Thursday, July 22, 2010
Gunnar Peterson on Cloud Security: Gateway, STS, PEP/PDP and Monitoring
This looks like an excellent presentation today at the
Cloud Identity Summit
in Colorado:
Gunnar Peterson on Cloud Security - Yesterday, Today, and Tomorrow
Newer Post
Older Post
Home
Blog author: Mark O'Neill
I'm CTO at
Vordel
- Vordel connects apps to other apps, connects businesses to other businesses, and connects SOA to the Cloud. I am based in Boston, Mass., USA.
On Twitter as
@TheMarkONeill
Featured Articles
-
Cloud Security Alliance: Protect the API Keys to your Cloud
-
It's 4am, do you know where your cloud provider is?- CTO Edge
-
Securing APIs - DZone
-
All the Web's an API - SD Times
-
A Security Checklist for Cloud Models - CSO Magazine
-
Cloud Service Brokers - CTO Edge
Recorded Webinars
Bridging security from the Enterprise to the Cloud
Enabling Mobile Apps Securely - With Scott Matsumoto from Cigital
Case Study: How Blackhawk Network uses a secure REST API to deliver services to iPhone apps and Facebook Marketplace
Case Study: How Badenia AG Bank manages its Web Services and XML (in German)
Videos
-
Three Cloud Computing Case Studies: IaaS, SaaS, and PaaS
-
WS-Trust Security Token Service (STS)
-
Protecting RIA's (Rich Internet Applications)
-
Service Virtualization
Podcasts
Cloud Security - The question of API Keys
The strategic role of the Cloud Service Broker
Why a bank chose Vordel for its SOA
Blog Archive
►
2012
(14)
►
February
(7)
Job posting: Integration Architect skilled in CA S...
Using Search and Replace with the Vordel Gateway
Recommended reading: Dan Geer
Pro Tip: Kerberos Service and SPNEGO Token Authent...
Free your data and the apps will follow
Pro Tip: Replicated caching across Vordel Applicat...
Edge of the Cloud
►
January
(7)
Scheduling reports on API usage
Gateways and Load Balancers
Who manages Application Gateways?
Kin Lane's API Management Service Provider Roundup...
Mapping from Google login, with OpenID, to Oracle ...
Returning JSON fault information to JQuery-based A...
How to change the default alert email subject line...
►
2011
(93)
►
December
(10)
Testing HTTP Authentication to a Web API
NFC - a "hand wavy" technology that may succeed
Checking against a CRL from a Mutual SSL connectio...
Leveraging Cloud Computing for the Financial Servi...
Identity propagation from the Vordel Gateway with ...
Using Vordel SOAPbox to send a SAMLResponse struct...
Configuring a dynamic CRL lookup on the Vordel Gat...
Rutrell Yasin on "what to look for in a SOA App Ga...
From XBRL to Westminster
How to call a Web Service or API "Off to the side"...
►
November
(6)
Video: Enabling OAuth to a Google JSON API using t...
"A guy walks into a bar..."
How to check for a HTTP 404 response code from a s...
How do I read an attribute from an LDAP directory,...
Protecting API Keys for Cloud Services
How to configure load-balancing across services on...
►
October
(5)
APIEvangelist.com covers Vordel
IdP (Identity Provider) to SP (Service Provider) S...
Tablet-tastic new site
Video: Three Cloud Computing Case Studies
Today at Oracle Open World - Cloud SaaS, PaaS, and...
►
September
(10)
Automated API testing
Issuing a SAML Assertion with a simple STS on the ...
Authentication using custom tokens with the Vordel...
Catch the Vordel and Forrester Webinar next week: ...
Free Vordel Workshop next month - Hotel Nikko, San...
Content-based routing, with conversion for SOAP to...
How to authenticate then issue a SAML assertion in...
You know you're a geek when...
Speaking at Oracle Open World - Tuesday October 4t...
CRLs and browsers, and how a Gateway can help
►
August
(11)
Enabling Single Sign-On across Hybrid Clouds Manag...
Cloud Computing webinar presentation... using the ...
Upcoming webinar with Qualys and CSA: "Cloud Compu...
Request throttling and concurrent connection throt...
Lightning strikes the cloud (or does it?)
►
July
(9)
►
June
(4)
►
May
(7)
►
April
(8)
►
March
(8)
►
February
(4)
►
January
(11)
▼
2010
(71)
►
December
(2)
►
November
(5)
►
October
(10)
►
September
(6)
►
August
(3)
▼
July
(3)
Catalyst discussion blocked by the Twitter API
Gunnar Peterson on Cloud Security: Gateway, STS, P...
Lotus knows how to ask you to bypass security (or ...
►
June
(7)
►
May
(5)
►
April
(5)
►
March
(7)
►
February
(10)
►
January
(8)
►
2009
(130)
►
December
(13)
►
November
(16)
►
October
(21)
►
September
(16)
►
August
(16)
►
July
(19)
►
June
(4)
►
May
(6)
►
April
(5)
►
March
(5)
►
February
(4)
►
January
(5)
►
2008
(70)
►
December
(6)
►
November
(5)
►
October
(9)
►
September
(22)
►
August
(24)
►
July
(4)
Recommended Reading
Service-Oriented Architecture
Latest federal 'shared services' strategy is actually SOA redux
1 hour ago
Financial Cryptography
one week later - chewing on the last morsel of Trust in the PKI business
15 hours ago
confused of calcutta
Musing lazily about tells and poker faces
22 hours ago
On IT-business alignment and related things
Taking the pulse of BPM in the cloud
2 days ago
Jon Udell
Tagging mechanisms and strategies part 1: General and specific
2 days ago
Cloudscaling
Open, Cloud, Confusion
2 days ago
Oracle Fusion Middleware Security
Hostname References and Architecture Simplification in the IDM Build Out for Fusion Apps
4 days ago
Chris Swan's Weblog
Nanode thermometer
1 week ago
Daryl Plummer
Gartner Cool Vendors Nominations are All In
1 week ago
1 Raindrop
Envy and the Facebook IPO
1 week ago
William Vambenepe's blog
Come for the PaaS Functional Model, stay for the Cloud Operational Model
2 weeks ago
InformationWeek Cloud Computing Weblog
Are There Too Many Storage Solutions?
2 weeks ago
James Governor's Monkchips
Our first major European conference is taking shape nicely.
5 weeks ago
The Wisdom of Clouds
Deliveryman rescues NY woman from burning home
2 months ago
Vordel XML Gateway
Live from 36000 Feet - How to deploy the Vordel Gateway in Multiple Environments
5 months ago
How to make the most of your gateway
Request throttling – a proactive approach
6 months ago
WebService & Cloud Security (auf Deutsch)
Sorry for beeing late ..
6 months ago