<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <title>Anil John</title>
    <link>http://www.aniltj.com/blog/</link>
    <description>On Architecture, Digital Security, Service Orientation...</description>
    <image><link>http://www.aniltj.com/blog/</link><url>http://www.aniltj.com/blog/images/aniltj88x31.png</url><title>Anil John</title></image>
    <language>en-us</language>
    <copyright>Anil John</copyright>
    <lastBuildDate>Wed, 30 Apr 2008 02:14:07 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 2.0.7226.0</generator>
    <managingEditor>aniltj@gmail.com</managingEditor>
    <webMaster>aniltj@gmail.com</webMaster>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/AnilJohn" type="application/rss+xml" /><feedburner:emailServiceId>152077</feedburner:emailServiceId><feedburner:feedburnerHostname>http://www.feedburner.com</feedburner:feedburnerHostname><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=6b0911a5-8086-4c6f-a7d1-d0e450783273</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,6b0911a5-8086-4c6f-a7d1-d0e450783273.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,6b0911a5-8086-4c6f-a7d1-d0e450783273.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=6b0911a5-8086-4c6f-a7d1-d0e450783273</wfw:commentRss>
      
      <title>Bloody Brilliant!</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,6b0911a5-8086-4c6f-a7d1-d0e450783273.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/280472643/BloodyBrilliant.aspx</link>
      <pubDate>Wed, 30 Apr 2008 02:14:07 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
        &lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:86c73c0e-a9d7-4ab9-9fe8-b48a92d55216" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;&#xD;
          &lt;div&gt;&#xD;
            &lt;object width="425" height="355"&gt;&#xD;
              &lt;param name="movie" value="http://www.youtube.com/v/KA2B5X0LhMY&amp;amp;hl=en"&gt;&lt;/param&gt;&#xD;
              &lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&#xD;
              &lt;embed src="http://www.youtube.com/v/KA2B5X0LhMY&amp;amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&#xD;
              &lt;/embed&gt;&#xD;
            &lt;/object&gt;&#xD;
          &lt;/div&gt;&#xD;
        &lt;/div&gt;&#xD;
        &lt;p&gt;&#xD;
Awesome! I hope this act wins!&#xD;
&lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:aae864c2-cfcf-4e56-b054-c79d492ceb0e" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/Desi" rel="tag"&gt;Desi&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:c148999d-16c0-400f-97e8-0d38348da303" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/Desi" rel="tag"&gt;Desi&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=6b0911a5-8086-4c6f-a7d1-d0e450783273"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=8SpveG"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=8SpveG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=CGlN7G"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=CGlN7G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=K3Pjjg"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=K3Pjjg" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/280472643" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,6b0911a5-8086-4c6f-a7d1-d0e450783273.aspx</comments>
      <category>Musings</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/04/30/BloodyBrilliant.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=f4e283f1-9139-40b7-a175-fbaf2715732c</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,f4e283f1-9139-40b7-a175-fbaf2715732c.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,f4e283f1-9139-40b7-a175-fbaf2715732c.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=f4e283f1-9139-40b7-a175-fbaf2715732c</wfw:commentRss>
      
      <title>The Zen of Identity Attributes</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,f4e283f1-9139-40b7-a175-fbaf2715732c.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/276933094/TheZenOfIdentityAttributes.aspx</link>
      <pubDate>Thu, 24 Apr 2008 14:21:26 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
Federating identities across information and security domains is not just a technical&#xD;
problem, and anyone who tells/sells you that it is, is not operating in a frame of&#xD;
reality that is conducive to success!&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
          &lt;img style="border-right: 0px; border-top: 0px; margin: 0px 0px 0px 10px; border-left: 0px; border-bottom: 0px" height="261" alt="Identity Attribute Zen" src="http://www.aniltj.com/blog/content/binary/WindowsLiveWriter/TheZenofIdentityAttributes_91C4/Attribute_Zen_3.png" width="362" align="right" border="0"&gt;&lt;/img&gt; Please&#xD;
note that, for me, an implementation of an Identity Federation architecture takes&#xD;
into account both Authentication and Authorization as well as a host of other areas. &#xD;
As such I've always found it amusing to be informed (usually by a vendor) that this&#xD;
is a straight forward problem and that once I deploy [Insert technology / tool / product&#xD;
/ magic pixie dust of choice here], we will have you "federating in no time". Ha!&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
We have been wrestling with this and at one of our working meetings recently, one&#xD;
of my team-mates came up with the following representation to describe the challenges&#xD;
of reaching agreement on what information needs to flow across federation boundaries,&#xD;
and what needs to be in place to accomplish it. Based on the same principle as the&#xD;
Boy Scout's triangle (heat, oxygen, fuel), you take away one side, and the entire&#xD;
Attribute Triangle (or as we call it, "Tom's Triangle", in honor of our team-mate&#xD;
who came up with it) collapses. &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
When you look at it, it seems so obvious and simplistic, but we have found value in&#xD;
thinking thinking about it in this manner.  Organizational Policy determines&#xD;
the rules of the road. Those rules in turn are reflected in the choices of attributes&#xD;
and the agreements around their semantics. At the same time, you need to be assured&#xD;
that the agreed upon attributes are not things that you come up out of the blue but&#xD;
are instead drawn from trusted and authoritative sources in the Enterprise.&#xD;
&lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:cf6f0e09-9acd-45cf-9b61-1494627e3c31" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/ABAC" rel="tag"&gt;ABAC&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Federated-Identity" rel="tag"&gt;Federated-Identity&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:766a51c6-1569-487c-b868-c7bef1fa0b38" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://technorati.com/tags/ABAC" rel="tag"&gt;ABAC&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Federated-Identity" rel="tag"&gt;Federated-Identity&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=f4e283f1-9139-40b7-a175-fbaf2715732c"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=hm6YnI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=hm6YnI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=34RzBI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=34RzBI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=O7GZ3i"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=O7GZ3i" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/276933094" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,f4e283f1-9139-40b7-a175-fbaf2715732c.aspx</comments>
      <category>Security</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/04/24/TheZenOfIdentityAttributes.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=d438e885-0430-4b3b-903d-27ea089d66c1</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,d438e885-0430-4b3b-903d-27ea089d66c1.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,d438e885-0430-4b3b-903d-27ea089d66c1.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=d438e885-0430-4b3b-903d-27ea089d66c1</wfw:commentRss>
      
      <title>Metal on Target</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,d438e885-0430-4b3b-903d-27ea089d66c1.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/273285314/MetalOnTarget.aspx</link>
      <pubDate>Sat, 19 Apr 2008 02:32:55 GMT</pubDate>
      <description>&lt;blockquote&gt;&#xD;
          &lt;p&gt;&#xD;
"&lt;em&gt;... part of our job is to make deliveries of metal to deserving customers. Business&#xD;
is Good!&lt;/em&gt;"&#xD;
&lt;/p&gt;&#xD;
        &lt;/blockquote&gt;&#xD;
        &lt;p&gt;&#xD;
An excerpt from a conversation with an Army Colonel.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
        &lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:f80d90d1-996a-4946-9988-a415d74e4cef" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/Military%20Humor" rel="tag"&gt;Military Humor&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:8be23af1-f3ab-4e52-a31a-67edb5f1efd4" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/Military%20Humor" rel="tag"&gt;Military Humor&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=d438e885-0430-4b3b-903d-27ea089d66c1"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=trmYUI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=trmYUI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=DUkDmI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=DUkDmI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=n4Hu6i"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=n4Hu6i" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/273285314" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,d438e885-0430-4b3b-903d-27ea089d66c1.aspx</comments>
      <category>Musings</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/04/19/MetalOnTarget.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=77809f34-1d41-493b-b619-d28fb4cf1c3a</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,77809f34-1d41-493b-b619-d28fb4cf1c3a.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,77809f34-1d41-493b-b619-d28fb4cf1c3a.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=77809f34-1d41-493b-b619-d28fb4cf1c3a</wfw:commentRss>
      
      <title>National response to hazards and Identity Management</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,77809f34-1d41-493b-b619-d28fb4cf1c3a.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/269730983/NationalResponseToHazardsAndIdentityManagement.aspx</link>
      <pubDate>Mon, 14 Apr 2008 02:07:28 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
GSA's USA Services/Intergovernmental Solutions sponsors monthly workshops around topics&#xD;
such as emergency preparedness, environmental monitoring, healthcare and law enforcement.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
The upcoming "&lt;a href="http://colab.cim3.net/cgi-bin/wiki.pl?ExpeditionWorkshop/ExploringIdentityManagementLandscapeInNationalPreparednessAndResponseScenarios_2008_04_30"&gt;Exploring&#xD;
Identity Management: Global Landscape and Implications for Stakeholder Engagement&#xD;
Around the National Response Framework&lt;/a&gt;" session is focused on the implications&#xD;
of the "&lt;a href="http://www.fema.gov/pdf/emergency/nrf/nrf-core.pdf"&gt;National Response&#xD;
Framework [PDF]&lt;/a&gt;" to Identity Management.&#xD;
&lt;/p&gt;&#xD;
        &lt;blockquote&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;em&gt;&#xD;
              &lt;a href="http://www.fema.gov/pdf/emergency/nrf/nrf-core.pdf"&gt;National Response&#xD;
Framework&lt;/a&gt; (NRF) is a guide to how the Nation conducts all-hazards response. &#xD;
It is built upon scalable, flexible, and adaptable coordinating structures to align&#xD;
key roles and responsibilities across the Nation, linking all levels of government,&#xD;
nongovernmental organizations, and the private sector.  It is intended to capture&#xD;
specific authorities and best practices for managing incidents that range from the&#xD;
serious but purely local, to large-scale terrorist attacks or catastrophic natural&#xD;
disasters.&lt;/em&gt;&#xD;
          &lt;/p&gt;&#xD;
        &lt;/blockquote&gt;&#xD;
        &lt;p&gt;&#xD;
I had the opportunity to speak with both &lt;a href="http://colab.cim3.net/cgi-bin/wiki.pl?SusanTurnbull"&gt;Susan&#xD;
Turnbull&lt;/a&gt; at the GSA as well as Dr. Duane Caneva, Director of Medical Preparedness&#xD;
at the White House Homeland Security Council, who are putting this event together,&#xD;
and came away impressed with their obvious passion in addressing this critical issue. &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
Basically, this is all about the technical, social and organizational infrastructure&#xD;
that needs to be in place to respond to a Katrina-like or Tsunami-like event. &#xD;
Identity Management is seen as an enabler in bringing the right people, the right&#xD;
resources and the right information together to help make a difference in responding&#xD;
to a crisis of this magnitude.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
I also came away with an action item :-) to discuss with this community how some of&#xD;
the &lt;a href="http://colab.cim3.net/cgi-bin/wiki.pl?ExpeditionWorkshop/ExploringIdentityManagementLandscapeInNationalPreparednessAndResponseScenarios_2008_04_30#nid3WE4"&gt;work&#xD;
that I am currently involved with&lt;/a&gt; could help out in this particular domain. &#xD;
The agenda looks pretty interesting and builds upon past events such as the IDTrust&#xD;
2008 etc. Looking forward to this! &#xD;
&lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:ef0b0b46-98d1-49b9-9db2-46e15f94da43" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/DHS" rel="tag"&gt;DHS&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/GSA" rel="tag"&gt;GSA&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/National%20Response%20Framework" rel="tag"&gt;National&#xD;
Response Framework&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:4d176b50-3775-42ae-9c88-1ffc71b39578" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://technorati.com/tags/DHS" rel="tag"&gt;DHS&lt;/a&gt;, &lt;a href="http://technorati.com/tags/GSA" rel="tag"&gt;GSA&lt;/a&gt;, &lt;a href="http://technorati.com/tags/National%20Response%20Framework" rel="tag"&gt;National&#xD;
Response Framework&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=77809f34-1d41-493b-b619-d28fb4cf1c3a"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=xZl10I"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=xZl10I" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=rf8q6I"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=rf8q6I" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=xsN0Zi"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=xsN0Zi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/269730983" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,77809f34-1d41-493b-b619-d28fb4cf1c3a.aspx</comments>
      <category>Security</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/04/14/NationalResponseToHazardsAndIdentityManagement.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=eb3799b8-0900-48bb-9101-5c7276d90465</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,eb3799b8-0900-48bb-9101-5c7276d90465.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,eb3799b8-0900-48bb-9101-5c7276d90465.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=eb3799b8-0900-48bb-9101-5c7276d90465</wfw:commentRss>
      
      <title>Wanted - Computer Systems Engineer Identity Management</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,eb3799b8-0900-48bb-9101-5c7276d90465.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/265203610/WantedComputerSystemsEngineerIdentityManagement.aspx</link>
      <pubDate>Sun, 06 Apr 2008 19:08:54 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
I typically &lt;a href="http://www.aniltj.com/blog/FormatPage.aspx?path=siteConfig/disclaimer.format.html"&gt;don't&#xD;
do this&lt;/a&gt;, but this particular job opening in &lt;a href="http://www.jhuapl.edu/aboutapl/"&gt;my&#xD;
organization&lt;/a&gt; is for someone that I will be directly working with.  As such,&#xD;
it is in my best interest to make sure that the opening gets socialized to folks in&#xD;
the right communities so that I can continue to work with folks who are a whole lot&#xD;
smarter and more knowledgeable than I am :-)&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
So if you have a knowledge base that spans identity, security and privacy technologies,&#xD;
would like a job that has a direct impact on and enhances of the security of the nation,&#xD;
and would like to work in an environment that values your individual contributions&#xD;
to a kick-ass team, we are hiring!  &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
Here are some of what I consider to be the relevant details of the job opening. The &lt;a href="https://owa.jhuapl.edu/psp/cg89prod_cg/EMPLOYEE/HRMS/c/HRS_HRAM.HRS_CE.GBL?Page=HRS_CE_JOB_DTL&amp;amp;Action=A&amp;amp;JobOpeningId=61317&amp;amp;SiteId=1"&gt;full&#xD;
description of the job, as well as how to apply for it, can be found on the official&#xD;
job requisition&lt;/a&gt;.&#xD;
&lt;/p&gt;&#xD;
        &lt;blockquote&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;em&gt;The ideal candidate will have a knowledge base that spans identity, security and&#xD;
privacy technologies as well as the ability to bridge the software development and&#xD;
computing infrastructure domains.&lt;/em&gt;&#xD;
          &lt;/p&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;b&gt;&#xD;
              &lt;em&gt;Duties:&lt;/em&gt;&#xD;
            &lt;/b&gt;&#xD;
          &lt;/p&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;b&gt;&#xD;
              &lt;em&gt;&#xD;
              &lt;/em&gt;&#xD;
            &lt;/b&gt;&#xD;
          &lt;/p&gt;&#xD;
          &lt;ul&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;Provide subject matter expertise in implementing identity and access control solutions&#xD;
in support of a variety of sponsors in the Government and Intelligence Communities.&#xD;
[...] &lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;Maintain current knowledge of identity technologies in the commercial marketplace&#xD;
with an eye towards how it could be applied to sponsor needs. Expectation is that&#xD;
the candidate actively participates in the technical community [...]&lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;Actively work to share knowledge and experience gained in external community participation&#xD;
and project work via participation in internal Communities of Practice, online forums&#xD;
[...]&lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;Participate in standards organizations such as OASIS, W3C and others on behalf&#xD;
of JHU/APL in the creation and modification of standards [...]&lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
          &lt;/ul&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;em&gt;&#xD;
              &lt;b&gt;Desired:&lt;/b&gt;&#xD;
            &lt;/em&gt;&#xD;
          &lt;/p&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;b&gt;&#xD;
              &lt;em&gt;&#xD;
              &lt;/em&gt;&#xD;
            &lt;/b&gt;&#xD;
          &lt;/p&gt;&#xD;
          &lt;ul&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;&#xD;
                &lt;b&gt;Self-motivated to learn and apply technology to solve problems&lt;/b&gt;&#xD;
              &lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;&#xD;
                &lt;b&gt;Ability to “Argue like you are right, Listen like you are wrong”&lt;/b&gt;&#xD;
              &lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;&#xD;
                &lt;b&gt;Self-starter who proactively searches for and obtains potential solutions to&#xD;
problems&lt;/b&gt;&#xD;
              &lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;Demonstrated experience with the implementation of identity solutions which may&#xD;
include: &lt;/em&gt;&#xD;
              &lt;ul&gt;&#xD;
                &lt;li&gt;&#xD;
                  &lt;em&gt;Application of relevant standards such as SAML, XACML, WS-SX, etc. &lt;/em&gt;&#xD;
                &lt;/li&gt;&#xD;
                &lt;li&gt;&#xD;
                  &lt;em&gt;Implementation and/or administration of directory services (LDAP etc) and/or Virtual&#xD;
Directory Capabilities, &lt;/em&gt;&#xD;
                &lt;/li&gt;&#xD;
                &lt;li&gt;&#xD;
                  &lt;em&gt;Implementation and/or administration of PKI, &lt;/em&gt;&#xD;
                &lt;/li&gt;&#xD;
                &lt;li&gt;&#xD;
                  &lt;em&gt;Implementation and/or administration of Web Access Management solutions &lt;/em&gt;&#xD;
                &lt;/li&gt;&#xD;
                &lt;li&gt;&#xD;
                  &lt;em&gt;RBAC/ABAC&lt;/em&gt;&#xD;
                &lt;/li&gt;&#xD;
              &lt;/ul&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;Full lifecycle implementation experience as related to an Identity Management&#xD;
Project&lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
          &lt;/ul&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;b&gt;&#xD;
              &lt;em&gt;Required:&lt;/em&gt;&#xD;
            &lt;/b&gt;&#xD;
          &lt;/p&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;b&gt;&#xD;
              &lt;em&gt;&#xD;
              &lt;/em&gt;&#xD;
            &lt;/b&gt;&#xD;
          &lt;/p&gt;&#xD;
          &lt;ul&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;Demonstrated experience in one or more of the relevant areas of Identity, Security,&#xD;
and Privacy with an interest in focusing on the Identity Management area.&lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;At least 5 years of increasingly complex software development with one or more&#xD;
of the major software platforms (i.e. .NET and/or JEE) and/or infrastructure experience&#xD;
with one or more major operating systems (i.e., *nix, Windows) in an Enterprise class&#xD;
environment&lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;Awareness of the fundamental principles of Service Oriented Architecture&lt;/em&gt;&#xD;
            &lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
              &lt;em&gt;&#xD;
                &lt;a href="https://www.dss.mil/portal/ShowBinary/BEA%20Repository/new_dss_internet/psco/ps_faqs.html"&gt;Must&#xD;
be eligible for US Department of Defense (DoD) clearance requiring background investigation&#xD;
and/or polygraph examination&lt;/a&gt;.&lt;/em&gt;  [Please be aware that holding a U.S.&#xD;
Citizenship is part of the requirement for obtaining a security clearance] &#xD;
&lt;/li&gt;&#xD;
            &lt;li&gt;&#xD;
[...]&lt;/li&gt;&#xD;
          &lt;/ul&gt;&#xD;
        &lt;/blockquote&gt;&#xD;
        &lt;p&gt;&#xD;
If you are interested, &lt;a href="https://owa.jhuapl.edu/psp/cg89prod_cg/EMPLOYEE/HRMS/c/HRS_HRAM.HRS_CE.GBL?Page=HRS_CE_JOB_DTL&amp;amp;Action=A&amp;amp;JobOpeningId=61317&amp;amp;SiteId=1"&gt;apply&#xD;
via the official job site&lt;/a&gt;, but in addition, &lt;strong&gt;drop me a note that you have&#xD;
applied with your attached resume&lt;/strong&gt; to my work e-mail (anil dot john -at- jhuapl&#xD;
dot edu), so that I can have it flagged internally and properly routed. &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
If you would simply like to find out more about the job, the work environment etc,&#xD;
or would like any clarifications before you take action, please feel free to contact&#xD;
me.  Needless to say, if you know of someone else who would be interested, please&#xD;
pass the details on to them.&#xD;
&lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:52a5be71-502f-4092-9eea-b4f60dbdde7b" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/JHUAPL" rel="tag"&gt;JHUAPL&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:045388e4-9ada-42d8-8525-ab181352d199" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://technorati.com/tags/JHUAPL" rel="tag"&gt;JHUAPL&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=eb3799b8-0900-48bb-9101-5c7276d90465"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=iU99ZI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=iU99ZI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=NZ4JeI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=NZ4JeI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=UbLaIi"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=UbLaIi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/265203610" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,eb3799b8-0900-48bb-9101-5c7276d90465.aspx</comments>
      <category>Musings</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/04/06/WantedComputerSystemsEngineerIdentityManagement.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=d7f1953e-0460-4638-ab3b-86e23d99be68</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,d7f1953e-0460-4638-ab3b-86e23d99be68.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,d7f1953e-0460-4638-ab3b-86e23d99be68.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=d7f1953e-0460-4638-ab3b-86e23d99be68</wfw:commentRss>
      
      <title>New Information Sharing Strategy for the DNI</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,d7f1953e-0460-4638-ab3b-86e23d99be68.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/265150041/NewInformationSharingStrategyForTheDNI.aspx</link>
      <pubDate>Sun, 06 Apr 2008 16:53:44 GMT</pubDate>
      <description>&lt;blockquote&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;em&gt;A new &lt;/em&gt;&#xD;
            &lt;a href="http://www.fas.org/irp/dni/iss.pdf"&gt;&#xD;
              &lt;em&gt;“Information Sharing&#xD;
Strategy”&lt;/em&gt;&#xD;
            &lt;/a&gt;&#xD;
            &lt;em&gt; (PDF) from the Office of the Director of National Intelligence&#xD;
warns that traditional security practices that restrict disclosure of information&#xD;
have become counterproductive.&lt;/em&gt;&#xD;
          &lt;/p&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;em&gt;“The Intelligence Community’s ‘need to know’ culture, a necessity during the Cold&#xD;
War, is now a handicap that threatens our ability to uncover, respond, and protect&#xD;
against terrorism and other asymmetric threats,” the document declares.&lt;/em&gt;&#xD;
          &lt;/p&gt;&#xD;
          &lt;p&gt;&#xD;
            &lt;em&gt;The new Strategy defines information sharing goals and as well as near-term and&#xD;
long-term implementation objectives. Goals include uniform government-wide information&#xD;
policies, improved connectivity, and increased inter-agency collaboration.&lt;br&gt;&lt;br&gt;&lt;/em&gt;&#xD;
            &lt;strong&gt;Source: FAS Project on Government Secrecy&lt;/strong&gt;&#xD;
          &lt;/p&gt;&#xD;
        &lt;/blockquote&gt;&#xD;
        &lt;p&gt;&#xD;
The document notes that in order to achieve their information sharing vision, the&#xD;
IC has "...  adopted a new information sharing model, which is depicted in Figure&#xD;
1:" &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
          &lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="407" alt="DNI Information Sharing Model" src="http://www.aniltj.com/blog/content/binary/WindowsLiveWriter/NewInformationSharingStrategyfortheDNI_12754/InformationSharingModel_3.png" width="585" border="0"&gt;&lt;/img&gt;&#xD;
        &lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
        &lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:eb407b33-678a-48dc-b7d8-cea65a9034a7" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/ABAC" rel="tag"&gt;ABAC&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Net-Centric" rel="tag"&gt;Net-Centric&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:e62af9e7-bf71-4663-8210-a6fb6d5771df" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/ABAC" rel="tag"&gt;ABAC&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Net-Centric" rel="tag"&gt;Net-Centric&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=d7f1953e-0460-4638-ab3b-86e23d99be68"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=WVbPQI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=WVbPQI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=KM2ceI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=KM2ceI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=jAQvbi"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=jAQvbi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/265150041" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,d7f1953e-0460-4638-ab3b-86e23d99be68.aspx</comments>
      <category>Musings</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/04/06/NewInformationSharingStrategyForTheDNI.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=304e8b6f-feee-4c30-8a2d-7895e83bdf94</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,304e8b6f-feee-4c30-8a2d-7895e83bdf94.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,304e8b6f-feee-4c30-8a2d-7895e83bdf94.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=304e8b6f-feee-4c30-8a2d-7895e83bdf94</wfw:commentRss>
      
      <title>IEEE Security &amp;amp; Privacy on Identity Management</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,304e8b6f-feee-4c30-8a2d-7895e83bdf94.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/264241332/IEEESecurityAmpPrivacyOnIdentityManagement.aspx</link>
      <pubDate>Fri, 04 Apr 2008 22:12:35 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
Just picked up the current issue of &lt;a href="http://www.computer.org/portal/site/security/"&gt;IEEE&#xD;
Security &amp;amp; Privacy&lt;/a&gt; Magazine and it is full of Identity Management Goodness!&#xD;
&lt;/p&gt;&#xD;
        &lt;ul&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://www.computer.org/portal/site/security/menuitem.6f7b2414551cb84651286b108bcd45f3/index.jsp?&amp;amp;pName=security_level1_article&amp;amp;TheCat=1015&amp;amp;path=security/2008/n2&amp;amp;file=gei.xml&amp;amp;"&gt;I'm&#xD;
Pc01002/SpringPeeper/ED288l.6; Who are You?&lt;/a&gt; by Susan Landau and Deirdre K. Mulligan &#xD;
&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/mags/sp/&amp;amp;toc=comp/mags/sp/2008/02/msp02toc.xml&amp;amp;DOI=10.1109/MSP.2008.50"&gt;The&#xD;
Venn of Identity: Options and Issues in Federated Identity Management&lt;/a&gt; (Abstract)&#xD;
by Eve Maler and Drummond Reed &#xD;
&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/mags/sp/&amp;amp;toc=comp/mags/sp/2008/02/msp02toc.xml&amp;amp;DOI=10.1109/MSP.2008.49"&gt;The&#xD;
Seven Flaws of Identity Management: Usability and Security Challenges&lt;/a&gt; (Abstract)&#xD;
by Rachna Dhamija and Lisa Dusseault &#xD;
&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/mags/sp/&amp;amp;toc=comp/mags/sp/2008/02/msp02toc.xml&amp;amp;DOI=10.1109/MSP.2008.28"&gt;Biometrics&#xD;
in Identity Management Systems&lt;/a&gt; (Abstract) by James L. Wayman &#xD;
&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/mags/sp/&amp;amp;toc=comp/mags/sp/2008/02/msp02toc.xml&amp;amp;DOI=10.1109/MSP.2008.41"&gt;Privacy&#xD;
and Identity Management&lt;/a&gt; (Abstract) by Marit Hansen, Ari Schwartz and Alissa Cooper &#xD;
&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/mags/sp/&amp;amp;toc=comp/mags/sp/2008/02/msp02toc.xml&amp;amp;DOI=10.1109/MSP.2008.35"&gt;Identity&#xD;
Management, Privacy, and Price Discrimination&lt;/a&gt; (Abstract) by Alessandro Acquisti &#xD;
&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/mags/sp/&amp;amp;toc=comp/mags/sp/2008/02/msp02toc.xml&amp;amp;DOI=10.1109/MSP.2008.51"&gt;Use&#xD;
Cases for Identity Management in E-Government&lt;/a&gt; (Abstract) by Robin McKenzie, Malcolm&#xD;
Crompton and Colin Wallis &#xD;
&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://www.computer.org/portal/site/security/index.jsp?pageID=security_level1_article&amp;amp;TheCat=1001&amp;amp;path=security/2008/n2&amp;amp;file=bsi.xml"&gt;Dynamic&#xD;
Security Assertion Markup Language: Simplifying Single Sign-On&lt;/a&gt; by Patrick Harding,&#xD;
Leif Johansson, and Nate Klingenstein&lt;/li&gt;&#xD;
        &lt;/ul&gt;&#xD;
        &lt;p&gt;&#xD;
Looking forward to this read!&#xD;
&lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:c01b9522-575a-40ee-8530-1711400a693d" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SAML" rel="tag"&gt;SAML&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Privacy" rel="tag"&gt;Privacy&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:27261b3a-eca4-4b27-864c-7da1b1be55e6" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SAML" rel="tag"&gt;SAML&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Privacy" rel="tag"&gt;Privacy&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=304e8b6f-feee-4c30-8a2d-7895e83bdf94"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=uDsj1I"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=uDsj1I" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=GnKMHI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=GnKMHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=vaQkVi"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=vaQkVi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/264241332" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,304e8b6f-feee-4c30-8a2d-7895e83bdf94.aspx</comments>
      <category>Security</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/04/04/IEEESecurityAmpPrivacyOnIdentityManagement.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=6139227b-f6e5-4358-8a7d-a951b8d7d845</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,6139227b-f6e5-4358-8a7d-a951b8d7d845.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,6139227b-f6e5-4358-8a7d-a951b8d7d845.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=6139227b-f6e5-4358-8a7d-a951b8d7d845</wfw:commentRss>
      <slash:comments>2</slash:comments>
      
      <title>Authentication, PKI and SAML</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,6139227b-f6e5-4358-8a7d-a951b8d7d845.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/260997936/AuthenticationPKIAndSAML.aspx</link>
      <pubDate>Mon, 31 Mar 2008 01:59:52 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
Some time ago, I was having a conversation with some folks about the usage of SAML&#xD;
Authentication Assertions for Web Browser Single Sign-On (SSO) versus Digital Certificates. &#xD;
The folks that I was having this conversation with support one of the larger PKI deployments&#xD;
in the US, and their response to my comment about the lack of support for SAML for&#xD;
Web Browser SSO in that particular vertical was the following question: &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
"&lt;em&gt;Provided the experience to the user is the same, why does it matter?&lt;/em&gt;" &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
I didn't have a very good answer at that point in time but it is something that I've&#xD;
been mulling over since that time. The issue has come up again in separate conversations,&#xD;
including &lt;a href="http://blog.pingidentity.com/blog/ctotalk/2008/02/14/PKI-and-SAML-Friends-or-Foes"&gt;this&#xD;
one by Patrick Harding&lt;/a&gt; of Ping Identity and &lt;a href="http://duckdown.blogspot.com/2008/03/pki-and-saml-friend-or-foes.html"&gt;this&#xD;
posting by James McGovern&lt;/a&gt;.  This blog posting is an attempt to articulate&#xD;
some of the points on both sides of this debate. &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
          &lt;strong&gt;SAML 2.0 and Web Browser SSO&lt;/strong&gt;&#xD;
        &lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
The Web Browser SSO Profile in SAML 2.0 supports both an Identity Provider (IdP) initiated&#xD;
and Service Provider (SP) initiated SSO message flows. As described in the SAML documentation&#xD;
"&lt;em&gt;.. the most common scenario for starting a web SSO exchange is the SP-initiated&#xD;
web SSO model which begins with the user choosing a browser bookmark or clicking a&#xD;
link that takes them directly to an SP application resource they need to access. However,&#xD;
since the user is not logged in at the SP, before it allows access to the resource,&#xD;
the SP sends the user to an IdP to authenticate. The IdP builds an assertion representing&#xD;
the user's authentication at the IdP and then sends the user back to the SP with the&#xD;
assertion.  The SP processes the assertion and determines whether to grant the&#xD;
user access to the resource.&lt;/em&gt;&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
          &lt;em&gt;In an IdP-initiated scenario, the user is visiting an IdP where they are already&#xD;
authenticated and they click on a link to a partner SP. The IdP builds an assertion&#xD;
representing the user's authentication state at the IdP and sends the user's browser&#xD;
over to the SP's assertion consumer service, which processes the assertion and creates&#xD;
a local security context for the user at the SP.&lt;/em&gt;"&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
Some points to keep in mind regarding these two flows:&#xD;
&lt;/p&gt;&#xD;
        &lt;ul&gt;&#xD;
          &lt;li&gt;&#xD;
The user's credentials are maintained at their IdP, which means that the SP must trust&#xD;
the IdP to assert information about its users. The establishment of this "organizational&#xD;
trust" is typically done out of band.&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;strong&gt;The IdP can support multiple authentication mechanisms of varying strengths&lt;/strong&gt; including&#xD;
user-id/password, software certificates and smart-cards based on a PKI, biometrics&#xD;
etc.&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;strong&gt;The type and the strength of the authentication used by the user can be conveyed&#xD;
in a SAML authentication context&lt;/strong&gt; which can be used in (or referred to from)&#xD;
a SAML Authentication Assertion. In fact an SP can include an authentication context&#xD;
in a request to an IdP to request that the user be authenticated using a specific&#xD;
set of authentication requirements, such as a multi-factor authentication.&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;strong&gt;Do not conflate authentication with authorization!&lt;/strong&gt; Although the user&#xD;
has been authenticated, the SP more than likely needs a LOT more information about&#xD;
the user (than what was provided in the Authentication Assertion) in order to make&#xD;
an access control decision.  This typically requires the usage of SAML attribute&#xD;
statements and/or SAML authorization decision statements. And in any reasonably complex&#xD;
environment that wants to remain standards based, this more than likely involves the&#xD;
usage of XACML for defining access control criteria.&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
SAML supports mechanisms to support the integrity and confidentiality of the assertions&#xD;
themselves including SSL mutual authentication, XML Signature etc. and does so across&#xD;
both the HTTP and SOAP bindings.&lt;/li&gt;&#xD;
        &lt;/ul&gt;&#xD;
        &lt;p&gt;&#xD;
          &lt;strong&gt;PKI and Web Browser SSO&lt;/strong&gt;&#xD;
        &lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
This is pretty straight forward from the usage perspective. It begins with a user&#xD;
choosing a bookmark or clicking a link that takes them directly to a Relying Party&#xD;
(RP) i.e. application resource they need to access.  The user is prompted to&#xD;
present a digital certificate as the authentication mechanism.  The user's certificate,&#xD;
whether it is in the form of a soft certificate or coming from a smart card, is used&#xD;
to authenticate the user.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
Some points to keep in mind:&#xD;
&lt;/p&gt;&#xD;
        &lt;ul&gt;&#xD;
          &lt;li&gt;&#xD;
In a PKI environment, when a Certification Authority issues a certificate, it is making&#xD;
a statement to a RP that a particular public key is bound to a specific entity (i.e.&#xD;
the subject of the certificate).&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
The degree to which a RP trusts a CA is based on the RP's understanding of the CA's&#xD;
user identification and credential issuance practices, operating policies, security&#xD;
controls etc.&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
Depending on the identity issuance requirements of a CA, &lt;strong&gt;the digital certificate&#xD;
is usually consider a higher assurance authentication mechanism&lt;/strong&gt; than something&#xD;
like a user-id and password.&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;strong&gt;Each RP has to put into place the technical infrastructure needed to make&#xD;
it PKI-aware&lt;/strong&gt; i.e. the ability to use digital certificates as authentication&#xD;
mechanism.&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;strong&gt;Each RP has to put into place the mechanisms for both validation and revocation&#xD;
operations&lt;/strong&gt;. This is especially challenging when you have CA's that are cross-certified&#xD;
and CA's and clients need to support certificate path processing.&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
The user experience, in browsing from one PKI protected resource to another may not&#xD;
be seamless.&lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
The authorization aspect is indeed separate from the authentication.  Information&#xD;
needed to make an access control decision may not be present in the information provided&#xD;
by a digital certificate.&lt;/li&gt;&#xD;
        &lt;/ul&gt;&#xD;
        &lt;p&gt;&#xD;
What strikes me when I look at these two options is that the question posed at the&#xD;
start of this entry may not be the right one to ask. The question one should be asking&#xD;
instead is "&lt;em&gt;Who do you trust?&lt;/em&gt;"&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
The fundamental precept of a PKI environment is that everyone must buy into trusting&#xD;
the CA. I would bet that that a lot of the "entrenched PKI communities" have expended&#xD;
significant amount of resources in standing up not just the technical infrastructure&#xD;
but the credential proofing and issuance processes for their domain. As such, they&#xD;
implicitly trust a certificate vouched for by the CA. The downside to this is that&#xD;
every single RP must be PKI-enabled, which is non-trivial.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
SAML is not a trust mechanism but more of a mechanism for a particular domain to make&#xD;
assertions about its users. As such, what is needed in the federated world for this&#xD;
to work is for a relying domain to trust the asserting domain. The relying domain&#xD;
would have to have confidence in the credential proofing and issuance process of the&#xD;
asserting domain. The advantages here would be that SAML-enabling an SP is a more&#xD;
straight forward process and there is significant out-of-the-box support for SAML&#xD;
in vendor tooling.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
In each case, I consider authorization to be separate and distinct from the authentication.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
But that organizational trust... Ah!  Is it not remarkable that the truly hard&#xD;
problems, whether one is discussing Identity Management or Service Orientation, really&#xD;
do not have to do with technology but with people, culture and behavior?&#xD;
&lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:1bfe8c48-a7b1-4c92-863a-fdf121ce8b8f" style="margin: 0px; padding: 0px; display: inline;"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SAML" rel="tag"&gt;SAML&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/PKI" rel="tag"&gt;PKI&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:94bf300e-efdb-42f4-8198-4fec79eaf567" style="margin: 0px; padding: 0px; display: inline;"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SAML" rel="tag"&gt;SAML&lt;/a&gt;, &lt;a href="http://technorati.com/tags/PKI" rel="tag"&gt;PKI&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=6139227b-f6e5-4358-8a7d-a951b8d7d845"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=EdI0sI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=EdI0sI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=SbowdI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=SbowdI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=bpYKhi"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=bpYKhi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/260997936" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,6139227b-f6e5-4358-8a7d-a951b8d7d845.aspx</comments>
      <category>Security</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/03/31/AuthenticationPKIAndSAML.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=e5258a44-a6c7-4625-947a-4381dd7525b4</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,e5258a44-a6c7-4625-947a-4381dd7525b4.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,e5258a44-a6c7-4625-947a-4381dd7525b4.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=e5258a44-a6c7-4625-947a-4381dd7525b4</wfw:commentRss>
      
      <title>Threat Modeling</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,e5258a44-a6c7-4625-947a-4381dd7525b4.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/254621400/ThreatModeling.aspx</link>
      <pubDate>Thu, 20 Mar 2008 01:25:41 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
Series of posts on threat modeling. Good stuff!&lt;br&gt;&#xD;
[&lt;em&gt;Found via &lt;a href="http://www.schneier.com/blog/archives/2008/03/more_threat_mod.html"&gt;Bruce&#xD;
Schneier&lt;/a&gt;&lt;/em&gt;]&#xD;
&lt;/p&gt;&#xD;
        &lt;ul&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://blogs.msdn.com/sdl/archive/2007/09/26/the-trouble-with-threat-modeling-2.aspx"&gt;The&#xD;
Trouble with Threat Modeling&lt;/a&gt;&#xD;
          &lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://blogs.msdn.com/sdl/archive/2007/10/01/the-new-threat-modeling-process.aspx"&gt;The&#xD;
New Threat Modeling Process&lt;/a&gt;&#xD;
          &lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://blogs.msdn.com/sdl/archive/2007/10/11/getting-into-the-flow-with-threat-modeling.aspx"&gt;Getting&#xD;
into the Flow With Threat Modeling&lt;/a&gt;&#xD;
          &lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://blogs.msdn.com/sdl/archive/2007/10/16/making-threat-modeling-work-better.aspx"&gt;Making&#xD;
Threat Modeling Work Better&lt;/a&gt;&#xD;
          &lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://blogs.msdn.com/sdl/archive/2007/10/22/threat-modeling-self-checks-and-rules-of-thumb.aspx"&gt;Threat&#xD;
Modeling Self Checks and Rules of Thumb&lt;/a&gt;&#xD;
          &lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://blogs.msdn.com/sdl/archive/2007/10/29/the-stride-per-element-chart.aspx"&gt;The&#xD;
STRIDE per Element Chart&lt;/a&gt;&#xD;
          &lt;/li&gt;&#xD;
          &lt;li&gt;&#xD;
            &lt;a href="http://blogs.msdn.com/sdl/archive/2008/02/14/wrapping-up-threat-modeling.aspx"&gt;Wrapping&#xD;
up Threat Modeling&lt;/a&gt;&#xD;
          &lt;/li&gt;&#xD;
        &lt;/ul&gt;&#xD;
        &lt;p&gt;&#xD;
Also check out JD's post on &lt;a href="http://blogs.msdn.com/jmeier/archive/2007/12/20/getting-started-with-threat-modeling.aspx"&gt;Getting&#xD;
Started with Threat Modeling&lt;/a&gt; and the &lt;a href="http://blogs.msdn.com/threatmodeling/"&gt;Threat&#xD;
Modeling Blog&lt;/a&gt; maintained by the Microsoft Application Consulting and Engineering&#xD;
Team.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
        &lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:a35ecd26-0a23-4a8b-a253-10bd4ac14fe5" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/ThreatModeling" rel="tag"&gt;ThreatModeling&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SDL" rel="tag"&gt;SDL&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:55eaf5ba-1f9e-4b96-84cf-09f3fae19610" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/ThreatModeling" rel="tag"&gt;ThreatModeling&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SDL" rel="tag"&gt;SDL&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=e5258a44-a6c7-4625-947a-4381dd7525b4"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=1Y5d1I"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=1Y5d1I" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=K7FeHI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=K7FeHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=XCGtIi"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=XCGtIi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/254621400" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,e5258a44-a6c7-4625-947a-4381dd7525b4.aspx</comments>
      <category>Security</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/03/20/ThreatModeling.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=2c3cdee0-ea28-46e9-a878-531ea5527a8a</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,2c3cdee0-ea28-46e9-a878-531ea5527a8a.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,2c3cdee0-ea28-46e9-a878-531ea5527a8a.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=2c3cdee0-ea28-46e9-a878-531ea5527a8a</wfw:commentRss>
      
      <title>Shibboleth 2.0 is now available</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,2c3cdee0-ea28-46e9-a878-531ea5527a8a.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/254566152/Shibboleth20IsNowAvailable.aspx</link>
      <pubDate>Wed, 19 Mar 2008 22:47:10 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
Congratulations to the Shibboleth Team on the &lt;a href="http://shibboleth.internet2.edu/shib-v2.0.html"&gt;release&#xD;
of Shibboleth &lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 0px 0px 10px; border-right-width: 0px" height="54" alt="gryphon" src="http://www.aniltj.com/blog/content/binary/WindowsLiveWriter/Shibboleth2.0isnowavailable_1084C/gryphon_6.jpg" width="46" align="right" border="0"&gt;&lt;/img&gt;2.0&lt;/a&gt;. &#xD;
This version provides support for SAML 2.0 as well as integration with most major&#xD;
identity stores, including Microsoft Active Directory, Kerberos, LDAP-compliant directory&#xD;
services, and JDBC-compliant databases.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
For those not familiar with this fine piece of open source software, &lt;a href="http://shibboleth.internet2.edu/"&gt;Shibboleth&lt;/a&gt; is&#xD;
a "... standards-based, open source middleware software which provides Web Single&#xD;
Sign-On (SSO) across or within organizational boundaries. It allows sites to make&#xD;
informed authorization decisions for individual access of protected online resources&#xD;
in a privacy-preserving manner."&#xD;
&lt;/p&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:35e58ad3-68f5-4110-963e-eb0b86bf5c32" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us&#xD;
tags: &lt;a href="http://del.icio.us/popular/Shibboleth" rel="tag"&gt;Shibboleth&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SAML" rel="tag"&gt;SAML&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:c8d25928-78e1-4293-933f-cebbd6d493ac" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati&#xD;
tags: &lt;a href="http://technorati.com/tags/Shibboleth" rel="tag"&gt;Shibboleth&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SAML" rel="tag"&gt;SAML&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=2c3cdee0-ea28-46e9-a878-531ea5527a8a"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=w7SxeI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=w7SxeI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=5NJghI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=5NJghI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=bFgmpi"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=bFgmpi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/254566152" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,2c3cdee0-ea28-46e9-a878-531ea5527a8a.aspx</comments>
      <category>Security</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/03/19/Shibboleth20IsNowAvailable.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=cc704578-84f5-4c36-bad1-67417e8ea58b</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,cc704578-84f5-4c36-bad1-67417e8ea58b.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,cc704578-84f5-4c36-bad1-67417e8ea58b.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=cc704578-84f5-4c36-bad1-67417e8ea58b</wfw:commentRss>
      
      <title>Abstraction, Remote Controls and Service Orientation</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,cc704578-84f5-4c36-bad1-67417e8ea58b.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/248444684/AbstractionRemoteControlsAndServiceOrientation.aspx</link>
      <pubDate>Sun, 09 Mar 2008 18:10:33 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
          &lt;img style="border-width: 0px; margin: 0px 0px 0px 10px;" alt="Abstraction" src="http://www.aniltj.com/blog/content/binary/WindowsLiveWriter/AbstractionRemoteControlsandServiceOrien_C775/Abstraction_3.png" align="right" border="0" height="248" width="329"&gt;&lt;/img&gt;As &lt;a href="http://epp.jhu.edu/course-homepages/viewpage.php?homepage_id=2980"&gt;part&#xD;
of my SOA class&lt;/a&gt;, we are currently going over some of the principles of service&#xD;
design. In particular, we were going over the principle of abstraction.  The&#xD;
example of technology abstraction that I used in class was a remote control.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
The funny thing for me has been just recently my 10+ year old Pioneer AV receiver&#xD;
that is part of my home entertainment system finally started having problems after&#xD;
years of excellent service.  I had to replace it with a new Onkyo AV receiver&#xD;
that really has more options in it that I know what to do with. So I spent some time&#xD;
two nights ago, after the kids and wife had gone to bed, to swap out this component. &#xD;
But the greatest thing for me was that when they went to watch TV and to listen to&#xD;
the radio the next day, they did not have to do anything differently! &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
Everything just worked using the same interface that they have always been used to,&#xD;
down to using the same key presses, because I had invested some time in consolidating&#xD;
my "service interface" to &lt;a href="http://www.aniltj.com/blog/2007/12/08/UpgradingToHDTV.aspx"&gt;one&#xD;
programmable and extendable universal remote&lt;/a&gt;. So, the only additional thing I&#xD;
had done was to update the firmware in the remote control to now point to the new&#xD;
receiver on the back-end.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
I would definitely consider this a practical example of the implementation of the&#xD;
principle of abstraction.&#xD;
&lt;/p&gt;&#xD;
        &lt;div style="margin: 0px; padding: 0px; display: inline;"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/SOA" rel="tag"&gt;SOA&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Teaching" rel="tag"&gt;Teaching&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div style="margin: 0px; padding: 0px; display: inline;"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/SOA" rel="tag"&gt;SOA&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Teaching" rel="tag"&gt;Teaching&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=cc704578-84f5-4c36-bad1-67417e8ea58b"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=welnRI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=welnRI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=T95hyI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=T95hyI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=CzIKqi"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=CzIKqi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/248444684" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,cc704578-84f5-4c36-bad1-67417e8ea58b.aspx</comments>
      <category>Service Orientation</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/03/09/AbstractionRemoteControlsAndServiceOrientation.aspx</feedburner:origLink></item>
    <item>
      <trackback:ping>http://www.aniltj.com/blog/Trackback.aspx?guid=7f32cbd8-ab51-421c-b2b2-cc753c1d9ca7</trackback:ping>
      <pingback:server>http://www.aniltj.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://www.aniltj.com/blog/PermaLink,guid,7f32cbd8-ab51-421c-b2b2-cc753c1d9ca7.aspx</pingback:target>
      <dc:creator>Anil John</dc:creator>
      <wfw:comment>http://www.aniltj.com/blog/CommentView,guid,7f32cbd8-ab51-421c-b2b2-cc753c1d9ca7.aspx</wfw:comment>
      <wfw:commentRss>http://www.aniltj.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=7f32cbd8-ab51-421c-b2b2-cc753c1d9ca7</wfw:commentRss>
      <slash:comments>2</slash:comments>
      
      <title>Managing the release of Identity Attributes</title>
      <guid isPermaLink="false">http://www.aniltj.com/blog/PermaLink,guid,7f32cbd8-ab51-421c-b2b2-cc753c1d9ca7.aspx</guid>
      <link>http://feeds.feedburner.com/~r/AnilJohn/~3/248163615/ManagingTheReleaseOfIdentityAttributes.aspx</link>
      <pubDate>Sun, 09 Mar 2008 03:22:09 GMT</pubDate>
      <description>&lt;p&gt;&#xD;
One of the things I have been doing a bit of work on has been Attribute Authorities&#xD;
in the SAML 2.0 sense i.e. a SAML entity that produces assertions in response to identity&#xD;
attribute queries from an entity acting as an attribute requester.  In particular,&#xD;
my interest lies in controlling the release of attributes based on policies that could&#xD;
be externalized.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
My interest in finding a hopefully standardized way of doing this was sparked by the&#xD;
article "&lt;a href="http://www.mnm-team.org/pub/Publikationen/homm05a/PDF-Version/homm05a.pdf"&gt;Using&#xD;
XACML for Privacy Control in SAML-Based Identity Federations&lt;/a&gt;" by Wolfgang Hommel,&#xD;
which I found on the &lt;a href="http://xml.coverpages.org/xacml.html"&gt;XACML section&#xD;
of the OASIS Cover Pages&lt;/a&gt;. The article describes the use of XACML to control the&#xD;
release of attributes and an implementation of this using an earlier release of Shibboleth.&#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
At the &lt;a href="http://middleware.internet2.edu/idtrust/2008/"&gt;IDTrust 2008 Symposium&lt;/a&gt;,&#xD;
one of the sessions that I enjoyed was the panel session on "Federations Today and&#xD;
Tomorrow" hosted by Ken Klingenstein of Internet2 and Patrick Harding of Ping Identity. &#xD;
When Ken spoke a bit about the release of Shibboleth 2.0, which supports SAML 2.0,&#xD;
this brought me back full circle. &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
In an earlier conversation I had had on this topic with some colleagues who are working&#xD;
with release candidate versions of Shibboleth 2.0, I was curious to find out if the&#xD;
"Attribute Filter" capability in Shibboleth had made it into the SAML 2.0 standard&#xD;
given that Shibboleth 2.0 is the convergence of Shibboleth, SAML 1.X and the Liberty&#xD;
IDFF. Unfortunately, I was informed that it had not. The implementation is specific&#xD;
to the Shibboleth functionality and does not seem to exist as part of the SAML 2.0&#xD;
specification. &#xD;
&lt;/p&gt;&#xD;
        &lt;p&gt;&#xD;
So what I asked the panel was that given that both SAML 2.0 and XACML 2.0 are based&#xD;
out of OASIS, is there any work in integrating the two standards to enable this type&#xD;
of functionality, as there is definitely a use case for this in a lot of the communities&#xD;
that I am familiar with. The answer I got back was that, while this is not outside&#xD;
the realm of possibility, it is not something that someone is working on. In a hallway&#xD;
conversation I had with some other folks after the session, someone mentioned that&#xD;
this type of functionality may be built into one of the Oracle products, but again&#xD;
the implementation was proprietary to that vendor.&#xD;
&lt;/p&gt;&#xD;
        &lt;div style="margin: 0px; padding: 0px; display: inline;"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/idtrust2008" rel="tag"&gt;idtrust2008&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SAML" rel="tag"&gt;SAML&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Shibboleth" rel="tag"&gt;Shibboleth&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;div style="margin: 0px; padding: 0px; display: inline;"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/idtrust2008" rel="tag"&gt;idtrust2008&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Identity-Management" rel="tag"&gt;Identity-Management&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SAML" rel="tag"&gt;SAML&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Shibboleth" rel="tag"&gt;Shibboleth&lt;/a&gt;&lt;/div&gt;&#xD;
        &lt;img width="0" height="0" src="http://www.aniltj.com/blog/aggbug.ashx?id=7f32cbd8-ab51-421c-b2b2-cc753c1d9ca7"&gt;&lt;/img&gt;&#xD;
        &lt;br&gt;&#xD;
        &lt;hr&gt;&lt;/hr&gt;&#xD;
These are solely my opinions and do not represent the thoughts, intentions, plans&#xD;
or strategies of any third party, including my employer, except where explicitly stated.&#xD;
This work is licensed under a Creative Commons Attribution 3.0 License.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=X629NI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=X629NI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=t2ndFI"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=t2ndFI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/AnilJohn?a=MACRGi"&gt;&lt;img src="http://feeds.feedburner.com/~f/AnilJohn?i=MACRGi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/248163615" height="1" width="1"/&gt;</description>
      <comments>http://www.aniltj.com/blog/CommentView,guid,7f32cbd8-ab51-421c-b2b2-cc753c1d9ca7.aspx</comments>
      <category>Security</category>
    <feedburner:origLink>http://www.aniltj.com/blog/2008/03/09/ManagingTheReleaseOfIdentityAttributes.aspx</feedburner:origLink></item>
  </channel>
</rss>
