Re: ADAM and Application Security

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I'm guessing that AzMan is in fact the thing that you want. How ADAM
figures into that depends on a lot of things, but ADAM can be used a both a
policy store for AzMan as well as a user store. If you already have a user
store working, then that wouldn't make much sense (unless that's what your
boss wants to change). It might make sense as a policy store though.

My experience in application authorization is that there are many good
solutions and whether or not one is valid or not depends on a lot of things.
It certainly doesn't hurt to learn more about the options though.

I also second Lee's recommendation to check out Dominick's book. Mine is
more about raw LDAP programming stuff and could be applied to an
authorization framework, but it doesn't actually talk about that directly.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
<zigrat88@xxxxxxxxx> wrote in message
news:1162955006.324625.80270@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Lee - Thanks for the reply. I actually had stumbled across AzMan but
never dug in to deep on the product. From the link you provided it
really seems like that may be the type of solution we are looking for.
I'll probably have some followup questions on that product but I'll
shoot for a .Net security group. Thanks again!



.



Relevant Pages

  • Re: ADAM : Beginner and need help
    ... AzMan probably isn't a good solution for Java, but the AzMan design might be ... ADAM also supports the AD "tokenGroups" attribute which can be used to ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... ADAM can also support lots of password policy features that Windows ...
    (microsoft.public.windows.server.active_directory)
  • Re: HRESULT: 0X80070490 with Azman and AD LDS on 2008 server
    ... it may be that you are either missing some part of the AzMan schema for your LDS server or that some aspect of the MMC snap-in that manages AzMan and persists the policy didn't save all the objects correctly. ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... I tried to give permission on ADAM for authenticated users> but ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: HRESULT: 0X80070490 with Azman and AD LDS on 2008 server
    ... I think I'd probably use the ldp.exe tool that comes with ADAM to look at the data in both servers and see if it looks the same. ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... with 2003 server... ... > I'm developing a WPF application which is using AzMan as its policy> store. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: ADAM, AzMan question
    ... Yes - it should be possible to use ADAM as your policy store for AzMan - ... just as you can use the XML file store. ...
    (microsoft.public.dotnet.security)
  • Re: ADAM, AzMan question
    ... Yes - it should be possible to use ADAM as your policy store for AzMan - ... just as you can use the XML file store. ...
    (microsoft.public.dotnet.distributed_apps)