<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Azeems Identity Management Blog</title>
	<atom:link href="http://azeemkhan.info/id/feed/" rel="self" type="application/rss+xml" />
	<link>http://azeemkhan.info/id</link>
	<description>Identity Management Exploration</description>
	<pubDate>Tue, 16 Dec 2008 16:40:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<item>
		<title>Identropy Blog Launch</title>
		<link>http://azeemkhan.info/id/2008/identropy-blog-launch/</link>
		<comments>http://azeemkhan.info/id/2008/identropy-blog-launch/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 16:35:15 +0000</pubDate>
		<dc:creator>Azeem</dc:creator>
		
		<category><![CDATA[Identity]]></category>

		<category><![CDATA[Identity management]]></category>

		<category><![CDATA[Identity Resources]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=86</guid>
		<description><![CDATA[Check out the new Identropy Identity Management Blog. Or subscribe to the rss feed.
I recommend this resource to anyone who would like to learn about Identity Management. It is particularly geared towards those who want to learn about the basics of Identity Management. The Identity 101 series is particularly insightful. The various aspects of Identity [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://azeemkhan.info/id/wp-content/uploads/2008/12/identropylogo.jpg"><img class="alignright size-full wp-image-87" title="identropylogo" src="http://azeemkhan.info/id/wp-content/uploads/2008/12/identropylogo.jpg" alt="" width="223" height="74" /></a><a href="http://identropy.com/blog">Check out</a> the new Identropy <a class="zem_slink" title="Identity management" rel="wikipedia" href="http://en.wikipedia.org/wiki/Identity_management">Identity Management</a> Blog. Or subscribe to <a href="http://identropy.com/CMS/UI/Modules/BizBlogger/rss.aspx?tabid=85591&amp;moduleid=85510&amp;maxcount=25&amp;t=57ab2aec-d986-b424-ceb1-0338709a934d">the rss feed.</a></p>
<p>I recommend this resource to anyone who would like to learn about Identity Management. It is particularly geared towards those who want to learn about the basics of Identity Management. The Identity 101 series is particularly insightful. The various aspects of Identity Management (<a href="http://identropy.com/blog/bid/8697/Identity-Management-Solutions-101-User-Provisioning">provisioning</a>, <a href="http://identropy.com/blog/bid/9799/Identity-Management-Solutions-101-Enterprise-Single-Sign-On">single sign on</a> etc) are covered and use cases are given to help illustrate the need for finding solutions.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/e55d4e5e-74fc-4e98-8f17-b4cb086c4148/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=e55d4e5e-74fc-4e98-8f17-b4cb086c4148" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/identropy-blog-launch/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Manual processes are as good as&#8230;</title>
		<link>http://azeemkhan.info/id/2008/your-manual-processes-are-only-as-good-as-the-errors-they-produce/</link>
		<comments>http://azeemkhan.info/id/2008/your-manual-processes-are-only-as-good-as-the-errors-they-produce/#comments</comments>
		<pubDate>Wed, 03 Dec 2008 18:08:43 +0000</pubDate>
		<dc:creator>Azeem</dc:creator>
		
		<category><![CDATA[Identity]]></category>

		<category><![CDATA[Automation]]></category>

		<category><![CDATA[Data cleansing]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=80</guid>
		<description><![CDATA[



Image via Wikipedia



Ash asked for Idm one-liners so here&#8217;s one for you: Your Manual processes are as good as the errors they produce. Recently I was working with a client that had various rules in place concerning employee Identities. The problem was they were relying on manual processes to enforce them thus opening themselves up [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; float: right; display: block;">
<div>
<dl class="wp-caption" style="width: 212px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Automator_Icon.png"><img title="Automator" src="http://upload.wikimedia.org/wikipedia/en/thumb/7/7e/Automator_Icon.png/202px-Automator_Icon.png" alt="Automator" width="202" height="202" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Automator_Icon.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><a href="http://identityman.blogspot.com/" target="_blank">Ash</a> asked for <a href="http://identityman.blogspot.com/2008/11/few-more-snappy-idm-one-liners.html" target="_blank">Idm one-liners</a> so here&#8217;s one for you: Your Manual processes are as good as the errors they produce. Recently I was working with a client that had various rules in place concerning employee Identities. The problem was they were relying on manual processes to enforce them thus opening themselves up to human error. One example would be their username naming convention which consisted of a combination of characters from the first name, middle name and last name. There are also special cases involving exceptions (if a username was already taken). While working on the IdentityMap for this client they decided they wanted to do some <a class="zem_slink" title="Data cleansing" rel="wikipedia" href="http://en.wikipedia.org/wiki/Data_cleansing">data cleansing</a> as well. So I starting writing rules for excluding problem records. Hundreds of records were out of compliance with their various rules.</p>
<p>So the lesson to learn here is:<br />
<span id="more-80"></span></p>
<p><a class="zem_slink" title="Automation" rel="wikipedia" href="http://en.wikipedia.org/wiki/Automation">automation</a>, automation, automation. Clients ought to automate as many <a class="zem_slink" title="Business process" rel="wikipedia" href="http://en.wikipedia.org/wiki/Business_process">business processes</a> as possible to prevent human errors. The next best thing is checking for compliance at key points to prevent bad data from becoming widespread and irreversible.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/ef2eafbe-a655-4f85-becd-4e303acedef0/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=ef2eafbe-a655-4f85-becd-4e303acedef0" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/your-manual-processes-are-only-as-good-as-the-errors-they-produce/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What&#8217;s your favorite LDAP browser?</title>
		<link>http://azeemkhan.info/id/2008/whats-your-favorite-ldap-browser/</link>
		<comments>http://azeemkhan.info/id/2008/whats-your-favorite-ldap-browser/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 23:42:25 +0000</pubDate>
		<dc:creator>Azeem</dc:creator>
		
		<category><![CDATA[Reviews]]></category>

		<category><![CDATA[LDAP]]></category>

		<category><![CDATA[LDAP Browser]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=78</guid>
		<description><![CDATA[

I found this LDAP browser/editor to be really good! If you use this on a client and have write privileges be careful about not overwriting anything. Another cross platform browser suggested by Eric is LDAPSoft&#8217;s browser.
The popular softerra ldap browser is not so great in my view. It has failed me before, and I will [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-click">
<div class="wp-caption alignright" style="width: 212px"><a href="http://en.wikipedia.org/wiki/Image:OpenLDAP-logo.png"><img title="OpenLDAP Software" src="http://upload.wikimedia.org/wikipedia/en/thumb/c/c7/OpenLDAP-logo.png/202px-OpenLDAP-logo.png" alt="OpenLDAP Software" width="202" height="79" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p>I found <a href="http://www.mcs.anl.gov/~gawor/ldap/index.html" target="_blank">this LDAP browser</a>/editor to be really good! If you use this on a client and have write privileges be careful about not overwriting anything. Another cross platform browser suggested by Eric is <a href="http://www.ldapsoft.com/download.html" target="_blank">LDAPSoft&#8217;s browser</a>.</p>
<p><span id="more-78"></span>The popular <a href="http://www.ldapbrowser.com/download.htm" target="_blank">softerra ldap browser</a> is not so great in my view. It has failed me before, and I will never use it again. How about you? What is your favorite LDAP browser?</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/9f2d95a7-76b1-4687-8122-a942b24f71a8/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=9f2d95a7-76b1-4687-8122-a942b24f71a8" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/whats-your-favorite-ldap-browser/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Understanding Identity: Provisioning; The Players</title>
		<link>http://azeemkhan.info/id/2008/understanding-idenity-provisioning-the-players/</link>
		<comments>http://azeemkhan.info/id/2008/understanding-idenity-provisioning-the-players/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 23:06:08 +0000</pubDate>
		<dc:creator>Azeem</dc:creator>
		
		<category><![CDATA[Identity]]></category>

		<category><![CDATA[Identity management]]></category>

		<category><![CDATA[Provisioning]]></category>

		<category><![CDATA[report]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=74</guid>
		<description><![CDATA[

Gartner puts out its Magic Quadrant for User Provisioning report Annually. This report identifies the leading players in the Market and provides alot of data on the adoption of Provisioning Identity Products.
the usual suspects: Sun, Novell, Microsoft, IBM are mentioned. Although there areothers major players as well i.e. Courion. The company I work for Identropy [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-click">
<div class="wp-caption alignright" style="width: 212px"><a href="http://en.wikipedia.org/wiki/Image:Microsoft_Messenger_for_Mac_7_icon.png"><img title="Microsoft Messenger:mac" src="http://upload.wikimedia.org/wikipedia/en/thumb/4/46/Microsoft_Messenger_for_Mac_7_icon.png/202px-Microsoft_Messenger_for_Mac_7_icon.png" alt="Microsoft Messenger:mac" width="202" height="202" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p><a class="zem_slink" title="Gartner" rel="homepage" href="http://www.gartner.com/">Gartner</a> puts out its <a class="zem_slink" title="Magic Quadrant" rel="wikipedia" href="http://en.wikipedia.org/wiki/Magic_Quadrant">Magic Quadrant</a> for User <a class="zem_slink" title="Provisioning" rel="wikipedia" href="http://en.wikipedia.org/wiki/Provisioning#User_provisioning">Provisioning</a> report Annually. This report identifies the leading players in the Market and provides alot of data on the adoption of Provisioning Identity Products.</p>
<p>the usual suspects: Sun, Novell, Microsoft, IBM are mentioned. Although there areothers major players as well i.e. Courion. The company I work for Identropy gets a mention, in relation to being an innovating force with as a <a href="http://www.courion.com">Courion</a> partner.  Understanding these products may give you a practical feel for what role Identity is playng at this point in time.</p>
<p>Read the full report here:<br />
<a href="http://mediaproducts.gartner.com/reprints/novell/159740.html" target="_blank">http://mediaproducts.gartner.com/reprints/novell/159740.html</a></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://bhc3.wordpress.com/2008/10/14/notes-on-presenting-to-gartnerand-that-magic-quadrant-thing/">Notes on Presenting to Gartner&#8230;and That Magic Quadrant Thing</a></li>
<li class="zemanta-article-ul-li"><a href="http://blogs.adobe.com/acrobatconnect/2008/09/connect_pro_a_leader_once_agai.html">Connect Pro a &#8220;Leader&#8221; Once Again In Gartner&#8217;s Magic Quadrant</a></li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/683287b1-5388-4727-9c12-8ab9c1dbc753/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=683287b1-5388-4727-9c12-8ab9c1dbc753" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/understanding-idenity-provisioning-the-players/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Mapping Tivoli- Lessons Learnt</title>
		<link>http://azeemkhan.info/id/2008/mapping-tivoli-lessons-learnt/</link>
		<comments>http://azeemkhan.info/id/2008/mapping-tivoli-lessons-learnt/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 21:34:27 +0000</pubDate>
		<dc:creator>Azeem</dc:creator>
		
		<category><![CDATA[Identity]]></category>

		<category><![CDATA[LDAP]]></category>

		<category><![CDATA[SSIS]]></category>

		<category><![CDATA[TIM]]></category>

		<category><![CDATA[Tivoli]]></category>

		<category><![CDATA[VB.net]]></category>

		<category><![CDATA[VBScript]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=68</guid>
		<description><![CDATA[

I was at a client doing some Identity mapping. They have TIM Tivoli, which had to be mapped against their people soft data. I needed to pull their usernames (eruid), employeeIDs (eradEmployeeID) from objectclass eradaccount (AD stuff), I also had to get their email accounts (which are under a custom objectClass (did not come from [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-click">
<div class="wp-caption alignright" style="width: 180px"><a href="http://www.crunchbase.com/company/ibm"><img title="Image representing IBM as depicted in CrunchBase" src="http://www.crunchbase.com/assets/images/resized/0002/1370/21370v1-max-250x250.png" alt="Image representing IBM as depicted in CrunchBase" width="170" height="68" /></a><p class="wp-caption-text">Image via CrunchBase</p></div>
</div>
<p>I was at a client doing some Identity mapping. They have TIM <span class="nfakPe">Tivoli</span>, which had to be mapped against their people soft data. I needed to pull their usernames (eruid), employeeIDs (eradEmployeeID) from objectclass eradaccount (AD stuff), I also had to get their email accounts (which are under a custom objectClass (did not come from AD originally). I was trying to write a <a class="zem_slink" title="VBScript" rel="wikipedia" href="http://en.wikipedia.org/wiki/VBScript">VBScript</a> to pull everything. But Unfortunately all the code that&#8217;s out there on the web is very AD specific (AD Provider, adspath etc) and was not able to properly run a query from a VBscript to hit <a class="zem_slink" title="Lightweight Directory Access Protocol" rel="wikipedia" href="http://en.wikipedia.org/wiki/Lightweight_Directory_Access_Protocol">LDAP</a>.</p>
<p>So I emailed <a href="http://charlesahart.blogspot.com/" target="_blank">Charles Ahart</a> a blogger who blogs about his Tivoli experiences. And I tell him about my problem. I mentioned I was trying to pull this data into SSIS to map against their PeopleSoft Employee ID. So VBScript or Vb.net code would work. I was also given access to their DB2 database. That thing is crazy I could connect from SSIS to it, but the data is just all over the place. While I needed just 3 attributes It was so difficult to track them down. Even the Client&#8217;s TIM dba couldn&#8217;t figure it out. So I thought if I can&#8217;t do this with a script, I will have to do it through running a query against the DB2. I think the script would be an easier route to take.<br />
<strong><br />
Charles Responded:</strong><span id="more-68"></span></p>
<blockquote><p>Yes TIM is quite a &#8220;bear&#8221; when you try to dig into it.  It&#8217;s not usually a good idea to interact with TIM at the DB2 layer except for maybe doing some historical reporting against the transaction database.  Talking to the LDAP DB2 directly is dangerous.  If you are looking to read data you could make LDAP calls to get what it is you need or you can write a web service to talk to TIM via the <span class="nfakPe">Tivoli</span> API&#8217;s.  All the <span class="nfakPe">Tivoli</span> Java Docs are available on the TIM server under /opt/itim/extensions/examples.</p>
<div>If you need to just read some attributes then LDAP calls would be easier.Also, TIM comes with TDI which is a very powerful tool for moving data around.  You could leverage that as well.  Chances are if they are running TIM then they have licenses for TDI and this is a very easy tool to run from your desktop or server.  It has many connectors already built for LDAP, JDBC, file system connectors with built-in parsers, and much more.  You can code JavaScript in that tool to pull data very easily from one system to another.BTW, TIM comes with connectors to Peoplesoft, so you could integrate Peoplesoft directly with TIM or you could be using TDI to connect the two.  I&#8217;m not sure what data your trying to move from where to where.</p>
<p>To see what&#8217;s under the hood in TIM, you will need access to login to the TIM LDAP and point an LDAP Client at the TIM Box.  There are TIM Identities (TIM Profiles) which are the Persons in the TIM System.  These reside in a subtree like the following:</p>
<p>ou=people,erglobalid=00000000000000000000,ou=Largecorp,dc=largecorp,dc=com</p>
<p>There will be another entry for each person&#8217;s accounts under the following  subtree:</p>
<p>ou=0,ou=accounts,erglobalid=00000000000000000000,ou=Largecorp,dc=largecorp,dc=com</p>
<p>In this subtree you will find all the user accounts which are linked to the account owner.  So the owner attribute for each account references the DN value for the TIM Person who owns that account.  All the attributes for an AD user would be contained in the AD account entry for that use.</p></div>
</blockquote>
<div>I appreciated Charles taking the time to write such a detailed response. After trying about 5 different approaches. I was able to utilize Vb.net in the <a class="zem_slink" title="SQL Server Integration Services" rel="wikipedia" href="http://en.wikipedia.org/wiki/SQL_Server_Integration_Services">SSIS Package</a>. The code I used was taken from:<br />
<a href="http://www.google.ca/search?hl=en&amp;q=www.experts-exchange.com%2FDatabase%2FLDAP%2FQ_23186562.html&amp;btnG=Search&amp;meta=" target="_blank">http://www.google.ca/search?hl=en&amp;q=www.experts-exchange.com%2FDatabase%2FLDAP%2FQ_23186562.html&amp;btnG=Search&amp;meta=</a><br />
(click on the first link, and scroll down to the bottom). This page also explains why VBScript wont work. I had figured out the LDAP queries using the LDAP Browser and Editor. It was just really frustrating that I couldn&#8217;t make it work in VbScript. The explanation given on that page is</p>
<blockquote><p>The problem I was encountering finds its roots in the limits of ADSI. As per MS article 251195, ADSI uses the subschema information to expose the proper interfaces for a given class, and to retrieve attributes in the correct syntax from the property cache.</p>
<p>If ADSI is unable to locate or properly validate the subschema information, it uses the default LDAP version 2 schema. Because LDAP version 2 servers do not expose a subschema, ADSI maintains schema information internally about many standard attributes and classes. If ADSI uses the default version 2 schema, it does not have access to nonstandard schema information, including custom classes or attributes that have been created on the server.</p></blockquote>
<p>In a future post, I&#8217;ll share the Vb.net code to run LDAP 3.0 queries (works for non-AD LDAP interfaces) and how to use that in SSIS using Variables in a manner that will help make the script reusable.</p>
<p>On a Final Note I said to Charles:</p>
<p>&#8220;It&#8217;s interesting to know IBM has so many tools but that&#8217;s such a catch 22, they have so many tools its hard to know as a non-IBMer what the usage and flexibility is. &#8221;</p>
<p>His response:</p>
<blockquote><p>Your right about the IBM tools.  There are so many and while it is highly extensible, it can be quite challenging to get these products to stand up initially.  Their Identity Management system has come a long way with TIM 5, but I still think that the UI leaves something to be desired.  But hey, doing Identity Management products is only partly about the technology anyways.</p></blockquote>
</div>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/2da10bc7-1344-42f0-b71b-433d8c963749/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=2da10bc7-1344-42f0-b71b-433d8c963749" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/mapping-tivoli-lessons-learnt/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Understanding Identity Part 1</title>
		<link>http://azeemkhan.info/id/2008/understanding-identity-part-1/</link>
		<comments>http://azeemkhan.info/id/2008/understanding-identity-part-1/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 06:37:30 +0000</pubDate>
		<dc:creator>Azeem</dc:creator>
		
		<category><![CDATA[Identity]]></category>

		<category><![CDATA[Courion]]></category>

		<category><![CDATA[Identity management]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=63</guid>
		<description><![CDATA[

If you want to understand identity Management, you have to first be able to analyze the problems surrounding coorporate identities today. Courion, an identity software vendor (I recently completed training on their product), held an event where they presented their product. An attendee wrote:
Observations from Converge:
- The main industry vertical customers attending were financial and [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-click">
<div class="wp-caption alignright" style="width: 212px"><a href="http://en.wikipedia.org/wiki/Image:IdentityLogo.jpg"><img title="Identity (game show)" src="http://upload.wikimedia.org/wikipedia/en/thumb/5/54/IdentityLogo.jpg/202px-IdentityLogo.jpg" alt="Identity (game show)" width="202" height="112" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p>If you want to understand <a class="zem_slink" title="Identity management" rel="wikipedia" href="http://en.wikipedia.org/wiki/Identity_management">identity Management</a>, you have to first be able to analyze the problems surrounding coorporate identities today. <a href="http://www.Courion.com">Courion</a>, an identity software vendor (I recently completed training on their product), held an event where they presented their product. An attendee <a href="http://community.citrix.com/blogs/citrite/kateb/2008/05/23/Courion+Converge+show" target="_blank">wrote</a>:</p>
<blockquote><p>Observations from Converge:</p>
<p>- The main industry vertical customers attending were financial and health care.   User provisioning is a key issue and it is very expensive to do manually</p>
<p>- RoleCourier is gaining traction as customers are using it to avoid complexity, excessive roles, and political situations that arise when doing role-based provisioning</p>
<p>- ComplianceCourier is getting a lot of interest for its capability to enable business managers to periodically review and verify employee access rights</p>
<p>- There was a great customer presentation from Goodyear Tire and Rubber Corporation, where they discussed a previous failed attempt at implementing <a class="zem_slink" title="Identity and Access Management" rel="wikipedia" href="http://en.wikipedia.org/wiki/Identity_and_Access_Management">IAM</a>, followed by their project with Courion, which is rolling out very smoothly.  One interesting note: a focus on educating and motivating users to appreciate the new system really pays off.</p></blockquote>
<p><span id="more-63"></span>So from this persons take, and from the Courion products spectrum we see that some of the major IT security needs are: Provisioning/De-provisioning, Role Management, Compliance (government regulation etc), and there is also Password management (which the writer left out).</p>
<p>In subsequent posts, I will explore each one of these  areas of Identity. I will also be sharing more details about Courion&#8217;s product,  how it works, as well as what some of the technical challenges await Identity integrators.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/d92c7b71-ecae-456c-9a93-550baf184f09/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=d92c7b71-ecae-456c-9a93-550baf184f09" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/understanding-identity-part-1/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Installing VMWare on Linux</title>
		<link>http://azeemkhan.info/id/2008/installing-vmware-on-linux/</link>
		<comments>http://azeemkhan.info/id/2008/installing-vmware-on-linux/#comments</comments>
		<pubDate>Sat, 18 Oct 2008 11:28:14 +0000</pubDate>
		<dc:creator>Azeem</dc:creator>
		
		<category><![CDATA[Environments]]></category>

		<category><![CDATA[Linux]]></category>

		<category><![CDATA[openSUSE]]></category>

		<category><![CDATA[Virtualization]]></category>

		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=59</guid>
		<description><![CDATA[

When doing Identity Management integrations its very important to properly train consultants/integrators. While shadowing is a good way to get someone aquainted, its even more important to provide hands on training. Dedicating an entire machine for each employees testing purposes becomes difficult quickly.
Virtualization helps eliminate the resource intensive requirements of having all that hardware. Plus [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-click">
<div class="wp-caption alignright" style="width: 250px"><a href="http://www.flickr.com/photos/16226024@N00/448779720"><img title="VMware Fusion Beta 3" src="http://farm1.static.flickr.com/231/448779720_1715009d9f_m.jpg" alt="VMware Fusion Beta 3" width="240" height="215" /></a><p class="wp-caption-text">Image by FHKE via Flickr</p></div>
</div>
<p>When doing Identity Management integrations its very important to properly train consultants/integrators. While shadowing is a good way to get someone aquainted, its even more important to provide hands on training. Dedicating an entire machine for each employees testing purposes becomes difficult quickly.</p>
<p>Virtualization helps eliminate the resource intensive requirements of having all that hardware. Plus it allows you to deal with multiple environments and makes reusing an entire insallation as easy as copy and paste.</p>
<p>In an earlier post I had mentioned that you can setup a VMWare test server using VMWare on <a class="zem_slink" title="Linux" rel="wikipedia" href="http://en.wikipedia.org/wiki/Linux">Linux</a> as a Development Sever for multiple users.</p>
<p>I followed <a href="http://www.susegeek.com/virtualization/install-and-configure-vmware-server-virtualization-in-opensuse/" target="_blank">this link</a> to recently install VMWare 1.0.7 on <a class="zem_slink" title="OpenSUSE" rel="homepage" href="http://www.opensuse.org">OpenSUSE 11</a>. Before doing anything update your linux installation from Yast or run the following command in terminal: apt-get update  . Run all updates (and do this frequently). Then grab the latest version of VMWare Server from Vmware.com. After unzipping the file these are the commands you should run in terminal and these are the results you should get. The trick is getting your dependencies right. If you get an error along the way just search for that library in yast, or do a google search on the library that is missing and find out how to install it from the terminal. After installing the libraries start the process again. I had to install the latest version of gcc to make this work.</p>
<p><span id="more-59"></span>linux-d49o:~ # rpm -qa | grep -i vmware</p>
<p>VMware-server-1.0.7-108231</p>
<p>linux-d49o:~ #  /usr/bin/vmware-config.pl</p>
<p>Making sure services for <a class="zem_slink" title="VMware Server" rel="homepage" href="http://www.vmware.com/products/server/">VMware Server</a> are stopped.</p>
<p>Stopping VMware services:</p>
<p>Virtual machine monitor                                             done</p>
<p>You must read and accept the End User License Agreement to continue.</p>
<p>Press enter to display it.</p>
<p>Do you accept? (yes/no) yes</p>
<p>Thank you.</p>
<p>Configuring fallback GTK+ 2.4 libraries.</p>
<p>In which directory do you want to install the mime type icons?</p>
<p>[/usr/share/icons] /usr/share/icons</p>
<p>What directory contains your desktop menu entry files? These files have a</p>
<p>.desktop file extension. [/usr/share/applications] /usr/share/applications</p>
<p>In which directory do you want to install the application&#8217;s icon?</p>
<p>[/usr/share/pixmaps] /usr/share/pixmaps</p>
<p>/usr/share/applications/vmware-server.desktop: warning: value &#8220;vmware-server.png&#8221; for key &#8220;Icon&#8221; in group &#8220;Desktop Entry&#8221; is an icon name with an extension, but there should be no extension as described in the Icon Theme Specification if the value is not an absolute path</p>
<p>/usr/share/applications/vmware-console-uri-handler.desktop: warning: value &#8220;vmware-server.png&#8221; for key &#8220;Icon&#8221; in group &#8220;Desktop Entry&#8221; is an icon name with an extension, but there should be no extension as described in the Icon Theme Specification if the value is not an absolute path</p>
<p>Trying to find a suitable vmmon module for your running kernel.</p>
<p>None of the pre-built vmmon modules for VMware Server is suitable for your</p>
<p>running kernel.  Do you want this program to try to build the vmmon module for</p>
<p>your system (you need to have a C compiler installed on your system)? [yes] yes</p>
<p>Using compiler &#8220;/usr/bin/gcc&#8221;. Use environment variable CC to override.</p>
<p>Your kernel was built with &#8220;gcc&#8221; version &#8220;4.3.1&#8243;, while you are trying to use</p>
<p>&#8220;/usr/bin/gcc&#8221; version &#8220;4.3&#8243;. This configuration is not recommended and VMware</p>
<p>Server may crash if you&#8217;ll continue. Please try to use exactly same compiler as</p>
<p>one used for building your kernel. Do you want to go with compiler</p>
<p>&#8220;/usr/bin/gcc&#8221; version &#8220;4.3&#8243; anyway? [no] yes</p>
<p>What is the location of the directory of C header files that match your running</p>
<p>kernel? [/lib/modules/2.6.25.11-0.1-pae/build/include]</p>
<p>Extracting the sources of the vmmon module.</p>
<p>Building the vmmon module.</p>
<p>Using 2.6.x kernel build system.</p>
<p>make: Entering directory `/tmp/vmware-config0/vmmon-only&#8217;</p>
<p>make -C /lib/modules/2.6.25.11-0.1-pae/build/include/.. SUBDIRS=$PWD SRCROOT=$PWD/. modules</p>
<p>make[1]: Entering directory `/usr/src/linux-2.6.25.11-0.1-obj/i386/pae&#8217;</p>
<p>make -C /usr/src/linux-2.6.25.11-0.1 O=/usr/src/linux-2.6.25.11-0.1-obj/i386/pae/. modules</p>
<p>CC [M]  /tmp/vmware-config0/vmmon-only/linux/driver.o</p>
<p>CC [M]  /tmp/vmware-config0/vmmon-only/linux/hostif.o</p>
<p>CC [M]  /tmp/vmware-config0/vmmon-only/common/cpuid.o</p>
<p>CC [M]  /tmp/vmware-config0/vmmon-only/common/hash.o</p>
<p>CC [M]  /tmp/vmware-config0/vmmon-only/common/memtrack.o</p>
<p>CC [M]  /tmp/vmware-config0/vmmon-only/common/phystrack.o</p>
<p>CC [M]  /tmp/vmware-config0/vmmon-only/common/task.o</p>
<p>CC [M]  /tmp/vmware-config0/vmmon-only/common/vmx86.o</p>
<p>/tmp/vmware-config0/vmmon-only/common/vmx86.c: In function &#8216;Vmx86_GetkHzEstimate&#8217;:</p>
<p>/tmp/vmware-config0/vmmon-only/common/vmx86.c:1899: warning: passing argument 4 of &#8216;Div643264&#8242; from incompatible pointer type</p>
<p>/tmp/vmware-config0/vmmon-only/common/vmx86.c:1908: warning: passing argument 4 of &#8216;Div643232&#8242; from incompatible pointer type</p>
<p>CC [M]  /tmp/vmware-config0/vmmon-only/vmcore/moduleloop.o</p>
<p>LD [M]  /tmp/vmware-config0/vmmon-only/vmmon.o</p>
<p>Building modules, stage 2.</p>
<p>MODPOST 1 modules</p>
<p>WARNING: modpost: module vmmon.ko uses symbol &#8216;init_mm&#8217; marked UNUSED</p>
<p>CC      /tmp/vmware-config0/vmmon-only/vmmon.mod.o</p>
<p>LD [M]  /tmp/vmware-config0/vmmon-only/vmmon.ko</p>
<p>make[1]: Leaving directory `/usr/src/linux-2.6.25.11-0.1-obj/i386/pae&#8217;</p>
<p>cp -f vmmon.ko ./../vmmon.o</p>
<p>make: Leaving directory `/tmp/vmware-config0/vmmon-only&#8217;</p>
<p>The module loads perfectly in the running kernel.</p>
<p>Do you want networking for your virtual machines? (yes/no/help) [yes]</p>
<p>Configuring a bridged network for vmnet0.</p>
<p>The following bridged networks have been defined:</p>
<p>All your ethernet interfaces are already bridged.</p>
<p>Do you want to be able to use NAT networking in your virtual machines? (yes/no)</p>
<p>[yes]</p>
<p>Configuring a NAT network for vmnet8.</p>
<p>Do you want this program to probe for an unused private subnet? (yes/no/help)</p>
<p>[yes]</p>
<p>Probing for an unused private subnet (this can take some time)&#8230;</p>
<p>The subnet 192.168.141.0/255.255.255.0 appears to be unused.</p>
<p>This system appears to have a DHCP server configured for normal use.  Beware</p>
<p>that you should teach it how not to interfere with VMware Server&#8217;s DHCP server.</p>
<p>There are two ways to do this:</p>
<p>1) Modify the file /etc/dhcpd.conf to add something like:</p>
<p>subnet 192.168.141.0 netmask 255.255.255.0 {</p>
<p># Note: No range is given, vmnet-dhcpd will deal with this subnet.</p>
<p>}</p>
<p>2) Start your DHCP server with an explicit list of network interfaces to deal</p>
<p>with (leaving out vmnet8). e.g.:</p>
<p>dhcpd eth0</p>
<p>Consult the dhcpd(8) and dhcpd.conf(5) manual pages for details.</p>
<p>Hit enter to continue.</p>
<p>The following NAT networks have been defined:</p>
<p>Do you wish to configure another NAT network? (yes/no) [no]</p>
<p>Do you want to be able to use host-only networking in your virtual machines?</p>
<p>[yes]</p>
<p>Configuring a host-only network for vmnet1.</p>
<p>Do you want this program to probe for an unused private subnet? (yes/no/help)</p>
<p>[yes]</p>
<p>Probing for an unused private subnet (this can take some time)&#8230;</p>
<p>The subnet 172.16.56.0/255.255.255.0 appears to be unused.</p>
<p>This system appears to have a DHCP server configured for normal use.  Beware</p>
<p>that you should teach it how not to interfere with VMware Server&#8217;s DHCP server.</p>
<p>There are two ways to do this:</p>
<p>1) Modify the file /etc/dhcpd.conf to add something like:</p>
<p>subnet 172.16.56.0 netmask 255.255.255.0 {</p>
<p># Note: No range is given, vmnet-dhcpd will deal with this subnet.</p>
<p>}</p>
<p>2) Start your DHCP server with an explicit list of network interfaces to deal</p>
<p>with (leaving out vmnet1). e.g.:</p>
<p>dhcpd eth0</p>
<p>Consult the dhcpd(8) and dhcpd.conf(5) manual pages for details.</p>
<p>Hit enter to continue.</p>
<p>The following host-only networks have been defined:</p>
<p>Do you wish to configure another host-only network? (yes/no) [no]</p>
<p>Extracting the sources of the vmnet module.</p>
<p>Building the vmnet module.</p>
<p>Using 2.6.x kernel build system.</p>
<p>make: Entering directory `/tmp/vmware-config0/vmnet-only&#8217;</p>
<p>make -C /lib/modules/2.6.25.11-0.1-pae/build/include/.. SUBDIRS=$PWD SRCROOT=$PWD/. modules</p>
<p>make[1]: Entering directory `/usr/src/linux-2.6.25.11-0.1-obj/i386/pae&#8217;</p>
<p>make -C /usr/src/linux-2.6.25.11-0.1 O=/usr/src/linux-2.6.25.11-0.1-obj/i386/pae/. modules</p>
<p>CC [M]  /tmp/vmware-config0/vmnet-only/driver.o</p>
<p>CC [M]  /tmp/vmware-config0/vmnet-only/hub.o</p>
<p>CC [M]  /tmp/vmware-config0/vmnet-only/userif.o</p>
<p>CC [M]  /tmp/vmware-config0/vmnet-only/netif.o</p>
<p>CC [M]  /tmp/vmware-config0/vmnet-only/bridge.o</p>
<p>CC [M]  /tmp/vmware-config0/vmnet-only/procfs.o</p>
<p>CC [M]  /tmp/vmware-config0/vmnet-only/smac_compat.o</p>
<p>SHIPPED /tmp/vmware-config0/vmnet-only/smac_linux.x386.o</p>
<p>LD [M]  /tmp/vmware-config0/vmnet-only/vmnet.o</p>
<p>Building modules, stage 2.</p>
<p>MODPOST 1 modules</p>
<p>WARNING: could not find /tmp/vmware-config0/vmnet-only/.smac_linux.x386.o.cmd for /tmp/vmware-config0/vmnet-only/smac_linux.x386.o</p>
<p>CC      /tmp/vmware-config0/vmnet-only/vmnet.mod.o</p>
<p>LD [M]  /tmp/vmware-config0/vmnet-only/vmnet.ko</p>
<p>make[1]: Leaving directory `/usr/src/linux-2.6.25.11-0.1-obj/i386/pae&#8217;</p>
<p>cp -f vmnet.ko ./../vmnet.o</p>
<p>make: Leaving directory `/tmp/vmware-config0/vmnet-only&#8217;</p>
<p>The module loads perfectly in the running kernel.</p>
<p>The default port : 902 is not free. We have selected a suitable alternative</p>
<p>port for VMware Server use. You may override this value now.</p>
<p>Remember to use this port when connecting to this server.</p>
<p>Please specify a port for remote console connections to use [904]</p>
<p>WARNING: VMware Server has been configured to run on a port different from the</p>
<p>default port. Remember to use this port when connecting to this server.</p>
<p>Shutting down xinetd:                                                done</p>
<p>Starting INET services. (xinetd)                                     done</p>
<p>Configuring the VMware VmPerl Scripting API.</p>
<p>Building the VMware VmPerl Scripting API.</p>
<p>Using compiler &#8220;/usr/bin/gcc&#8221;. Use environment variable CC to override.</p>
<p>Installing the VMware VmPerl Scripting API.</p>
<p>The installation of the VMware VmPerl Scripting API succeeded.</p>
<p>Generating SSL Server Certificate</p>
<p>In which directory do you want to keep your virtual machine files?</p>
<p>[/var/lib/vmware/Virtual Machines]</p>
<p>The path &#8220;/var/lib/vmware/Virtual Machines&#8221; does not exist currently. This</p>
<p>program is going to create it, including needed parent directories. Is this</p>
<p>what you want? [yes]</p>
<p>Please enter your 20-character serial number.</p>
<p>Type XXXXX-XXXXX-XXXXX-XXXXX or &#8216;Enter&#8217; to cancel:</p>
<p>You cannot power on any virtual machines until you enter a valid serial number.</p>
<p>To enter the serial number, run this configuration program again, or choose</p>
<p>&#8216;Help &gt; Enter Serial Number&#8217; in the virtual machine console.</p>
<p>Starting VMware services:</p>
<p>Virtual machine monitor                                             done</p>
<p>Virtual ethernet                                                    done</p>
<p>Bridged networking on /dev/vmnet0                                   done</p>
<p>Host-only networking on /dev/vmnet1 (background)                    done</p>
<p>Host-only networking on /dev/vmnet8 (background)                    done</p>
<p>NAT service on /dev/vmnet8                                          done</p>
<p>The configuration of VMware Server 1.0.7 build-108231 for Linux for this</p>
<p>running kernel completed successfully.</p>
<p>linux-d49o:~ #</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.infoworld.com/article/08/06/16/Novell_patches_Suse_Linux_kernel_for_VMware_efficiency_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/06/16/Novell_patches_Suse_Linux_kernel_for_VMware_efficiency_1.html">Novell patches Suse Linux kernel for VMware efficiency</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.tuaw.com/2008/09/23/vmware-offers-free-training-videos-on-youtube/">VMWare offers free training videos on YouTube<br />
</a></li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/4fe06b63-28ed-4ae5-8ee0-762aea1035ee/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=4fe06b63-28ed-4ae5-8ee0-762aea1035ee" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/installing-vmware-on-linux/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Novell Sentinel Training Day 4</title>
		<link>http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/</link>
		<comments>http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/#comments</comments>
		<pubDate>Thu, 16 Oct 2008 03:58:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Novell]]></category>

		<category><![CDATA[Sentinel]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=46</guid>
		<description><![CDATA[To conclude my thoughts on the training. I thought I would include some screenshots so you can see Sentinel in action for yourself!
To sum up, the way Sentinel works is:

Logs are pulled into Sentinel and each line is seperated into events with severity levels ranging from 1 to 5
You define filters to look for events [...]]]></description>
			<content:encoded><![CDATA[<p>To conclude my thoughts on the training. I thought I would include some screenshots so you can see Sentinel in action for yourself!<br />

<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/01screen/' title='01screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/01screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/02screen/' title='02screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/02screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/03screen/' title='03screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/03screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/04screen/' title='04screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/04screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/05screen/' title='05screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/05screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/06screen/' title='06screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/06screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/07screen/' title='07screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/07screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/08screen/' title='08screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/08screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/09screen/' title='09screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/09screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
<a href='http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/10screen/' title='10screen'><img src="http://azeemkhan.info/id/wp-content/uploads/2008/10/10screen-150x150.jpg" width="150" height="150" class="attachment-thumbnail" alt="" /></a>
</p>
<p>To sum up, the way Sentinel works is:</p>
<ol>
<li>Logs are pulled into Sentinel and each line is seperated into events with severity levels ranging from 1 to 5</li>
<li>You define filters to look for events of interest. For example a filter might look like:<br />
filter(((e.DeviceCategory = &#8220;IDS&#8221;) and (e.Severity &gt;= 4)))</li>
<li>Multiple Events can be groups together and marked as incidents. Each incident can be assigned a category and can be assigned to a person for further investigation</li>
<li>Utilizing Filters a correlated event can kick of an action (or trigger) such as sending an e-mail, appending a list, appending an ldap attribute or kicking off a javascript file (for further flexibility)</li>
<li>ProcessWork Flows can be designed to dictate the logic behind how an event is handled. The chain of command can be worked into the work flow. I.e. when a correlated event takes place ad Analyst can be prompted to check out the incident. Once the analyst attempts to rectify the problem and closes it out. It then can go to an Administrator who can further investigate or close out the incident.</li>
</ol>
<p>This is the process in a nutshell, if you follow the screens after reading the explanation it might make more sense.</p>
<p><span id="more-46"></span>I mentioned the learning curve before. Where does that come in? Definitely when it comes to writing filters. attempting to fully leverage this product will take a concerted effort of Administrators who must keep evaluating the data coming in, to come up with new filters and rules to look for. This will take out of the box thinking. If Sentinel could become smarter over time and share its own suggestions for filters that would be great. When I shared this idea with someone they said that would be Sentinel for Sentinel. Til that point comes where Artificial Intelligence is worked into apps like this Admins will have to play close attention and help make their companies investment worthwhile.</p>
<p>Sentinel is beast and can do a whole lot. The challenge is getting people trained and involving those with the security background that can help them identify what attacks to look for. The filtering language can be very powerful if an Admin can logically think about what sequence of events might take place during an attack. There is a &#8220;window&#8221; feature where a current attack can be compared to an attack that took place earlier where a set range of time can be specified. For example a usecase can be if someone attempts to login as administrator 5 times within 24 hours you might want to have a filter and event setup to disable that account temporarily and kick off a workflow to reenable that account once its been approved.</p>
<p>For those firms this product may be overkill and they may want to look into Novell&#8217;s new identity Audit application which was formerly known as Novell Scout. PS that is a totally different application. Sentinel was aquired in the purchase of a company called esecurity. Scout was an application that Novell developed and is not a light version of Sentinel.</p>
<p>This training was pretty well laid out. The labs were pretty good. The environment was great. There were about 25 integrators (Novell partners) representing companies from all over the US. They had a few give aways (i.e. blu ray player and external drive). They even took us out to dinner  one night, paid for our hotel rooms, and provided lunch every day. So Thanks to Novell for treating us right and getting us aquainted with Sentinel.</p>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/novell-sentinel-training-day-4/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Novell Sentinel Training Day 3</title>
		<link>http://azeemkhan.info/id/2008/novell-sentinel-training-day-3/</link>
		<comments>http://azeemkhan.info/id/2008/novell-sentinel-training-day-3/#comments</comments>
		<pubDate>Fri, 10 Oct 2008 08:11:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Identity management]]></category>

		<category><![CDATA[Novell]]></category>

		<category><![CDATA[Sentinel]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=37</guid>
		<description><![CDATA[

Alright Day 3 of Sentinel training was pretty good. We reviewed performing actions when a correlation rule is met on an event filter.  We also learned about &#8220;solution packs&#8221;.  A little bit about how they are structured, but mainly how to import, edit and redeloy them. We were shown the PCI DSS solution pack. I [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-click">
<div class="wp-caption alignright" style="width: 212px"><a href="http://commons.wikipedia.org/wiki/Image:Nuvola_apps_kchart.svg"><img title="Icon for Nuvola icon theme for KDE 3.x." src="http://upload.wikimedia.org/wikipedia/commons/thumb/3/32/Nuvola_apps_kchart.svg/202px-Nuvola_apps_kchart.svg.png" alt="Icon for Nuvola icon theme for KDE 3.x." width="202" height="202" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p>Alright Day 3 of Sentinel training was pretty good. We reviewed performing actions when a correlation rule is met on an event filter.  We also learned about &#8220;solution packs&#8221;.  A little bit about how they are structured, but mainly how to import, edit and redeloy them. We were shown the <a class="zem_slink" title="PCI DSS" rel="wikipedia" href="http://en.wikipedia.org/wiki/PCI_DSS">PCI DSS</a> solution pack. I must say it was pretty comprehensive, which is sold for $30K by itself. We also were given a sales presentation breaking down the scope of <a class="zem_slink" title="Novell" rel="homepage" href="http://www.novell.com/">Novell</a>&#8217;s ISM (Identity and Security Management) products. It was explained to us that ISM is now one of Novell&#8217;s 3 focuses. Any supported products will fall under their main areas of focus. They also mentioned that they did very well this final quarter which is about to end for them. That&#8217;s really good news for <a class="zem_slink" title="Identity management" rel="wikipedia" href="http://en.wikipedia.org/wiki/Identity_management">Identity Management</a>, especially at a time when the economy is not doing well. We also heard from some attendees in the training course that <a class="zem_slink" title="IBM" rel="homepage" href="http://www.ibm.com/">IBM</a> is also doing very well. And of course IBM has its own Identity Management suite. So even more good news for Identity Management. The sales rep explained that Identity Management was initially seen as a sub-area of focus for IT departments and was not seen as being under security. But now Identity Management is seen more as being under security rather than traditional IT because of the specialization that goes into it.<br />
<span id="more-37"></span></p>
<p>Back to Sentinel&#8230;  the Actions that can be performed when a correlation rule is met are: configure Correlation Event, Create Incident (to be assigned and resolved), Execute Command (custom batch file), remove Dynamic list, Send Email, Set <a class="zem_slink" title="Lightweight Directory Access Protocol" rel="wikipedia" href="http://en.wikipedia.org/wiki/Lightweight_Directory_Access_Protocol">LDAP</a> attribute (i.e. in E-directory), and the latest addition giving much flexibility is executing Javascript. We also learned how to import collectors and connectors. The Higherarchy seems to be Collector-&gt;connectors.  Also there has been quite a bit of <a href="http://www.novell.com/products/sentinel/sentinel_6_upgrade.html" target="_blank">changes</a> from 6.0 to 6.1.  We also learned that Collectors and Connectors can be bundled and deployed with solution packs. A base install of Sentinel does not include any collectors or connectors. You have to download them from the Novell Site. Some are free i.e. the Collector for <a class="zem_slink" title="Active Directory" rel="wikipedia" href="http://en.wikipedia.org/wiki/Active_Directory">Active Directory</a>. I am still looking for a comprehensive list of whats free and whats for purchase.</p>
<p>The Salesperson also broke down the CMP (Compliance Management Platform) product line (which is really a bundle) a little bit.  The first product that is pushed is Analyzer which does some data sanatizing/analytics to help show how more resources can be used. Identity Manager and Sentinel are the 2 major components of CMP.  Aside from there being some collectors and connectors to integrate Identity Manager with Sentinel I did not hear a whole lot else about how they integrate. The only example I have heard is being able to pull data from Identity Manager when a user is involved in an incident. Imagine if someone tries to access something they should not access. Not only can their account be disabled if they try repeatedly over a certain window of time, but their profile can be pulled from Identity Manager which would even show their picture. We were also told that an action from a correlated event in Sentinel could kick off an Identity Manager workflow. I guess that would be done through the SOAP connector? (not sure) Aside from this I haven&#8217;t heard too much more about how these products integrate. The rights to Sentinel were brought from E-security when Novell purchaed them. Eric noted that the UI must have been changed from the original version because it now looks similar to Novell&#8217;s Identity manager. Another confusing thing that came up is how roles are managed. Identity Manager apparently has its own role based system, but there is another Novell product called Access manager which does nothing but roles. There is another program called Identity Audit which is supposed to help with compliancy but does nothing but reports. So there is some redundancy in the offering of some ot these products. Crystal reports (a little lincse comes with CMS).</p>
<p>In my next post on the final day of Sentinel training, I will include screenshots from my training image.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.news.com/PCI-DSS-hits-Web-2.0/2324-12640_3-6238296.html?part=rss&amp;subj=news">PCI DSS hits Web 2.0</a></li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/c1db3683-293b-430f-9190-25be5d5f64d9/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=c1db3683-293b-430f-9190-25be5d5f64d9" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/novell-sentinel-training-day-3/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Novell Sentinel Training Day 2</title>
		<link>http://azeemkhan.info/id/2008/novell-sentinel-training-day-2/</link>
		<comments>http://azeemkhan.info/id/2008/novell-sentinel-training-day-2/#comments</comments>
		<pubDate>Thu, 09 Oct 2008 11:42:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Novell]]></category>

		<category><![CDATA[Sentinel]]></category>

		<guid isPermaLink="false">http://azeemkhan.info/id/?p=30</guid>
		<description><![CDATA[What a day! I have a headache, not because of the material or anything. Before I talk about what we did today I was thinking of sharing some usecases with you on where Sentinel would be highly beneficial to have. Imagine someone who is not an Administrator attempts to login as administrator, wouldn&#8217;t you want [...]]]></description>
			<content:encoded><![CDATA[<p>What a day! I have a headache, not because of the material or anything. Before I talk about what we did today I was thinking of sharing some usecases with you on where Sentinel would be highly beneficial to have. Imagine someone who is not an Administrator attempts to login as administrator, wouldn&#8217;t you want to know? If there were repeated login failures on a very important server or someone was trying to access a port which was designated for something important. Or Imagine an administrator assigns a non-administrator certain rights which are out of the oridnary you might want to know. An example that came up in class is: Someone who logs in at a Bank, withdraws or transfers a large amount of cash, and then changes their password. If a combination of such an event happened, imagine having a rule in place where an alert was triggered. All of these use cases were mentioned in the training so far.</p>
<p>Today we spent alot of time on writing correlation rules, learning the syntax (expressions and other things) which are unique to the sentinel product. We also spent a large ammount of time learning the administrative tools.</p>
<p>Due to my headache, Ill be more detailed in the next post.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/07d971c4-eb62-4193-98cf-b0a495716637/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=07d971c4-eb62-4193-98cf-b0a495716637" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://azeemkhan.info/id/2008/novell-sentinel-training-day-2/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
