Pages

Database Management is Not Just for Tech Junkies

While information and also technology acquire more complex by the second, the necessity for database management is better than ever before since highlighted through the growth of various kinds of database management software in the market. Business owners and also brains of corporations know very well to invest a large section of their particular finances within a database management system which sets up just about all pertinent files within an efficient manner.

Database management plays an important role in many of market sectors and job areas, one example which is identification and access management. From the CIA right down to the closest 7-11, hypersensitive info is often obtained and also saved, whether it's a " inside info " authorities plan or bank card amount of a client. Vulnerable info could possibly be exposed to unauthorized entry in case a poor home alarm system is location because of the unproductive database management system. However, in the event that information is been able so wherein access is restricted depending on the identity from the person, secrecy of knowledge is just not jeopardized.

Database management can be crucial within relational database management. Information can just be stored with regard to taking uses, but most of that time period, it can be accessed to complete a number of deals and also routines. Through these instances, interactions involving different kinds of data have to be obviously described just before any kind of procedure takes place. By way of example, a few activities possess the right after structure: "if information Any and data B are genuine, next course of action Any happens; otherwise, procedure B can be accomplished." When associations among different kinds of data are certainly not effectively set up in advance, it's not hard to find out how techniques regarding these may go drastically wrong. It is essential that information is not only located correctly, but you are related to each other in the significant manner.

Because of the need for database management, nothing less than a talented database manager must preside more than managing databases. Publication rack willing to spend expensive for individuals designed with the essential expertise and knowledge. Those that have a strong basis in IT, computer science, and software design will discover a fulfilling profession in the field of database management. A formal qualifications in database management, whether obtained through knowledge as well as research, will really improve someone's benefit within the employment market.

Identity Access Management

Every business features specific details which needs to be resistant to unauthorized customers. Identity Access management (IAM) is the method that enables business administration to identify along with handle information and also system resources through unauthenticated people. The main aim involving IAM is always to grant as well as reject the accessibility involving discreet information for the venture assets.

By using access management method, your approved government from the business organization can simply research along with identify the individual that can be accessing the trick info without having approval. For that reason, it can help business organization to meet their safety needs. Usually, Identity Access management comprises of segments like Validation, Authorization, Person Management and Key Individual Repository.

Certification entails affirmation regarding user Identity and pass word thereby delivering accessibility control along with personal privacy for the individual and the details with the firm. It will help in tracking the user's action over distinct sessions regarding connection involving the consumer and the computer system. On the other hand, Agreement verifies your approved person, no matter whether he/she has the approval to gain access to the individual data you aren't. That determines the access request up against the guidelines manufactured by the business. Acceptance involves checking regarding information such as individual qualities, person teams, channels and data resources that could be used and more.

The user management method in Identity Access management establishes specific features including security password resetting, identity design, tyranny of data etc. Apart from benefiting from this particular component, business organization also can choose implementing your Main Consumer Archive module for identity management. Central User Repository can retailer and also exchange id details from a single origin to numerous authorized sectors from the firm. That identifies the eye-sight of present identities as well as their relationship while using a variety of methods.

Now-a-days, numerous business owners make use of access management software to keep up privacy inside organization. By employing this software, business owners is able to reduce the price needed in employing human resources, as being a defender of the hypersensitive information. In addition to, additionally, it stops seepage of the secret choice created by the companies, which could be considered a a few concern when confronted with somebody rather than computer software.

Nokia Lumia 800 The Dark Knight Rises Limited Edition launched in India


It has been a busy day today, with Nokia announcing the launch of two phones in India. Along with the Nokia Lumia 610, the Lumia 800 The Dark Knight Rises Limited Edition phone has also been launched, and should be available in markets from tomorrow.
The Lumia 800 The Dark Knight Rises phone will truly be limited edition, with Nokia announcing that only 200 units will be available. So, we suggest that if you want one, hurry and grab one now!
This edition of the phone will carry forward the same unibody build as seen on Lumia 800 (read our review) phones, but the black colour will be accompanied by a laser etched Batman logo on the back, to make it stand out in a crowd.
“A truly global initiative, the Nokia Lumia Dark Knight Rises campaign is an exciting new initiative for our Lumia customers, that will recreate the movie’s unique experience, right on the consumer’s devices”, said Vipul Mehrotra, Director – Smart Devices, Nokia India.
Buyers will get access to a whole host of exclusive stuff. First off, the phone will be loaded with the Dark Knight Rises app, with exclusive trailers, photo galleries, integration with Maps to list where the movie theaters premiering the movie are, as well as a game that has been introduced in a tie up with Foursquare.

More Here

Google Reveals Nexus Q Social Streaming Media Player

Google just posted a video on YouTube for what it’s calling the first social streaming media player made for Google Play at Home, the Nexus Q.
The clip was discovered in the final minutes leading up to the Google I/O — Google’s annual developer conference in San Francisco — where it is likely gearing up to announce an array of new products, platforms and services.
SEE ALSO: Live From the Google I/O Keynote [LIVE BLOG]
The video of Nexus Q shows that the device streams music and entertainment from the cloud to your home.
“It’s the first device that lets you create social playlists with your friends,” the video states. “All they need is an Android phone or tablet and connection to your Wi-Fi.”
By launching the Google Play music app, you can list songs and albums to the queue and friends can add the same from their own collections. The Nexus Q also works for streaming YouTube videos and movies.


Courtesy:http://mashable.com/2012/06/27/nexus-q/

Google Nexus Q streamer

It's an orb-like streaming-media device with a $300 price tag, that looks to act as the bridge between Android tablets and smartphones, and your TV. The (currently unlisted) YouTube video shows off its ability to integrate with your Google Music account, as well as "push" videos to your TV, similar to Apple's AirPlay functionality.
While it's not entirely clear from the product shots currently available, the Nexus Q has a micro HDMI output (and includes an HDMI cable), in addition to an optical audio port, Ethernet jack, and banana jack speaker outputs. The Nexus Q also has a built-in 25-watt amp, which means you won't need a separate AV receiver to power speakers, similar to a Sonos Connect:Amp. There's also built-in Wi-Fi, Bluetooth and NFC support.
The Nexus Q runs a version of Android 4.0, with 16GB of onboard flash memory and 1GB of RAM. Unlike streaming media boxes like Roku or the Apple TV, the Nexus Q only supports a few Google-centric apps: Google Play Music, Google Play Movies and TV and YouTube. The "social" aspect of Nexus Q initially appears to be the ability for multiple Android devices to create a group playlist.
According to the product page, the Nexus Q should be shipping in 2-3 weeks. Also listed is a set of $400 bookshelf speakers, made by Triad Speakers, designed to be used with the Nexus Q.
This is a developing story and will be updated with more details shortly.
 

Google Unveils Nexus Q Streaming Media Player

Google's Nexus Q uses your Android smartphone or tablet in conjunction with Google Play to stream music and videos to your HDTV, sound system, or just speakers.



Google debuted a new orb-shaped media streaming device called the Nexus Q before it took the stage for its Google I/O keynote. The Nexus , what the company calls “the first social streaming media player” first appeared on the Google Play website store.
Closer look at Nexus QGoogle's Nexus Q uses your Android smartphone or tablet in conjunction with Google Play to stream music and videos to your HDTV, sound system, or a pair of speakers. What sets the Nexus Q apart from similar media streaming devices, such as Apple TV, is that it allows you to collaborate with friends via your Android device to create playlists of music and video clips.
The Nexus Q isn’t just an Apple TV clone device from Google. Think of the Nexus Q as a hybrid between Apple’s streaming puck and the Sonos music streaming stereo component. The Q features a built-in 25W amp that can power a pair of bookshelf speakers. In addition, users can sync Qs across multiple rooms.
From a video promo (see below) of the Nexus Q Google says: "streams your favorite entertainment from Google Play and YouTube to the biggest speakers and screen in the house."
Using the Q, Android users on the same WiFi network can “queue” (get it?) up their Google Play Music tracks. Every user sees the same playlist, and can edit it as they see fit, hence “the first social streaming media player.”
The Nexus Q runs Ice Cream Sandwich, is powered by a dual-core OMAP4460, with 16GB of storage. Google will be shipping the Nexus Q in the next 2-3 weeks for a list price of $299. It’s thrice the price of an Apple TV, but it packs lots more features.

Courtesy:http://www.pcworld.com/article/258414/google_unveils_nexus_q_streaming_media_player.html

Google's Nexus 7 tablet

Well, it looks like the rumors are true. This morning, just ahead of 2012's Google I/O initial keynote,Android Police dug up what looks to be an official press shot of Mountain View's unannounced 7-inch tablet, aptly named the Nexus 7. As opposed to our previous sneak peek, this shot shows what is most assuredly the home screen for Jelly Bean, and comes directly from Google's servers. Glad we got that settled. Now we just need to know about the actual hardware inside -- good thing we've only gotta wait another hour or so to find out.
Update: Hoo, boy! The hits keep comin.' The good golks at Modaco managed to grab screenshots for the sale page of the Nexus 7, replete with screenshots and specs. Turns out, the tablet has a 1280x800 IPS display coated in "scratch-resistant Corning glass," which we presume is of the Gorilla variety, plus a front-facing, 1.2-megapixel camera. Within its 198.5 x 120 x 10.45mm case lies either 8 ($199) or 16GB ($249) of storage, plus 1GB of RAM, and NVIDIA's quad-core Tegra 3 SoC. Connectivity comes courtesy of GPS, Bluetooth, 802.11b/g/n WiFi and Micro USB, plus it's got NFC for all your Android Beaming needs. Rounding things out is a 4325mAh battery and the usual spate of sensors: accelerometer, magnetometer, and a gyroscope. Want more? A video all about Jelly Bean and the new hardware running it awaits after the break, or you can hop on over to the source to order one for yourself.


This Is Google’s New Nexus 7 Android Tablet for $199

In the final minutes leading up to the Google’s annual developer conference in San Francisco, Google confirmed the release of its tablet Nexus 7, which will run on Android 4.1 Jelly Bean.
The Nexus 7 comes in both 8GB and 16GB models, featuring a 7-inch 1280×800 HD display (216 ppi), back-lit IPS display, scratch-resistant Croning glass, a quad-core Nvidia Tegra 3 processor, a 12-core CPU and a 4325 mAh battery that promises about 8 hours of power use. The devices also tout near field communications (NFC) technology with Google Wallet, GPS and a 1.2MP front-facing camera.
The specs make the Nexus 7 a visually rich platform for watching movies, playing games and reading e-magazines. The device was built by PC manufacturer Asus.
The 8GB model will cost $199, while the 16GB device will be priced at $249. Google is taking pre-orders now and will ship the Nexus 7 in the next two weeks.
A picture of the Nexus 7 Android device was spotted earlier in the day via Google’s Play Store servers. Images of the device’s hardware have surfaced online already, but this is the first time we’ve been able to see the interface.

Courtesy:http://mashable.com/2012/06/27/nexus-7-google-table/

Google introduces ‘Nexus 7′ tablet

At its Google I/O developers conference at Moscone Center Wednesday morning, Google was to introduce its much-rumored new tablet computer. Here’s a report from our friends at Bloomberg News from a video posted on YouTube. Come back for more details and insights on the Google I/O announcement from Chronicle tech reporter Casey Newton:
By Brian Womack
Google Inc. unveiled a handheld computer called the Nexus 7 that features a 7-inch screen and is designed to help the company vie with Apple Inc. and Microsoft Corp. in the surging market for tablets.
The Nexus 7 will feature Google’s Android operating system, according to a video posted on the YouTube website. The company is expected to unveil other information about the product at its San Francisco event.
Google is on the hunt for ways to fuel sales of tablets, a market that may almost double this year to 118.9 million units, according to Gartner Inc. Though Android has grabbed more than half of the smartphone market, tablets with the software have won less than half the iPad’s share, and will face new pressure from Microsoft, which unveiled its own tablet last week.
“The tablet market is a major challenge for Google at this point,” said Clayton Moran, a Delray Beach, Florida-based analyst at Benchmark Co. “They need to have a competitive product with the iPad.”
The Google tablet will also showcase Android’s latest iteration, which is named Jelly Bean, according to the video.
This would also be the first tablet to get Google’s Nexus designation. Google has worked with manufacturers such as Samsung in the past for Nexus smart phones to highlight the best features of Android software. The processor in the new tablet will be provided by Nvidia Corp., one of the people familiar with the matter said.

Jelly Bean Android Google

Web giant Google has revealed its newest version of its Android operating system, by rolling out a 'Jelly Bean' statue on its front lawn at its headquarters in Mountain View, California. 

The Jelly Bean statue now joins other dessert-themed statues on Google's lawn, including an Ice Cream Sandwich, Donut, Cupcake, andEclair, all representing the different versions of Android. 

According to ABC News, Google will share the details on Jelly Bean at its Google I/O conference in San Francisco, where the firm will preview and demonstrate the software for developers and press; no real details have been shared on what the operating system will include. 

The current version of Android, called Ice Cream Sandwich or Android 4.0, was released last November which brought sweeping changes to the mobile phone and tablet operating system, and was released with a phone called the Samsung Galaxy Nexus, as it worked closely with Samsung to create a phone for the new software. 

Google also is expected to release a new Nexus device, except this time it is a tablet. Rumored to be called the Nexus 7, Google-watchers believe the tablet will have a 7-inch screen, a quad-core processor, made by Asus and will be priced at 199 dollars.

Courtesy :http://timesofindia.indiatimes.com/tech/personal-tech/computing/Google-makes-Jelly-Bean-official-with-statue/articleshow/14430857.cms

Vinod Kumar and Co

Vinod Kumar and Co

La Chocolat...

Advanced SSL configuration on IBM Http Server – Restrict unused HTTP methods and Verbose HTTP headers

Restricting unused HTTP methods

The HTTP method is supplied in the request line and specifies the operation that the client has requested. Browsers will generally just use two methods to access and interact with web sites; GET for queries that can be safely repeated and POST for operations that may have side effects. This means, we need to disable unused http methods. some of them are:(PUT|DELETE|TRACE|TRACK|COPY|MOVE|LOCK|UNLOCK|PROPFIND|PROPPATCH|SEARCH|MKCOL). Check with the application teams, if they need any of these methods for the application to work, before disabling them.

Testing before limiting http methods:

telnet josephamrithraj.mp 80
Trying xx.xx.xx.xx…
Connected to josephamrithraj.mp.
Escape character is ‘^]’.
OPTIONS / HTTP/1.1
Host: josephamrithraj.mp

HTTP/1.1 200 OK
Date: Thu, 14 Sep 2010 00:11:57 GMT
Server: Apache Web Server
Content-Length: 0
Allow: GET, HEAD, POST, PUT, DELETE, CONNECT, OPTIONS, PATCH, PROPFIND, PROPPATCH, MKCOL, COPY, MOVE, LOCK, UNLOCK, TRACE

Connection closed by foreign host.

your IBM http servers configuration file [httpd.conf] has 2 sections named main and virtualhost sections. you need to add the following code at both the places. I am explaining this task using mod_rewrite module. So, first make sure that… mod_rewrite is enabled. then, add the following lines to your http.conf files main and virtualhost sections.

RewriteEngine On
RewriteCond %{REQUEST_METHOD} ^(PUT|DELETE|TRACE|TRACK|COPY|MOVE|LOCK|UNLOCK|PROPFIND|PROPPATCH|SEARCH|MKCOL)
RewriteRule .* – [F]

Restart the web server after adding the above lines.


Now, when someone tried to use one of these http methods, they will get forbidden response since we specified [F] in the rewrite rule.

Testing after adding and restarting web server

telnet josephamrithraj.mp 80
Trying xx.xx.xx.xx...
Connected to josephamrithraj.mp.
Escape character is '^]'.
OPTIONS / HTTP/1.1
Host: josephamrithraj.mp

HTTP/1.1 200 OK
Date: Thu, 14 Sep 2010 00:15:44 GMT
Server: Apache Web Server
Content-Length: 0
Allow: GET, POST
Connection closed by foreign host.
Testing TRACE methods

telnet josephamrithraj.mp 80
Trying xx.xx.xx.xx...
Connected josephamrithraj.mp
Escape character is '^]'.
TRACE / HTTP/1.0
Host: josephamrithraj.mp
testing... <- ENTER twice HTTP/1.1 403 Forbidden Date: Thu, 14 Sep 2010 00:18:31 GMT Server: Apache Web Server Content-Length: 320 Connection: close Content-Type: text/html; charset=iso-8859-1

403 Forbidden

Forbidden

You don't have permission to access / on this server.


Connection closed by foreign host.
Disable verbose HTTP headers:


you might have seen this … when the web server [apache or ibm http server] throws errors page, sometimes it might show the information related to its version, build, modules etc. This is a security issue since you are giving away the details about your web server. for example, take a look at this:

Server: Apache/2.0.53 (Ubuntu) PHP/4.3.10-10ubuntu4 Server at xx.xx.xx.xx Port 80
The line in the server header expose important version and variant information about the Linux operating system and Apache software used on the machine, indirectly expose the possible security holes that are existed to the hackers, or at least make malicious attackers easier to identify your system for available attack points.
To ensure that the Apache HTTP web server does not broadcast this message to the whole world publicly and fix possible security issue, modify these two directives ServerTokes and ServerSignature in httpd.conf configuration file.

ServerTokens

This directive configures what you return as the Server HTTP response Header. The built-in default is ‘Full’ which sends information about the OS-type and compiled in modules. The recommended value is ‘Prod’ which sends the least information.

Options: Full | OS | Minor | Minimal | Major | Prod

“ServerTokens Prod”

This configures Apache to return only Apache as product in the server response header on very page request, suppressing OS, major and minor version info.

ServerSignature

This directive lets you add a line containing the server version and virtual host name to server-generated pages. It is recommended to set it to OFF and Set to "EMail" to also include a mailto: link to the ServerAdmin.

Options: On | Off | EMail

“ServerSignature Off”

This instructs Apache not to display a trailing footer line under server-generated documents, which displays server version number, ServerName of the serving virtual host, email setting etc..


Courtesy:http://josephamrithraj.wordpress.com/2010/09/16/advanced-ssl-configuration-on-ibm-http-server-restrict-unused-http-methods-and-verbose-http-headers/

Advanced SSL configuration on IBM Http Server – Client Authentication and Ciphers

The Advanced SSL Configuration settings are

Client Authentication
Setting Ciphers
SSL for multiple IP virtual Hosts
Client Authentication:

If you enable client authentication, the server validates clients by checking for trusted certificate authority, Known as CA root certificates in the local key database. To enable client authentication, you need to use SSLClientAuth directive. The options to use with this stanza are:

None – The server requests no client certificate from the client.
Optional – The server requests, but does not require, a client certificate. If presented, the client certificate must prove valid.
Required – The server requires a valid certificate from all clients and returns a 403 status code if no certificate is present.
Required_reset – The server requires a valid certificate from all clients, and if no certificate is available, the server sends an SSL alert to the client. This enables the client to understand that the SSL failure is client-certificate related, and will cause browsers to re-prompt for client certificate information on subsequent access. make sure you have GSKit version 7.0.4.19 or later when you choose this option.
For example, If i want all the clients to be authenticated, then i need to add the following stanza
SSLClientAuth required

Ciphers

We set the cipher specification to use during secure transactions. The specified cipher specifications validate against the level of the Global Security Kit (GSK) toolkit that is installed on your system. Invalid cipher specifications cause an error to log in the error log. If the client issuing the request does not support the ciphers specified, the request fails and the connection closes to the client. IBM HTTP Server has a built-in list of cipher specifications to use for communicating with clients over Secure Sockets Layer (SSL). The actual cipher specification that is used for a particular client connection is selected from those which are supported by both IBM HTTP Server and the client.

Some cipher specifications provide a weaker level of security than others, and might need to be avoided for security reasons. Some of the stronger cipher specifications are more computationally intensive than weaker cipher specifications and might be avoided if required for performance reasons. When an SSL connection is established, the client (web browser) and the web server negotiate the cipher to use for the connection. The web server has an ordered list of ciphers, and the first cipher in that list which is supported by the client will be selected.

IBM HTTP Server supports the following SSL ciphers: SSLv3 and TLS and SSLv2

IBM recommends the following setting, keeping in mind both strong security and performance

## SSLv3 128 bit Ciphers
SSLCipherSpec SSL_RSA_WITH_RC4_128_MD5
SSLCipherSpec SSL_RSA_WITH_RC4_128_SHA

## FIPS approved SSLV3 and TLSv1 128 bit AES Cipher
SSLCipherSpec TLS_RSA_WITH_AES_128_CBC_SHA

## FIPS approved SSLV3 and TLSv1 256 bit AES Cipher
SSLCipherSpec TLS_RSA_WITH_AES_256_CBC_SHA

## Triple DES 168 bit Ciphers
## These can still be used, but only if the client does
## not support any of the ciphers listed above.
SSLCipherSpec SSL_RSA_WITH_3DES_EDE_CBC_SHA

## The following block enables SSLv2. Excluding it in the presence of
## the SSLv3 configuration above disables SSLv2 support.

## Uncomment to enable SSLv2 (with 128 bit Ciphers)
#SSLCipherSpec SSL_RC4_128_WITH_MD5
#SSLCipherSpec SSL_RC4_128_WITH_SHA
#SSLCipherSpec SSL_DES_192_EDE3_CBC_WITH_MD5
View the Ciphers which the server uses for Secure transactions

Set the LogLevel to info in the configuration file. Look in the error log for messages in this format: TimeStamp info_message mod_ibm_ssl: Using Version 2/3 Cipher: longname|shortname. The order that the cipher specifications are displayed in the error log from top to bottom represents the attempted order of the cipher specifications.

View the Ciphers were used for negotiating a connection

You can use the following LogFormat directive to view and log the SSL cipher negotiated for each connection:

LogFormat “%h %l %u %t \”%r\” %>s %b \”SSL=%{HTTPS}e\” \”%{HTTPS_CIPHER}e\” \”%{HTTPS_KEYSIZE}e\” \”%{HTTPS_SECRETKEYSIZE}e\”" ssl_common

CustomLog logs/ssl_cipher.log ssl_common

This logformat will produce an output to the ssl_cipher.log that looks something like this:

127.0.0.1 – - [01/Sep/2010:00:02:05 -0800] “GET / HTTP/1.1″ 200 1582 “SSL=ON” “SSL_RSA_WITH_RC4_128_MD5″ “128″ “128″

SSL for multiple IP virtual hosts

When you do not define an SSL directive on a virtual host, the server uses the directive default. You can define different (SSL) options for various virtual hosts. To enable SSL:

Specify the SSLEnable directive on the virtual host stanza in the configuration file, to enable SSL for a virtual host.
Specify a Keyfile directive and
Any SSL directives you want enabled for that particular virtual host.
Restart the server.
With all the above security options enabled, your virtual host may look like this:



SSLEnable

Keyfile keyfile.kdb

SSLCientAuth required

## SSLv3 128 bit Ciphers

SSLCipherSpec SSL_RSA_WITH_RC4_128_MD5

SSLCipherSpec SSL_RSA_WITH_RC4_128_SHA

## FIPS approved SSLV3 and TLSv1 128 bit AES Cipher

SSLCipherSpec TLS_RSA_WITH_AES_128_CBC_SHA

## FIPS approved SSLV3 and TLSv1 256 bit AES Cipher

SSLCipherSpec TLS_RSA_WITH_AES_256_CBC_SHA

## Triple DES 168 bit Ciphers

## These can still be used, but only if the client does not support any of the ciphers listed above.

SSLCipherSpec SSL_RSA_WITH_3DES_EDE_CBC_SHA

## The following block enables SSLv2.
## Excluding it in the presence of the SSLv3 configuration above disables SSLv2 support.

## Uncomment to enable SSLv2 (with 128 bit Ciphers)

#SSLCipherSpec SSL_RC4_128_WITH_MD5

#SSLCipherSpec SSL_RC4_128_WITH_SHA

#SSLCipherSpec SSL_DES_192_EDE3_CBC_WITH_MD5



Courtesy:http://josephamrithraj.wordpress.com/2010/09/04/advanced-ssl-configuration-on-ibm-http-server-client-authentication-and-ciphers/

Virtual Users with SAML in WebLogic

A small blogpost how you can use virtual users on your SAML Service Provider WebLogic Server. A virtual user is a user who is authenticated on the SAML Identity Provider and this user is transfered ( with all his attributes and roles )  in a SAML Token to the Service Provider, this user does not need to exists on the WebLogic server of the Service Provider.
Before you can use this feature you need to setup SAML 2.0 SSO on your WebLogic Domain. You can follow this blogpost for all the instructions. You can also do this with Web Services but then you need to follow this guide.

First we need to enable Generate Attributes on the Identity Provider Side.
Go to the myrealm security realm ->  Providers -> Credentials Mapping -> your SAML 2.0 Credential Mapping Provider -> Provider Specific.
Also do this on the imported Service Provider Partner located at the Management tab of your SAML 2.0 Credential Mapping Provider. Open the Service Provider Partner and also enable here Generate Attributes.

Next step is to configure the SAML Service Provider.
Go to the myrealm security realm ->  Providers ->  Authentication -> your SAML 2.0 Identity Assertion Provider -> Management Tab.
Open your imported Identity Provider Partner configuration.
Enable Virtual User and also enable Process Attributes.

Now we need to add an extra WebLogic SAML Authentication Provider. This provider will process the virtual user SAML token with all its attributes and roles.
Set the Control Flag to Sufficient also change the other authentication provider from Required to Sufficient.

Courtesy:http://biemond.blogspot.com/2011/09/virtual-users-with-saml-in-weblogic.html

How to collect performance data on Linux

Collect the following information when high CPU consumption is with IBM Java process:
Enable garbage collection trace to see whether Java garbage collection is thrashing if possible. If you want to enable Java garbage collection trace on IBM WebSphere Application Server, please refer to the following document: Enabling verbose garbage collection (verbosegc) in WebSphere application Server


Run the following command:

top -d delaytime -c -b > top.log

Where delaytime is the number of seconds to delay. This must be 60 seconds or greater, depending on how soon the failure is expected.


Create a script file, vmstat.sh with the following content:

#vmstat.sh
#output file name
VMSTAT_LOG=$1
LIMIT=288
#sleep for 5 miniutes
SLEEP_TIME=300
while true
do
i=0
echo >$VMSTAT_LOG
while [ $i -le "$LIMIT" ];
do
date >> $VMSTAT_LOG;
vmstat 5 12 >> $VMSTAT_LOG;
i=`expr $i + 1`;
sleep $SLEEP_TIME;
done
done

Create a script, ps.sh with the following content:

#ps.sh
#output file name
PS_LOG=$1
LIMIT=288
#sleep for 5 miniutes
SLEEP_TIME=300
while true
do
i=0
echo >$PS_LOG
while [ $i -le "$LIMIT" ];
do
date >> $PS_LOG;
ps -eLf >> $PS_LOG;
i=`expr $i + 1`;
sleep $SLEEP_TIME;
done
done

Run the scripts:

./ps.sh ps_eLf.log
./vmstat.sh vmstat.log

Notes: . The scripts ps.sh and vmstat.sh, as provided, roll over every 24 hours. . You might need to modify the scripts to meet your needs. . The preceding scripts will run forever. After the error condition is reached, you will have to terminate them.


When high CPU consumption occurs, collect the following logs:

netstat -an > netstat1.out


If the Web server is remote, run the following on the Web server system:

netstat -an > netstatwebserver1.out


Run the following:

kill -3 [PID_of_problem_JVM]


The kill -3 commands create javacore*.txt files

Note: If you are not able to determine which JVM process is experiencing the high CPU usage then you should issue the kill -3 PID for each of the JVM processes.



Wait two minutes.


Run the following:

kill -3 [PID_of_problem_JVM]


Wait two minutes.


Run the following:

kill -3 [PID_of_problem_JVM]


Wait two minutes.


Run the following:

netstat -an > netstat2.out



If the Web server is remote, run the following on the Web server system:

netstat -an > netstatwebserver2.out



If you are unable to generate javacore files, then perform the following:

kill -11 [PID_of_problem_JVM]

WARNING: kill -11 will terminate the JVM process, produce a core file, and possibly a javacore.


Review all output files and collect the following files for IBM Performance Analysis Tool for Java for Linux


ps_eLf.log
javacore*.txt files

Courtesy:http://wasissues.blogspot.com/

Configuring OpenLDAP as a SiteMinder Policy Store

SiteMinder supports OpenLDAP for use as a Policy Store. OpenLDAP provides a freely available, replicated directory that can be used as a redundant store for SiteMinder’s configuration information. Unfortunately, the SiteMinder documentation covering how to configure OpenLDAP is at best incomplete and at worst incorrect. This article breaks down the steps required to enable OpenLDAP to be a Policy Store and configure the Policy Server to leverage the directory. Keep in mind that SiteMinder currently only supports OpenLDAP 2.3.x. This means that only Master/Slave replication is supported. While this is sufficient to ensure the availability of the Policy Store, if the Master directory is down, no policy or key updates can be performed. This article also assumes that the Key Store is set to the default setting of using the Policy Store as the location to store key information. Switch the directory paths outlined below to use backslashes if these steps are being performed on Windows.

1. Download and Install OpenLDAP
This article does not cover the specific details on how to build and install OpenLDAP. The details for this can be found on the OpenLDAP site. A quick start guide is located there as well.

2. Download the OpenLDAP Schema Files for SiteMinder
OpenLDAP is considered a “Tier 2″ directory for SiteMinder. As such, the ability to configure the directory as a Policy Store is not automated. In order to obtain the needed schema files for the Policy Store, the “CA SiteMinder Tier 2 Directories- ESD Only” package must be downloaded. To download this file (current as of 10/12/2011):

1. Log in to the Technical Support Site
2. Click “Download Center” in the lefthand navigation
3. Type siteminder into the “Select a Product” field
4. Select the listed SiteMinder product
5. Select 12.0 in the “Select a Release” drop-down
6. Select SP3 in the “Select a Gen level” drop-down
7. Click the [GO] button
8. Scroll down to the bottom of the list of returned downloads
9. Download and unzip the “CA SiteMinder Tier 2 Directories- ESD Only” download to the Policy Server

3. Configure OpenLDAP To Support the SiteMinder Policy Store
The OpenLDAP server requires manual configuration to support its use as a SiteMinder Policy Store. The following steps are required:

3a. Copy the Policy Store schema files into the OpenLDAP schema directory
3b. Include the SiteMinder Policy Store schema files in the OpenLDAP configuration
3c. Ensure that SiteMinder can detect it is an OpenLDAP Policy Store
3d. Create the base Policy Store structure
3e. Restart OpenLDAP

Note that these instructions assume that the install location for OpenLDAP is under the /usr/local path and the default directories are used. For this example, the root of the directory is “dc=company,dc=com” for the location of the Policy Store. These steps will need to be modified if a different path or directory structure is used.

3a. Copy the Policy Store schema files into the OpenLDAP schema directory
The OpenLDAP schema needs to be extended to support the SiteMinder Policy Store objects. This is done by copying the schema files to the server and adding them into the slapd.conf configuration file. To copy the schema files:
.........
More Here

Courtesy:http://www.coreblox.com/blog/2011/10/configuring-openldap-as-a-siteminder-policy-store/

SiteMinder federation to SharePoint 2010

This paper shows how to configure identity federation between CA SiteMinder and Microsoft SharePoint 2010, using the CA Federation Manager Add-on for SiteMinder. Two scenarios are presented. The first is an intra-organizational scenario that is useful where SiteMinder, the user accounts, and SharePoint are all maintained within the enterprise. The second is a traditional identity federation scenario where the user accounts are maintained outside of the enterprise hosting SharePoint. A federated identity environment features the following advantages:

· Helps control Information Technology (IT) costs and gain efficiencies. Federation targets areas that require lots of manual processes such as user account management, and access management. These manual processes are the focus of cost control.

· Enables compliance with expanding regulatory requirements. A standards-based identity federation can increase security of websites and portals and enable an organization to identify and authenticate a user only once. The organization can then use that identity information to access multiple systems which can include websites of external partners and various portals.

While both scenarios create a federated identity environment, the techniques or methodology used in the two lab scenarios is different. The two lab scenarios are:

1. Lab scenario 1 - Intra-organization scenario. In this lab scenario, SiteMinder is the Trusted Identity Provider for SharePoint and authenticates users to one or more user directories maintained within the organization. Once authenticated, these users (which may be employees, partners or customers) can access SharePoint as well as other applications protected by SiteMinder. This lab scenario uses the CA Federation Manager Add-on to SiteMinder (a.k.a., SiteMinder Federation Security Services) to generate a WS-Federation 1.0 token that is in turn read by SharePoint 2010.

2. Lab scenario 2 - Cross-organization, traditional Federation scenario. In this lab scenario, SiteMinder is deployed at the external partner organization, along with the CA Federation Manager Add-on, and Microsoft AD FS 2.0 is deployed within the enterprise where SharePoint is hosted. SiteMinder authenticates the partners to the partner organization's user directory and generates a SAML 2.0 token. AD FS 2.0, which acts as a security token service, translates the SAML 2.0 token into a WS-Federation token for use with SharePoint. In this lab scenario, we also configure SharePoint's native claims-based Windows provider to illustrate how employees within the enterprise could access SharePoint alongside partners who use the federated approach (The claims-based Windows provider is listed along with the other Identity Providers configured in ADFS 2.0, in the lab it is identified with as ADFSMachine.CompanyA.com).

Courtesy:http://interopvendoralliance.org/labs/siteminder-federation-to-sharepoint-2010.aspx

SiteMinder Overview

CA SiteMinder is enterprise level web access management software which allows organizations to manage their web users and help control their access to applications, portals and web services.

SiteMinder consists of two core components:

Policy Server:

The Policy Server provides policy management, authentication, authorization, and accounting.

SiteMinder Agents:

Integrated with a standard Web server or application server, SiteMinder Agents enable SiteMinder to manage access to Web applications and content according to predefined security policies.

How CA SiteMinder Works:

The process for securely accessing web applications:

1. User attempts to access a protected resource.

2. User is challenged for credentials and presents them to the CA SiteMinder web agent or to the Secure Proxy Server.

3. The user’s credentials are passed to the Policy Server.

4. The user is authenticated against the appropriate user store.

5. The Policy Server evaluates the user’s entitlements and grants access.

6. User profile and entitlement information is passed to the application.

7. The user gets access to the secured application, which delivers customized content.

Courtesy:http://webspheresolution.wordpress.com/2011/09/29/siteminder-overview/