Arch2Arch Tab BEA.com
Syndicate this blog (XML)

Shameless Plug for My Talk at BEA World

Bookmark Blog Post

del.icio.us del.icio.us
Digg Digg
DZone DZone
Furl Furl
Reddit Reddit

Josh Bregman's Blog | September 12, 2005  12:15 PM | Comments (0)


Regardless of the actual presentation title, I'll be speaking on Tuesday, September 27th in the afternoon. The purpose of the chat is to try to share some of my experiences over the past year in support of the AquaLogic Enterprise Security Product.

I've been travelling quite a bit (Delta Silver/UsAir Silver/Marriott Silver) and there is really quite an interest in this product. I think the message to developers is that they no longer have to worry about keeping up with constantly changing security requirements. In most applications, the security logic is hard-coded into the applications. By that, I mean that decisions about who can get access to what is ultimately determined by application code, not by a centralized security service. Certainly, enterprises have some notion of entitlements - RDBMS based systems that maintain profile data - but at the end of the day the decision is being made inside of the application.

Externalizing this logic is certainly easier said than done, but there are certainly some techniques and approaches which can make this less painful. Some will be covered in the presentation...others will be covered here and hopefully in some code samples etc in dev2dev itself


Comments

Comments are listed in date ascending order (oldest first) | Post Comment



Only logged in users may post comments. Login Here.

Powered by
Movable Type 3.31