Wednesday, February 13, 2008

WebDAV Vulnerability Worst of Four Windows Flaws « Bardissi Enterprises Blog

As a lot of us know, there are some serious DOS (denial of service) issues with AD.  AD just isn't fully LDAP compatible, that's the bottom line in my book.  If I have to interface to AD to multiple sources outside Microsoft designed use (inside the NOS), I recommend using a virtual directory to protect AD. Such LDAP packets as described below and other causes of DOS can be dealt with. 

Quoted from http://bardissi.wordpress.com/2008/02/12/webdav-vulnerability-worst-of-four-windows-flaws/:

WebDAV Vulnerability Worst of Four Windows Flaws « Bardissi Enterprises Blog

12 February, 2008

 

MS08-003: Active Directory Denial of Service Vulnerability

Active Directory is the Windows component that provides central authentication and authorization services for Windows computers. Active Directory runs on Windows servers, but also on Windows clients as the Active Directory Application Mode (ADAM) service. Microsoft’s security bulletin warns of an unspecified Denial of Service (DoS) vulnerability involving the way Active Directory handles specially crafted LDAP packets. By sending a malicious LDAP request, a remote attacker could exploit this vulnerability to cause your Windows computer to lock up or to reboot. The attacker could repeatedly exploit this vulnerability to keep your Windows machines offline for as long as he could sustain this attack. However, most administrators don’t allow LDAP traffic (TCP ports 389 and 3268) through their perimeter firewall. Therefore, this vulnerability primarily poses an internal threat.
Microsoft rating: Important.

 

Wednesday, February 6, 2008

Oracle Virtual Directory Webinar

I thought I would share an interesting webinar on virtual directories recently from Oracle on their virtual directory (OVD).

You can view the recording here.

This is the first time I've mentioned a product by name, and referenced a particular company. I try to stay as neutral as possible, perhaps out of habit due to my role to help customers decide. I usually always give at least two options for any decision and list the pro's and con's.

This webinar is a little generic, although I was able to get in a couple questions which the moderator answered decently. OVD certainly has a place in the marketplace and a specific role.

If you want an introduction at a high-level for what a virtual directory can do for you, this is a great resource so check it out.

What OVD doesn't do is offer solutions to more complex integration problems that you can face that require more feature sets, which Oracle will gladly provide to you, of course, at an additional price, as part of their IdM Suite, such as synchronization capabilities, data modeling, provisioning services, and more...

Monday, January 28, 2008

Problems extending Active Directory Schema

Jackson Shaw blogs about still MORE issues that are arising from trying to update schemas in active directory. This is why I encourage people NOT TO TRY THIS AT HOME (or at work). It's disruptive and can have some serious effects on your network infrastructure. Use the existing schema in a virtual directory, extend the schema there. Then you don't have to worry about the issues involved here. Point the applications that need this schema extension to the virtual directory instead of AD. Most virtual directories will let you mount an existing structure (proxy) and extend the entries from various data sources (including data bases, other directories, applications or web services). Some virtual directories will even allow a join function to extend the entry from its own local store if the needed schema attributes do not currently exist. Kind of neat huh? So why all the drama? I think people just don't understand this technology - you can use your existing stores and pretty much do anything you want with them, without replication. Performance you say? Well, if it really becomes a problem, there are several caching options and cache refresh options in virtual directories also. If you don't have a virtual directory (or one that has these options) in your arsenal, get one - it will save you a lot of headaches, and a lot of time. Become the famed Engineer Mr Scott of Star Trek fame and get everything done in one third the time or less!

read more | digg story

Friday, January 25, 2008

Matt Flynn Blog, Burton Group, affirm Virtual Directories as a Valuable IdM infrastructure component

Matt (see http://360tek.blogspot.com/2008/01/year-of-virtual-directory.html) asserts his continued position as an advocate of using virtual directories- and references Burton Group's affirmation of this technology as well in a recent webinar. Burton also published a paper recently (Nov'07) "Virtual Directories: Valuable Present, Promising Future" that is great information on the state of the vendors in this market and their capabilities. Not all of them have all the flexibility that Matt refers to "That is, virtualizing the data structure, access protocols, server locations, etc. and presenting the same useful data from its original source in real time (or cached) in virtually any format and over most common data interfaces." The Burton Group study will help a lot in sorting that out.http://identityinfrastructure.blogspot.com/

read more | digg story

Thursday, January 24, 2008

Weakness in IdM Products

http://duckdown.blogspot.com/2008/01/common-weakness-in-all-identity.htmlThis author takes a harsh, but not well versed stand, into criticizing ALL IdM software packages out there for the lack of integration into various data stores, especially Active Directory. If it were that simple, don't you think all the vendors would do it? Just the fact that the symptom is there for ALL IdM packages, should tell you there is MORE to the story, no??? First check out Gavin's response, a good one - and saved me from more ranting on here... http://blog.suretecsystems.com/archives/77-A-Common-Weakness-in-all-Identity-Management-Products,-but-not-OpenLDAP.html First - Active Directory is for INTERNAL users primarily. Not useful for all IdM initiatives, say for a partner portal, or federated business environment where the user list is NOT your network users. Second - If you know much about Active Directory you will know 1st AD admins don't want you messing with it, you can cause serious problems if you do - extending schemas, customer object classes, etc pose problems, plus its SLOW - HENCE why ADAM exists in the first place, but then why isn't everyone clamouring over the use of ADAM? Like Gavin Henry says... I encourage this author to take a look at the white paper Open LDAP wrote (http://symas.com/documents/Adam-Eval1-0.pdf) and you will start to see the limitations and disjointed nature of LDAP compliant directory services and AD.

read more | digg story

Completeness of Metadata

http://www.b-eye-network.com/view/6722 This is just kind of interesting, nothing great... BUT the issue of how you do handle large amounts of metadata does ring true. The author states that perhaps you must limit your metadata and not try to get a complete picture. Of course you do! You must limit it to the context in which it is relevant! This is why I think the hierarchal views found in directories are great, they can give you direct context of data, natively (i.e. look at the DN of a user object) - if you build these trees correctly you have some great information to leverage. Let's take it one step further, look at a virtual directory - where you can change the labels and tags as you want, giving the DN a more explicit meaning.If your confused, don't feel bad, I've confused many on this topic - but if you can get your head around it, it will pay off!!

read more | digg story

Five Steps to Better Data Management

In this article Michael Daconta spells out in his vision what steps need to be taken to ensure successful future growth of your enterprise architecture. http://www.gcn.com/print/27_2/45685-1.htmlPay attention to step#4. Install a data services layer in your service-oriented architecture plumbing. This isn't just an SOA thing, don't wait for SOA come to you, create a data service layer now. You will be one step closer to SOA (if planned well, so go ahead and ask the vendors you talk to, what the plan is for SOA integration in future releases) and one step closer to unbelievable flexibility and an almost end to this constant reinventing the wheel for each application you bring online.

read more | digg story

Friday, January 11, 2008

Global Key Mapping

I read an article a few days ago in the latest issue of DMReview titled, "Global Keys: A Unified Key Mapping Architecture".

I visited the authors blog at http://www.globalkeysdesign.com/global_keys/blog_index.html and found it to be a good start of a very important discussion about creating a centralized mapping of keys for multiple data repositories that contain equivalent data (or identities).

Check out my post
http://www.globalkeysdesign.com/global_keys/2008/01/what-me-work.html

Thursday, January 3, 2008

MDM without boiling the ocean

The concepts are the same for Identity Management, you don't have to solve every problem in the world to get started solving your integration problems... BUT you can make some savvy choices, like planning ahead and going with solutions that have "legs". If you have read my blog entries you know I love the data-virtualization concept and benefits. The author of this article (http://www.it-director.com/blogs/Fern_Halper/2007/12/MDM_without_boiling_the_ocean.html) is starting to see some of the benefits of the data-virtualization idea, its too bad there isn't any examples given or benefits achieved. Identity Management can be as daunting as MDM (master data management), and in many ways more critical. My recent run-in with Blue-Cross of California shows my point, they have decided to integrate their multiple systems (e.g. star, gemcorp, etc) into a web service so that members can access information and services at a single point - sounds simple enough right? on the contrary, its not working and they are puzzled as to why... members who are in multiple systems, perhaps inactive in one data silo and active in another for example, can not access the website or retrieve registration information. As of my last contact with that group, they have no ETA on when they will solve this problem, nor have they isolated where the problem lies... amazing... It is obvious to me that it lies in the choice of data integration tools, it looks like Blue Cross will be relying on their old systems, and a lot more member calls (btw their tech support is reporting a minimum wait time of 25 minutes as of yesterday), and upset customers for awhile longer.... Create an abstraction layer that can grow with you. Solve one piece of the puzzle at a time, when you have a piece in place, implement it without disrupting other current systems.... this one of the largest benefits I am finding in using data-virtualization tools like virtual directories, I don't have to use it for everything at once (I can implement authentication via ldap proxy using a virtual directory server, and later add services such as provisioning or user management), and it operates into my current environment natively as I need it to (i.e. ldap, or sql, or xml/web services, etc) not some new custom protocol. How do you eat an elephant? one bite at a time! Break your project into small pieces, with your eye on creating tools for the future, you just might be able to boil the ocean yet...

read more | digg story

Wednesday, December 12, 2007

LDAP support via sudo in UNIX

An enterprising blogger expounds how you do no longer need to be limited in how UNIX users are managed, such as storing user account in flat files. Using sudo will let the administrator utilize a directory service for security (i.e. authentication/authorization). There are other solutions, but here is one that is relatively easy and cheap since sudo is open-source and the functionality is built-in.http://breakablelinux.blogspot.com/2007/12/linux-authentication-and-authorization.html

read more | digg story

Thursday, December 6, 2007

Solving the privacy puzzle in a federated identity model

In this article Rosie Lombardi contrasts virtual directories and meta-directories as the central access point options in creating a federated environment for consolidated authentication via web. A simple overview, but some good points of discussion, how do governments establish a way for people to gain information and access to services across agencies, states, and other governing systems?Unique Identifier or FIM?She quotes Temoshok at the GSA... "I don't want to simplify too much, but governments have two basic choices for this: a national ID or federated identity management system," So, here are the questions that arise. >> If you have FIM how do the silos correlate identities without the national ID# to act as the unique identifier? >> If you have a national ID, how do you facilitate the data sharing? Where do you verify the national ID is valid? What is the person in question is using the same national ID# with different alias'? You need a silo to set up the "master" national ID list - creating a huge repository of all your citizens. After the initial verification, what about continued information exchange? What if the person moves, the address is not updated. What about national security concerns? I see virtual directories as offering more to solving these problems than just being easier and less expensive to deploy (as the only benefit asserted by James Quin, senior analyst at Info-Tech Research Group asserts in the article). A virtual directory solution can be used to solve the correlation problem between identities (without the pesky national id#), impose policy (logic) to alert administrators of suspicious activity (i.e. same ID# using several different names/aliases) and update (synchronize) information across systems such as new phone numbers, address changes, or other contact information. Quin also brings up the question of security, he feels that one meta-directory is more secure (although admittedly most expensive and complicated to deploy) because there is only one point of failure. With the virtual directory solution he says there are multiple points of failure, the virtual directory and all connected sources - how is this not true of the meta-directory system, unless you are planning not to synchronize and if you don't synchronize, how you expect to keep the information current? Or perhaps you are not using the virtual directory as the point of access, and securing the underlying sources behind firewalls, etc? "But the virtual directory approach means personal information about citizens resides in many government systems and servers in redundant and potentially inaccurate forms." Here we see a lack of understanding of the functions and features of virtual directories. Virtual directories are perfectly able to perform synchronization services, correlation, identity aggregation, directory replication, and more, perfectly designed for exactly this problem.I don't see a down side to virtual directories, I just don't. The more I learn and the more I use virtual directories to solve these problems, the more I love them! Virtual directories can be made just a secure using SAML, SSL, and ACI's just as a metadirectory (only if you have a good directory service attached to the front end). http://www.intergovworld.com/article/abc978260a01040800129dda8cb5dba1/pg1.htm

read more | digg story

Monday, December 3, 2007

Logical Data Models for SOA Information Exchange

See what some say is the major road-block to SOA deployments and why it doesn't have to be so hard to solve - you need to think hierarchy, data modeling, object-classes, and abstraction (flexibility). If you are used to working with Directories and even more so, virtual directories, you will have a leg up on understanding these concepts and how they are useful in simplifying the issues in SOA deployments. It doesn't have to be that bad, REALLY!

read more | digg story

SOA in the IdM

Here is a definition of SOA given in the article found at http://www.itbusinessedge.com/item/?ci=23055 - its a short understandable definition;
"SOA. Service-oriented architecture refers to a paradigm that focuses on how you maximize the sharing, reuse and interoperability of distributed corporate resources across your network. And to maximize sharing, reuse, etc., you need a universal middleware environment, an integration fabric, a set of standards. So that comes down to things like the Web services standards" and I would add LDAP and SQL to these standards, don't keep this idea only in the world of external users, internet, or even intranet - use these concepts at the data integration level inside your IT deployments, especially in the IdM services space....

Virtual Directories are such a middleware component that can accomplish this. SOA is here if you want it, or you can wait until the vendors catch up and start helping you understand how to use their products....

Security and Data Management

Identity Management and Data Management starting to overlap in your mind? Then maybe its because you have dug into the topic deep enough to see the problems, or you are just losing sight of where the lines are? Certainly some of the issues are the same and have the same solutions, so where is the future of IdM?

read more | digg story

Friday, November 30, 2007

Why use LDAP?

Why LDAP?

The question is a good one and I think as LDAP proliferates across more systems, many people will have the same question - and it deserves a good answer, so here is my two-cents-worth.

What we are really talking about is directory services, not just the protocol. Directories have some serious advantages over DBMS. Databases are optimized for OLTP (online transaction processing), but not for performing quick searches of information that is frequently used, but not updated constantly. In other words, Directories can deliver data very quickly (read) compared to a DB, but handles updates (write) slower in comparison to databases.

Features and Benefits using LDAP

§ Cross-platform functionality and industry standards-based (important consideration for future growth and deployments)

§ Widely accepted standard for the Internet

§ Inexpensive since licensing is usually not based on number of connections or clients open source directories are widely available. Also, replication and synchronization features are usually built-in rather than requiring a separate license as is the case for many databases.

§ Replication and synchronization is easy compared to complex DBMS implementation with highly specific SQL script requirements.

§ ACI’s for delegated administration so you can setup accounts that are highly specific in what administration functions a group has {e.g. an account may only allow for phone numbers to be updated, another for new objects (name, email, phone number) to be inserted, but not deleted or existing objects modified}

§ High Performance, since directory data is store hieratical you have very high availability over DBMS, sometimes up to 10 times higher.

Sample Use Cases.

The following is a short list of common uses of directory services since these uses are data profiles that are fairly static and do not have deep relationships – they are stored as relatively “flat” trees.

§ Phone / Address book

§ Infrastructure Resource List (ip addresses, etc)

§ Public Certificates

§ User credentials, groups, roles (for authentication/ authorization)

Directories are also more secure and can keep credentials “locked” and unable to read or copy from an outside source, and you can do in a database. Directories are based on a hierarchal storage schema, a “tree” structure. Information that would be able bi-directionally in a database are not available in this manner in a directory. Items that are lower in the hierarchy could be read, but data higher in the hierarchy are not available to the client. So you could read a person’s contact information, but not necessarily be able to see what accounts he has, or other people in a group that she is a part of. In a database, records are stored relationally, so if you can read a person in a group, you can read the group and theoretically see the records of everyone in the group if you have direct access to the tables, not true in a directory. read more | digg story