<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v5.9.2 (http://www.squarespace.com/) on Wed, 10 Mar 2010 07:48:44 GMT--><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:rss="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:cc="http://web.resource.org/cc/"><rss:channel rdf:about="http://www.shutuplaura.com/journal/"><rss:title>Identity Rants &amp; Raves</rss:title><rss:link>http://www.shutuplaura.com/journal/</rss:link><rss:description></rss:description><dc:language>en-US</dc:language><dc:date>2010-03-10T07:48:44Z</dc:date><admin:generatorAgent rdf:resource="http://www.squarespace.com/">Squarespace Site Server v5.9.2 (http://www.squarespace.com/)</admin:generatorAgent><rss:items><rdf:Seq><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/27/a-book-every-identity-person-should-read.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/19/minasi-conference-2010.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/18/be-it-known-that-lha-consulting-works-with-some-fantastic-pe.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/16/adfs-gets-rbac-y.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/16/openid-welcomes-new-board-member.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/14/amazon-web-services-amp-adfs.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/13/federated-identity-management-legal-task-force.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/12/the-legal-thicket-of-federated-identity-management.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/12/ad-lds-for-windows-7.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2010/1/7/sharepoint-identity-claims-oh-my.html"/></rdf:Seq></rss:items></rss:channel><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/27/a-book-every-identity-person-should-read.html"><rss:title>A Book Every Identity Person Should Read</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/27/a-book-every-identity-person-should-read.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-27T14:23:47Z</dc:date><dc:subject>ADFS Identity tech</dc:subject><content:encoded><![CDATA[<p><a href="http://www.amazon.com/Understanding-Windows-CardSpace-Introduction-Challenges/dp/0321496841/ref=sr_1_3?ie=UTF8&amp;s=books&amp;qid=1264602180&amp;sr=8-3">http://www.amazon.com/Understanding-Windows-CardSpace-Introduction-Challenges/dp/0321496841/ref=sr_1_3?ie=UTF8&amp;s=books&amp;qid=1264602180&amp;sr=8-3</a></p>
<p>Understanding Windows Cardspace - An Introduction to the Concepts and Challenges of Digital Identities. Written by the brilliant Mssrs. <a href="http://blogs.msdn.com/vbertocci/">Vittorio Bertocci</a>, Caleb Baker &amp; Garrett Serack.</p>
<p>I'll admit that this one was relegated to "Page 7 of 8" on my list of unread Kindle titles for many moons, and I just pulled it up while working out on the elliptical last night. (Best use case <em>ever</em> for the Kindle, I might add - I can stay on the elliptical for an hour at a decent clip without getting bored, since I'm reading.) I think the reason I hadn't gotten 'round to it was because...I'm an enterprise Identity lady, and I just haven't quite gotten my brain around use cases for Cardspace &amp; InfoCard in a corporate environment yet. (Hi <a href="http://imav8n.wordpress.com">BP</a>. Hi <a href="http://channel9.msdn.com/shows/Identity/ADFS-20-RC-is-Here/">Matt</a>.) Now, in the consumer identity space? Boy howdy will Cardspace be a killer thing...I'm just not quite sure where it fits into my happy world of AD domain controllers and ADFS federation agreements yet, still thinking on that one.</p>
<p>But even if you're of a similar mindset/background, <strong>you want to read this book</strong>. It's kinda Bruce Schneier-esque in its treatment of capital "I" Identity as&nbsp;a concept - how it has evolved on the Internet, what the problems and attack vectors are, and how to think about them conceptually as well as technically. And more to the point, it does all of this in a ridiculously well-written manner (again with the parallels to Schneier). Unlike a lot of technical books that are dry to the point of being a good substitute for Ambien at night, this one is actually erudite, occasionally funny, and an entirely enjoyable read.</p>
<p>So go buy it. And pre-order <a href="http://www.amazon.com/Programming-Windows-Identity-Foundation-Dev/dp/0735627185/ref=sr_1_3?ie=UTF8&amp;s=books&amp;qid=1264602713&amp;sr=8-3">Vittorio's WIF book</a> as well while you're at it.</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/19/minasi-conference-2010.html"><rss:title>Minasi Conference 2010</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/19/minasi-conference-2010.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-19T00:34:20Z</dc:date><dc:subject>ADFS Active Directory Community tech</dc:subject><content:encoded><![CDATA[<p>For all those interested, Mark Minasi’s annual conference is coming up in May of this year in Virginia Beach. Yours truly will be there doing an ADFS session!</p>  <p>Details as follows:</p>  <p>Minasi Conference 2010   <br />May 2nd – May 5th     <br />Virginia Beach, VA, USA </p>  <p>The conference runs from Sunday May 2nd until Wednesday May 5th and has some of the world’s top speakers. </p>  <p>The Minasi conference is unlike any other tech conference you’ve attended before due to its intimacy, favourable student:lecturer ratio, variety of topics and quality of instructors. </p>  <p>The conference is organized and staffed by volunteers from Mark Minasi’s forum and includes well known veteran lecturers like Mark Minasi, Rhonda Layfield, Todd Lammle, Roger Grimes, Microsoft MVP’s and author’s such as Aidan Finn, Nathan Winters and Eric Rux and forum members who just want to share what they’re doing. </p>  <p>The conference has enjoyed some prestigious special guest lecturers and this year is no exception. The chance to rub elbows and ask questions in such a small environment is found only at the Minasi conference. Previous years special guests have included: </p>  <p>-Cisco Guru and all around nice guy, Todd Lammle   <br />-All things Security (now featuring the Cloud), Steve Riley    <br />-Group Policy Experts Jeremy Moskowitz and Darren Mar-Elia    <br />-Super Scripter, Don Jones    <br />-Internet Fixer, Roger Grimes </p>  <p>We invite you to join us both online and in person. Take a look at the website for loads more info and to register – </p>  <p><a href="http://www.minasiconference.com">www.minasiconference.com</a>&#160;&#160; </p>  <p>Pre-Conference Event </p>  <p>For the 2010 Conference we are pleased to offer our first Pre-Conference session. </p>  <p>The aim is to provide a 4 hour event at a small additional cost which will cover a topic that is closely related to the main conference but just slightly different! </p>  <p>In this case Todd Lammle will lead the session on the morning of Sunday 2nd May from 08:30 until 12:30. </p>  <p>The topic is “Configuring Basic Cisco and Router Configurations”   <br />All students would need is their own laptop and we will provide a free copy of Todd’s latest book as well as very slick router and switch simulator that you get to keep. </p>  <p>We are currently working to flesh out the details of this session and will update with a full agenda shortly. </p>  <p>This pre-con session will cost $85 which includes the Book, The Simulator, a light breakfast, Lunch and of course the 4 hours tuition! </p>  <p>For more information check the conference website in the Pre-Conference section. </p>  <p>I look forward to seeing you in Virginia! </p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/18/be-it-known-that-lha-consulting-works-with-some-fantastic-pe.html"><rss:title>Be it known that LHA Consulting works with some fantastic people.</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/18/be-it-known-that-lha-consulting-works-with-some-fantastic-pe.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-18T17:29:38Z</dc:date><dc:subject>Community personal</dc:subject><content:encoded><![CDATA[<p>(Non-technical post to follow.)</p>  <p>So a placement firm that I’ve done some work for, <a href="http://www.psicareers.com" target="_blank">Pro Search Inc.</a> in Portland Maine, has a nice little charitable arm as part of their business model:</p>  <blockquote>   <p>“<em>About the Pro Search Gives Back Program</em>:&#160; Each Quarter, on behalf of our clients, Pro Search donates 5 cents for every hour our temporary and contract employees work to community organizations and not-for-profits in Southern Maine.&#160;&#160;&#160;&#160; In 2009, thanks to the hard work and dedication of you and other Pro Search contractors, this totaled over $11,000.”</p> </blockquote>  <p>Now, clearly all eyes are on the ongoing humanitarian efforts in Haiti right now, and these guys are no exception. Come to find that one of their contractors is a Haitian immigrant with significant family base still in Port-au-Prince. As a directed giving measure, Pro Search is paying to fly this person and his brother home in order to re-connect with family and friends, and to assist in the relief efforts.</p>  <p>Yes indeed. I work with some truly outstanding people.</p>  <p>Now, go give some money to the relief organization of your choice. Mine is the <a href="http://www.salvationarmypendel.org" target="_blank">Salvation Army</a>, since having worked in IT Operations for them I know first-hand what percentage of every donation dollar goes directly to relief efforts instead of administrative overhead, and they’re ridiculously efficient…something like 85 cents on the dollar goes into the mission. But there are innumerable others…go get in the game.</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/16/adfs-gets-rbac-y.html"><rss:title>ADFS gets RBAC-y</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/16/adfs-gets-rbac-y.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-16T21:52:35Z</dc:date><dc:subject>ADFS Identity tech</dc:subject><content:encoded><![CDATA[<p><a title="http://blogs.msdn.com/card/archive/2010/01/08/introduction-to-token-issuance-authorization-in-ad-fs-2-0-rc.aspx" href="http://blogs.msdn.com/card/archive/2010/01/08/introduction-to-token-issuance-authorization-in-ad-fs-2-0-rc.aspx">http://blogs.msdn.com/card/archive/2010/01/08/introduction-to-token-issuance-authorization-in-ad-fs-2-0-rc.aspx</a></p>  <p>Token Issuance Authorization, new feature in the ADFSv2 release candidate. Allows the Identifying Party STS to control which users are authorized to receive tokens, thus decoupling both AuthN as well as certain aspects of AuthZ from the Relying Party.</p>  <p>From the blog post, in describing a scenario in which Contoso users are accessing a Fabrikam online store:</p>  <blockquote>   <p><em>With the new token issuance authorization feature, the administrator of the Contoso STS can create a policy that authorizes token issuance to Fabrikam based on membership in an Active Directory security group. This implements a form of role based access control (RBAC) at the STS. The administrators of the Fabrikam online store need not be aware of the details of the [Contoso] access control policy and no action is required from the vendor if the [Contoso] policy changes. </em></p></blockquote>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/16/openid-welcomes-new-board-member.html"><rss:title>OpenID Welcomes new Board Member</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/16/openid-welcomes-new-board-member.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-16T20:34:07Z</dc:date><dc:subject>ADFS Community Identity personal</dc:subject><content:encoded><![CDATA[<p><a title="http://eternallyoptimistic.com/2010/01/13/openid-bound/" href="http://eternallyoptimistic.com/2010/01/13/openid-bound/" target="_blank">http://eternallyoptimistic.com/2010/01/13/openid-bound/</a></p>  <p>The lovely Pamela Dingle, recent addition to the brilliant staff of <a href="http://pingidentity.com/" target="_blank">Ping Identity</a>, has joined the <a href="http://openid.net/foundation/" target="_blank">OpenID Foundation</a> as a board member representing Ping.</p>  <p>Congratulations!</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/14/amazon-web-services-amp-adfs.html"><rss:title>Amazon Web Services &amp;amp; ADFS</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/14/amazon-web-services-amp-adfs.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-14T01:05:13Z</dc:date><dc:subject>ADFS Identity tech</dc:subject><content:encoded><![CDATA[<p>David Chappell has released a <a href="http://go2.wordpress.com/?id=725X1342&amp;site=stvrly.wordpress.com&amp;url=http%3A%2F%2Fdownload.microsoft.com%2Fdownload%2F6%2FC%2F2%2F6C2DBA25-C4D3-474B-8977-E7D296FBFE71%2FEC2-Windows%2520SSO%2520v1%25200--Chappell.pdf" target="_blank">white paper</a> describing ways to connect your Amazon resources directly to your on-premises domain, followed by integration with ADFS1.1 and ADFSv2.</p>  <p>This flurry of Amazon-related ADFS goodness courtesy of <a href="http://go2.wordpress.com/?id=725X1342&amp;site=stvrly.wordpress.com&amp;url=http%3A%2F%2Fdownload.microsoft.com%2Fdownload%2F6%2FC%2F2%2F6C2DBA25-C4D3-474B-8977-E7D296FBFE71%2FEC2-Windows%2520SSO%2520v1%25200--Chappell.pdf" target="_blank">Steve Riley</a>, whom I’m incredibly happy to see speaking with such a passion around my favorite technology in the communities. :-)</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/13/federated-identity-management-legal-task-force.html"><rss:title>Federated Identity Management Legal Task Force</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/13/federated-identity-management-legal-task-force.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-13T02:01:10Z</dc:date><dc:subject>ADFS Community Identity tech</dc:subject><content:encoded><![CDATA[<p><a title="http://www.abanet.org/dch/committee.cfm?com=CL320041" href="http://www.abanet.org/dch/committee.cfm?com=CL320041" target="_blank">http://www.abanet.org/dch/committee.cfm?com=CL320041</a></p>  <p>There appears to be a list-serv that you can subscribe to without being an ABANet member. Some of the doc links don’t seem to be showing love, though the ones that do make for some pretty cool reading.</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/12/the-legal-thicket-of-federated-identity-management.html"><rss:title>The Legal Thicket of Federated Identity Management</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/12/the-legal-thicket-of-federated-identity-management.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-12T17:41:39Z</dc:date><dc:subject>ADFS Community Identity</dc:subject><content:encoded><![CDATA[<p><a href="http://www.ecommercetimes.com/story/The-Legal-Thicket-of-Federated-Identity-Management-69077.html">http://www.ecommercetimes.com/story/The-Legal-Thicket-of-Federated-Identity-Management-69077.html</a></p>
<p>In a nutshell - federated identity presents legal and audit challenges that all organizations will need to address before it gains wide acceptance. This is not news; fed zealots have been saying this for years. The thing that keeps me up at night has actually been the fact that the non-technical side of the house isn't ready for this, in my case thinking about auditors.</p>
<p>Current auditing process:</p>
<p>Auditor: "Tell me who has access to Resource Foo."</p>
<p>IT Guy: "Let me dump the ACL on that resource and parse through the groups...okay, here's a list of users."</p>
<p>Auditing in a federated world:</p>
<p>Auditor: "Tell me who has access to Resource Foo."</p>
<p>IT Guy: "The list of users I gave you last week, plus any one of my federated partners' users who presents me with a claim that reads "Marketing." No, I can't tell you who those people are. Yes, the list of who those people are can change from nanosecond to nanosecond without my being aware of it...erm, why are you crying, Mr. Auditor?"</p>
<p>It's these kinds of process problems that need to be resolved even moreso than the technical ones...though PKI is still a big technical one to contend with. :-)</p>
<p>One phrase that jumped off the page at me in the above article: "Recognizing the need to comprehensively address the legal issues raised by identity management, the American Bar Association has established a Federated Identity Management Legal Task Force to undertake such a project."</p>
<p>Shiny. Must Google.</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/12/ad-lds-for-windows-7.html"><rss:title>AD LDS for Windows 7</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/12/ad-lds-for-windows-7.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-12T15:05:41Z</dc:date><dc:subject>Active Directory Community Identity</dc:subject><content:encoded><![CDATA[<p>Now downloadable from:<br /><a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=a45059af-47a8-4c96-afe3-93dab7b5b658">http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=a45059af-47a8-4c96-afe3-93dab7b5b658</a></p>
<p>It's a long time in coming, but I'm so happy to see LDS back on the client!<br />&nbsp;</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2010/1/7/sharepoint-identity-claims-oh-my.html"><rss:title>SharePoint, Identity &amp; Claims, Oh My!</rss:title><rss:link>http://www.shutuplaura.com/journal/2010/1/7/sharepoint-identity-claims-oh-my.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2010-01-07T19:58:08Z</dc:date><dc:subject>ADFS Identity tech</dc:subject><content:encoded><![CDATA[<p>In keeping with this week's theme of the "rising claims tide", the SharePoint Identity team at MS have spun up a blog surrounding Identity options in the new SP2010 beta. First posting deals with enabling scenarios that we're already familiar with from previous versions of SharePoint: Forms-Based Auth, and anonymous access.</p>
<p>Watch this space for more on incorporating the claims model into the SP2010 Identity model:</p>
<p><a href="http://blogs.msdn.com/spidentity/" target="_blank">http://blogs.msdn.com/spidentity/</a></p>]]></content:encoded></rss:item></rdf:RDF>