Re: AzMan Still the way to go?



There is also a new whitepaper:

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetserv/html/AzManApps.asp

and Keith's excellent roadmap

http://msdn.microsoft.com/security/identityaccess/

---
Dominick Baier, DevelopMentor
http://www.leastprivilege.com

Certainly. I was just trying to answer the question a little
diffierently by pointing out the way AzMan is intended to be used and
what the point of the policy stuff is. I think your points are good
and well taken.

I'd actually like to understand the membership provider stuff a bit
better as well, especially the AD version. I wrote a book about DS
programming, but we purposefully skipped that and I never had a chance
to get into it, so I see a lot of the problems that people have with
it and I still don't know the answers. The fact that ADAM should work
as a user store doesn't mean that it is particularly easy to do.

I see similar struggles with AzMan, such as the errors you mentioned
in your other post, and don't usually know what the problem there is
either (although it is almost always an issue with security context).

Whether or not I'll actually get around to any of this is hard to say.
I'm spending most of my time these days with ADFS or general .NET
development stuff. :)

Joe K.



.



Relevant Pages

  • Re: AzMan threading problems
    ... Dominick Baier - DevelopMentor ... > one seems to be working extensively with AzMan. ... >> Are you using an XML based store or ActiveDirectory? ... >> I understand that there can be concurrency problems when using an XML ...
    (microsoft.public.dotnet.security)
  • Re: Securing static files
    ... Dominick Baier - DevelopMentor ... they are kicked back to the login page. ... The user may log in with other credentials. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: How to determine if the logged on user is in a group
    ... Dominick Baier - DevelopMentor ... I found that you to reboot the SERVER after you create a new group and put users in it so that the new group and the users appear in the whoami list on the server. ... although he is a member of these groups. ...
    (microsoft.public.dotnet.security)
  • Re: HOWTO: Prevent Dynamic Loading of internal Types
    ... Dominick Baier - DevelopMentor ... Henning Krause ... I could get the public key from the entry assembly via ...
    (microsoft.public.dotnet.security)
  • Re: How to call Web Service Securely
    ... which .net version - which type of authentication (username/password against a db??) ... Dominick Baier - DevelopMentor ... make a web method via dialup to my IIS Web Service. ...
    (microsoft.public.dotnet.framework.aspnet.security)