<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v5.9.2 (http://www.squarespace.com/) on Fri, 12 Mar 2010 09:13:24 GMT--><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><title>Identity Rants &amp; Raves</title><link>http://www.shutuplaura.com/journal/</link><description></description><lastBuildDate>Wed, 10 Mar 2010 20:41:07 +0000</lastBuildDate><copyright></copyright><language>en-US</language><generator>Squarespace Site Server v5.9.2 (http://www.squarespace.com/)</generator><item><title>Claims-Based Identity &amp; Access Control Guide RTM (MS Patterns &amp; Practices)</title><dc:creator>Laura E. Hunter</dc:creator><pubDate>Wed, 10 Mar 2010 20:40:06 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/3/10/claims-based-identity-access-control-guide-rtm-ms-patterns-p.html</link><guid isPermaLink="false">69025:595923:6971493</guid><description><![CDATA[<p><a href="http://blogs.southworks.net/mwoloski/2010/03/05/claims-based-identity-and-access-control-guide-rtm/">http://blogs.southworks.net/mwoloski/2010/03/05/claims-based-identity-and-access-control-guide-rtm/</a></p>
<p>Go.</p>
<p>Download.</p>
<p>Read.</p>
<p>Become claims-enabled.</p>
<p>...</p>
<p>You done? Good.</p>
<p>Now federate.</p>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6971493.xml</wfw:commentRss></item><item><title>Shooting yourself in the foot with certificate rollover for fun and profit.</title><dc:creator>Laura E. Hunter</dc:creator><pubDate>Wed, 10 Mar 2010 17:16:52 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/3/10/shooting-yourself-in-the-foot-with-certificate-rollover-for.html</link><guid isPermaLink="false">69025:595923:6969386</guid><description><![CDATA[<p>Alternate title: this weekend's "Adventures in PKI."</p>
<p>So ADFS 2.0 has this new feature called automatic certificate rollover, which theoretically allows ADFS to generate new service certificates on your behalf when the old ones are close to expiring. This feature is turned on by default if you configure a new ADFS server or server farm via the Config Wizard on initial install.</p>
<p>In order to manually add/remove certs to a store, such as the token-signing cert store, you need to disable this feature first, so that ADFS will "let go" of the certificate management process. Drop to a PowerShell prompt:</p>
<p style="padding-left: 30px;">set-ADFSProperties -AutoCertificateRollover $false</p>
<p>Easy-peasy.</p>
<p style="padding-left: 30px;"><em>(Though I guarantee a slew of administrator-created issues when an admin disables this feature to add a new cert, forgets to turn it back on, and then forgets that they forgot. But we won't see whether I'm right about this for 12-24 months, since that's the average lifetime of a TS cert in most environments. Nevermind, the Internets will remember that I said it. :-))</em></p>
<p>Anyway. Shooting yourself in the foot with this feature? Is accomplished by doing the following:</p>
<ul>
<li>Have an ADFS server with this feature turned on.</li>
<li>Realize that you've done something stupid with the CDP URL on the TS cert, and you need to issue a new one.</li>
</ul>
<p>(watch very carefully, here comes the "Fire!" part)</p>
<ul>
<li>Open the Certificates MMC on the box and delete the TS cert from the computer's&nbsp;personal store...<em>without first removing it from the ADFS MMC</em>.</li>
</ul>
<p>What happens next? Is that you open the ADFS MMC and try to add the new TS cert with the fixed-up CDP. MMC barks at you, complaining that AutoCertRollover is on and you need to turn it off.</p>
<p>Drop out to a PowerShell prompt, issue the command above...</p>
<p>...</p>
<p>...</p>
<p>...and then realize upon staring at the output of the resultant error message, that the cmdlet is <em>checking for the presence of the old cert</em> before it will allow you to turn off AutoCertRollover. (And there's no -force switch to bypass that...unless it's undocumented...and called something other than -force, 'cos I tried that one.)</p>
<p>So. Where does this leave us?</p>
<ul>
<li>Can't install the new cert into the ADFS MMC without turning off auto cert rollover.</li>
<li>Can't turn off auto cert rollover because you deleted the old cert.</li>
</ul>
<p>At this point I truly hope you've got a backup of the cert you deleted, complete with private key. (Did you mark it as exportable? And we won't talk about the fact that I didn't, because it was just a test box and I didn't care that much.)</p>
<p>:-)</p>
<p>Tip from the ADFS Kitteh. Here to help you people.</p>
<p>Carry on.</p>
<p>&nbsp;</p>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6969386.xml</wfw:commentRss></item><item><title>Upcoming Speaking Events</title><dc:creator>Laura E. Hunter</dc:creator><pubDate>Wed, 10 Mar 2010 15:32:15 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/3/10/upcoming-speaking-events.html</link><guid isPermaLink="false">69025:595923:6968430</guid><description><![CDATA[<p>Wow, has it been a month? Sorry 'bout that, travel has gotten the better of me lately!</p>
<p>Anywho, your heroine will be speaking at the following upcoming User Group events and conferences about ADFS 2.0, ADFS troubleshooting, and a bit of SharePoint 2010 thrown in here and there for federated demo-y goodness.</p>
<p>Be there, or be hexagonal!</p>
<ul>
<li><a href="http://codecamp.phillydotnet.org/2010-1/default.aspx">Philly .NET Code Camp 2010.1</a> - Saturday April 10th, @ DeVry University in Ft. Washington PA</li>
<li><a href="http://www.windows-hied.org/15.html">Windows in Higher Education Conference 2010</a> - Monday April 12th-Wednesday April 14th in Redmond WA. <em>(Not 100%&nbsp;confirmed yet, more details as I get them.)</em></li>
<li><a href="http://www.tec2010.com/">The Experts Conference 2010</a> - Monday April 25th- Thursday April 28th in Los Angeles CA</li>
<li><a href="http://minasiconference.wordpress.com/">Minasi Conference 2010</a> - Monday May 3rd-Wednesday May 5th in Virginia Beach VA</li>
<li><a href="http://www.sharepointsaturday.org/philly/default.aspx">SharePoint Saturday Philadelphia 2010 </a>- Saturday May 8th, location TBA but most likely Ft. Washington DeVry</li>
</ul>
<p>See you all there!</p>
<p>&nbsp;</p>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6968430.xml</wfw:commentRss></item><item><title>A Book Every Identity Person Should Read</title><category>ADFS</category><category>Identity</category><category>tech</category><dc:creator>Laura E. Hunter</dc:creator><pubDate>Wed, 27 Jan 2010 14:23:47 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/1/27/a-book-every-identity-person-should-read.html</link><guid isPermaLink="false">69025:595923:6442339</guid><description><![CDATA[<p><a href="http://www.amazon.com/Understanding-Windows-CardSpace-Introduction-Challenges/dp/0321496841/ref=sr_1_3?ie=UTF8&amp;s=books&amp;qid=1264602180&amp;sr=8-3">http://www.amazon.com/Understanding-Windows-CardSpace-Introduction-Challenges/dp/0321496841/ref=sr_1_3?ie=UTF8&amp;s=books&amp;qid=1264602180&amp;sr=8-3</a></p>
<p>Understanding Windows Cardspace - An Introduction to the Concepts and Challenges of Digital Identities. Written by the brilliant Mssrs. <a href="http://blogs.msdn.com/vbertocci/">Vittorio Bertocci</a>, Caleb Baker &amp; Garrett Serack.</p>
<p>I'll admit that this one was relegated to "Page 7 of 8" on my list of unread Kindle titles for many moons, and I just pulled it up while working out on the elliptical last night. (Best use case <em>ever</em> for the Kindle, I might add - I can stay on the elliptical for an hour at a decent clip without getting bored, since I'm reading.) I think the reason I hadn't gotten 'round to it was because...I'm an enterprise Identity lady, and I just haven't quite gotten my brain around use cases for Cardspace &amp; InfoCard in a corporate environment yet. (Hi <a href="http://imav8n.wordpress.com">BP</a>. Hi <a href="http://channel9.msdn.com/shows/Identity/ADFS-20-RC-is-Here/">Matt</a>.) Now, in the consumer identity space? Boy howdy will Cardspace be a killer thing...I'm just not quite sure where it fits into my happy world of AD domain controllers and ADFS federation agreements yet, still thinking on that one.</p>
<p>But even if you're of a similar mindset/background, <strong>you want to read this book</strong>. It's kinda Bruce Schneier-esque in its treatment of capital "I" Identity as&nbsp;a concept - how it has evolved on the Internet, what the problems and attack vectors are, and how to think about them conceptually as well as technically. And more to the point, it does all of this in a ridiculously well-written manner (again with the parallels to Schneier). Unlike a lot of technical books that are dry to the point of being a good substitute for Ambien at night, this one is actually erudite, occasionally funny, and an entirely enjoyable read.</p>
<p>So go buy it. And pre-order <a href="http://www.amazon.com/Programming-Windows-Identity-Foundation-Dev/dp/0735627185/ref=sr_1_3?ie=UTF8&amp;s=books&amp;qid=1264602713&amp;sr=8-3">Vittorio's WIF book</a> as well while you're at it.</p>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6442339.xml</wfw:commentRss></item><item><title>Minasi Conference 2010</title><category>ADFS</category><category>Active Directory</category><category>Community</category><category>tech</category><dc:creator>Laura E. Hunter</dc:creator><pubDate>Tue, 19 Jan 2010 00:34:20 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/1/19/minasi-conference-2010.html</link><guid isPermaLink="false">69025:595923:6363147</guid><description><![CDATA[<p>For all those interested, Mark Minasi’s annual conference is coming up in May of this year in Virginia Beach. Yours truly will be there doing an ADFS session!</p>  <p>Details as follows:</p>  <p>Minasi Conference 2010   <br />May 2nd – May 5th     <br />Virginia Beach, VA, USA </p>  <p>The conference runs from Sunday May 2nd until Wednesday May 5th and has some of the world’s top speakers. </p>  <p>The Minasi conference is unlike any other tech conference you’ve attended before due to its intimacy, favourable student:lecturer ratio, variety of topics and quality of instructors. </p>  <p>The conference is organized and staffed by volunteers from Mark Minasi’s forum and includes well known veteran lecturers like Mark Minasi, Rhonda Layfield, Todd Lammle, Roger Grimes, Microsoft MVP’s and author’s such as Aidan Finn, Nathan Winters and Eric Rux and forum members who just want to share what they’re doing. </p>  <p>The conference has enjoyed some prestigious special guest lecturers and this year is no exception. The chance to rub elbows and ask questions in such a small environment is found only at the Minasi conference. Previous years special guests have included: </p>  <p>-Cisco Guru and all around nice guy, Todd Lammle   <br />-All things Security (now featuring the Cloud), Steve Riley    <br />-Group Policy Experts Jeremy Moskowitz and Darren Mar-Elia    <br />-Super Scripter, Don Jones    <br />-Internet Fixer, Roger Grimes </p>  <p>We invite you to join us both online and in person. Take a look at the website for loads more info and to register – </p>  <p><a href="http://www.minasiconference.com">www.minasiconference.com</a>&#160;&#160; </p>  <p>Pre-Conference Event </p>  <p>For the 2010 Conference we are pleased to offer our first Pre-Conference session. </p>  <p>The aim is to provide a 4 hour event at a small additional cost which will cover a topic that is closely related to the main conference but just slightly different! </p>  <p>In this case Todd Lammle will lead the session on the morning of Sunday 2nd May from 08:30 until 12:30. </p>  <p>The topic is “Configuring Basic Cisco and Router Configurations”   <br />All students would need is their own laptop and we will provide a free copy of Todd’s latest book as well as very slick router and switch simulator that you get to keep. </p>  <p>We are currently working to flesh out the details of this session and will update with a full agenda shortly. </p>  <p>This pre-con session will cost $85 which includes the Book, The Simulator, a light breakfast, Lunch and of course the 4 hours tuition! </p>  <p>For more information check the conference website in the Pre-Conference section. </p>  <p>I look forward to seeing you in Virginia! </p>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6363147.xml</wfw:commentRss></item><item><title>Be it known that LHA Consulting works with some fantastic people.</title><category>Community</category><category>personal</category><dc:creator>Laura E. Hunter</dc:creator><pubDate>Mon, 18 Jan 2010 17:29:38 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/1/18/be-it-known-that-lha-consulting-works-with-some-fantastic-pe.html</link><guid isPermaLink="false">69025:595923:6359536</guid><description><![CDATA[<p>(Non-technical post to follow.)</p>  <p>So a placement firm that I’ve done some work for, <a href="http://www.psicareers.com" target="_blank">Pro Search Inc.</a> in Portland Maine, has a nice little charitable arm as part of their business model:</p>  <blockquote>   <p>“<em>About the Pro Search Gives Back Program</em>:&#160; Each Quarter, on behalf of our clients, Pro Search donates 5 cents for every hour our temporary and contract employees work to community organizations and not-for-profits in Southern Maine.&#160;&#160;&#160;&#160; In 2009, thanks to the hard work and dedication of you and other Pro Search contractors, this totaled over $11,000.”</p> </blockquote>  <p>Now, clearly all eyes are on the ongoing humanitarian efforts in Haiti right now, and these guys are no exception. Come to find that one of their contractors is a Haitian immigrant with significant family base still in Port-au-Prince. As a directed giving measure, Pro Search is paying to fly this person and his brother home in order to re-connect with family and friends, and to assist in the relief efforts.</p>  <p>Yes indeed. I work with some truly outstanding people.</p>  <p>Now, go give some money to the relief organization of your choice. Mine is the <a href="http://www.salvationarmypendel.org" target="_blank">Salvation Army</a>, since having worked in IT Operations for them I know first-hand what percentage of every donation dollar goes directly to relief efforts instead of administrative overhead, and they’re ridiculously efficient…something like 85 cents on the dollar goes into the mission. But there are innumerable others…go get in the game.</p>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6359536.xml</wfw:commentRss></item><item><title>ADFS gets RBAC-y</title><category>ADFS</category><category>Identity</category><category>tech</category><dc:creator>Laura E. Hunter</dc:creator><pubDate>Sat, 16 Jan 2010 21:52:35 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/1/16/adfs-gets-rbac-y.html</link><guid isPermaLink="false">69025:595923:6345311</guid><description><![CDATA[<p><a title="http://blogs.msdn.com/card/archive/2010/01/08/introduction-to-token-issuance-authorization-in-ad-fs-2-0-rc.aspx" href="http://blogs.msdn.com/card/archive/2010/01/08/introduction-to-token-issuance-authorization-in-ad-fs-2-0-rc.aspx">http://blogs.msdn.com/card/archive/2010/01/08/introduction-to-token-issuance-authorization-in-ad-fs-2-0-rc.aspx</a></p>  <p>Token Issuance Authorization, new feature in the ADFSv2 release candidate. Allows the Identifying Party STS to control which users are authorized to receive tokens, thus decoupling both AuthN as well as certain aspects of AuthZ from the Relying Party.</p>  <p>From the blog post, in describing a scenario in which Contoso users are accessing a Fabrikam online store:</p>  <blockquote>   <p><em>With the new token issuance authorization feature, the administrator of the Contoso STS can create a policy that authorizes token issuance to Fabrikam based on membership in an Active Directory security group. This implements a form of role based access control (RBAC) at the STS. The administrators of the Fabrikam online store need not be aware of the details of the [Contoso] access control policy and no action is required from the vendor if the [Contoso] policy changes. </em></p></blockquote>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6345311.xml</wfw:commentRss></item><item><title>OpenID Welcomes new Board Member</title><category>ADFS</category><category>Community</category><category>Identity</category><category>personal</category><dc:creator>Laura E. Hunter</dc:creator><pubDate>Sat, 16 Jan 2010 20:34:07 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/1/16/openid-welcomes-new-board-member.html</link><guid isPermaLink="false">69025:595923:6344993</guid><description><![CDATA[<p><a title="http://eternallyoptimistic.com/2010/01/13/openid-bound/" href="http://eternallyoptimistic.com/2010/01/13/openid-bound/" target="_blank">http://eternallyoptimistic.com/2010/01/13/openid-bound/</a></p>  <p>The lovely Pamela Dingle, recent addition to the brilliant staff of <a href="http://pingidentity.com/" target="_blank">Ping Identity</a>, has joined the <a href="http://openid.net/foundation/" target="_blank">OpenID Foundation</a> as a board member representing Ping.</p>  <p>Congratulations!</p>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6344993.xml</wfw:commentRss></item><item><title>Amazon Web Services &amp;amp; ADFS</title><category>ADFS</category><category>Identity</category><category>tech</category><dc:creator>Laura E. Hunter</dc:creator><pubDate>Thu, 14 Jan 2010 01:05:13 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/1/14/amazon-web-services-amp-adfs.html</link><guid isPermaLink="false">69025:595923:6317142</guid><description><![CDATA[<p>David Chappell has released a <a href="http://go2.wordpress.com/?id=725X1342&amp;site=stvrly.wordpress.com&amp;url=http%3A%2F%2Fdownload.microsoft.com%2Fdownload%2F6%2FC%2F2%2F6C2DBA25-C4D3-474B-8977-E7D296FBFE71%2FEC2-Windows%2520SSO%2520v1%25200--Chappell.pdf" target="_blank">white paper</a> describing ways to connect your Amazon resources directly to your on-premises domain, followed by integration with ADFS1.1 and ADFSv2.</p>  <p>This flurry of Amazon-related ADFS goodness courtesy of <a href="http://go2.wordpress.com/?id=725X1342&amp;site=stvrly.wordpress.com&amp;url=http%3A%2F%2Fdownload.microsoft.com%2Fdownload%2F6%2FC%2F2%2F6C2DBA25-C4D3-474B-8977-E7D296FBFE71%2FEC2-Windows%2520SSO%2520v1%25200--Chappell.pdf" target="_blank">Steve Riley</a>, whom I’m incredibly happy to see speaking with such a passion around my favorite technology in the communities. :-)</p>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6317142.xml</wfw:commentRss></item><item><title>Federated Identity Management Legal Task Force</title><category>ADFS</category><category>Community</category><category>Identity</category><category>tech</category><dc:creator>Laura E. Hunter</dc:creator><pubDate>Wed, 13 Jan 2010 02:01:10 +0000</pubDate><link>http://www.shutuplaura.com/journal/2010/1/13/federated-identity-management-legal-task-force.html</link><guid isPermaLink="false">69025:595923:6306920</guid><description><![CDATA[<p><a title="http://www.abanet.org/dch/committee.cfm?com=CL320041" href="http://www.abanet.org/dch/committee.cfm?com=CL320041" target="_blank">http://www.abanet.org/dch/committee.cfm?com=CL320041</a></p>  <p>There appears to be a list-serv that you can subscribe to without being an ABANet member. Some of the doc links don’t seem to be showing love, though the ones that do make for some pretty cool reading.</p>]]></description><wfw:commentRss>http://www.shutuplaura.com/journal/rss-comments-entry-6306920.xml</wfw:commentRss></item></channel></rss>