact that people will need a system that allows them to trust other people.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;At Ping’s recent Cloud Identity Summit, Accenture’s &lt;a href="http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/6/14/CIS-Series-Mike-Neuenschwander-The-issue-is-trust"&gt;Mike Neuenschwander told the audience&lt;/a&gt;, "If we are going to have an environment of any-to-any and not repave existing partnerships, the industry has to develop a systematic approach to trust."&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Trust frameworks were a foundational element of the Obama administration’s recent National Strategy for Trusted Identities in Cyberspace (NSTIC).&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Get yourself plugged into the work of groups like &lt;a href="http://kantarainitiative.org/index.php"&gt;Kantara&lt;/a&gt;,&lt;a href="http://www.incommonfederation.org/"&gt; InCommon&lt;/a&gt; and the&lt;a href="http://openidentityexchange.org/"&gt; Open Identity Exchange (OIX)&lt;/a&gt;, which was approved by the federal government in early March to certify online identity management providers.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Trust me, watch this space.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Follow John on &lt;a href="http://twitter.com/JohnFontana"&gt;Twitter&lt;/a&gt;  and check out                                         our Identity-Conversation &lt;a href="http://twitter.com/JohnFontana/identity-conversation"&gt;Tweet                                          list&lt;/a&gt;&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=WDB6DPkUbTE:Y3-zm1eoLro:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=WDB6DPkUbTE:Y3-zm1eoLro:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=WDB6DPkUbTE:Y3-zm1eoLro:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=WDB6DPkUbTE:Y3-zm1eoLro:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/WDB6DPkUbTE" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/24/Got-trust</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-3202333073278756422.post-4977502202483644487</id>
    <link href="http://independentidentity.blogspot.com/2010/08/pulling-for-change.html#comment-form" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/3202333073278756422/posts/default/4977502202483644487" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/3202333073278756422/posts/default/4977502202483644487" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/_62IO7wPyEI/pulling-for-change.html" rel="alternate" type="text/html" />
    <title>Phil Hunt - Oracle: Pulling For Change</title>
    <content type="html">&lt;div&gt;This past spring, several organizations began a discussion on the SAML TC about the possibility of adding subject and attribute management functions to SAML. The proposal was the subject of a some debate. Why was this an important requirement? Why not use SPML or other protocols? After considering several possibilities, a new concept emerged called "&lt;a href="http://www.oasis-open.org/committees/document.php?document_id=38737&amp;amp;wg_abbrev=security"&gt;Change Notify&lt;/a&gt;" which suggests converting identity management operations from state-based explicit adds/modifies/deletes to pull based operations that could enable identity changes to be exchanged between partners in federated scenarios.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Before we talk about the new proposal, let's cover some of the discussion about why the state-basedm, push solutions wouldn't work.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Yes, Updates Happen&lt;/b&gt;&lt;/div&gt;&lt;div&gt;There was agreement that there are lots of scenarios where updates of some kind are needed. A web retailer, after completing a sales process with a user, might want to have some method to update a shipping address at a customer's IDP after the user indicated the address was out-of-date. An Identity Provider might want to notify relying parties with retained data of important changes. An enterprise might want to notify a cloud service provider that the employee has changed roles or has been retired.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Some of you may be asking, but why is this an issue?  Shouldn't applications avoid retaining data from Identity Providers? There is often a need for some data to be retained. Applications may need to retain data because of complexity with other integrated systems. It might be needed for offline processing (where backend calls to the identity provider aren't practical or possible). Consider that business applications often generate application specific data that is tied to individuals (purchase history, reputation, to name a few) and is not associate with data originating at an identity provider. Because of this, even in a so-called "zero data" scenario where applications retain no federated data about users, there is still one key update that cloud applications often need: the de-provisioning update. How does an enterprise, acting as an Identity Provider, notify a web service provider that an employee has retired?&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Why Traditional IDM Protocols Won't Work&lt;/b&gt;&lt;/div&gt;&lt;div&gt;We realized that traditional "push" approaches of adds/modifies/deletes would probably not function well because traditional enterprise approaches assume an updater has full knowledge of the target identity to be updated. Yet, by design, federated systems work at arms reach. Identity Providers have many relying parties and thus support many federated relationships. &lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Conversely a service provider can have many organizations, each with their own identity provider as clients. Or, even more complex, individuals may have a relationship with a service provider having nothing to do with their employer. Cell phones come to mind as an industry where there is often both an employee and personal relationship with a telephone company. Because of this, the state of an personal information and relationships in a federated system are not assured, and thus they cannot be assumed to be fact. Traditional "state" based approaches will run into issues such as adds of entries that already exist, or modify operations failing because an entity no longer exists.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Are we saying that state based protocols aren't useful?  Quite the contrary. State-based protocols work very well inside the enterprise environments. They can also work in some federated scenarios where there is tight agreement between business partners.  But assumptions about "state" begin to break down when you consider that federated business entities are working independently of each other.  &lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Pulling For Change&lt;/b&gt;&lt;/div&gt;&lt;div&gt;It was interesting timing that &lt;a href="http://www.burtongroup.com/AboutUs/Bios/AnalystBios.aspx"&gt;Bob Blakley&lt;/a&gt;, &lt;a href="http://analyzingidentity.com/2010/08/20/weighing-in-on-pull-vs-push/"&gt;Gerry Gebel&lt;/a&gt;, and my colleague &lt;a href="http://blog.talkingidentity.com/2010/08/pull-is-about-evolution-not-revolution.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+TalkingIdentity+%28Talking+Identity%29&amp;amp;utm_content=Google+Reader"&gt;Nishant Kaushik&lt;/a&gt; blogged recently on Pull vs. Push. While our requirements were focused on how to share ongoing updates to federated entities, there seems to be some natural alignment in thinking going on. For it was a "pull" oriented solution proposed to the SAML TC in July just prior to the Catalyst conference. The &lt;b&gt;Change Notify&lt;/b&gt; specification allows one party to notify another about a change without actually pushing raw data. Rather then "push" a transaction, the initiating party simply pushes a notification. The receiver can then simply "pull" data using a protocol of its choosing. A few important observations:&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;There is no rigid assumption of state between parties&lt;/li&gt;&lt;li&gt;The modify operation is converted into a simple "read" by the pulling entity.&lt;/li&gt;&lt;li&gt;The change notification is relatively lightweight and doesn't need to carry data values other then references to the entity being modified.&lt;/li&gt;&lt;li&gt;The technique can be applied to almost any federation protocol.&lt;/li&gt;&lt;li&gt;There is flexibility to switch protocols.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;div&gt;The initial &lt;b&gt;Change Notify&lt;/b&gt; proposal can be found &lt;a href="http://www.oasis-open.org/committees/document.php?document_id=38737&amp;amp;wg_abbrev=security"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Since publication to the SAML TC there has been some broader interest in building a lighter weight profile supporting a simple HTTP binding, REST, or JSON. While SAML adds a lot of messaging security, there is argument to be made that Change Notify can run in lighter weight implementations. These comments seem reasonable. I'm looking for your thoughts on how we can broaden this proposal in a multi-protocol way. Would people like to discuss the proposal at the next west coast IIW? Feel free to comment!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/3202333073278756422-4977502202483644487?l=independentidentity.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_62IO7wPyEI:qlYUb4grCMc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_62IO7wPyEI:qlYUb4grCMc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_62IO7wPyEI:qlYUb4grCMc:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=_62IO7wPyEI:qlYUb4grCMc:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/_62IO7wPyEI" height="1" width="1"/&gt;</content>
    <updated>2010-08-24T19:46:12Z</updated>
    <published>2010-08-24T19:28:00Z</published>
    <category scheme="http://www.blogger.com/atom/ns#" term="OASIS" />
    <category scheme="http://www.blogger.com/atom/ns#" term="standards" />
    <category scheme="http://www.blogger.com/atom/ns#" term="Federation" />
    <category scheme="http://www.blogger.com/atom/ns#" term="Provisioning" />
    <author>
      <name>Phil Hunt</name>
      <email>noreply@blogger.com</email>
      <uri>http://www.blogger.com/profile/08974996068290136413</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-3202333073278756422</id>
      <author>
        <name>Phil Hunt</name>
        <email>noreply@blogger.com</email>
        <uri>http://www.blogger.com/profile/08974996068290136413</uri>
      </author>
      <link href="http://independentidentity.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://www.blogger.com/feeds/3202333073278756422/posts/default" rel="self" type="application/atom+xml" />
      <link href="http://independentidentity.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <link href="http://www.blogger.com/feeds/3202333073278756422/posts/default?start-index=26&amp;max-results=25" rel="next" type="application/atom+xml" />
      <subtitle>Phil Hunt's blog on issues of Identity and Privacy and other stuff.</subtitle>
      <title>Independent Identity</title>
      <updated>2010-08-26T16:41:42Z</updated>
    </source>
  <feedburner:origLink>http://independentidentity.blogspot.com/2010/08/pulling-for-change.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.windley.com/archives/2010/08/cto_breakfast_this_thursday_the_once_and_future_web.shtml</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/row61DApVvo/cto_breakfast_this_thursday_the_once_and_future_web.shtml" rel="alternate" type="application/xhtml+xml" />
    <title xml:lang="en">Phil Windley - Kynetx: CTO Breakfast this Thursday: The Once and Future Web</title>
    <summary xml:lang="en" type="html">The CTO Breakfast will happen this Thursday at 8am in the cafeteria at Novell's Provo Campus. As usual, we'll talk tech; so bring interesting topics you'd like to discuss. Anyone interested in how information technology is used to build...</summary>
    <content type="html" xml:lang="en">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;img align="right" alt="CTO Breakfast" border="0" hspace="3" src="http://www.windley.com/images/iconUCTOB.gif" style="margin-top: 10px;" title="CTO Breakfast" vspace="3"&gt;&lt;/img&gt;&#xD;
&lt;p&gt;&#xD;
The &lt;a href="http://www.windley.com/cto_forum"&gt;CTO Breakfast&lt;/a&gt; will happen this Thursday at 8am in the &lt;a href="http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=novell+provo+utah&amp;amp;sll=40.33467,-111.687205&amp;amp;sspn=0.010288,0.012639&amp;amp;g=novell+provo+utah&amp;amp;ie=UTF8&amp;amp;z=16&amp;amp;iwloc=addr"&gt;cafeteria at Novell's Provo Campus&lt;/a&gt;.  As usual, we'll talk tech; so bring interesting topics you'd like to discuss.  &#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
Anyone interested in how information technology is used to build products or run companies. Despite it's name, you don't have to be a CTO to attend--just interested in technology, where it's headed, and the problems of starting and building a high-tech business in Utah.&#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
There's a &lt;a href="http://www.google.com/calendar/render?cid=elc1ns8qtncojt4adrveag2jo4%40group.calendar.google.com"&gt;calendar of upcoming CTO Breakfast events&lt;/a&gt; if you'd like to subscribe.  &#xD;
&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&#xD;
At this CTO Breakfast, Sam will have a special demo of some cool ideas we've been working on at Kynetx that foreshadows the future Web and the role personal data can play.  This will blow your mind.  &#xD;
&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=row61DApVvo:ELRXoCBTQn0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=row61DApVvo:ELRXoCBTQn0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=row61DApVvo:ELRXoCBTQn0:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=row61DApVvo:ELRXoCBTQn0:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/row61DApVvo" height="1" width="1"/&gt;</content>
    <updated>2010-08-24T19:45:25Z</updated>
    <published>2010-08-24T19:44:40Z</published>
    <category term="cto, breakfast, utah, events," />
    <source>
      <id>http://www.windley.com/</id>
      <icon>http://www.windley.com/favicon.ico</icon>
      <logo>http://www.niallkennedy.com/alive.gif</logo>
      <author>
        <name>windley</name>
        <email>phil@windley.org</email>
        <uri>http://www.windley.com</uri>
      </author>
      <link href="http://www.windley.com/" rel="alternate" type="application/xhtml+xml" />
      <link href="http://www.windley.com/atom.xml" rel="self" type="application/atom+xml" />
      <rights xml:lang="en">Creative Commons Attribution 2.5</rights>
      <subtitle xml:lang="en">Organizations Get the IT They Deserve</subtitle>
      <title xml:lang="en">Phil Windley's Technometria</title>
      <updated>2010-09-02T15:57:10Z</updated>
    </source>
  <feedburner:origLink>http://www.windley.com/archives/2010/08/cto_breakfast_this_thursday_the_once_and_future_web.shtml</feedburner:origLink></entry>

  <entry xml:lang="en-us">
    <id>http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/24/Provisioning-searching-for-door-out-of-no-mans-land</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/3aR7Gbm2_TQ/Provisioning-searching-for-door-out-of-no-mans-land" rel="alternate" type="text/html" />
    <title>Ping Talk - Ping Identity: Provisioning searching for door out of no man's land</title>
    
    <updated>2010-08-24T18:10:00Z</updated>
    <category term="Cloud" />
    <source>
      <id>http://www.pingidentity.com/blogs/pingtalk/index.cfm</id>
      <category scheme="http://www.itunes.com/" term="Technology" />
      <category scheme="http://www.itunes.com/" term="Podcasting" />
      <category scheme="http://www.itunes.com/" term="Tech News" />
      <author>
        <name>Ping Talk - Ping Identity</name>
        <email>pingtalkblog@pingidentity.com</email>
      </author>
      <link href="http://www.pingidentity.com/blogs/pingtalk/index.cfm" rel="alternate" type="text/html" />
      <link href="http://www.pingidentity.com/blogs/pingtalk/rss.cfm?mode=full" rel="self" type="application/rss+xml" />
      <title>Ping Talk Blog</title>
      <updated>2010-09-03T00:23:13Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Standards-based provisioning, which is lining up to be the next major evolution of cloud computing, is facing some significant gyrations in the near future.&lt;/p&gt;&#xD;
&lt;p&gt;Major players staking major bets on the cloud want to see something get done given that SPML 2 has not garnered any takers. Cloud providers need a standard specification that speaks squarely to their particular use cases.&lt;/p&gt;&#xD;
&lt;p&gt;Large enterprises need reliable, standards-based tools for deploying users in mass to cloud applications in order to preserve cost and agility benefits.&lt;/p&gt;&#xD;
&lt;div&gt;Will the solution eventually be an evolution of SPML, the &lt;a href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=provision"&gt;OASIS Provisioning Services Technical Committee&lt;/a&gt; is &lt;a href="http://lists.oasis-open.org/archives/provision/201008/threads.html#00005"&gt;going again&lt;/a&gt; after a near death experience, or will something different come to pass?&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Those with provisioning on their minds met in July at the Burton Catalyst Conference as part of a special interest group (SIG). Burton analyst Mark Diodati was tasked with writing up a statement for the group, which he published a few days ago on his &lt;a href="http://blogs.gartner.com/mark-diodati/2010/08/20/consensus-on-the-future-of-standards-based-provisioning-and-spml"&gt;blog&lt;/a&gt;.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;The conclusion is that work should revert to the basics, Diodati wrote. “The next iteration of SPML should focus on solving ‘the connector problem’ and provisioning use cases for cloud-based applications.”&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Diodati said 11 of the 12 &lt;a href="http://blogs.gartner.com/mark-diodati/2010/08/20/consensus-on-the-future-of-standards-based-provisioning-and-spml"&gt;participants&lt;/a&gt;, which are listed on his blog, agreed that a standards-based provisioning protocol is needed, and that it is best to evolve the SPML standard rather than introduce a new one.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Prateek Mishra, product manager for Oracle identity management and a major contributor to the &lt;a href="http://www.pingidentity.com/knowledge-center/SAML-Tutorials-and-Resources.cfm"&gt;SAML&lt;/a&gt; specification, said on the OASIS TC mailing list that Oracle is opposed to a new version of SPML. “This is a very large effort and typically takes 3-4 calendar years and dozens of person years to complete.” Oracle would like to evolve SPML and focus on specific use cases that are “important to the community.”&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;But Diodati noted that one SIG participant, Chuck Mortimore from Salesforce.com, had still not made a decision one way or the other.&lt;/div&gt;&#xD;
&lt;div&gt;Mortimore is not alone. His stance aligns with some of what I heard at Catalyst. &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Some of the big cloud vendors are not yet convinced that SPML can meet their requirements. One vendor told me that there is also concern that SPML comes with a lot of baggage.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;But there is agreement that provisioning is a sore spot for cloud providers who need an answer to customer questions about on-boarding users in an efficient and relatively painless manner. SPML 2 failed at passing the acid test on those requirements.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Does a provisioning standard need to be hashed out among an independent group of motivated participants who can set a framework and then move it into a more formalized standards body for critique and refinement?&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;That is how it worked with many of the early SOA standards that Microsoft and IBM developed. Not all survived scrutiny, but many are still around today after going through the wash at standards bodies.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;The notion of an independent group framing a provisioning specification is a 180-degree turn from the path SPML has taken. The specification was incubated at OASIS.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;In May, Richard Sand, CEO for Skyworth TTG and the co-chair of the revised OASIS Provisioning Services TC, told me his goal for a “SPML 3.0” would be to ignore compatibility with 2.0 and adopt only “building blocks” from the existing work.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;He said he would like to simplify some of the use cases and add some higher level ones. In addition, he favors REST over SOAP.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;But what he needs is support for a majority of the major cloud vendors – including Microsoft, Google and Amazon. None of those companies were part of the Catalyst meeting nor are they currently part of the OASIS TC.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Consensus and forward progress needs to come quickly, however.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;As one vendor told me, “We can’t defer this problem any longer.”&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Where do you stand? Should SPML be revived and revised? Or should something new be created that might better align with the rise of cloud computing?&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Follow John on &lt;a href="http://twitter.com/JohnFontana"&gt;Twitter&lt;/a&gt;  and check out                                        our Identity-Conversation &lt;a href="http://twitter.com/JohnFontana/identity-conversation"&gt;Tweet                                         list&lt;/a&gt;&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3aR7Gbm2_TQ:Lpx5Xi2jgpc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3aR7Gbm2_TQ:Lpx5Xi2jgpc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3aR7Gbm2_TQ:Lpx5Xi2jgpc:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=3aR7Gbm2_TQ:Lpx5Xi2jgpc:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/3aR7Gbm2_TQ" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.pingidentity.com/blogs/pingtalk/index.cfm/2010/8/24/Provisioning-searching-for-door-out-of-no-mans-land</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.imprivata.com/content52341.html</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/84KKG43SEgw/content52341.html" rel="alternate" type="text/html" />
    <title>Identity 360 - Imprivata: HIPAA NEWS - Survey Says Preventing HIPAA Data Breaches is the No.1 Concern in Healthcare IT</title>
    
    <updated>2010-08-24T18:06:21Z</updated>
    <source>
      <id>http://www.imprivata.com/</id>
      <author>
        <name>Identity 360 - Imprivata</name>
      </author>
      <link href="http://www.imprivata.com/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/ImprivataNews" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Updates from Imprivata.</subtitle>
      <title>Imprivata News</title>
      <updated>2010-09-02T21:03:08Z</updated>
    </source>
  <content type="html">http://hipaanews.net/archives/2010/08/18/survey-says-preventing-hipaa-data-breaches-is-the-no-1-concern-in-healthcare-it/&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=84KKG43SEgw:Oif_rA35T3s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=84KKG43SEgw:Oif_rA35T3s:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=84KKG43SEgw:Oif_rA35T3s:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=84KKG43SEgw:Oif_rA35T3s:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/84KKG43SEgw" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.imprivata.com/content52341.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blog.talkingidentity.com/?p=1014</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/1jI8TIp4qus/upcoming-webcast-on-service-oriented-security.html" rel="alternate" type="text/html" />
    <title>Nishant Kaushik - Oracle: Upcoming Webcast on Service-Oriented Security</title>
    <summary type="html">You’ve seen me blog a whole lot about Service-Oriented Security over the years; now you can also hear me talk about it. I’ll be doing a live webcast on “Service-Oriented Security: Blazing a New Trail of Innovation in Application Security” on Wednesday, August 25th (that’s tomorrow!) at 11:00 a.m. PT/2:00 p.m. ET . In it, [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;You’ve seen me blog a whole lot about Service-Oriented Security over the years; now you can also hear me talk about it. I’ll be doing a live webcast on “&lt;strong&gt;Service-Oriented Security: Blazing a New Trail of Innovation in Application Security&lt;/strong&gt;” on &lt;em&gt;Wednesday, August 25th&lt;/em&gt; (that’s tomorrow!) at &lt;em&gt;11:00 a.m. PT/2:00 p.m. ET&lt;span style="font-family: Arial,Helvetica,sans-serif; font-size: x-small;"&gt; &lt;/span&gt;&lt;/em&gt;. In it, I and my colleague Bharath Shashikumar will talk about how SOS offers a revolutionary architectural approach to efficiently develop security as discrete reusable services – resulting in faster development lifecycles, better IT agility and dramatically lower integration costs. You can get more information on the webcast &lt;a href="http://bit.ly/9soO21"&gt;here&lt;/a&gt; and register to attend for free &lt;a href="http://bit.ly/9aXzr8"&gt;here&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;p&gt;And if there are any questions you want to ask me, then ask them during the webcast, or send them my way ahead of time via &lt;a href="http://twitter.com/NishantK"&gt;twitter&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;address&gt;&lt;img alt="" class="alignnone" height="60" src="http://www.oracle.com/dm/11h1images/eseminars_170.jpg" title="Ziff-Davis Enterprise eSeminars" width="170"&gt;&lt;/img&gt;&lt;/address&gt;&#xD;
&lt;p class="tags"&gt;Tags: &lt;a href="http://blog.talkingidentity.com/tag/application-security" rel="tag"&gt;Application Security&lt;/a&gt;, &lt;a href="http://blog.talkingidentity.com/tag/application-centric-idm" rel="tag"&gt;Application-Centric IdM&lt;/a&gt;, &lt;a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag"&gt;Service-Oriented Security&lt;/a&gt;&lt;/p&gt;&#xD;
&#xD;
&#xD;
Share This:&#xD;
&#xD;
&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" id="twitter" rel="nofollow" title="Twitter"&gt;&lt;img alt="Twitter" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Bbodytext%3DYou%2527ve%2520seen%2520me%2520blog%2520a%2520whole%2520lot%2520about%2520Service-Oriented%2520Security%2520over%2520the%2520years%253B%2520now%2520you%2520can%2520also%2520hear%2520me%2520talk%2520about%2520it.%2520I%2527ll%2520be%2520doing%2520a%2520live%2520webcast%2520on%2520%2522Service-Oriented%2520Security%253A%2520Blazing%2520a%2520New%2520Trail%2520of%2520Innovation%2520in%2520Application%2520Security%2522%2520on%2520Wednesda';" id="digg" rel="nofollow" title="Digg"&gt;&lt;img alt="Digg" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Bt%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" id="facebook" rel="nofollow" title="Facebook"&gt;&lt;img alt="Facebook" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;img alt="LinkedIn" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn"&gt;&lt;/img&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" id="stumbleupon" rel="nofollow" title="StumbleUpon"&gt;&lt;img alt="StumbleUpon" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Bannotation%3DYou%2527ve%2520seen%2520me%2520blog%2520a%2520whole%2520lot%2520about%2520Service-Oriented%2520Security%2520over%2520the%2520years%253B%2520now%2520you%2520can%2520also%2520hear%2520me%2520talk%2520about%2520it.%2520I%2527ll%2520be%2520doing%2520a%2520live%2520webcast%2520on%2520%2522Service-Oriented%2520Security%253A%2520Blazing%2520a%2520New%2520Trail%2520of%2520Innovation%2520in%2520Application%2520Security%2522%2520on%2520Wednesda';" id="google" rel="nofollow" title="Google Bookmarks"&gt;&lt;img alt="Google Bookmarks" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" id="identi.ca" rel="nofollow" title="Identi.ca"&gt;&lt;img alt="Identi.ca" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Bnotes%3DYou%2527ve%2520seen%2520me%2520blog%2520a%2520whole%2520lot%2520about%2520Service-Oriented%2520Security%2520over%2520the%2520years%253B%2520now%2520you%2520can%2520also%2520hear%2520me%2520talk%2520about%2520it.%2520I%2527ll%2520be%2520doing%2520a%2520live%2520webcast%2520on%2520%2522Service-Oriented%2520Security%253A%2520Blazing%2520a%2520New%2520Trail%2520of%2520Innovation%2520in%2520Application%2520Security%2522%2520on%2520Wednesda';" id="del.icio.us" rel="nofollow" title="del.icio.us"&gt;&lt;img alt="del.icio.us" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" id="reddit" rel="nofollow" title="Reddit"&gt;&lt;img alt="Reddit" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" id="technorati" rel="nofollow" title="Technorati"&gt;&lt;img alt="Technorati" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Bh%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" id="newsvine" rel="nofollow" title="NewsVine"&gt;&lt;img alt="NewsVine" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" id="slashdot" rel="nofollow" title="Slashdot"&gt;&lt;img alt="Slashdot" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%2520Upcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" id="techmeme" rel="nofollow" title="Suggest to Techmeme via Twitter"&gt;&lt;img alt="Suggest to Techmeme via Twitter" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='mailto%3A%3Fsubject%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" id="email" rel="nofollow" title="E-mail this story to a friend!"&gt;&lt;img alt="E-mail this story to a friend!" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
&#xD;
&#xD;
&lt;br&gt;&lt;br&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=1jI8TIp4qus:tN622IBCZrQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=1jI8TIp4qus:tN622IBCZrQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=1jI8TIp4qus:tN622IBCZrQ:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=1jI8TIp4qus:tN622IBCZrQ:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/1jI8TIp4qus" height="1" width="1"/&gt;</content>
    <updated>2010-08-24T17:16:51Z</updated>
    <category term="Oracle Identity Management" />
    <category term="Application Security" />
    <category term="Application-Centric IdM" />
    <category term="Service-Oriented Security" />
    <author>
      <name>Nishant Kaushik</name>
    </author>
    <source>
      <id>http://blog.talkingidentity.com</id>
      <link href="http://blog.talkingidentity.com/feed" rel="self" type="application/atom+xml" />
      <link href="http://blog.talkingidentity.com" rel="alternate" type="text/html" />
      <subtitle>An Architect's Quest to make sense of the world of Identity and Access Management</subtitle>
      <title>Talking Identity | Nishant Kaushik's Look at the World of Identity Management</title>
      <updated>2010-08-24T17:33:24Z</updated>
    </source>
  <feedburner:origLink>http://blog.talkingidentity.com/2010/08/upcoming-webcast-on-service-oriented-security.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blog.talkingidentity.com/?p=1011</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/dbJfNdUkXdE/pushing-forward-on-standards-based-provisioning.html" rel="alternate" type="text/html" />
    <title>Nishant Kaushik - Oracle: Pushing forward on Standards-based Provisioning</title>
    <summary type="html">Lest all the recent posts about “pull”-based identity make you think that I have completely forgotten about good old “push”-based identity provisioning, here is some news on that. As I have discussed here in the past, SPML has been under a cloud in recent years, with low adoption and a litany of issues being documented. [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Lest all the recent posts about “pull”-based identity make you think that I have completely forgotten about good old “push”-based identity provisioning, here is some news on that. As &lt;a href="http://bit.ly/a6q8AX"&gt;I have discussed here&lt;/a&gt; in the past, SPML has been under a cloud in recent years, with low adoption and a litany of issues being documented. At the same time, the need for a standards-based approach has never been clearer. So something needs to be done.&lt;/p&gt;&#xD;
&lt;p&gt;This was the topic of discussion at a SIG on &lt;strong&gt;Standards-based Provisioning&lt;/strong&gt; organized by Gartner’s Mark Diodati at the recent Catalyst conference. The meeting was attended by some really smart folks in the community, and engendered a lively discussion on the future of SPML and the direction it should take. Mark has &lt;a href="http://bit.ly/dDlHhI" target="_blank"&gt;published a statement&lt;/a&gt; on the Gartner blog network that reflects the outcome of the discussion. Given the recent reboot of the &lt;a href="http://bit.ly/dghWhK" target="_blank"&gt;Provisioning Services Technical Committee&lt;/a&gt; at OASIS, this is an important document for everyone concerned to read.&lt;/p&gt;&#xD;
&lt;p&gt;One of the most important points raised during the meeting was this:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&lt;p&gt;In trying to address every possible use case, interoperable provisioning  services leveraging the SPML v2 standard became impractical. Since the  approval, few (if any) conformant implementations exist due to the  complexity of the v2 standard.&lt;/p&gt;&lt;/blockquote&gt;&#xD;
&lt;p&gt;The path to success in the standards world is based on a focused approach to solving specific use cases. No standard can be all things to all people, and with provisioning in particular, we need to recognize that there are different approaches that solve the challenge in optimal ways for their use cases (my recent assertion regarding IGF as underlying pull-based provisioning is an example). So there need to be an effort to continue refinement of SPML 2.0, making it simpler to implement and based on specific use-cases that are of interest to the community. If you have such use-cases, please consider joining the discussion within the PSTC and submitting them there. There is much that needs to be done.&lt;/p&gt;&#xD;
&lt;p&gt;And a big thank you to Mark for pulling together the SIG. It was an excellent and timely effort, one that I hope proves instrumental in accomplishing it’s goal.&lt;/p&gt;&#xD;
&lt;p class="tags"&gt;Tags: &lt;a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag"&gt;Burton Catalyst Conference&lt;/a&gt;, &lt;a href="http://blog.talkingidentity.com/tag/cat10" rel="tag"&gt;Cat10&lt;/a&gt;, &lt;a href="http://blog.talkingidentity.com/tag/provisioning" rel="tag"&gt;Provisioning&lt;/a&gt;, &lt;a href="http://blog.talkingidentity.com/tag/spml" rel="tag"&gt;SPML&lt;/a&gt;&lt;/p&gt;&#xD;
&#xD;
&#xD;
Share This:&#xD;
&#xD;
&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" id="twitter" rel="nofollow" title="Twitter"&gt;&lt;img alt="Twitter" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Bbodytext%3DLest%2520all%2520the%2520recent%2520posts%2520about%2520%2522pull%2522-based%2520identity%2520make%2520you%2520think%2520that%2520I%2520have%2520completely%2520forgotten%2520about%2520good%2520old%2520%2522push%2522-based%2520identity%2520provisioning%252C%2520here%2520is%2520some%2520news%2520on%2520that.%2520As%2520I%2520have%2520discussed%2520here%2520in%2520the%2520past%252C%2520SPML%2520has%2520been%2520under%2520a%2520cloud%2520in%2520r';" id="digg" rel="nofollow" title="Digg"&gt;&lt;img alt="Digg" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Bt%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning';" id="facebook" rel="nofollow" title="Facebook"&gt;&lt;img alt="Facebook" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;img alt="LinkedIn" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn"&gt;&lt;/img&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning';" id="stumbleupon" rel="nofollow" title="StumbleUpon"&gt;&lt;img alt="StumbleUpon" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Bannotation%3DLest%2520all%2520the%2520recent%2520posts%2520about%2520%2522pull%2522-based%2520identity%2520make%2520you%2520think%2520that%2520I%2520have%2520completely%2520forgotten%2520about%2520good%2520old%2520%2522push%2522-based%2520identity%2520provisioning%252C%2520here%2520is%2520some%2520news%2520on%2520that.%2520As%2520I%2520have%2520discussed%2520here%2520in%2520the%2520past%252C%2520SPML%2520has%2520been%2520under%2520a%2520cloud%2520in%2520r';" id="google" rel="nofollow" title="Google Bookmarks"&gt;&lt;img alt="Google Bookmarks" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" id="identi.ca" rel="nofollow" title="Identi.ca"&gt;&lt;img alt="Identi.ca" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Bnotes%3DLest%2520all%2520the%2520recent%2520posts%2520about%2520%2522pull%2522-based%2520identity%2520make%2520you%2520think%2520that%2520I%2520have%2520completely%2520forgotten%2520about%2520good%2520old%2520%2522push%2522-based%2520identity%2520provisioning%252C%2520here%2520is%2520some%2520news%2520on%2520that.%2520As%2520I%2520have%2520discussed%2520here%2520in%2520the%2520past%252C%2520SPML%2520has%2520been%2520under%2520a%2520cloud%2520in%2520r';" id="del.icio.us" rel="nofollow" title="del.icio.us"&gt;&lt;img alt="del.icio.us" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning';" id="reddit" rel="nofollow" title="Reddit"&gt;&lt;img alt="Reddit" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" id="technorati" rel="nofollow" title="Technorati"&gt;&lt;img alt="Technorati" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Bh%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning';" id="newsvine" rel="nofollow" title="NewsVine"&gt;&lt;img alt="NewsVine" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" id="slashdot" rel="nofollow" title="Slashdot"&gt;&lt;img alt="Slashdot" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%2520Pushing%2520forward%2520on%2520Standards-based%2520Provisioning';" id="techmeme" rel="nofollow" title="Suggest to Techmeme via Twitter"&gt;&lt;img alt="Suggest to Techmeme via Twitter" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
	&lt;a href="javascript:window.location='mailto%3A%3Fsubject%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" id="email" rel="nofollow" title="E-mail this story to a friend!"&gt;&lt;img alt="E-mail this story to a friend!" class="sociable-hovers" src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
&#xD;
&#xD;
&lt;br&gt;&lt;br&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dbJfNdUkXdE:DOwoHxnCIjE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dbJfNdUkXdE:DOwoHxnCIjE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dbJfNdUkXdE:DOwoHxnCIjE:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=dbJfNdUkXdE:DOwoHxnCIjE:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/dbJfNdUkXdE" height="1" width="1"/&gt;</content>
    <updated>2010-08-24T15:57:18Z</updated>
    <category term="Insight IdM" />
    <category term="Burton Catalyst Conference" />
    <category term="Cat10" />
    <category term="Provisioning" />
    <category term="SPML" />
    <author>
      <name>Nishant Kaushik</name>
    </author>
    <source>
      <id>http://blog.talkingidentity.com</id>
      <link href="http://blog.talkingidentity.com/feed" rel="self" type="application/atom+xml" />
      <link href="http://blog.talkingidentity.com" rel="alternate" type="text/html" />
      <subtitle>An Architect's Quest to make sense of the world of Identity and Access Management</subtitle>
      <title>Talking Identity | Nishant Kaushik's Look at the World of Identity Management</title>
      <updated>2010-08-24T17:33:24Z</updated>
    </source>
  <feedburner:origLink>http://blog.talkingidentity.com/2010/08/pushing-forward-on-standards-based-provisioning.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.identityblog.com/?p=1154</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/J-BdHeLY4O4/" rel="alternate" type="text/html" />
    <title>Kim Cameron - Microsoft: Non-Personal Information - like where you live?</title>
    <summary type="html">The notion that location information tied to random identifiers is not personally identifiable information is total hogwash.</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Last week I gave a presentation at &lt;a href="http://pii2010.com/"&gt;PII 2010 in Seattle&lt;/a&gt; where I tried to summarize what I had learned from my recent work on WiFi location services and identity.  During the question period  an audience member asked me to return to the slide where I recounted &lt;a href="http://www.identityblog.com/?p=1136"&gt;how I had first&lt;/a&gt; encountered Apple’s new location tracking policy:&lt;/p&gt;&#xD;
&lt;p&gt; &lt;img alt="" src="http://www.identityblog.com/wp-content/images/2010/08/iphoneloc.jpg"&gt;&lt;/img&gt;&lt;/p&gt;&#xD;
&lt;p&gt;My questioner was clearly a bit irritated with me,  Didn’t I realize that the “unique device identifier” was just a GUID - a purely random number?  It wasn’t a MAC address.  It was not personally identifying.&lt;/p&gt;&#xD;
&lt;p&gt;The question really perplexed me, since I had just shown a slide demonstrating how if you go to &lt;a href="http://www.whitepages.com/reverse_address"&gt;this well-known web site&lt;/a&gt; (for example) and enter a location you find out who lives there (I used myself as an example, and by the way, “whitepages” releases this information even though I have had an unlisted number…).&lt;/p&gt;&#xD;
&lt;p&gt;&lt;img alt="" src="http://www.identityblog.com/wp-content/images/2010/08/reverse1.JPG"&gt;&lt;/img&gt;&lt;/p&gt;&#xD;
&lt;p&gt;I pointed out the obvious:  if Apple releases your location and a GUID to a third party on multiple occasions, one location will soon stand out as being your residence… Then presto, if the third pary looks up the address in a “Reverse Address” search engine, the “random” GUID &lt;strong&gt;identifies you personally&lt;/strong&gt; forever more.  The notion that location information tied to random identifiers is not personally identifiable information is total hogwash.&lt;/p&gt;&#xD;
&lt;p&gt;My questioner then asked, “Is your problem that Apple’s privacy policy is so clear?  Do you prefer companies who don’t publish a privacy policy at all, but rather just take your information without telling you?”  A chorus of groans seemed to answer his question to everyone’s satisfaction.  But I personally found the question thought provoking.  I assume corporations publish privacy policies - even those as duplicitous as Apple’s - because they have to.  I need to learn more about why. &lt;/p&gt;&#xD;
&lt;p&gt;[Meanwhile, if you're wondering how I could possibly post my own residential address on my blog, it turns out I've moved and it is no longer my address.  Beyond that, the initial "A" in the listing above has nothing to do with my real name - it's just a mechanism I use to track who has given out my personal information.]&lt;/p&gt;&#xD;
&lt;p&gt; &lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=J-BdHeLY4O4:q7aWhE3rpOA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=J-BdHeLY4O4:q7aWhE3rpOA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=J-BdHeLY4O4:q7aWhE3rpOA:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=J-BdHeLY4O4:q7aWhE3rpOA:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/J-BdHeLY4O4" height="1" width="1"/&gt;</content>
    <updated>2010-08-24T14:56:08Z</updated>
    <category term="Digital Rights" />
    <category term="Ethics" />
    <category term="Identity" />
    <category term="Location" />
    <category term="Minimal Disclosure" />
    <category term="Privacy" />
    <category term="Wifi" />
    <author>
      <name>Kim Cameron</name>
    </author>
    <source>
      <id>http://www.identityblog.com</id>
      <link href="http://www.identityblog.com/wp-rss2.php" rel="self" type="application/atom+xml" />
      <link href="http://www.identityblog.com" rel="alternate" type="text/html" />
      <subtitle>Digital Identity And Our Future</subtitle>
      <title>Kim Cameron's Identity Weblog</title>
      <updated>2010-08-30T15:12:39Z</updated>
    </source>
  <feedburner:origLink>http://www.identityblog.com/?p=1154</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.discoveringidentity.com/2010/08/23/stuxnet-worm-hijacking-critical-infrastructure/</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/svO3VcsXC_w/" rel="alternate" type="text/html" />
    <title>Mark Dixon - Sun: Stuxnet Worm: Hijacking Critical Infrastructure</title>
    <summary type="html">CNET published a thought-provoking article last week,  about Stuxnet, a sophiscated software worm that “targets critical infrastructure companies.”  It “doesn’t just steal data, it leaves a back door that could be used to remotely and secretly control plant operations.”
This complex software is targeted not at desktop or laptop PC’s, but at industrial control systems.  It [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://news.cnet.com/8301-27080_3-20013545-245.html" target="_blank"&gt;&lt;img align="right" alt="[article image]" src="http://cacm.acm.org/system/assets/0000/3587/081310.cnet.cyberdefense.large.jpg?1281708557&amp;amp;1281708557" style="margin: 0px 0px 5px 10px; display: inline;" title="Cyberdefense"&gt;&lt;/img&gt;&lt;/a&gt;CNET published a &lt;a href="http://news.cnet.com/8301-27080_3-20013545-245.html" target="_blank"&gt;thought-provoking article&lt;/a&gt; last week,  about&lt;strong&gt;&lt;em&gt; Stuxnet&lt;/em&gt;&lt;/strong&gt;, a sophiscated software worm that “targets critical infrastructure companies.”  It “doesn’t just steal data, it leaves a back door that could be used to remotely and secretly control plant operations.”&lt;/p&gt;&#xD;
&lt;p&gt;This complex software is targeted not at desktop or laptop PC’s, but at industrial control systems.  It has infected systems particularly in Iran and India, but also companies in the US.&lt;/p&gt;&#xD;
&lt;blockquote&gt;&lt;p&gt;The malware, which made headlines &lt;a href="http://news.cnet.com/8301-27080_3-20011159-245.html"&gt;in July&lt;/a&gt;, is written to steal code and design projects from databases inside systems found to be running Siemens Simatic WinCC software used to control systems such as industrial manufacturing and utilities. The Stuxnet software also &lt;a href="http://www.symantec.com/connect/blogs/stuxnet-introduces-first-known-rootkit-scada-devices"&gt;has been found&lt;/a&gt; to upload its own encrypted code to the Programmable Logic Controllers (PLCs) that control the automation of industrial processes and which are accessed by Windows PCs. …&lt;/p&gt;&#xD;
&lt;p&gt;An attacker could use the back door to remotely do any number of things on the computer, like download files, execute processes, and delete files, but an attacker could also conceivably interfere with critical operations of a plant to do things like close valves and shut off output systems&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;The &lt;a href="http://www.ecommercetimes.com/story/70622.html?wlc=1282617648" target="_blank"&gt;eCommerce Times&lt;/a&gt; commented:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&lt;p&gt;“The Stuxnet worm, which targets industrial control systems, or "&lt;a href="http://en.wikipedia.org/wiki/SCADA"&gt;SCADA&lt;/a&gt;" systems, is one of the most sophisticated bits of digital malware security researchers have come across in a long time. Now, those researchers want to know where it came from. Was Stuxnet the product of a den of hackers working on their own accord, or did a national government somewhere in the world have a hand in its creation?&lt;/p&gt;&#xD;
&lt;p&gt;"Given the sophistication and organization behind it, we highly suspect it has nation-state involvement rather than being a tool for competitive intelligence," Roel Schouwenberg, a senior antivirus researcher with Kaspersky Lab, told TechNewsWorld.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;In a recent post, I quoted a report entitled, “&lt;a href="http://www.oe.netl.doe.gov/docs/prepare/21stepsbooklet.pdf"&gt;21 Steps to Improve Cyber Security of SCADA Networks&lt;/a&gt;,” where the US Department of Energy stressed the importance of security in control systems:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&lt;p&gt;The U.S. energy sector operates the most robust and reliable energy infrastructure in the world. This level of reliability is made possible by the extensive use of Supervisory Control and Data Acquisition (SCADA), Distributed Control System (DCS), and other control systems that enable automated control of energy production and distribution. These systems integrate a variety of distributed electronic devices and networks to help monitor and control energy flows in the electric grid and oil and gas infrastructure. &lt;/p&gt;&#xD;
&lt;p&gt;Automated control has helped to improve the productivity, flexibility, and reliability of energy systems. However, energy control systems communicate with a multitude of physically dispersed devices and various information systems that can expose energy systems to malicious cyber attacks. A successful cyber attack could compromise control systems and disrupt energy networks and the critical sectors that depend on them.&lt;/p&gt;&#xD;
&lt;p&gt;Securing control systems is a key element in protecting the Nation’s energy infrastructure. The National Research Council identified "protecting energy distribution services by improving the security of SCADA systems" as one of the 14 most important technical initiatives for making the nation safer across all critical infrastructures.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;By targeting systems that control vital parts of a nation’s critical infrastructure, this worm is an example of how increasingly sophisticated technology can be used as an offensive weapon.  Lots of questions still exist about this specific worm, but it really illustrates how we must be concerned about the security of all computer-based systems, not just those in data centers.&lt;/p&gt;&#xD;
&lt;p&gt;Somehow, this causes more concern in my paranoid mind than &lt;a href="http://www.discoveringidentity.com/2010/08/20/security-vulnerabilities-in-popular-platforms/" target="_blank"&gt;vulnerabilities in my iPhone&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:f7995d00-bd73-46cc-bdb9-9de71ea83f26" style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px;"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Information+Security" rel="tag"&gt;Information Security&lt;/a&gt;,&lt;a href="http://technorati.com/tags/SCADA" rel="tag"&gt;SCADA&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Worm" rel="tag"&gt;Worm&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Malware" rel="tag"&gt;Malware&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Critical+Infrastructure+Protection" rel="tag"&gt;Critical Infrastructure Protection&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=svO3VcsXC_w:kstgltCuroM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=svO3VcsXC_w:kstgltCuroM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=svO3VcsXC_w:kstgltCuroM:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=svO3VcsXC_w:kstgltCuroM:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/svO3VcsXC_w" height="1" width="1"/&gt;</content>
    <updated>2010-08-24T03:29:32Z</updated>
    <category term="Information Security" />
    <category term="Critical Infrastructure Protection" />
    <category term="Malware" />
    <category term="SCADA" />
    <category term="Worm" />
    <author>
      <name>Mark Dixon</name>
    </author>
    <source>
      <id>http://www.discoveringidentity.com</id>
      <link href="http://www.discoveringidentity.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.discoveringidentity.com" rel="alternate" type="text/html" />
      <subtitle>Just another WordPress weblog</subtitle>
      <title>Discovering Identity</title>
      <updated>2010-08-26T22:02:24Z</updated>
    </source>
  <feedburner:origLink>http://www.discoveringidentity.com/2010/08/23/stuxnet-worm-hijacking-critical-infrastructure/</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://blogs.msdn.com/b/vbertocci/archive/2010/08/23/selfsts-when-you-need-a-saml-token-now-right-now.aspx</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/Uvk20AkjTaY/selfsts-when-you-need-a-saml-token-now-right-now.aspx" rel="alternate" type="text/html" />
    <title xml:lang="en-US">Vittorio Bertocci - Microsoft: SelfSTS: when you need a SAML token NOW, RIGHT NOW</title>
    <content type="html" xml:lang="en-US">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;div class="wlWriterHeaderFooter" style="float: right; margin: 0px; padding: 0px 0px 4px 8px;"&gt;&lt;/div&gt;&lt;p&gt;A little new toy for you claims-based identity aficionados to play with! Available &lt;a href="http://bit.ly/c76W7P"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;img alt="systray" border="0" height="149" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/7026.systray_5F00_76483EE6.png" style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px;" title="systray" width="293"&gt;&lt;/img&gt; &lt;/p&gt;  &lt;p&gt;Tokens are the currency on the identity market. Any identity solution you develop will require you to acquire &amp;amp; consume tokens (&amp;amp; associated claims) at some point.    &lt;br&gt;ADFS2 is super-easy to install, but does require Active Directory and as a result it is not always readily available at development time, especially if you are not targeting a departmental application or a classic federation scenario. And even in that case, you don’t always have a test endpoint set up. When you test a payment service you don’t move real money right away, there’s no reason to do the same with identities: do you have a test account for all the role values you want to test?     &lt;br&gt;The standard solution, one that has been used big time also in out training kit and other examples, is creating a custom STS. Almost three years have passed since &lt;a href="http://blogs.msdn.com/b/vbertocci/archive/2007/11/18/adfs-2-teched-breakout-session-wrapup.aspx"&gt;the very first preview we gave in Barcelona of what became WIF&lt;/a&gt;, and I still remember &lt;a href="http://idunno.org/"&gt;Barry&lt;/a&gt; in the first row facepalming at the sight of one STS built in under 10 minutes. Well, with the WIF SDK tooling now that happens in &lt;em&gt;seconds&lt;/em&gt; (or less, if your machine has an SSD ;-)) hence it’s incredibly easy to set up a test STS. However, after you’ve done that hundreds of times (and believe me, I did) even that can start to wear you off; writing new fed metadata every time you change something takes time; and above all, creating many custom STSes can litter your IIS and certificates stores if you are not disciplined in keeping things clean (I’m not). Also, if you are packing your solution for others (in my case for making labs and sample code available to you, more commonly you need to do that when something is not working and you want the help of others) you need to include some setup, which has requirements (IIS, certificate stores, etc) and impact on the target machine.&lt;/p&gt;  &lt;p&gt;Well, enter &lt;a href="http://bit.ly/c76W7P"&gt;SelfSTS&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://bit.ly/c76W7P"&gt;SelfSTS&lt;/a&gt; is a little winform app which will not deny a token to anyone. It’s an EXE which exposes one endpoint for a passive STS, and one endpoint with the corresponding fed metadata document. The claim types and values are taken from a config section, which can be edited directly in the &lt;a href="http://bit.ly/c76W7P"&gt;SelfSTS&lt;/a&gt; UI. The tokens are signed with simple self-signed certificates from PFX files, the certificates tore remains untouched. You can even create new self-signed certs with a simple UI, instead of risking to conjure mystical beasts by mistake if you write the wrong makecert parameter.&lt;/p&gt;  &lt;p&gt;With &lt;a href="http://bit.ly/c76W7P"&gt;SelfSTS&lt;/a&gt; you can produce test input for your apps very easily: you start it, point the Add STS Wizard to to the metadata endpoint, and hit F5. If you want the token to have a different claim type or value, you just go to the claims editing UI and change things accordingly. If you need more than one STS at once, you just copy the exe, the config and the PFX certificate you want to another folder, you change the port on which the STS is listening and you fire it up; here you go, you can now do all the home realm discovery experiments you want. I already heard people considering to use this for testing SharePoint even in situations in which you don’t have the WIF SDK installed: that’s right, it just requires the WIF runtime! I am sure you’ll come out with your own creative ways to use that. I am even considering using it instead of many of the custom STSes in the next drops of the training kit…&lt;/p&gt;  &lt;p&gt;I feel silly even at having to say that, but for due diligence… &lt;strong&gt;&lt;font color="#ff0000"&gt;SelfSTS is obviously ABSOLUTELY INSECURE&lt;/font&gt;&lt;/strong&gt;. It is just a test toy, and as such it should be used. It gives tokens without even checking who the caller is, and it does that on plain HTTP. It signs tokens with self-signed certificates, and it stores the associated passwords in the clean in the web config. It is the very essence of insecurity itself. Do not use it for anything else than testing applications at development time, on non production systems. &lt;/p&gt;  &lt;p&gt;Below there’s an online version of the readme we packed &lt;a href="http://bit.ly/c76W7P"&gt;in the sample&lt;/a&gt;. Have fun!&lt;/p&gt;  &lt;h3&gt;Overview&lt;/h3&gt;  &lt;p&gt;Securing web applications with Windows Identity Foundation require the use of an identity provider, which may not always be available at development or test time. The standard solution to the issue is creating a test STS. The WIF SDK templates make it very easy to create a minimal STS; however it requires you to write code for customizing the claims it emits and, if you want to be able to use the WIF tooling to its fullest, customize the metadata generation code. What’s worse, you need to repeat the process for every new application. &lt;/p&gt;  &lt;p&gt;&lt;b&gt;SelfSTS&lt;/b&gt; is a quick &amp;amp; dirty utility which provides a minimal WS-Federation STS endpoint and its associated federation metadata document. You can use SelfSTS for testing your web applications by simply pointing WIF’s Add STS Wizard to its metadata endpoint.&lt;/p&gt;  &lt;p&gt;&lt;img alt="selfsts1" border="0" height="405" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/7345.selfsts1_5F00_43783872.png" style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px;" title="selfsts1" width="300"&gt;&lt;/img&gt;  &lt;br&gt;&lt;strong&gt;Figure 1      &lt;br&gt;&lt;/strong&gt;&lt;em&gt;The main SelfSTS screen &lt;/em&gt;&lt;/p&gt;  &lt;p&gt;SelfSTS is a simple .EXE file, which does not require IIS and never touches the certificates store. There is no installation required, you just need the .EXE file itself, its configuration file and the PFX file of the certificate you want to use for signing tokens. Its only requirements are .NET 4.0, the WIF runtime and (if you want to generate extra certificates) the Windows SDK.&lt;/p&gt;  &lt;p&gt;SelfSTS provides a simple UI for easily editing the types and values of the claims it will emit: the metadata document will be dynamically updated accordingly. &lt;/p&gt;  &lt;p&gt;SelfSTS offers a UI for simplified creation of self-signed X.509 certificates, which you can use if you need to use a signing certificate with a specific subject or if for some reason you cannot use the certificate provided out of the box.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;WARNING&lt;/b&gt;: &lt;b&gt;&lt;i&gt;SelfSTS is not, and is not meant to be, secure&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;by any measure&lt;/i&gt;&lt;/b&gt;. All traffic takes place in the clear, on HTTP; requests are automatically accepted regardless of who the caller is; certificates are handled from the file system, without specific passwords protections. This is all by design, SelfSTS is just meant to help you to test web applications by providing you with an easy way of obtaining tokens via WS-Federation.&lt;/p&gt;  &lt;p&gt; &lt;/p&gt;  &lt;h3&gt;Using SelfSTS&lt;/h3&gt;  &lt;p&gt;The simplest way of using SelfSTS is launching the .EXE, hitting the start button (marked as (a) in figure 2), using the (e) button for copying to the clipboard the metadata address, and pasting that address in the Add STS Reference wizard in your web application. Just hit F5 and you’ll get your token right away: SelfSTS does not attempt any form of authentication.&lt;/p&gt;  &lt;p&gt; &lt;img alt="image" border="0" height="311" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/3323.image_5F00_34CD8C8D.png" style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px;" title="image" width="508"&gt;&lt;/img&gt;     &lt;br&gt;&lt;strong&gt;Figure 2      &lt;br&gt;&lt;/strong&gt;&lt;em&gt;The elements of the main SelfSTS UI and their function&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;The button Hide (f) will minimize SelfSTS to the system tray, but the endpoint will remain active until you don’t hit the button Stop again.&lt;/p&gt;  &lt;p&gt;If you want to configure things by hand, you can get the endpoint address in the clipboard via (d). The details of the signing certificate are shown on the UI, but remember that the certificate itself is not present in the store.&lt;/p&gt;  &lt;p&gt; &lt;/p&gt;  &lt;h4&gt;Editing Claims&lt;/h4&gt;  &lt;p&gt;You can easily change the claim types and values issued by SelfSTS.&lt;/p&gt;  &lt;p&gt;&lt;img alt="image" border="0" height="408" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/1256.image_5F00_689582DE.png" style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px;" title="image" width="624"&gt;&lt;/img&gt;  &lt;br&gt;&lt;strong&gt;Figure 3      &lt;br&gt;&lt;/strong&gt;&lt;em&gt;The Edit Claims Dialog&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Clicking on (b) from Figure 2 opens the dialog shown in Figure 3.&lt;/p&gt;  &lt;p&gt;You can edit existing claims in place through (a), (b) and (c). (a) is a dropdown populated with all the claim types which come out of the box with WIF; however you can explicitly type in (a) an arbitrary URI if you need to define a custom claim.&lt;/p&gt;  &lt;p&gt;If you want to delete a claim entry you can just press on the corresponding X button (d).&lt;/p&gt;  &lt;p&gt;You can add a new entry using the button add (e): of course you can have as many instances of the same time as you want (for example, you will often have multiple entries with the Group claim type).&lt;/p&gt;  &lt;p&gt;If you hit Save the current configuration will be committed to the config file of SelfSTS. Please consider that SelfSTS does not make a lot of validation checks, hence if you leave things in messed state you may have to go to the config and fix things manually afterwards.&lt;/p&gt;  &lt;p&gt;If you hit Cancel you’ll be back to the main UI, and all the changes will be lost.&lt;/p&gt;  &lt;p&gt; &lt;/p&gt;  &lt;h4&gt;Generating a New Certificate&lt;/h4&gt;  &lt;p&gt;SelfSTS comes with its own default certificate file. However there will be times in which you will want to use a different certificate, for example if there is a specific subject you want to assign to the issuer or if you need to simulate multiple issuers.&lt;/p&gt;  &lt;p&gt;SelfSTS offers you a wrapper on top of MakeCert and similar utilities, allowing you to easily create a new self-signed certificate.&lt;/p&gt;  &lt;p&gt;&lt;img alt="image" border="0" height="213" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/7851.image_5F00_525F678C.png" style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px;" title="image" width="410"&gt;&lt;/img&gt;  &lt;br&gt;&lt;strong&gt;Figure 4      &lt;br&gt;&lt;/strong&gt;&lt;em&gt;The New Certificate Generation Dialog&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;One interesting side effect of generating a PFX is that the underlying utilities will prompt you for the certificate password multiple times, as shown in Figure 5. Make sure you always use the same password!&lt;/p&gt;  &lt;p&gt;&lt;img alt="image" border="0" height="542" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-26-94-metablogapi/4718.image_5F00_58A63E1A.png" style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px;" title="image" width="376"&gt;&lt;/img&gt;  &lt;br&gt;&lt;strong&gt;Figure 5      &lt;br&gt;&lt;/strong&gt;&lt;em&gt;Creating a new certificate will result in multiple password prompts&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Once the certificate generation is done, SelfSTS changes its config accordingly and will use the new certificate for signing form now on. The certificate password is saved in clear in the config. &lt;/p&gt;  &lt;p&gt;&lt;b&gt;WARNING: &lt;/b&gt;Needless to say, this is all astonishingly insecure. SelfSTS is not meant to provide a token securely, or to have access to certificates actually in use for business functions. NEVER use a certificate that has actual business uses with SelfSTS.&lt;/p&gt;  &lt;p&gt; &lt;/p&gt;  &lt;h3&gt;SelfSTS Configuration Section&lt;/h3&gt;  &lt;p&gt;The SelfSTS UI is largely an editor for the SelfSTS custom config section. There are things you can do only by touching the config directly.&lt;/p&gt;  &lt;pre class="code"&gt;&lt;span style="color: blue;"&gt;&amp;lt;&lt;/span&gt;&lt;span style="color: #a31515;"&gt;SelfSTSSettings &lt;/span&gt;&lt;span style="color: red;"&gt;port&lt;/span&gt;&lt;span style="color: blue;"&gt;="8000"&#xD;
                 &lt;/span&gt;&lt;span style="color: red;"&gt;signingcertificate&lt;/span&gt;&lt;span style="color: blue;"&gt;="SelfSTS.pfx"&#xD;
                 &lt;/span&gt;&lt;span style="color: red;"&gt;signingcertificatepassword&lt;/span&gt;&lt;span style="color: blue;"&gt;="Passw0rd!"&#xD;
                 &lt;/span&gt;&lt;span style="color: red;"&gt;issuername&lt;/span&gt;&lt;span style="color: blue;"&gt;="SelfSTS"&amp;gt;&#xD;
  &amp;lt;&lt;/span&gt;&lt;span style="color: #a31515;"&gt;claims&lt;/span&gt;&lt;span style="color: blue;"&gt;&amp;gt;&#xD;
    &amp;lt;&lt;/span&gt;&lt;span style="color: #a31515;"&gt;clear &lt;/span&gt;&lt;span style="color: blue;"&gt;/&amp;gt;&#xD;
    &amp;lt;&lt;/span&gt;&lt;span style="color: #a31515;"&gt;add &lt;/span&gt;&lt;span style="color: red;"&gt;type&lt;/span&gt;&lt;span style="color: blue;"&gt;="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"          &lt;/span&gt;&lt;span style="color: red;"&gt;displayname&lt;/span&gt;&lt;span style="color: blue;"&gt;="Email Address" &lt;/span&gt;&lt;span style="color: red;"&gt;value&lt;/span&gt;&lt;span style="color: blue;"&gt;="test@company.com" /&amp;gt;&#xD;
    &amp;lt;&lt;/span&gt;&lt;span style="color: #a31515;"&gt;add &lt;/span&gt;&lt;span style="color: red;"&gt;type&lt;/span&gt;&lt;span style="color: blue;"&gt;="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname"          &lt;/span&gt;&lt;span style="color: red;"&gt;displayname&lt;/span&gt;&lt;span style="color: blue;"&gt;="Given name" &lt;/span&gt;&lt;span style="color: red;"&gt;value&lt;/span&gt;&lt;span style="color: blue;"&gt;="Joe" /&amp;gt;&#xD;
    &amp;lt;&lt;/span&gt;&lt;span style="color: #a31515;"&gt;add &lt;/span&gt;&lt;span style="color: red;"&gt;type&lt;/span&gt;&lt;span style="color: blue;"&gt;="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname"          &lt;/span&gt;&lt;span style="color: red;"&gt;displayname&lt;/span&gt;&lt;span style="color: blue;"&gt;="Surname" &lt;/span&gt;&lt;span style="color: red;"&gt;value&lt;/span&gt;&lt;span style="color: blue;"&gt;="Doe" /&amp;gt;&#xD;
    &amp;lt;&lt;/span&gt;&lt;span style="color: #a31515;"&gt;add &lt;/span&gt;&lt;span style="color: red;"&gt;type&lt;/span&gt;&lt;span style="color: blue;"&gt;=http://schemas.xmlsoap.org/ws/2005/05/identity/claims/otherphone         &lt;/span&gt;&lt;span style="color: red;"&gt;displayname&lt;/span&gt;&lt;span style="color: blue;"&gt;="Other Phone" &lt;/span&gt;&lt;span style="color: red;"&gt;value&lt;/span&gt;&lt;span style="color: blue;"&gt;="555-5555-5555" /&amp;gt;&#xD;
    &amp;lt;&lt;/span&gt;&lt;span style="color: #a31515;"&gt;add &lt;/span&gt;&lt;span style="color: red;"&gt;type&lt;/span&gt;&lt;span style="color: blue;"&gt;="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name"          &lt;/span&gt;&lt;span style="color: red;"&gt;displayname&lt;/span&gt;&lt;span style="color: blue;"&gt;="Name" &lt;/span&gt;&lt;span style="color: red;"&gt;value&lt;/span&gt;&lt;span style="color: blue;"&gt;="joe" /&amp;gt;&#xD;
    &amp;lt;&lt;/span&gt;&lt;span style="color: #a31515;"&gt;add &lt;/span&gt;&lt;span style="color: red;"&gt;type&lt;/span&gt;&lt;span style="color: blue;"&gt;="http://schemas.xmlsoap.org/claims/Group" &#xD;
         &lt;/span&gt;&lt;span style="color: red;"&gt;displayname&lt;/span&gt;&lt;span style="color: blue;"&gt;="Group" &lt;/span&gt;&lt;span style="color: red;"&gt;value&lt;/span&gt;&lt;span style="color: blue;"&gt;="Sales" /&amp;gt;&#xD;
  &amp;lt;/&lt;/span&gt;&lt;span style="color: #a31515;"&gt;claims&lt;/span&gt;&lt;span style="color: blue;"&gt;&amp;gt;&#xD;
&amp;lt;/&lt;/span&gt;&lt;span style="color: #a31515;"&gt;SelfSTSSettings&lt;/span&gt;&lt;span style="color: blue;"&gt;&amp;gt;&#xD;
&lt;/span&gt;&lt;/pre&gt;&#xD;
&#xD;
&lt;p&gt;The config format is very straightforward. &#xD;
  &lt;br&gt;You might want to edit the config directly if you want more than one instance of SelfSTS to run at the same time (in which case you can just copy the exe and the config in a new folder, and edit the port value to avoid collisions). You might also want to edit the config for pointing to a certificate you already have as opposed to the default or newly generated ones (NEVER use a certificate you are using in production or that has any business value).&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;Finally, sometimes you may end up in a messed state when using the UI (say if the certificate generation fails at mid-operation) and you may come here to fix the values before being able to restart SelfSTS.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt; &lt;/p&gt;&#xD;
&#xD;
&lt;h3&gt;Summary&lt;/h3&gt;&#xD;
&#xD;
&lt;p&gt;SelfSTS can help you to test your web application by providing a WS-Federation endpoint readily available and with little/no infrastructure requirements. Please use it only in test and dev environments and exclusively with self-issued certificates. &#xD;
  &lt;br&gt;SelfSTS will help you to experiment with WIF and claims-based identity without worrying about finding a token source to test against. Have fun!&lt;/p&gt;&#xD;
&#xD;
&lt;h3&gt;&lt;/h3&gt;&#xD;
&lt;span style="color: blue;"&gt;&lt;a href="http://11011.net/software/vspaste"&gt;&lt;/a&gt;&lt;/span&gt;&lt;div style="clear: both;"&gt;&lt;/div&gt;&lt;img height="1" src="http://blogs.msdn.com/aggbug.aspx?PostID=10053369" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Uvk20AkjTaY:HfuaAdWzPYY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Uvk20AkjTaY:HfuaAdWzPYY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Uvk20AkjTaY:HfuaAdWzPYY:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=Uvk20AkjTaY:HfuaAdWzPYY:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/Uvk20AkjTaY" height="1" width="1"/&gt;</content>
    <updated>2010-08-23T23:15:06Z</updated>
    <published>2010-08-23T23:15:06Z</published>
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Wild+Ideas/" term="Wild Ideas" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Identity/" term="Identity" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/Windows+Identity+Foundation/" term="Windows Identity Foundation" />
    <category scheme="http://blogs.msdn.com/b/vbertocci/archive/tags/WIF/" term="WIF" />
    <author>
      <name>vibro</name>
      <uri>http://blogs.msdn.com/members/vibro/</uri>
    </author>
    <source>
      <id>http://blogs.msdn.com/b/vbertocci/atom.aspx</id>
      <link href="http://blogs.msdn.com/b/vbertocci/" rel="alternate" type="text/html" />
      <link href="http://blogs.msdn.com/b/vbertocci/atom.aspx" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Scatter thoughts</subtitle>
      <title xml:lang="en-US">Vibro.NET</title>
      <updated>2010-05-11T17:27:14Z</updated>
    </source>
  <feedburner:origLink>http://blogs.msdn.com/b/vbertocci/archive/2010/08/23/selfsts-when-you-need-a-saml-token-now-right-now.aspx</feedburner:origLink></entry>

  <entry xml:lang="en-us">
    <id>http://blog.beuchelt.org/PermaLink,guid,d0895686-e935-4e7f-8bc3-03bbd3a0f963.aspx</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/1jGZWjh4iro/An+Annoying+Neverending+Story+REST+Vs+SOAP.aspx" rel="alternate" type="text/html" />
    <link href="http://creativecommons.org/licenses/by/2.5/" rel="license" />
    <title>Gerry Beuchelt - MITRE: An annoying Neverending Story: REST vs. SOAP</title>
    
    <updated>2010-08-23T21:27:45Z</updated>
    <category term="General" />
    <category term="Web Services" /><feedburner:origlink>http://blog.beuchelt.org/2010/08/23/An+Annoying+Neverending+Story+REST+Vs+SOAP.aspx</feedburner:origlink>
    <author>
      <name>Gerald Beuchelt</name>
    </author>
    <source>
      <id>http://blog.beuchelt.org/</id>
      <logo>http://clustrmaps.com/counter/index2.php?url=http://blog.beuchelt.com</logo>
      <author>
        <name>Gerry Beuchelt - MITRE</name>
        <email>work@beuchelt.com</email>
      </author>
      <link href="http://blog.beuchelt.org/" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/WebServicesContraptions" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <rights>Gerald Beuchelt</rights>
      <title>Web Services Contraptions</title>
      <updated>2010-08-30T19:32:56Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&#xD;
Who does not know and dread the recurring discussion of a topic long thought dead?&#xD;
The most egregious one lately was a discussion about the applicability of RFC 2119&#xD;
to a particular standard I was working on (to protect the innocent I will not disclose&#xD;
the name of the SDO) - the last time I had a discussion about the meaning of "SHOULD"&#xD;
was about 11 years ago... sigh!&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
But this is not the reason for my current urge to vent - a bug long thought dead is&#xD;
reappearing once more: the old discussion about REST vs. SOAP. It is really annoying&#xD;
for two reasons. Firstly, it is settled - both have their place, and pitting them&#xD;
against each other is pointless. But secondly, posing the question of "Is SOAP or&#xD;
REST better?" is - to paraphrase &lt;a href="http://www.imdb.com/title/tt0104952/quotes?qt0404590"&gt;Mona&#xD;
Lisa Vito&lt;/a&gt; - a bu****it question. &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
Representational State Transfer (REST) is an architectural style, i.e. a general approach&#xD;
on how to design distributed computing architecture. While it was initially described&#xD;
by Roy Fielding using HTTP, and also uses constraints familiar from the web, it is&#xD;
not tied to a particular technology. &#xD;
&lt;br&gt;&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
The Simple Object Access Protocol (SOAP) is - in contrast - a specific technology;&#xD;
more precisely an XML based protocol designed to transport data across a variety of&#xD;
different underlying transports. In real-world deployments it often uses HTTP (actually&#xD;
almost exclusively its POST method) as underlying transport for the SOAP Infoset.&#xD;
The architectural style used by many (if not most) SOAP designs is best captured by&#xD;
describing it as remote procedure call (RPC) oriented [1]. &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
So a correct (in the sense of "apples to apples") comparison would align itself along&#xD;
the lines of comparing &lt;i&gt;HTTP web service using an RESTful architectural style&lt;/i&gt; with &lt;i&gt;SOAP&#xD;
web services using an RPC-based architectural style&lt;/i&gt;. A simple, incomplete table&#xD;
might look like this: &#xD;
&lt;br&gt;&lt;/p&gt;&#xD;
        &lt;table border="1" cellpadding="1" cellspacing="1" style="width: 750px; height: 123px;"&gt;&#xD;
          &lt;tbody&gt;&#xD;
            &lt;tr&gt;&#xD;
              &lt;th scope="col"&gt;Architectural&lt;br&gt;&#xD;
Style&lt;br&gt;&lt;/th&gt;&#xD;
              &lt;th scope="col"&gt;&#xD;
RPC&lt;br&gt;&lt;/th&gt;&#xD;
              &lt;th scope="col"&gt;&#xD;
REST  &#xD;
&lt;/th&gt;&#xD;
            &lt;/tr&gt;&#xD;
            &lt;tr&gt;&#xD;
              &lt;td&gt;&#xD;
Commonly used protocol&lt;br&gt;&lt;/td&gt;&#xD;
              &lt;td&gt;&#xD;
SOAP over HTTP/POST&lt;br&gt;&lt;/td&gt;&#xD;
              &lt;td&gt;&#xD;
HTTP&lt;br&gt;&lt;/td&gt;&#xD;
            &lt;/tr&gt;&#xD;
            &lt;tr&gt;&#xD;
              &lt;td&gt;&#xD;
Common payload&lt;br&gt;&lt;/td&gt;&#xD;
              &lt;td&gt;&#xD;
XML&lt;br&gt;&lt;/td&gt;&#xD;
              &lt;td&gt;&#xD;
Any Internet Media TYpe&lt;br&gt;&lt;/td&gt;&#xD;
            &lt;/tr&gt;&#xD;
            &lt;tr&gt;&#xD;
              &lt;td&gt;&#xD;
Number of methods/verbs&lt;br&gt;&lt;/td&gt;&#xD;
              &lt;td&gt;&#xD;
many&lt;br&gt;&lt;/td&gt;&#xD;
              &lt;td&gt;&#xD;
four (PUT, GET, POST, DELETE)&lt;br&gt;&lt;/td&gt;&#xD;
            &lt;/tr&gt;&#xD;
            &lt;tr&gt;&#xD;
              &lt;td&gt;&#xD;
Scalability technology&lt;br&gt;&lt;/td&gt;&#xD;
              &lt;td&gt;&#xD;
ESB&lt;br&gt;&lt;/td&gt;&#xD;
              &lt;td&gt;&#xD;
Load balancer&lt;br&gt;&lt;/td&gt;&#xD;
            &lt;/tr&gt;&#xD;
          &lt;/tbody&gt;&#xD;
        &lt;/table&gt;&#xD;
        &lt;p&gt;&#xD;
That's it - rant over. &#xD;
&lt;br&gt;&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
          &lt;br&gt;&#xD;
        &lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
[1] Note that while SOAP operates typically in two different modes (rpc/encoded and&#xD;
doc/literal), these have nothing to do with the architectural style of the distributed&#xD;
design. &#xD;
&lt;br&gt;&lt;/p&gt;&#xD;
        &lt;img height="0" src="http://blog.beuchelt.org/aggbug.ashx?id=d0895686-e935-4e7f-8bc3-03bbd3a0f963" width="0"&gt;&lt;/img&gt;&#xD;
      &#xD;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/FuZUH7_JBWsF-99yZXf4SqN6Ji0/0/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/FuZUH7_JBWsF-99yZXf4SqN6Ji0/0/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a href="http://feedads.g.doubleclick.net/~a/FuZUH7_JBWsF-99yZXf4SqN6Ji0/1/da"&gt;&lt;img border="0" ismap="true" src="http://feedads.g.doubleclick.net/~a/FuZUH7_JBWsF-99yZXf4SqN6Ji0/1/di"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/WebServicesContraptions/~4/Kd8iXO_PzA4" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=1jGZWjh4iro:YIHl0mtX2Jc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=1jGZWjh4iro:YIHl0mtX2Jc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=1jGZWjh4iro:YIHl0mtX2Jc:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=1jGZWjh4iro:YIHl0mtX2Jc:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/1jGZWjh4iro" height="1" width="1"/&gt;</content><feedburner:origLink>http://feedproxy.google.com/~r/WebServicesContraptions/~3/Kd8iXO_PzA4/An+Annoying+Neverending+Story+REST+Vs+SOAP.aspx</feedburner:origLink></entry>

  <entry>
    <id>tag:blogs.oracle.com,2010:/mwilcox//68.21586</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/VyoDBt6sefQ/what_to_do_when_you_cannot_log.html" rel="alternate" type="text/html" />
    <title>Mark Wilcox - Oracle: What To Do When You Cannot Login to Oracle Directory Server Manager (ODSM)</title>
    <summary type="html">By default during an ODSM install Weblogic will configure the managed node that is running ODSM so it's only able to accept incoming connections from browsers running on the same machine as Weblogic. Assuming that's not the behavior you want...</summary>
    <content type="html" xml:lang="en">&lt;div class="posterous_autopost"&gt;By default during an ODSM install Weblogic will configure the managed node that is running ODSM so it's only able to accept incoming connections from browsers running on the same machine as Weblogic. &lt;p&gt;&lt;/p&gt; Assuming that's not the behavior you want (usually expressed by "Why can't I get to ODSM from my laptop or desktop") here is how to fix it: &lt;p&gt;&lt;/p&gt; Go to weblogic console( &lt;a href="http://emservenamer:7001/console)"&gt;http://emservenamer:7001/console)&lt;/a&gt;. &lt;p&gt;&lt;/p&gt; Go to wls_ods1 (make sure it's running). &lt;p&gt;&lt;/p&gt; Make sure the field listen address is empty (you'll need to click lock &amp;amp; edit, then edit, then save). &lt;p&gt;&lt;/p&gt; Restart the wls_ods1 if weblogic console doesn't do this for you.      &lt;p style="font-size: 10px;"&gt;  &lt;a href="http://posterous.com"&gt;Posted via email&lt;/a&gt;   from &lt;a href="http://mewldap.posterous.com/what-to-do-when-you-cannot-login-to-oracle-di"&gt;Virtual Identity Dialogue&lt;/a&gt;  &lt;/p&gt;  &lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VyoDBt6sefQ:VzlM16w9Qc0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VyoDBt6sefQ:VzlM16w9Qc0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VyoDBt6sefQ:VzlM16w9Qc0:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=VyoDBt6sefQ:VzlM16w9Qc0:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/VyoDBt6sefQ" height="1" width="1"/&gt;</content>
    <updated>2010-08-23T21:15:34Z</updated>
    <published>2010-08-23T21:15:34Z</published>
    <author>
      <name>mark.wilcox</name>
    </author>
    <source>
      <id>tag:blogs.oracle.com,2010:/mwilcox//68</id>
      <link href="http://blogs.oracle.com/mwilcox/" rel="alternate" type="text/html" />
      <link href="http://blogs.oracle.com/mwilcox/xml/rss.xml" rel="self" type="application/atom+xml" />
      <title>Virtual Identity Dialogue</title>
      <updated>2010-09-02T03:44:47Z</updated>
    </source>
  <feedburner:origLink>http://blogs.oracle.com/mwilcox/2010/08/what_to_do_when_you_cannot_log.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://storm.alert.sk/blog/2010/08/23/Identity-Garbage</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/vCgSgOuB0tA/Identity-Garbage" rel="alternate" type="text/html" />
    <title>Radovan Semančík - nLight: Identity Garbage</title>
    
    <updated>2010-08-23T21:09:33Z</updated>
    <category term="/identity/" />
    <source>
      <id>http://storm.alert.sk/blog</id>
      <logo>http://storm.alert.sk/favicon.png</logo>
      <author>
        <name>Radovan Semančík</name>
      </author>
      <link href="http://storm.alert.sk/blog" rel="alternate" type="text/html" />
      <link href="http://storm.alert.sk/blog/index.rss" rel="self" type="application/rss+xml" />
      <subtitle>Radovan Semančík's Weblog</subtitle>
      <title>Storm Alert</title>
      <updated>2010-08-23T21:09:33Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;img class="blogPic" src="http://storm.alert.sk/gfx/clipart/pict0041-out.jpg"&gt;&lt;/img&gt;&#xD;
&lt;p&gt;&#xD;
Recent &lt;a href="http://blog.talkingidentity.com/2010/08/push-vs-pull-in-identity-management.html"&gt;discussions&lt;/a&gt; are about whether push or pull is the right model for future identity management. &lt;a href="http://blogs.gartner.com/mark-diodati/2010/08/20/consensus-on-the-future-of-standards-based-provisioning-and-spml"&gt;Unpractical standards&lt;/a&gt; are being revived. Everybody discussing the technology, the future, the visions. There is almost no discussion about the most difficult current problem of identity management: data.&#xD;
&lt;/p&gt;&#xD;
&lt;p&gt;&#xD;
There is (at least) one critical problem with implementation of single sign-on, identity federation, provisioning to the cloud and other fancy buzzwords. The problem is user database. It is not that difficult to deliver the information that &lt;i&gt;someone should have access somewhere&lt;/i&gt; using whatever push, pull, standard or proprietary method - as long as you have that information. The reality is that enterprises does not have that information in a usable form. It is almost always distributed in several data stores, usually provided in incompatible formats, it is often inconsistent and sometimes even contradictory. And it is far from complete. Many provisioning cases are solved by non-algorithmic methods, e.g. manager or security officer deciding whether the request "looks valid enough" to be approved. The current situation is best described as &lt;i&gt;semi-organized chaos&lt;/i&gt;.&#xD;
&lt;/p&gt;&#xD;
&lt;p&gt;&#xD;
How could anyone build an automated, Internet-scale, cloud-enabled and standards-based identity management mechanism on top of that? Hardly. Such project will most likely fail. But it will waste a lot of time and money before it fails.&#xD;
&lt;/p&gt;&#xD;
&lt;p&gt;&#xD;
The first step is to consolidate the data. Build a consistent user database, align policies, design business processes that can support 80% of cases with 20% of effort. It is naïve to expect that everything could be automated, therefore prepare for a reasonable amount of exceptions and human interactions from the very beginning. Single sign-on, identity federation, support for the cloud (whether push or pull) and even the standards will not provide any considerable help in that. It is mostly manual work of security staff, business people and engineers that is needed.&#xD;
&lt;/p&gt;&#xD;
&lt;p&gt;&#xD;
What can help is a well-designed and well-deployed provisioning system. In contrary to the popular beliefs the provisioning system is not really about provisioning. Yes, provisioning is a important part of the system, but other aspects are in fact much more important. Provisioning system can take data from several sources, covert them to a common format and merge them. Therefore it can create a unified database. Provisioning system can compare data among several system, correlating them, therefore detecting the inconsistencies. Provisioning system supports workflow and human interaction to clean up the data and supplement missing information. Both during initial migration and (most importantly) during the day-to-day operation. &#xD;
&lt;/p&gt;&#xD;
&lt;p&gt;&#xD;
Reasonable identity consolidation project including a decent provisioning system is a necessary pre-requisite for any other identity-related activity. It is a shame that engineers forget the &lt;i&gt;Garbage In, Garbage Out&lt;/i&gt; phrase that was popular few decades ago. If the data are bad, any system built on top of such data can only be worse.&#xD;
&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=vCgSgOuB0tA:SmpkzaH-Zzc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=vCgSgOuB0tA:SmpkzaH-Zzc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=vCgSgOuB0tA:SmpkzaH-Zzc:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=vCgSgOuB0tA:SmpkzaH-Zzc:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/vCgSgOuB0tA" height="1" width="1"/&gt;</content><feedburner:origLink>http://storm.alert.sk/blog/2010/08/23/Identity-Garbage</feedburner:origLink></entry>

  <entry>
    <id>tag:blogs.oracle.com,2010:/mwilcox//68.21585</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/NKx2ZZWcsn8/how_to_map_port_389_and_636_fo.html" rel="alternate" type="text/html" />
    <title>Mark Wilcox - Oracle: How To Map Port 389 and 636 For Oracle Virtual Directory</title>
    <summary type="html">OVD is a Java-based app and one of the limitations for Java-based servers is that if you want to run the service on a port under 1024 on Unix - you have to run it as root. The reason is...</summary>
    <content type="html" xml:lang="en">&lt;div class="posterous_autopost"&gt;OVD is a Java-based app and one of the limitations for Java-based servers is that if you want to run the service on a port under 1024 on Unix - you have to run it as root. The reason is that by default Unix requires anything on those ports to be run as root. In C-based applications - there is a switch-user API call that lets you start as root and then switch to another user. &lt;p&gt;&lt;/p&gt; Java never mapped this call and so there is lots of different schemes for dealing with it. For example in app servers - you might run Apache as a proxy running on 80 to Weblogic running on 7001. &lt;p&gt;&lt;/p&gt; I stumbled on another way to do this - at least on Linux. And that is to use iptables. &lt;p&gt;&lt;/p&gt; Here is how you can map 389 to 6501 (OVD 11g default non-SSL port): &lt;br&gt;/sbin/iptables -t nat -I PREROUTING -p tcp --dport 389 -j REDIRECT --to-port 6501 &lt;p&gt;&lt;/p&gt; Here is how can you map 636 to 7501 (OVD 11g default SSL port): &lt;br&gt;/sbin/iptables -t nat -I PREROUTING -p tcp --dport 636 -j REDIRECT --to-port 7501      &lt;p style="font-size: 10px;"&gt;  &lt;a href="http://posterous.com"&gt;Posted via email&lt;/a&gt;   from &lt;a href="http://mewldap.posterous.com/how-to-map-port-389-and-636-for-oracle-virtua"&gt;Virtual Identity Dialogue&lt;/a&gt;  &lt;/p&gt;  &lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=NKx2ZZWcsn8:3e42Wi3-5_c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=NKx2ZZWcsn8:3e42Wi3-5_c:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=NKx2ZZWcsn8:3e42Wi3-5_c:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=NKx2ZZWcsn8:3e42Wi3-5_c:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/NKx2ZZWcsn8" height="1" width="1"/&gt;</content>
    <updated>2010-08-23T21:06:49Z</updated>
    <published>2010-08-23T21:06:49Z</published>
    <author>
      <name>mark.wilcox</name>
    </author>
    <source>
      <id>tag:blogs.oracle.com,2010:/mwilcox//68</id>
      <link href="http://blogs.oracle.com/mwilcox/" rel="alternate" type="text/html" />
      <link href="http://blogs.oracle.com/mwilcox/xml/rss.xml" rel="self" type="application/atom+xml" />
      <title>Virtual Identity Dialogue</title>
      <updated>2010-09-02T03:44:47Z</updated>
    </source>
  <feedburner:origLink>http://blogs.oracle.com/mwilcox/2010/08/how_to_map_port_389_and_636_fo.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blogs.gartner.com/kevin-kampman/?p=12</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/AidKpvQnH4o/" rel="alternate" type="text/html" />
    <title>Kevin Kampman - Gartner: Role Management – Demonstrating value, or not</title>
    <summary type="html">Those of you who attended Catalyst in San Diego in 2009 may remember the lively panel on Role Management’s Evolution. The participants included Edward Coyne of SAIC, representing InterNational Committee for Information Technology Standards (INCITS), David Laurance of JPMC, Alan O’Connor of RTI, Robert Amos of NuStar Energy LP, and Paul Rarey of Safeway. The [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Those of you who attended Catalyst in San Diego in 2009 may remember the lively panel on Role Management’s Evolution. The participants included Edward Coyne of SAIC, representing InterNational Committee for Information Technology Standards (INCITS), David Laurance of JPMC, Alan O’Connor of RTI, Robert Amos of NuStar Energy LP, and Paul Rarey of Safeway. The panel provided a candid perspective on the adoption of role management in organizations; details of the panel discussion were published in the blog “Role” World Challenges.&lt;/p&gt;&#xD;
&lt;p&gt;In the course of the conversation, Alan O’Connor identified that the National Institute of Standards and Technology (NIST), the government sponsor for the role-based access control (RBAC) standard (ANSI INCITS 359-2004), will be soliciting real-world investment information on the implementation and benefits of role management. The purpose of this effort, ultimately, is to justify new government funding for the refinement of the RBAC standard, and also to provide organizations with information that can be used to demonstrate value in their own situations.&lt;/p&gt;&#xD;
&lt;p&gt;The survey was finally launched in August 2010. Sponsored by NIST, this solicitation, entitled “The Economics of Access Control,” covers access control strategies and lifecycles, user provisioning, and compliance activities. The survey is located at http://accesscontrolsurvey.rti.org. The results will be published by the end of 2010 and contributors will receive a copy of the report. This is a perfect opportunity to provide your input and perceptions about RBAC and related activities and to shape the standards activities in the future.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=AidKpvQnH4o:SwFV42soUZg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=AidKpvQnH4o:SwFV42soUZg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=AidKpvQnH4o:SwFV42soUZg:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=AidKpvQnH4o:SwFV42soUZg:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/AidKpvQnH4o" height="1" width="1"/&gt;</content>
    <updated>2010-08-23T17:59:37Z</updated>
    <category term="Uncategorized" />
    <category term="RBAC Roles" />
    <author>
      <name>Kevin Kampman</name>
    </author>
    <source>
      <id>http://blogs.gartner.com/kevin-kampman</id>
      <link href="http://blogs.gartner.com/kevin-kampman/feed/" rel="self" type="application/atom+xml" />
      <link href="http://blogs.gartner.com/kevin-kampman" rel="alternate" type="text/html" />
      <subtitle>A Member of The Gartner Blog Network</subtitle>
      <title>Kevin Kampman</title>
      <updated>2010-08-23T18:03:57Z</updated>
    </source>
  <feedburner:origLink>http://blogs.gartner.com/kevin-kampman/2010/08/23/role-management-%e2%80%93-demonstrating-value-or-not/</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-12447072.post-8409824203985156387</id>
    <link href="http://connectid.blogspot.com/feeds/8409824203985156387/comments/default" rel="replies" type="application/atom+xml" />
    <link href="https://www.blogger.com/comment.g?blogID=12447072&amp;postID=8409824203985156387" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/8409824203985156387?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/12447072/posts/default/8409824203985156387?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/-pdF6AkJ2OY/consent-can-be-without.html" rel="alternate" type="text/html" />
    <title>Paul Madsen: Consent can't be 'informed' without 'information'</title>
    <content type="html">&lt;div class="posterous_autopost"&gt;&lt;a href="http://posterous.com/getfile/files.posterous.com/paulmadsen/XxdgHSMZsFIhq6sO8Os51xZh0JcsWZmQrGFHrOXRm8sYRdZ9QjBLJAJzXU6F/Capture.jpg"&gt;&lt;img height="197" src="http://posterous.com/getfile/files.posterous.com/paulmadsen/nJ1od4iMRxYdk6MBXUwHlMvZi7MMP9Vg0TcCAVl7dzefyjSF0sjp4OWKHi3L/Capture.jpg.scaled.500.jpg" width="500"&gt;&lt;/img&gt;&lt;/a&gt; &lt;p&gt;In its OAuth consent flow, Google refers to the requesting party (Flickr in this instance) as the generic 'third party service'&lt;/p&gt;      &lt;p style="font-size: 10px;"&gt;  &lt;a href="http://posterous.com"&gt;Posted via email&lt;/a&gt;   from &lt;a href="http://paulmadsen.posterous.com/consent-cant-be-informed-without-information"&gt;Pre(posterous)&lt;/a&gt;  &lt;/p&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img alt="" height="1" src="https://blogger.googleusercontent.com/tracker/12447072-8409824203985156387?l=connectid.blogspot.com" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/blogspot/gMwy/~4/-pdF6AkJ2OY" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=-pdF6AkJ2OY:bB7c1ZPn4Aw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=-pdF6AkJ2OY:bB7c1ZPn4Aw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=-pdF6AkJ2OY:bB7c1ZPn4Aw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=-pdF6AkJ2OY:bB7c1ZPn4Aw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/-pdF6AkJ2OY" height="1" width="1"/&gt;</content>
    <updated>2010-08-23T16:01:47Z</updated>
    <published>2010-08-23T16:01:00Z</published>
    <author>
      <name>Paul Madsen</name>
      <email>noreply@blogger.com</email>
      <uri>http://www.blogger.com/profile/08489111023182783403</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-12447072</id>
      <author>
        <name>Paul Madsen</name>
        <email>noreply@blogger.com</email>
        <uri>http://www.blogger.com/profile/08489111023182783403</uri>
      </author>
      <link href="http://connectid.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://connectid.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/12447072/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/blogspot/gMwy" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>When you don't have anything nice to say, consider blogging it. or a tweet if you're rushed for time.</subtitle>
      <title>ConnectID</title>
      <updated>2010-09-01T22:30:26Z</updated>
    </source>
  <feedburner:origLink>http://connectid.blogspot.com/2010/08/consent-can-be-without.html</feedburner:origLink></entry>
</feed>
