App to App authentication model problem????

From: r (richard.scott@bestbuy.com)
Date: 01/28/03


From: richard.scott@bestbuy.com (r)
Date: 28 Jan 2003 12:54:07 -0800

Greetings all,

I am posting this here in teh hope to get some direction as to where
next to look. This ismore of an architecture question and not
specific to programming.

Given an enterprise Java, LDAP and Small PKI infrastructure what would
be a recommended solution to securing connection credentials to
database systems, queues etc.

Given that applications can be built in Java and the logical storage
of credentials to be stored in LDAP. What authentication mechanism,
model, architecture best allows applications legitimate access to LDAP
schema to obtain sensitive data such as connection credentials to
database systems?

The idea is to have developed applications use a framework to securely
obtain correct credentials for the applications based in environments
in DEV, QA and PROD.

Thus given some environment, the application executred within the
framework and requests to connect to the HR database, for example.
The application then must be authenticated and if successful, the
framework obtains the connection credentials to build a connection to
the database.
By running the same code in QA, the credentials for the QA database is
given, not the production one. A call for the production database
from a QA server is prohibited.

Any ideas of how this can be enforced?

cheers
r./



Relevant Pages

  • Application to Application authentication models....
    ... architecture best allows applications legitimate access to LDAP schema to ... obtain sensitive data such as connection credentials to database systems? ... The idea is to have developed applications use a framework to securely ...
    (SecProg)
  • Re: polymorphism (was: Poly Couples)
    ... but this is not really "business software"... ... Most of such applications are built as a combination of ... database with flat files or a different RDBMS vendor?" ... couldn't care less if I do it in using structured programming or OOP ...
    (comp.object)
  • Re: Unisys OS/2200 DMS / TIP / COBOL Migration
    ... support the legacy system api's that the application is using. ... differences in COBOL compiler dialects. ... What DBI does is to provide legacy database (DMS) ... the legacy database to the COBOL applications. ...
    (comp.sys.unisys)
  • Re: Database set up help
    ... let's see...I choose the y/n data type because I am using ... User opens up form and enters Employee Information in the fields ... 2 of the 38 options in my main menu are BPCS Applications ... I set up a database with this so far: ...
    (microsoft.public.access.gettingstarted)
  • Re: Advice needed for a growing Access 2000 project
    ... However, it turned out that quite a few of those were "leftovers" from previous releases, no longer accessible from anywhere but the database window, and, thus, no longer used. ... But that certainly isn't the _norm_ -- without any 'heroic' measures, there are routine reports of split Access DBs ... Finally, in my opinion, for "Windows apps", that is, individual-user applications, modest-sized multiuser applications, and client-server applications of any size, Dot Net does NOT "help along" any of these issues. ... The post I reference was in reference its self to the MS Access Help file under "Microsoft Access database general specifications" ...
    (comp.databases.ms-access)