<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>IYA Cyber Security</title><description>IYA Cyber Security is a boutique cybersecurity consulting firm specializing in application security, API security, identity, and API management.</description><link>https://iyasec.io/</link><language>en-us</language><item><title>Bearer, Proof of Possession, and Sender Vouches: Three Ways to Trust an Identity</title><link>https://iyasec.io/blog/bearer-proof-of-possession-and-sender-vouches-three-ways-to-trust-an/</link><guid isPermaLink="true">https://iyasec.io/blog/bearer-proof-of-possession-and-sender-vouches-three-ways-to-trust-an/</guid><description>One of the most fundamental questions in any identity or authorization system is how does the system know that the party presenting a credential is actually entitled to use it?</description><pubDate>Thu, 20 Aug 2026 17:13:23 GMT</pubDate><category>access-tokens</category><category>authorization</category><category>iam</category><category>saml</category><category>identity</category></item><item><title>Holder of Key vs. Proof of Possession: Two Sides of Cryptographic Identity</title><link>https://iyasec.io/blog/holder-of-key-vs-proof-of-possession-two-sides-of-cryptographic-identity/</link><guid isPermaLink="true">https://iyasec.io/blog/holder-of-key-vs-proof-of-possession-two-sides-of-cryptographic-identity/</guid><description>For years, identity protocols have used phrases such as Holder of Key, Proof of Possession, Key Binding, and Bearer almost interchangeably.</description><pubDate>Wed, 19 Aug 2026 19:16:17 GMT</pubDate><category>access-tokens</category><category>authentication</category><category>iam</category><category>cryptography</category><category>identity</category></item><item><title>Content Security Policy: Putting the Browser on a Security Diet</title><link>https://iyasec.io/blog/content-security-policy-putting-the-browser-on-a-security-diet/</link><guid isPermaLink="true">https://iyasec.io/blog/content-security-policy-putting-the-browser-on-a-security-diet/</guid><description>Web applications have become remarkably powerful.</description><pubDate>Wed, 19 Aug 2026 16:50:45 GMT</pubDate><category>application-security</category><category>web-application-security</category><category>security</category></item><item><title>OAuth2 + OIDC: All of the Specs (2026 Edition)</title><link>https://iyasec.io/blog/oauth2-oidc-all-of-the-specs-2026-edition/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth2-oidc-all-of-the-specs-2026-edition/</guid><description>Current as of August, 2026.</description><pubDate>Tue, 18 Aug 2026 16:36:31 GMT</pubDate><category>oauth2</category><category>openid-connect</category><category>standards</category></item><item><title>Cryptographic Bill of Materials: The CBOM To The Industry’s SBOM</title><link>https://iyasec.io/blog/cryptographic-bill-of-materials-the-cbom-to-the-industrys-sbom/</link><guid isPermaLink="true">https://iyasec.io/blog/cryptographic-bill-of-materials-the-cbom-to-the-industrys-sbom/</guid><description>A Cryptographic Bill of Materials (CBOM) is exactly what it sounds like: an inventory of every cryptographic component used throughout an organization. If a Software Bill of Materials (SBOM) tells you what software you have, a CBOM tells you how that software is protected.</description><pubDate>Tue, 18 Aug 2026 16:36:03 GMT</pubDate><category>post-quantum-cryptography</category><category>supply-chain-security</category><category>cryptography</category></item><item><title>Digital Death: Legal Frameworks</title><link>https://iyasec.io/blog/digital-death-legal-frameworks/</link><guid isPermaLink="true">https://iyasec.io/blog/digital-death-legal-frameworks/</guid><description>Disclaimer: I’m not a lawyer. I’m just trying to understand how this works.</description><pubDate>Mon, 17 Aug 2026 16:18:35 GMT</pubDate><category>digital-death</category><category>regulation</category><category>identity</category></item><item><title>MCP Governance With Bifrost AI Gateway</title><link>https://iyasec.io/blog/mcp-governance-with-bifrost-ai-gateway/</link><guid isPermaLink="true">https://iyasec.io/blog/mcp-governance-with-bifrost-ai-gateway/</guid><description>The Model Context Protocol (MCP) has changed the relationship between an LLM and the systems around it.</description><pubDate>Mon, 17 Aug 2026 16:01:29 GMT</pubDate><category>api-gateway</category><category>llm</category><category>mcp</category><category>ai</category><category>governance</category></item><item><title>The AI-Enhanced Afterlife: No Thanks</title><link>https://iyasec.io/blog/the-ai-enhanced-afterlife-no-thanks/</link><guid isPermaLink="true">https://iyasec.io/blog/the-ai-enhanced-afterlife-no-thanks/</guid><description>I like this one. It sits right at the intersection of AI, identity, law, and just enough existential dread to make people double-check their password manager.</description><pubDate>Sun, 16 Aug 2026 16:15:29 GMT</pubDate><category>digital-death</category><category>regulation</category><category>ai</category><category>identity</category></item><item><title>The Digital Dead: Existence Beyond Death Online</title><link>https://iyasec.io/blog/the-digital-dead-existence-beyond-death-online/</link><guid isPermaLink="true">https://iyasec.io/blog/the-digital-dead-existence-beyond-death-online/</guid><description>I started thinking about this post a while back when I saw a former colleague’s Medium profile still listed as following mine. He died in the early days of covid. A quick check showed that his LinkedIn profile seems to have disappeared — not sure how that works. It was still there a few years ago.</description><pubDate>Sun, 16 Aug 2026 15:46:00 GMT</pubDate><category>digital-death</category><category>iam</category><category>identity</category><category>security</category></item><item><title>PKCE: Proof Key for Code Exchange</title><link>https://iyasec.io/blog/pkce-proof-key-for-code-exchange/</link><guid isPermaLink="true">https://iyasec.io/blog/pkce-proof-key-for-code-exchange/</guid><description>One of the biggest misconceptions about OAuth2 is that it is a single protocol. In reality, OAuth2 has evolved considerably over the years as new attack vectors have been discovered and new security mechanisms introduced. One of the most significant of these improvements is Proof Key for Code…</description><pubDate>Sat, 15 Aug 2026 16:00:40 GMT</pubDate><category>iam</category><category>oauth2</category><category>pkce</category><category>security</category></item><item><title>DPoP: The Missing Security Layer in OAuth2 and OID4VCI</title><link>https://iyasec.io/blog/dpop-the-missing-security-layer-in-oauth2-and-oid4vci/</link><guid isPermaLink="true">https://iyasec.io/blog/dpop-the-missing-security-layer-in-oauth2-and-oid4vci/</guid><description>OAuth2 has long suffered from a fundamental weakness: bearer tokens.</description><pubDate>Sat, 15 Aug 2026 15:19:49 GMT</pubDate><category>access-tokens</category><category>dpop</category><category>oauth2</category><category>verifiable-credentials</category><category>security</category></item><item><title>Elliptic Curve Groups: The Mathematical Engine Behind Modern Digital Identity</title><link>https://iyasec.io/blog/elliptic-curve-groups-the-mathematical-engine-behind-modern-digital-identity/</link><guid isPermaLink="true">https://iyasec.io/blog/elliptic-curve-groups-the-mathematical-engine-behind-modern-digital-identity/</guid><description>If you’ve ever read a specification like WebAuthn, DID Core, SD-JWT VC, BBS Signatures, OID4VCI, or OID4VP, you’ve probably encountered references to P-256, secp256k1, Ed25519, or BLS12–381.</description><pubDate>Fri, 14 Aug 2026 15:56:00 GMT</pubDate><category>authentication</category><category>elliptic-curve-cryptography</category><category>jwt</category><category>sd-jwt</category><category>cryptography</category><category>identity</category></item><item><title>Discrete Algorithms: The Mathematics of Decisions, Networks, and Digital Intelligence</title><link>https://iyasec.io/blog/discrete-algorithms-the-mathematics-of-decisions-networks-and-digital-intelligence/</link><guid isPermaLink="true">https://iyasec.io/blog/discrete-algorithms-the-mathematics-of-decisions-networks-and-digital-intelligence/</guid><description>When we think about algorithms, we often imagine a computer executing a series of instructions:</description><pubDate>Fri, 14 Aug 2026 15:13:19 GMT</pubDate><category>mathematics</category><category>networking</category></item><item><title>WS-Federation Support Comes to the Identity Protocol Debugger</title><link>https://iyasec.io/blog/ws-federation-support-comes-to-the-identity-protocol-debugger/</link><guid isPermaLink="true">https://iyasec.io/blog/ws-federation-support-comes-to-the-identity-protocol-debugger/</guid><description>Yes, WS-Federation.</description><pubDate>Thu, 13 Aug 2026 15:40:20 GMT</pubDate><category>debugging</category><category>federation</category><category>tools</category><category>ws-federation</category><category>identity</category></item><item><title>Finite Fields: The Mathematics Behind Cryptography, Error Correction, and Digital Trust</title><link>https://iyasec.io/blog/finite-fields-the-mathematics-behind-cryptography-error-correction-and-digital-trust/</link><guid isPermaLink="true">https://iyasec.io/blog/finite-fields-the-mathematics-behind-cryptography-error-correction-and-digital-trust/</guid><description>Modern technology runs on mathematics that most people never see.</description><pubDate>Thu, 13 Aug 2026 14:58:42 GMT</pubDate><category>mathematics</category><category>cryptography</category></item><item><title>The Future of Mathematics: AI’s Impact on the Field</title><link>https://iyasec.io/blog/the-future-of-mathematics-ai-s-impact-on-the-field/</link><guid isPermaLink="true">https://iyasec.io/blog/the-future-of-mathematics-ai-s-impact-on-the-field/</guid><description>Or, how AI Is Changing Mathematics</description><pubDate>Wed, 12 Aug 2026 14:08:30 GMT</pubDate><category>mathematics</category><category>ai</category></item><item><title>Model Governance: Congratulations, You’ve Hired the Smartest Intern in History</title><link>https://iyasec.io/blog/model-governance-congratulations-you-ve-hired-the-smartest-intern-in-history/</link><guid isPermaLink="true">https://iyasec.io/blog/model-governance-congratulations-you-ve-hired-the-smartest-intern-in-history/</guid><description>The first thing people do after deploying a Large Language Model (LLM) is ask it to write a poem.</description><pubDate>Wed, 12 Aug 2026 08:34:18 GMT</pubDate><category>ai-governance</category><category>llm</category><category>ai</category><category>governance</category></item><item><title>SD-JWT VC vs. BBS-2023: Why These Aren’t Really the Things You’re Comparing</title><link>https://iyasec.io/blog/sd-jwt-vc-vs-bbs-2023-why-these-aren-t-really-the/</link><guid isPermaLink="true">https://iyasec.io/blog/sd-jwt-vc-vs-bbs-2023-why-these-aren-t-really-the/</guid><description>There is a recurring problem in the Verifiable Credentials world.</description><pubDate>Tue, 11 Aug 2026 13:47:44 GMT</pubDate><category>jwt</category><category>sd-jwt</category><category>selective-disclosure</category><category>verifiable-credentials</category><category>cryptography</category></item><item><title>Data Minimization: Why Does the Coffee Shop Need to Know My Blood Type?</title><link>https://iyasec.io/blog/data-minimization-why-does-the-coffee-shop-need-to-know-my-blood/</link><guid isPermaLink="true">https://iyasec.io/blog/data-minimization-why-does-the-coffee-shop-need-to-know-my-blood/</guid><description>Modern identity systems have a bit of a hoarding problem.</description><pubDate>Tue, 11 Aug 2026 07:41:41 GMT</pubDate><category>data-protection</category><category>privacy</category><category>identity</category></item><item><title>Decentralized Identifiers: Because Apparently We Needed to Rethink the Name Field</title><link>https://iyasec.io/blog/decentralized-identifiers-because-apparently-we-needed-to-rethink-the-name-field/</link><guid isPermaLink="true">https://iyasec.io/blog/decentralized-identifiers-because-apparently-we-needed-to-rethink-the-name-field/</guid><description>For most of the history of digital identity, we’ve had a remarkably simple solution to the question, “Who are you?”</description><pubDate>Mon, 10 Aug 2026 04:58:47 GMT</pubDate><category>decentralized-identity</category><category>identity</category></item><item><title>DPoP Support Comes to the Identity Protocol Debugger</title><link>https://iyasec.io/blog/dpop-support-comes-to-the-identity-protocol-debugger/</link><guid isPermaLink="true">https://iyasec.io/blog/dpop-support-comes-to-the-identity-protocol-debugger/</guid><description>OAuth2 has always had a fundamental problem: a bearer token is a bearer token. After all, it’s a bearer token.</description><pubDate>Mon, 10 Aug 2026 02:50:38 GMT</pubDate><category>access-tokens</category><category>debugging</category><category>dpop</category><category>oauth2</category><category>tools</category><category>identity</category></item><item><title>Bilinear Pairings: Modern Privacy-Preserving Cryptography</title><link>https://iyasec.io/blog/bilinear-pairings-modern-privacy-preserving-cryptography/</link><guid isPermaLink="true">https://iyasec.io/blog/bilinear-pairings-modern-privacy-preserving-cryptography/</guid><description>If you’ve spent any time reading about modern cryptography — especially BBS Signatures, attribute-based credentials, or identity-based encryption — you’ve probably encountered the phrase bilinear pairing.</description><pubDate>Fri, 07 Aug 2026 12:46:47 GMT</pubDate><category>selective-disclosure</category><category>privacy</category><category>cryptography</category><category>identity</category></item><item><title>Post Quantum Cryptography Migration Road Map: Because Waiting Until the Last Minute Has Never Gone…</title><link>https://iyasec.io/blog/post-quantum-cryptography-migration-road-map-because-waiting-until-the-last-minute/</link><guid isPermaLink="true">https://iyasec.io/blog/post-quantum-cryptography-migration-road-map-because-waiting-until-the-last-minute/</guid><description>There are two kinds of organizations in the world.</description><pubDate>Thu, 06 Aug 2026 12:08:20 GMT</pubDate><category>post-quantum-cryptography</category><category>cryptography</category></item><item><title>Elliptic Curve Cryptography: The Tiny Keys That Protect the Internet</title><link>https://iyasec.io/blog/elliptic-curve-cryptography-the-tiny-keys-that-protect-the-internet/</link><guid isPermaLink="true">https://iyasec.io/blog/elliptic-curve-cryptography-the-tiny-keys-that-protect-the-internet/</guid><description>If you’ve spent any time reading about modern cryptography, you’ve probably encountered the phrase Elliptic Curve Cryptography (ECC). It sounds less like a security technology and more like an elective mathematics course that everyone regrets taking — I’ve been in several of those.</description><pubDate>Thu, 06 Aug 2026 06:44:38 GMT</pubDate><category>elliptic-curve-cryptography</category><category>mathematics</category><category>cryptography</category><category>security</category></item><item><title>Selective Disclosure: The Math</title><link>https://iyasec.io/blog/selective-disclosure-the-math/</link><guid isPermaLink="true">https://iyasec.io/blog/selective-disclosure-the-math/</guid><description>Selective Disclosure is fundamentally a mathematical concept. The protocols (SD-JWT VC, BBS-2023, AnonCreds, Idemix, U-Prove, etc.) are really just engineering built on top of several branches of mathematics.</description><pubDate>Wed, 05 Aug 2026 00:39:01 GMT</pubDate><category>jwt</category><category>mathematics</category><category>sd-jwt</category><category>selective-disclosure</category><category>privacy</category><category>cryptography</category></item><item><title>Quantum Mechanics Explained: The Universe’s Passive-Aggressive User Manual</title><link>https://iyasec.io/blog/quantum-mechanics-explained-the-universe-s-passive-aggressive-user-manual/</link><guid isPermaLink="true">https://iyasec.io/blog/quantum-mechanics-explained-the-universe-s-passive-aggressive-user-manual/</guid><description>This post seemed like a missing link in my Post-Quantum Cryptography series. Note, this is for non-technical people, non-physicist, or maybe IT community.</description><pubDate>Tue, 04 Aug 2026 14:53:44 GMT</pubDate><category>post-quantum-cryptography</category><category>quantum-computing</category><category>cryptography</category></item><item><title>Selective Disclosure: Finally, an Identity System That Knows When to Stop Talking</title><link>https://iyasec.io/blog/selective-disclosure-finally-an-identity-system-that-knows-when-to-stop-talking/</link><guid isPermaLink="true">https://iyasec.io/blog/selective-disclosure-finally-an-identity-system-that-knows-when-to-stop-talking/</guid><description>For decades, digital identity has operated on a remarkably inefficient principle, “If someone asks for one piece of information, give them everything.”</description><pubDate>Tue, 04 Aug 2026 00:17:46 GMT</pubDate><category>selective-disclosure</category><category>privacy</category><category>identity</category></item><item><title>Verifiable Credentials: The Next Evolution of Identity &amp; Access Management</title><link>https://iyasec.io/blog/verifiable-credentials-the-next-evolution-of-identity-access-management/</link><guid isPermaLink="true">https://iyasec.io/blog/verifiable-credentials-the-next-evolution-of-identity-access-management/</guid><description>Identity &amp; Access Management (IAM) has spent decades answering fairly simple questions: “Who are you?” and “What are you allowed to do?”</description><pubDate>Mon, 03 Aug 2026 14:18:23 GMT</pubDate><category>verifiable-credentials</category><category>identity</category></item><item><title>WebAuthN: Passwordless Logins</title><link>https://iyasec.io/blog/webauthn-passwordless-logins/</link><guid isPermaLink="true">https://iyasec.io/blog/webauthn-passwordless-logins/</guid><description>WebAuthn is actually the tip of a much larger iceberg. Like the SD-JWT VC spec, it is built upon several W3C, FIDO Alliance, and IETF specifications. Together, these define a complete passwordless authentication ecosystem.</description><pubDate>Sun, 02 Aug 2026 14:06:34 GMT</pubDate><category>authentication</category><category>jwt</category><category>sd-jwt</category><category>selective-disclosure</category><category>webauthn</category></item><item><title>Unlinkability: Randomness Is Your Friend</title><link>https://iyasec.io/blog/unlinkability-randomness-is-your-friend/</link><guid isPermaLink="true">https://iyasec.io/blog/unlinkability-randomness-is-your-friend/</guid><description>Imagine if every time you bought groceries, boarded a plane, logged into a website, rented a car, or proved you were old enough to appreciate terrible coffee, someone quietly scribbled another note into your permanent file.</description><pubDate>Sun, 02 Aug 2026 12:29:46 GMT</pubDate><category>selective-disclosure</category><category>privacy</category></item><item><title>Identity Protocol Debugger Now Supports SD-JWT VC Issuance and Presentation Flows</title><link>https://iyasec.io/blog/identity-protocol-debugger-now-supports-sd-jwt-vc-issuance-and-presentation-flows/</link><guid isPermaLink="true">https://iyasec.io/blog/identity-protocol-debugger-now-supports-sd-jwt-vc-issuance-and-presentation-flows/</guid><description>Another day, another identity specification to debug.</description><pubDate>Sat, 01 Aug 2026 14:04:39 GMT</pubDate><category>debugging</category><category>jwt</category><category>sd-jwt</category><category>selective-disclosure</category><category>tools</category><category>verifiable-credentials</category></item><item><title>Privacy-Preserving Identity: Proving What Matters Without Revealing Everything</title><link>https://iyasec.io/blog/privacy-preserving-identity-proving-what-matters-without-revealing-everything/</link><guid isPermaLink="true">https://iyasec.io/blog/privacy-preserving-identity-proving-what-matters-without-revealing-everything/</guid><description>For decades, digital identity has followed a remarkably simple philosophy, “Tell me everything about yourself, and I’ll decide whether you may proceed.”</description><pubDate>Sat, 01 Aug 2026 11:45:56 GMT</pubDate><category>privacy</category><category>identity</category></item><item><title>AI Governance: Or, Congratulations on Inventing a Robot That Can Make Bad Decisions at Scale</title><link>https://iyasec.io/blog/ai-governance-or-congratulations-on-inventing-a-robot-that-can-make-bad/</link><guid isPermaLink="true">https://iyasec.io/blog/ai-governance-or-congratulations-on-inventing-a-robot-that-can-make-bad/</guid><description>Every new technology eventually discovers governance.</description><pubDate>Fri, 31 Jul 2026 05:49:08 GMT</pubDate><category>ai-governance</category><category>ai</category><category>governance</category></item><item><title>What are AI Gateways: API Gateways Learned a New Language</title><link>https://iyasec.io/blog/what-are-ai-gateways-api-gateways-learned-a-new-language/</link><guid isPermaLink="true">https://iyasec.io/blog/what-are-ai-gateways-api-gateways-learned-a-new-language/</guid><description>Or, the name was misspelled.</description><pubDate>Fri, 31 Jul 2026 05:09:55 GMT</pubDate><category>api-gateway</category><category>ai</category><category>apis</category></item><item><title>Risk Management: Or How Corporate IT Learned to Fear Everything Except the Things That Actually…</title><link>https://iyasec.io/blog/risk-management-or-how-corporate-it-learned-to-fear-everything-except-the/</link><guid isPermaLink="true">https://iyasec.io/blog/risk-management-or-how-corporate-it-learned-to-fear-everything-except-the/</guid><description>There is a wonderful phrase that gets tossed around in corporate IT meetings.</description><pubDate>Thu, 30 Jul 2026 05:41:07 GMT</pubDate><category>authorization</category><category>concurrency</category><category>disaster-recovery</category><category>pki</category><category>risk-management</category><category>tls</category></item><item><title>OpenID Federation Spec: Because Exchanging Metadata Spreadsheets Was Apparently Not a Great…</title><link>https://iyasec.io/blog/openid-federation-spec-because-exchanging-metadata-spreadsheets-was-apparently-not-a-great/</link><guid isPermaLink="true">https://iyasec.io/blog/openid-federation-spec-because-exchanging-metadata-spreadsheets-was-apparently-not-a-great/</guid><description>Or: How the Identity Industry Invented a Cryptographically Signed Phone Book</description><pubDate>Thu, 30 Jul 2026 04:58:27 GMT</pubDate><category>federation</category><category>openid-connect</category><category>standards</category><category>cryptography</category><category>identity</category></item><item><title>The Time I Had To Troubleshoot 6% Packet Loss: Or, How We Accidentally Discovered the Network Had…</title><link>https://iyasec.io/blog/the-time-i-had-to-troubleshoot-6-packet-loss-or-how-we/</link><guid isPermaLink="true">https://iyasec.io/blog/the-time-i-had-to-troubleshoot-6-packet-loss-or-how-we/</guid><description>Every engineer has that one project.</description><pubDate>Wed, 29 Jul 2026 05:29:33 GMT</pubDate><category>troubleshooting</category><category>war-stories</category><category>networking</category></item><item><title>Data Classification Best Practices: Knowing What Matters Before It Walks Out the Door</title><link>https://iyasec.io/blog/data-classification-best-practices-knowing-what-matters-before-it-walks-out-the/</link><guid isPermaLink="true">https://iyasec.io/blog/data-classification-best-practices-knowing-what-matters-before-it-walks-out-the/</guid><description>Organizations spend millions of dollars protecting data, yet many struggle to answer a surprisingly simple question:</description><pubDate>Wed, 29 Jul 2026 04:54:11 GMT</pubDate><category>data-classification</category><category>data-security</category></item><item><title>2 + Fish = Moon Rock: When Your Key Performance Indicator Dashboard Has More Charts Than Purpose</title><link>https://iyasec.io/blog/2-fish-moon-rock-when-your-key-performance-indicator-dashboard-has-more/</link><guid isPermaLink="true">https://iyasec.io/blog/2-fish-moon-rock-when-your-key-performance-indicator-dashboard-has-more/</guid><description>When the metrics you hold so dear no longer measure anything meaningful.</description><pubDate>Tue, 28 Jul 2026 03:37:28 GMT</pubDate><category>performance</category><category>regulation</category><category>apis</category></item><item><title>Our Identity Protocol Debugger Now Supports WS-Trust</title><link>https://iyasec.io/blog/our-identity-protocol-debugger-now-supports-ws-trust/</link><guid isPermaLink="true">https://iyasec.io/blog/our-identity-protocol-debugger-now-supports-ws-trust/</guid><description>There are moments in software development when you ask yourself an important question:</description><pubDate>Tue, 28 Jul 2026 03:35:40 GMT</pubDate><category>debugging</category><category>tools</category><category>ws-trust</category><category>identity</category></item><item><title>JWT as Oauth2 Access Tokens &amp; Refresh Tokens— Invalidation: The Awkward Reality</title><link>https://iyasec.io/blog/jwt-as-oauth2-access-tokens-refresh-tokens-invalidation-the-awkward-reality/</link><guid isPermaLink="true">https://iyasec.io/blog/jwt-as-oauth2-access-tokens-refresh-tokens-invalidation-the-awkward-reality/</guid><description>I’ve touched on the topic of using JWT as an Access Token on several previous blog posts:</description><pubDate>Mon, 27 Jul 2026 03:32:21 GMT</pubDate><category>access-tokens</category><category>jwt</category><category>oauth2</category></item><item><title>BBS-2023: The Digital Signature That Knows When To Keep Its Mouth Shut</title><link>https://iyasec.io/blog/bbs-2023-the-digital-signature-that-knows-when-to-keep-its-mouth/</link><guid isPermaLink="true">https://iyasec.io/blog/bbs-2023-the-digital-signature-that-knows-when-to-keep-its-mouth/</guid><description>Most digital signatures have the subtlety of a foghorn.</description><pubDate>Mon, 27 Jul 2026 03:30:56 GMT</pubDate><category>digital-signatures</category><category>selective-disclosure</category><category>cryptography</category></item><item><title>I Code in vi/vim and Loving It (And No, I’m Not Trying to Impress Anyone)</title><link>https://iyasec.io/blog/i-code-in-vi-vim-and-loving-it-and-no-i-m/</link><guid isPermaLink="true">https://iyasec.io/blog/i-code-in-vi-vim-and-loving-it-and-no-i-m/</guid><description>In 1996, I took my first Computer Science course in college. The professor encouraged us to use vi/vim. Later, at my first job out-of-school, the team was, also, using vi/vim. As the IDE craze took hold at the turn of the century (kind of weird typing that), I never really moved on from there. So,…</description><pubDate>Sun, 26 Jul 2026 00:57:21 GMT</pubDate><category>personal</category><category>war-stories</category></item><item><title>How Many IETF RFCs Actually Become Standards?</title><link>https://iyasec.io/blog/how-many-ietf-rfcs-actually-become-standards/</link><guid isPermaLink="true">https://iyasec.io/blog/how-many-ietf-rfcs-actually-become-standards/</guid><description>The Internet Engineering Task Force (IETF) has 10K+ published Request For Comments (RFCs) documents. The industry hears about RFCs all the time. But, as the name implies (“request for comments”) that isn’t the final step in the process. A very small number of RFCs are promoted to Internet…</description><pubDate>Sun, 26 Jul 2026 00:49:41 GMT</pubDate><category>digital-signatures</category><category>dpop</category><category>jwt</category><category>oauth2</category><category>pkce</category><category>standards</category></item><item><title>SD-JWT VC: The Identity Industry’s Latest Attempt to Win a Nobel Prize in Acronyms</title><link>https://iyasec.io/blog/sd-jwt-vc-the-identity-industry-s-latest-attempt-to-win-a/</link><guid isPermaLink="true">https://iyasec.io/blog/sd-jwt-vc-the-identity-industry-s-latest-attempt-to-win-a/</guid><description>If you’ve ever opened the specifications surrounding SD-JWT Verifiable Credentials and thought, “Surely this is a straightforward document that defines a credential format.”</description><pubDate>Fri, 24 Jul 2026 23:28:44 GMT</pubDate><category>jwt</category><category>sd-jwt</category><category>selective-disclosure</category><category>verifiable-credentials</category><category>identity</category></item><item><title>Your Phone vs. The Border: A Traveler’s Privacy Tour of the G20</title><link>https://iyasec.io/blog/your-phone-vs-the-border-a-traveler-s-privacy-tour-of-the/</link><guid isPermaLink="true">https://iyasec.io/blog/your-phone-vs-the-border-a-traveler-s-privacy-tour-of-the/</guid><description>Travelers Rights. Or, lack thereof.</description><pubDate>Fri, 24 Jul 2026 17:48:59 GMT</pubDate><category>regulation</category><category>privacy</category></item><item><title>Input Validation: Because Users Are Creative, and Attackers Are More Creative</title><link>https://iyasec.io/blog/input-validation-because-users-are-creative-and-attackers-are-more-creative/</link><guid isPermaLink="true">https://iyasec.io/blog/input-validation-because-users-are-creative-and-attackers-are-more-creative/</guid><description>There is a special kind of optimism that exists in software development.</description><pubDate>Thu, 23 Jul 2026 22:17:15 GMT</pubDate><category>api-gateway</category><category>api-management</category><category>apigee</category><category>application-security</category><category>aws</category><category>web-application-security</category></item><item><title>Secure Code Reviews: Finding Security Issues Before Attackers Do</title><link>https://iyasec.io/blog/secure-code-reviews-finding-security-issues-before-attackers-do/</link><guid isPermaLink="true">https://iyasec.io/blog/secure-code-reviews-finding-security-issues-before-attackers-do/</guid><description>For most corporate IT workshops, we are often trying to abstract as many security details away from application code as possible. I understand things may work differently at Big Tech / shops-with-many-competent developer resources. I initially started jotting down notes for this blog post while I…</description><pubDate>Thu, 23 Jul 2026 10:03:02 GMT</pubDate><category>application-security</category><category>secure-coding</category><category>security</category></item><item><title>Post-Quantum Migration Mistakes: How to Accidentally Recreate the Y2K Panic, But With More Math</title><link>https://iyasec.io/blog/post-quantum-migration-mistakes-how-to-accidentally-recreate-the-y2k-panic-but/</link><guid isPermaLink="true">https://iyasec.io/blog/post-quantum-migration-mistakes-how-to-accidentally-recreate-the-y2k-panic-but/</guid><description>For decades, organizations have enjoyed a comfortable arrangement with modern cryptography.</description><pubDate>Wed, 22 Jul 2026 18:51:47 GMT</pubDate><category>post-quantum-cryptography</category><category>cryptography</category></item><item><title>The OAuth2/OIDC Debugger Has Learned a New Trick: SAML2 Support Is Here</title><link>https://iyasec.io/blog/the-oauth2-oidc-debugger-has-learned-a-new-trick-saml2-support-is/</link><guid isPermaLink="true">https://iyasec.io/blog/the-oauth2-oidc-debugger-has-learned-a-new-trick-saml2-support-is/</guid><description>Identity engineers have a complicated relationship with SAML.</description><pubDate>Wed, 22 Jul 2026 10:01:58 GMT</pubDate><category>debugging</category><category>oauth2</category><category>openid-connect</category><category>saml</category><category>tools</category><category>identity</category></item><item><title>Introducing IDPTools: An Open Source OAuth2 &amp; OpenID Connect Debugger</title><link>https://iyasec.io/blog/introducing-idptools-an-open-source-oauth2-openid-connect-debugger/</link><guid isPermaLink="true">https://iyasec.io/blog/introducing-idptools-an-open-source-oauth2-openid-connect-debugger/</guid><description>If you’ve spent any amount of time integrating OAuth 2.0 or OpenID Connect (OIDC), you’ve probably experienced the same cycle:</description><pubDate>Sat, 18 Jul 2026 23:01:33 GMT</pubDate><category>debugging</category><category>oauth2</category><category>open-source</category><category>openid-connect</category><category>tools</category></item><item><title>Identity Protocol Debugger + IDPTools Series</title><link>https://iyasec.io/blog/identity-protocol-debugger-idptools-series/</link><guid isPermaLink="true">https://iyasec.io/blog/identity-protocol-debugger-idptools-series/</guid><description>This is a collection of blog posts about my OpenSource Software Project, OAuth2 / OIDC Debugger.</description><pubDate>Sat, 18 Jul 2026 21:59:13 GMT</pubDate><category>debugging</category><category>oauth2</category><category>open-source</category><category>tools</category><category>series</category><category>identity</category></item><item><title>IBM Says It’s Ready to Scale Quantum Computing</title><link>https://iyasec.io/blog/ibm-says-it-s-ready-to-scale-quantum-computing/</link><guid isPermaLink="true">https://iyasec.io/blog/ibm-says-it-s-ready-to-scale-quantum-computing/</guid><description>This is the next post in my Post-Quantum Cryptography Series.</description><pubDate>Sat, 11 Jul 2026 07:26:34 GMT</pubDate><category>post-quantum-cryptography</category><category>quantum-computing</category><category>cryptography</category></item><item><title>What Rights Do Tourists and Long-Term Foreign Residents Have?</title><link>https://iyasec.io/blog/what-rights-do-tourists-and-long-term-foreign-residents-have/</link><guid isPermaLink="true">https://iyasec.io/blog/what-rights-do-tourists-and-long-term-foreign-residents-have/</guid><description>This is the first of a two part series. In the second post, we will explore the privacy implications of traveler rights at the border across various countries.</description><pubDate>Sat, 27 Jun 2026 11:07:08 GMT</pubDate><category>regulation</category><category>privacy</category></item><item><title>The Time We Deleted Eleven Days from Production</title><link>https://iyasec.io/blog/the-time-we-deleted-eleven-days-from-production/</link><guid isPermaLink="true">https://iyasec.io/blog/the-time-we-deleted-eleven-days-from-production/</guid><description>Or: How Humanity Performed the Largest Calendar Data Correction in History</description><pubDate>Sat, 27 Jun 2026 06:12:25 GMT</pubDate><category>performance</category><category>war-stories</category><category>ai</category></item><item><title>The Year 2038 Problem: When Computers Discover Time Is Hard</title><link>https://iyasec.io/blog/the-year-2038-problem-when-computers-discover-time-is-hard/</link><guid isPermaLink="true">https://iyasec.io/blog/the-year-2038-problem-when-computers-discover-time-is-hard/</guid><description>For most of human history, keeping track of dates was relatively straightforward. The sun came up; the sun went down.</description><pubDate>Fri, 26 Jun 2026 06:15:06 GMT</pubDate><category>linux</category><category>memory-management</category><category>operating-systems</category><category>integration</category><category>networking</category><category>apis</category></item><item><title>US Government Mandates All Agencies Fast-Track PQC Migration</title><link>https://iyasec.io/blog/us-government-mandates-all-agencies-fast-track-pqc-migration/</link><guid isPermaLink="true">https://iyasec.io/blog/us-government-mandates-all-agencies-fast-track-pqc-migration/</guid><description>This post is part of my “Post-Quantum Cryptography Series”.</description><pubDate>Fri, 26 Jun 2026 05:23:00 GMT</pubDate><category>post-quantum-cryptography</category><category>cryptography</category></item><item><title>Understanding Unauthenticated Traffic: How Applications and APIs Represent The Unauthenticated User</title><link>https://iyasec.io/blog/understanding-unauthenticated-traffic-how-applications-and-apis-represent-the-unauthenticated-user/</link><guid isPermaLink="true">https://iyasec.io/blog/understanding-unauthenticated-traffic-how-applications-and-apis-represent-the-unauthenticated-user/</guid><description>Authentication is one of the most fundamental concepts in application security. Most developers spend considerable time designing how authenticated users are represented, authorized, and managed. Surprisingly, much less attention is given to the opposite state of users who have not authenticated at…</description><pubDate>Wed, 24 Jun 2026 23:13:08 GMT</pubDate><category>application-security</category><category>authentication</category><category>authorization</category><category>apis</category><category>security</category></item><item><title>Data Loss Prevention (DLP): Keeping Your Organization’s Secrets from Walking Out the Door</title><link>https://iyasec.io/blog/data-loss-prevention-dlp-keeping-your-organization-s-secrets-from-walking-out/</link><guid isPermaLink="true">https://iyasec.io/blog/data-loss-prevention-dlp-keeping-your-organization-s-secrets-from-walking-out/</guid><description>For decades, organizations have focused on keeping attackers out. Firewalls, antivirus software, intrusion detection systems, IAM solutions, and the like all serve a common purpose to prevent unauthorized access. However, many security incidents do not begin with an external attacker breaking in.…</description><pubDate>Wed, 24 Jun 2026 23:07:05 GMT</pubDate><category>authorization</category><category>data-security</category><category>dlp</category><category>identity</category><category>security</category></item><item><title>Post-Quantum Cryptography Series</title><link>https://iyasec.io/blog/post-quantum-cryptography-series/</link><guid isPermaLink="true">https://iyasec.io/blog/post-quantum-cryptography-series/</guid><description>There have been many questions about Post-Quantum Cryptography (PQC) recently with clients. So, I figured this would be a good topic to explore.</description><pubDate>Tue, 23 Jun 2026 12:55:04 GMT</pubDate><category>post-quantum-cryptography</category><category>series</category><category>cryptography</category></item><item><title>Sweden’s Cashless Revolution: The Hidden Costs of a Digital Economy</title><link>https://iyasec.io/blog/sweden-s-cashless-revolution-the-hidden-costs-of-a-digital-economy/</link><guid isPermaLink="true">https://iyasec.io/blog/sweden-s-cashless-revolution-the-hidden-costs-of-a-digital-economy/</guid><description>In my “Dangers of a Cashless Society” post, I briefly described my experiences in Sweden. This post expands on that.</description><pubDate>Tue, 23 Jun 2026 12:54:41 GMT</pubDate><category>cashless-society</category><category>surveillance</category><category>privacy</category><category>networking</category><category>security</category></item><item><title>AES-256 and the Post-Quantum Panic: The Rare Cryptographic Algorithm That Isn’t Sweating</title><link>https://iyasec.io/blog/aes-256-and-the-post-quantum-panic-the-rare-cryptographic-algorithm-that/</link><guid isPermaLink="true">https://iyasec.io/blog/aes-256-and-the-post-quantum-panic-the-rare-cryptographic-algorithm-that/</guid><description>Quick Summary: AES-256 is the workhorse of enterprise data encryption at rest. It is not considered impacted by quantum computers or Post-Quantum Cryptography. It is considered quantum-resistant, which means it can withstand attacks from quantum computers / algorithms better than other encryption…</description><pubDate>Mon, 22 Jun 2026 12:07:18 GMT</pubDate><category>aes</category><category>post-quantum-cryptography</category><category>quantum-computing</category><category>rest</category><category>cryptography</category></item><item><title>Shor’s Algorithm: The Quantum Computer’s Favorite Way to Ruin RSA’s Day</title><link>https://iyasec.io/blog/shor-s-algorithm-the-quantum-computer-s-favorite-way-to-ruin-rsa/</link><guid isPermaLink="true">https://iyasec.io/blog/shor-s-algorithm-the-quantum-computer-s-favorite-way-to-ruin-rsa/</guid><description>For decades, modern cryptography has rested on a comforting assumption that factoring really large numbers is hard.</description><pubDate>Mon, 22 Jun 2026 12:06:54 GMT</pubDate><category>quantum-computing</category><category>rsa</category><category>cryptography</category></item><item><title>Post-Quantum Cryptography (ML-KEM): The Math</title><link>https://iyasec.io/blog/post-quantum-cryptography-ml-kem-the-math/</link><guid isPermaLink="true">https://iyasec.io/blog/post-quantum-cryptography-ml-kem-the-math/</guid><description>ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism), formerly known as CRYSTALS-Kyber, is the post-quantum key exchange algorithm standardized by National Institute of Standards and Technology as FIPS 203. Its security is based on the difficulty of certain problems in lattice cryptography,…</description><pubDate>Sun, 21 Jun 2026 05:34:55 GMT</pubDate><category>mathematics</category><category>post-quantum-cryptography</category><category>quantum-computing</category><category>cryptography</category><category>security</category></item><item><title>Post-Quantum Cryptography (2026): Preparing for the End of RSA and ECC</title><link>https://iyasec.io/blog/post-quantum-cryptography-2026-preparing-for-the-end-of-rsa-and-ecc/</link><guid isPermaLink="true">https://iyasec.io/blog/post-quantum-cryptography-2026-preparing-for-the-end-of-rsa-and-ecc/</guid><description>For decades, modern cybersecurity has relied on a handful of cryptographic foundations. Technologies such as RSA and Elliptic Curve Cryptography (ECC) protect everything from online banking and VPNs to software updates and digital signatures. These algorithms have withstood years of scrutiny and…</description><pubDate>Sun, 21 Jun 2026 05:34:40 GMT</pubDate><category>digital-signatures</category><category>elliptic-curve-cryptography</category><category>post-quantum-cryptography</category><category>rsa</category><category>cryptography</category></item><item><title>RSA: The Internet’s Favorite Math Trick (Until Quantum Computers Show Up)</title><link>https://iyasec.io/blog/rsa-the-internet-s-favorite-math-trick-until-quantum-computers-show-up/</link><guid isPermaLink="true">https://iyasec.io/blog/rsa-the-internet-s-favorite-math-trick-until-quantum-computers-show-up/</guid><description>Most people use cryptography every day. They log into websites. They check their bank balances. They send messages. They order things they absolutely do not need from online retailers at 2:00 AM.</description><pubDate>Sat, 20 Jun 2026 05:25:56 GMT</pubDate><category>quantum-computing</category><category>rsa</category><category>cryptography</category></item><item><title>Introduction To Quantum Computing: Because Regular Computers Apparently Weren’t Complicated Enough</title><link>https://iyasec.io/blog/introduction-to-quantum-computing-because-regular-computers-apparently-weren-t-complicated-enough/</link><guid isPermaLink="true">https://iyasec.io/blog/introduction-to-quantum-computing-because-regular-computers-apparently-weren-t-complicated-enough/</guid><description>Disclaimer: I’m not a physicist. This is my attempt to understand quantum computing and the underlying physics, yet keeping it light. I do actually want my traditional audience to read this.</description><pubDate>Sat, 20 Jun 2026 05:24:50 GMT</pubDate><category>quantum-computing</category><category>regulation</category><category>cryptography</category></item><item><title>AI / LLM Software Security: Part 5</title><link>https://iyasec.io/blog/ai-llm-software-security-part-5/</link><guid isPermaLink="true">https://iyasec.io/blog/ai-llm-software-security-part-5/</guid><description>This is the fifth (and final) post in my “AI / LLM Software Security Series”.</description><pubDate>Sat, 13 Jun 2026 04:47:54 GMT</pubDate><category>ai-security</category><category>application-security</category><category>llm</category><category>ai</category><category>security</category></item><item><title>AI / LLM Software Security: Part 4</title><link>https://iyasec.io/blog/ai-llm-software-security-part-4/</link><guid isPermaLink="true">https://iyasec.io/blog/ai-llm-software-security-part-4/</guid><description>This is the forth post in my “AI / LLM Software Security Series”.</description><pubDate>Wed, 10 Jun 2026 21:30:16 GMT</pubDate><category>ai-security</category><category>application-security</category><category>llm</category><category>ai</category><category>security</category></item><item><title>Euler’s Identity: The Single Equation That Connects Five Fundamental Mathematical Constants</title><link>https://iyasec.io/blog/euler-s-identity-the-single-equation-that-connects-five-fundamental-mathematical-constants/</link><guid isPermaLink="true">https://iyasec.io/blog/euler-s-identity-the-single-equation-that-connects-five-fundamental-mathematical-constants/</guid><description>When I was writing the Zero Knowledge Proofs: The Math blog post, I had the bright (read stupid) idea of asking ChatGPT to generate an image about math. It didn’t matter which math, didn’t specifically mention ZPTs in the prompt. It initially generated the above image. It’s a good image. It’s the…</description><pubDate>Mon, 08 Jun 2026 21:57:40 GMT</pubDate><category>mathematics</category></item><item><title>Zero-Knowledge Proofs: The Math</title><link>https://iyasec.io/blog/zero-knowledge-proofs-the-math/</link><guid isPermaLink="true">https://iyasec.io/blog/zero-knowledge-proofs-the-math/</guid><description>This is my second article about Zero-Knowledge Proofs (ZKPs). If you haven’t read it, check out Part 1 as a starting point.</description><pubDate>Mon, 08 Jun 2026 21:57:20 GMT</pubDate><category>mathematics</category><category>zero-knowledge-proofs</category><category>cryptography</category></item><item><title>Zero-Knowledge Proofs: Proving Something Without Revealing Anything</title><link>https://iyasec.io/blog/zero-knowledge-proofs-proving-something-without-revealing-anything/</link><guid isPermaLink="true">https://iyasec.io/blog/zero-knowledge-proofs-proving-something-without-revealing-anything/</guid><description>Modern computing systems are built around a strange tradeoff in that proving identity or trust usually requires revealing information. Passwords, account numbers, private keys, medical records, financial history — all of these are routinely exposed simply to verify a claim.</description><pubDate>Sat, 06 Jun 2026 22:50:36 GMT</pubDate><category>zero-knowledge-proofs</category><category>cryptography</category><category>identity</category></item><item><title>The Dawn of De-Dollarization, Digital Sovereignty, and Digital Privacy</title><link>https://iyasec.io/blog/the-dawn-of-de-dollarization-digital-sovereignty-and-digital-privacy/</link><guid isPermaLink="true">https://iyasec.io/blog/the-dawn-of-de-dollarization-digital-sovereignty-and-digital-privacy/</guid><description>“De-dollarization” (moving away from the US Dollar as a reserve currency) is both real and accelerating, but it is gradual, uneven, and multi-dimensional. It is not a sudden collapse of the US dollar’s reserve status, but a persistent shift in the structure of global finance that reflects…</description><pubDate>Sat, 06 Jun 2026 02:23:25 GMT</pubDate><category>digital-sovereignty</category><category>privacy</category></item><item><title>AI / LLM Software Security: Part 3</title><link>https://iyasec.io/blog/ai-llm-software-security-part-3/</link><guid isPermaLink="true">https://iyasec.io/blog/ai-llm-software-security-part-3/</guid><description>This is the third post in my “AI / LLM Software Security Series”.</description><pubDate>Fri, 05 Jun 2026 07:56:50 GMT</pubDate><category>ai-security</category><category>application-security</category><category>llm</category><category>ai</category><category>security</category></item><item><title>AI / LLM Software Security Series</title><link>https://iyasec.io/blog/ai-llm-software-security-series/</link><guid isPermaLink="true">https://iyasec.io/blog/ai-llm-software-security-series/</guid><description>This series explores the “OWASP Top 10 for LLM Applications 2025” issues.</description><pubDate>Thu, 04 Jun 2026 02:01:42 GMT</pubDate><category>ai-security</category><category>application-security</category><category>llm</category><category>series</category><category>ai</category><category>security</category></item><item><title>AI / LLM Software Security: Part 2</title><link>https://iyasec.io/blog/ai-llm-software-security-part-2/</link><guid isPermaLink="true">https://iyasec.io/blog/ai-llm-software-security-part-2/</guid><description>This is the second post in my “AI / LLM Software Security Series”.</description><pubDate>Wed, 03 Jun 2026 01:59:22 GMT</pubDate><category>ai-security</category><category>application-security</category><category>llm</category><category>ai</category><category>security</category></item><item><title>Surveillance Capitalism: The Data Private Industry Gathers</title><link>https://iyasec.io/blog/surveillance-capitalism-the-data-private-industry-gathers/</link><guid isPermaLink="true">https://iyasec.io/blog/surveillance-capitalism-the-data-private-industry-gathers/</guid><description>Surveillance Capitalism is an economic system in which companies collect, analyze, predict, and monetize human behavior through massive-scale data gathering and behavioral tracking — what Americans (the US kind) call Tuesday. The term was popularized by Shoshana Zuboff in her book “The Age of…</description><pubDate>Wed, 03 Jun 2026 01:59:02 GMT</pubDate><category>surveillance</category><category>privacy</category></item><item><title>Government Data Collection: The Rise of Over-Collection</title><link>https://iyasec.io/blog/government-data-collection-the-rise-of-over-collection/</link><guid isPermaLink="true">https://iyasec.io/blog/government-data-collection-the-rise-of-over-collection/</guid><description>Before we start, please note, I’m not taking a stand on any particular issue (social, political, etc). I’m just exploring the potential privacy implications in recent headlines.</description><pubDate>Mon, 01 Jun 2026 23:28:52 GMT</pubDate><category>surveillance</category><category>privacy</category></item><item><title>AWS Outposts Migration Security Considerations: Part 2</title><link>https://iyasec.io/blog/aws-outposts-migration-security-considerations-part-2/</link><guid isPermaLink="true">https://iyasec.io/blog/aws-outposts-migration-security-considerations-part-2/</guid><description>The most common reaction to that image has been, “WTF?” I decided to go with it and use the image as originally generated.</description><pubDate>Mon, 01 Jun 2026 23:27:04 GMT</pubDate><category>aws</category><category>cloud</category><category>security</category></item><item><title>AWS Outposts Migration Security Considerations: Part 1</title><link>https://iyasec.io/blog/aws-outposts-migration-security-considerations-part-1/</link><guid isPermaLink="true">https://iyasec.io/blog/aws-outposts-migration-security-considerations-part-1/</guid><description>AWS Outposts moves the AWS cloud services into your onprem data center. It is a hybrid-cloud platform from Amazon Web Services that extends AWS infrastructure and services into your own datacenter, colocation facility, etc. With AWS Outposts, AWS ships you AWS-designed racks with pre-configured…</description><pubDate>Sun, 31 May 2026 21:52:57 GMT</pubDate><category>aws</category><category>web-services</category><category>cloud</category><category>security</category></item><item><title>AI / LLM Application Software Security: Part 1</title><link>https://iyasec.io/blog/ai-llm-application-software-security-part-1/</link><guid isPermaLink="true">https://iyasec.io/blog/ai-llm-application-software-security-part-1/</guid><description>This is the first post in my “AI / LLM Software Security Series”.</description><pubDate>Sun, 31 May 2026 21:48:21 GMT</pubDate><category>ai-security</category><category>application-security</category><category>llm</category><category>ai</category><category>security</category></item><item><title>Network Segmentation: Macro, Micro, and the Building Blocks</title><link>https://iyasec.io/blog/network-segmentation-macro-micro-and-the-building-blocks/</link><guid isPermaLink="true">https://iyasec.io/blog/network-segmentation-macro-micro-and-the-building-blocks/</guid><description>I’ve talked about network segmentation in many blog posts, but I’ve never had a blog post dedicated specifically to that topic. So, here we go.</description><pubDate>Mon, 20 Apr 2026 09:47:29 GMT</pubDate><category>network-security</category><category>security-architecture</category><category>networking</category></item><item><title>Multi-Factor Authentication (MFA): Don’t Let Your CyberSecurity Insurance Claim Get Denied On…</title><link>https://iyasec.io/blog/multi-factor-authentication-mfa-don-t-let-your-cybersecurity-insurance-claim-get/</link><guid isPermaLink="true">https://iyasec.io/blog/multi-factor-authentication-mfa-don-t-let-your-cybersecurity-insurance-claim-get/</guid><description>Multi-Factor Authentication (MFA) is the security control that can make, or break, your business. If there’s one cybersecurity control that consistently separates organizations that get breached from those that don’t, it’s Multi-Factor Authentication (or, to be precise, MFA, done correctly).</description><pubDate>Thu, 16 Apr 2026 08:15:01 GMT</pubDate><category>authentication</category><category>mfa</category><category>security</category></item><item><title>Dangers of a Cashless Society</title><link>https://iyasec.io/blog/dangers-of-a-cashless-society/</link><guid isPermaLink="true">https://iyasec.io/blog/dangers-of-a-cashless-society/</guid><description>IntroductionWhat Does Cashless Mean?Countries Embracing Going CashlessWhy Cashless Advocates Dislike Cash</description><pubDate>Mon, 13 Apr 2026 06:47:53 GMT</pubDate><category>cashless-society</category><category>surveillance</category><category>privacy</category><category>security</category></item><item><title>Application Security Best Practices</title><link>https://iyasec.io/blog/application-security-best-practices/</link><guid isPermaLink="true">https://iyasec.io/blog/application-security-best-practices/</guid><description>A starting point for application security.</description><pubDate>Sun, 12 Apr 2026 13:35:00 GMT</pubDate><category>application-security</category><category>security</category></item><item><title>Defense In Depth</title><link>https://iyasec.io/blog/defense-in-depth/</link><guid isPermaLink="true">https://iyasec.io/blog/defense-in-depth/</guid><description>“Defense in Depth” is the idea that no single security control is trusted to stop an attack. Instead, you stack multiple, independent layers so that if one fails, others still stand in the way.</description><pubDate>Wed, 08 Apr 2026 15:39:19 GMT</pubDate><category>defense-in-depth</category><category>security-architecture</category><category>security</category></item><item><title>Zero Trust Architecture</title><link>https://iyasec.io/blog/zero-trust-architecture/</link><guid isPermaLink="true">https://iyasec.io/blog/zero-trust-architecture/</guid><description>Zero Trust Architecture (ZT or ZTA) is a security model / framework based on one simple idea: Never trust, always verify. From NIST, we have, the “… ZT approach is primarily focused on data and service protection but can and should be expanded to include all enterprise assets (devices,…</description><pubDate>Wed, 08 Apr 2026 15:15:08 GMT</pubDate><category>application-security</category><category>security-architecture</category><category>zero-trust</category><category>security</category></item><item><title>Don’t Use Source IP Addresses As The Primary Authentication Mechanism</title><link>https://iyasec.io/blog/don-t-use-source-ip-addresses-as-the-primary-authentication-mechanism/</link><guid isPermaLink="true">https://iyasec.io/blog/don-t-use-source-ip-addresses-as-the-primary-authentication-mechanism/</guid><description>In certain US industries, usually legacy businesses with low margins and heavily regulated, it is still quite common to use source IP address as an authentication mechanism on the public internet. Now, never mind that in the age of cloud computing and SaaS applications, it is rare for cloud…</description><pubDate>Wed, 25 Mar 2026 16:31:32 GMT</pubDate><category>authentication</category><category>cloud</category></item><item><title>Core Security Precept: Principle of Least Privilege</title><link>https://iyasec.io/blog/core-security-precept-principle-of-least-privilege/</link><guid isPermaLink="true">https://iyasec.io/blog/core-security-precept-principle-of-least-privilege/</guid><description>The word “rule” is overused; so, I went with “precept” — a rule or principle that defines how one should think or act.</description><pubDate>Wed, 25 Mar 2026 16:22:05 GMT</pubDate><category>authorization</category><category>least-privilege</category><category>security</category></item><item><title>A Vendor DMZ Pattern</title><link>https://iyasec.io/blog/a-vendor-dmz-pattern/</link><guid isPermaLink="true">https://iyasec.io/blog/a-vendor-dmz-pattern/</guid><description>A long time ago, I was doing integration architecture work in the land of Enterprise Service Buses (ESBs) and API Gateways. Think IBM WebSphere DataPower and Apigee — I like to remember Apigee the way it was before it was integrated into GCP. After we had designed and built the ESB, we moved on to…</description><pubDate>Sat, 21 Mar 2026 10:26:40 GMT</pubDate><category>api-gateway</category><category>api-management</category><category>apigee</category><category>datapower</category><category>network-security</category><category>security-architecture</category></item><item><title>Begotten &amp; Forgotten Distributed Service Technologies</title><link>https://iyasec.io/blog/begotten-forgotten-distributed-service-technologies/</link><guid isPermaLink="true">https://iyasec.io/blog/begotten-forgotten-distributed-service-technologies/</guid><description>Sometime around 2012, I published a similar list (up to the point of APIs). I recently put the same list in another post. I thought having this as its own post would be useful, or, at least, amusing.</description><pubDate>Wed, 18 Mar 2026 16:36:48 GMT</pubDate><category>performance</category><category>rest</category><category>soap</category><category>apis</category></item><item><title>Internal Endpoints Must Have The Same Security Capabilities As External Endpoints</title><link>https://iyasec.io/blog/internal-endpoints-must-have-the-same-security-capabilities-as-external-endpoints/</link><guid isPermaLink="true">https://iyasec.io/blog/internal-endpoints-must-have-the-same-security-capabilities-as-external-endpoints/</guid><description>In a previous post, we made a point of “Non-Prod Environments Must Have The Same Security Protections As Production”. In this post, we’re going to go one step further and say that your internal and external endpoints, generally, should have the same security capabilities baked into their security…</description><pubDate>Wed, 18 Mar 2026 16:35:38 GMT</pubDate><category>environments</category><category>security</category></item><item><title>The Yearly Review Feedback That I Could Never Accept</title><link>https://iyasec.io/blog/the-yearly-review-feedback-that-i-could-never-accept/</link><guid isPermaLink="true">https://iyasec.io/blog/the-yearly-review-feedback-that-i-could-never-accept/</guid><description>I have the ability to be a profound jackass. So, most feedback that’s been included in yearly reviews is probably fair. But, fifteen, plus, years ago, I did get one annual review that had one negative remark on it that bothered me then and still does to this day.</description><pubDate>Tue, 17 Mar 2026 16:06:08 GMT</pubDate><category>war-stories</category><category>career</category></item><item><title>API Design: Planned, Unplanned, Security and Utter Chaos</title><link>https://iyasec.io/blog/api-design-planned-unplanned-security-and-utter-chaos/</link><guid isPermaLink="true">https://iyasec.io/blog/api-design-planned-unplanned-security-and-utter-chaos/</guid><description>I’ve discussed APIs and API Management in previous blog posts. These are among my older blog posts, but the points being made are, generally, still relevant. I’ve never published a blog post exclusively about API design. I have a blog post about “API Gateways and Multiple Consumer Types” where I…</description><pubDate>Tue, 17 Mar 2026 16:04:12 GMT</pubDate><category>api-design</category><category>api-gateway</category><category>api-management</category><category>apis</category><category>security</category></item><item><title>Any Day Your Socks Don’t Burst Into Flames Is A Good Day</title><link>https://iyasec.io/blog/any-day-your-socks-don-t-burst-into-flames-is-a-good/</link><guid isPermaLink="true">https://iyasec.io/blog/any-day-your-socks-don-t-burst-into-flames-is-a-good/</guid><description>I’ve been wanting to use this as a title for a blog post for a while now. It’s actually one of the quotes I have in my personal email signature. The open question has been what the topic of this blog post should be. There are so many asinine stories from fifteen years of consulting that could be…</description><pubDate>Fri, 13 Mar 2026 07:44:18 GMT</pubDate><category>application-security</category><category>war-stories</category><category>ai</category><category>identity</category><category>security</category></item><item><title>Non-Prod Environments Must Have The Same Security Protections As Production</title><link>https://iyasec.io/blog/non-prod-environments-must-have-the-same-security-protections-as-production/</link><guid isPermaLink="true">https://iyasec.io/blog/non-prod-environments-must-have-the-same-security-protections-as-production/</guid><description>Your non-production environments must have the same security capabilities as your production environment.</description><pubDate>Thu, 12 Mar 2026 16:15:25 GMT</pubDate><category>environments</category><category>security</category></item><item><title>Ability To Do Point In Time Restore / Rebuild Of Environments</title><link>https://iyasec.io/blog/ability-to-do-point-in-time-restore-rebuild-of-environments/</link><guid isPermaLink="true">https://iyasec.io/blog/ability-to-do-point-in-time-restore-rebuild-of-environments/</guid><description>Over the course of my consulting career, I’ve been brought into organizations to troubleshoot “weird” problems on several occasions — those stories for another time. These engagements are often fun; though, can be very challenging. The organizations where we had the most success in tracking down…</description><pubDate>Wed, 11 Mar 2026 07:58:58 GMT</pubDate><category>disaster-recovery</category><category>environments</category><category>troubleshooting</category></item><item><title>What Is Digital Sovereignty?</title><link>https://iyasec.io/blog/what-is-digital-sovereignty/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-digital-sovereignty/</guid><description>Digital sovereignty refers to a nation’s ability to control, regulate, and secure its digital infrastructure, data, platforms, and technological ecosystem in accordance with its own laws, values, and strategic interests.</description><pubDate>Fri, 06 Mar 2026 08:13:37 GMT</pubDate><category>digital-sovereignty</category><category>regulation</category><category>security</category></item><item><title>Achieving Application Environment Isolation</title><link>https://iyasec.io/blog/achieving-application-environment-isolation/</link><guid isPermaLink="true">https://iyasec.io/blog/achieving-application-environment-isolation/</guid><description>Your production environment should be isolated from your non-production environments. In fact, every application environment should be isolated from every other environment. Sounds simple in practice, but how does one accomplish this? Through a multi-layered isolation strategy:</description><pubDate>Sun, 01 Mar 2026 14:04:57 GMT</pubDate><category>authorization</category><category>aws</category><category>azure</category><category>environments</category><category>identity-provider</category><category>least-privilege</category></item><item><title>No, You Shouldn’t Use Production Data For Testing</title><link>https://iyasec.io/blog/no-you-shouldn-t-use-production-data-for-testing/</link><guid isPermaLink="true">https://iyasec.io/blog/no-you-shouldn-t-use-production-data-for-testing/</guid><description>But, let’s face it, you’re probably going to do it anyway.</description><pubDate>Fri, 27 Feb 2026 15:49:08 GMT</pubDate><category>authentication</category><category>authorization</category><category>data-protection</category><category>digital-sovereignty</category><category>environments</category><category>regulation</category></item><item><title>Privacy Series</title><link>https://iyasec.io/blog/privacy-series/</link><guid isPermaLink="true">https://iyasec.io/blog/privacy-series/</guid><description>Here is a collection of blog posts I’ve written about Privacy in the digital era.</description><pubDate>Wed, 25 Feb 2026 16:07:24 GMT</pubDate><category>series</category><category>privacy</category></item><item><title>Data Sovereignty Laws Around The World</title><link>https://iyasec.io/blog/data-sovereignty-laws-around-the-world/</link><guid isPermaLink="true">https://iyasec.io/blog/data-sovereignty-laws-around-the-world/</guid><description>Disclosures: AI (ChatGPT) assisted with summarizing this information.</description><pubDate>Wed, 25 Feb 2026 16:06:03 GMT</pubDate><category>digital-sovereignty</category><category>regulation</category><category>ai</category></item><item><title>Of Daffy Bastards And Goofy F*cks In The Land Of The Lost: Integration Anti-Patterns From The Dark Side</title><link>https://iyasec.io/blog/of-daffy-bastards-and-goofy-f-cks-in-the-land-of-the-2026/</link><guid isPermaLink="true">https://iyasec.io/blog/of-daffy-bastards-and-goofy-f-cks-in-the-land-of-the-2026/</guid><description>Some organizations keep following the same legacy, bad practices even though they know better. They keep doing it right up until the unfortunate happens.</description><pubDate>Mon, 23 Feb 2026 08:32:17 GMT</pubDate><category>j2ee</category><category>war-stories</category><category>governance</category><category>integration</category><category>security</category></item><item><title>What Is Digital Privacy?</title><link>https://iyasec.io/blog/what-is-digital-privacy/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-digital-privacy/</guid><description>Privacy (and Digital Privacy) is one of those terms that I’ve thrown around a lot in the last few years. However, I never took the time to define it.</description><pubDate>Mon, 23 Feb 2026 08:00:17 GMT</pubDate><category>application-security</category><category>authentication</category><category>authorization</category><category>data-protection</category><category>digital-sovereignty</category><category>privacy</category></item><item><title>Data Privacy Laws / Regulations Around The World</title><link>https://iyasec.io/blog/data-privacy-laws-regulations-around-the-world/</link><guid isPermaLink="true">https://iyasec.io/blog/data-privacy-laws-regulations-around-the-world/</guid><description>Disclosures: AI (ChatGPT) assisted with summarizing this information.</description><pubDate>Fri, 20 Feb 2026 16:05:34 GMT</pubDate><category>regulation</category><category>ai</category><category>privacy</category></item><item><title>My NAS Appliance Just Turned Ten Years Old</title><link>https://iyasec.io/blog/my-nas-appliance-just-turned-ten-years-old/</link><guid isPermaLink="true">https://iyasec.io/blog/my-nas-appliance-just-turned-ten-years-old/</guid><description>I’ve been waiting a couple of years to write this post. In November, 2015, I bought a Synology RS815 NAS appliance to replace the DIY solution that I had been using for years before that. A month ago, that NAS appliance turned ten years old. It’s been in daily use for the past decade. At the six…</description><pubDate>Sat, 20 Dec 2025 05:03:54 GMT</pubDate><category>personal</category><category>infrastructure</category></item><item><title>Of Daffy Bastards And Goofy F*cks In The Land Of The Lost: Integration Anti-Patterns From The Dark…</title><link>https://iyasec.io/blog/of-daffy-bastards-and-goofy-f-cks-in-the-land-of-the/</link><guid isPermaLink="true">https://iyasec.io/blog/of-daffy-bastards-and-goofy-f-cks-in-the-land-of-the/</guid><description>Some organizations keep following the same legacy, bad practices even though they know better. They keep doing it right up until the unfortunate happens.</description><pubDate>Sat, 22 Nov 2025 14:59:33 GMT</pubDate><category>war-stories</category><category>integration</category></item><item><title>Using Curl With SPNEGO</title><link>https://iyasec.io/blog/using-curl-with-spnego/</link><guid isPermaLink="true">https://iyasec.io/blog/using-curl-with-spnego/</guid><description>Recently, I had to setup a SPNEGO example to demonstrate a Kerberos identity integration. The details aren’t important, but I spent a bit of time figuring out how to use curl’s SPENGO support. So, we have the next blog post topic.</description><pubDate>Sat, 22 Nov 2025 13:58:00 GMT</pubDate><category>kerberos</category><category>integration</category><category>identity</category></item><item><title>SOFTWARE SUPPLY CHAIN SECURITY: CI/CD/CT PIPELINES AND SECURITY TOOLS — PART 2</title><link>https://iyasec.io/blog/software-supply-chain-security-ci-cd-ct-pipelines-and-security-tools-part-a5515d/</link><guid isPermaLink="true">https://iyasec.io/blog/software-supply-chain-security-ci-cd-ct-pipelines-and-security-tools-part-a5515d/</guid><description>This is part two of a two part blog post on Software Supply Chain Security. If you haven’t read Part 1 yet, starting there is recommended.</description><pubDate>Mon, 29 Sep 2025 15:09:34 GMT</pubDate><category>ci-cd</category><category>supply-chain-security</category><category>security</category></item><item><title>SOFTWARE SUPPLY CHAIN SECURITY: CI/CD/CT PIPELINES AND SECURITY TOOLS — PART 1</title><link>https://iyasec.io/blog/software-supply-chain-security-ci-cd-ct-pipelines-and-security-tools-part/</link><guid isPermaLink="true">https://iyasec.io/blog/software-supply-chain-security-ci-cd-ct-pipelines-and-security-tools-part/</guid><description>The DevOps movement of the last decade more-or-less led to the DevSecOps movement of this decade. This focus on automation to create efficient, end-to-end software publishing pipelines combined with incidents like the SolarWinds Hack in 2020 and the recent ‘S1ngularity’ attack on the NPM ecosystem…</description><pubDate>Mon, 29 Sep 2025 15:03:22 GMT</pubDate><category>ci-cd</category><category>supply-chain-security</category><category>security</category></item><item><title>Prevent XSS and Other Common Attacks on Your App</title><link>https://iyasec.io/blog/prevent-xss-and-other-common-attacks-on-your-app/</link><guid isPermaLink="true">https://iyasec.io/blog/prevent-xss-and-other-common-attacks-on-your-app/</guid><description>Regardless of your application architecture or front-end type, there are a variety of common attack types that the application security architecture’s capabilities must protect against. I’ve talked about these topics briefly before here, here, and here.</description><pubDate>Fri, 27 Dec 2024 14:08:15 GMT</pubDate><category>application-security</category><category>security-architecture</category><category>web-application-security</category><category>security</category></item><item><title>Authentication Series</title><link>https://iyasec.io/blog/authentication-series/</link><guid isPermaLink="true">https://iyasec.io/blog/authentication-series/</guid><description>Barcode / Christiaan Colen</description><pubDate>Tue, 19 Nov 2024 18:55:40 GMT</pubDate><category>authentication</category><category>series</category></item><item><title>Practical Business Continuity For The Small Organization</title><link>https://iyasec.io/blog/practical-business-continuity-for-the-small-organization/</link><guid isPermaLink="true">https://iyasec.io/blog/practical-business-continuity-for-the-small-organization/</guid><description>For the small business owner, should the power going out mean you can’t make money? Should the computer system going down for 20 minutes mean a restaurant can’t take or cook orders any longer? Some basic level of preparation for anything other than ideal circumstances and commonsense needs to be…</description><pubDate>Wed, 04 Sep 2024 21:12:40 GMT</pubDate><category>business-continuity</category><category>disaster-recovery</category><category>networking</category><category>security</category></item><item><title>Practical Business Continuity</title><link>https://iyasec.io/blog/practical-business-continuity/</link><guid isPermaLink="true">https://iyasec.io/blog/practical-business-continuity/</guid><description>For the small business owner, should the power going out mean you can’t make money? Should the computer system going down for 20 minutes mean a restaurant can’t take or cook orders any longer? Some basic level of preparation for anything other than ideal circumstances and commonsense needs to be…</description><pubDate>Wed, 04 Sep 2024 14:11:00 GMT</pubDate><category>business-continuity</category><category>disaster-recovery</category><category>security</category></item><item><title>Static Credentials Must Not Be Used In The Browser</title><link>https://iyasec.io/blog/static-credentials-must-not-be-used-in-the-browser/</link><guid isPermaLink="true">https://iyasec.io/blog/static-credentials-must-not-be-used-in-the-browser/</guid><description>Authentication is described in this post.</description><pubDate>Sat, 10 Aug 2024 20:38:51 GMT</pubDate><category>authentication</category><category>web-application-security</category></item><item><title>Datastore Security Requirements</title><link>https://iyasec.io/blog/datastore-security-requirements/</link><guid isPermaLink="true">https://iyasec.io/blog/datastore-security-requirements/</guid><description>This post will introduce a generic set of database / datastore security requirements that be used as a starting point when developing a database security strategy.</description><pubDate>Sat, 10 Aug 2024 20:34:56 GMT</pubDate><category>data-security</category><category>security</category></item><item><title>Application Front-Ends Must Not Make Authorization Decisions</title><link>https://iyasec.io/blog/application-front-ends-must-not-make-authorization-decisions/</link><guid isPermaLink="true">https://iyasec.io/blog/application-front-ends-must-not-make-authorization-decisions/</guid><description>First, let’s get the usual introductions out of the way. For an in-depth discussion of what Authorization is, check out this post. For a complete introduction to Authorization concepts see my Authorization Series. This post continues my long-running Authorization Series. In this post, we’re going…</description><pubDate>Tue, 06 Aug 2024 07:34:10 GMT</pubDate><category>api-gateway</category><category>application-security</category><category>authorization</category><category>ci-cd</category><category>debugging</category><category>rest</category></item><item><title>API Gateways and Multiple Consumer Types</title><link>https://iyasec.io/blog/api-gateways-and-multiple-consumer-types/</link><guid isPermaLink="true">https://iyasec.io/blog/api-gateways-and-multiple-consumer-types/</guid><description>Sometimes at client sites, I see a separation of APIs advertised on an API Gateway based upon consumer type. Sometimes, this is unavoidable, but there should be a core set of APIs and a general push to create APIs that are reusable. Reusability of APIs is a foundational building block of API…</description><pubDate>Fri, 24 May 2024 04:18:09 GMT</pubDate><category>api-gateway</category><category>apis</category></item><item><title>RFC 9068: A JWT-Based OAuth2 Access Token Format Standard</title><link>https://iyasec.io/blog/rfc-9068-a-jwt-based-oauth2-access-token-format-standard/</link><guid isPermaLink="true">https://iyasec.io/blog/rfc-9068-a-jwt-based-oauth2-access-token-format-standard/</guid><description>For anyone who has been paying attention, this blog post has been a long-time coming for multiple reasons. First, this is my first blog post in a couple of years — I’ve been heads down on a couple of projects for awhile now. This is literally the first time I’ve “come up for air” since the last…</description><pubDate>Thu, 23 May 2024 12:53:00 GMT</pubDate><category>access-tokens</category><category>jwt</category><category>oauth2</category><category>iam</category></item><item><title>Making Authorization Decisions</title><link>https://iyasec.io/blog/making-authorization-decisions/</link><guid isPermaLink="true">https://iyasec.io/blog/making-authorization-decisions/</guid><description>This blog post continues our discussion of Authorization in the API space. It will explore common authorization patterns with API Gateways and the backend API Providers. Generally, the API Gateway will apply a Coarse Grained Authorization (CGA) decision and the API Provider will implement Fine…</description><pubDate>Sat, 06 Feb 2021 07:37:40 GMT</pubDate><category>api-gateway</category><category>authorization</category><category>apis</category></item><item><title>Delegation — A General Discussion</title><link>https://iyasec.io/blog/delegation-a-general-discussion/</link><guid isPermaLink="true">https://iyasec.io/blog/delegation-a-general-discussion/</guid><description>This blog post expands on delegation and related concepts introduced in my Kerberos Delegation blog post. It also brings together two blog series I’ve been working on over the years: SAML2 vs. JWT Series and Kerberos and Windows Security Series. Delegation is a critical building block of end-to-end…</description><pubDate>Sat, 06 Feb 2021 07:33:03 GMT</pubDate><category>delegation</category><category>jwt</category><category>kerberos</category><category>saml</category><category>security</category></item><item><title>Kerberos and Windows Security: Delegation</title><link>https://iyasec.io/blog/kerberos-and-windows-security-delegation/</link><guid isPermaLink="true">https://iyasec.io/blog/kerberos-and-windows-security-delegation/</guid><description>In this next post in the Kerberos and Windows Security Series, we are going to explore a very useful, but abstract feature of the Kerberos Authentication Protocol: Delegation. In particular, we are going to focus on the Windows implementation of this feature. Delegation allows downstream actors to…</description><pubDate>Sat, 06 Feb 2021 07:32:22 GMT</pubDate><category>authentication</category><category>delegation</category><category>kerberos</category><category>security</category></item><item><title>HTTP POST vs GET: Is One More Secure For Use In REST APIs?</title><link>https://iyasec.io/blog/http-post-vs-get-is-one-more-secure-for-use-in-rest/</link><guid isPermaLink="true">https://iyasec.io/blog/http-post-vs-get-is-one-more-secure-for-use-in-rest/</guid><description>The use of HTTP POST vs HTTP GET for read-only (or query) operations in REST APIs recently came up in a conversation. For this particular shop, there had been a long-standing ban on the use of GET requests for use in homegrown applications. This had been the case since before REST APIs were in…</description><pubDate>Sat, 06 Feb 2021 07:31:12 GMT</pubDate><category>rest</category><category>http</category><category>apis</category><category>security</category></item><item><title>OAuth2 Access Tokens vs API Keys — Using JWTs</title><link>https://iyasec.io/blog/oauth2-access-tokens-vs-api-keys-using-jwts/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth2-access-tokens-vs-api-keys-using-jwts/</guid><description>There are several approaches to securing APIs. Every API Gateway vendor supports the same core set of API security mechanisms. API Keys and OAuth2 are two examples of these authentication (plus authorization) mechanism. When should one be used over the other? What are the differences between the…</description><pubDate>Wed, 15 Jul 2020 08:03:23 GMT</pubDate><category>access-tokens</category><category>api-gateway</category><category>api-security</category><category>authentication</category><category>oauth2</category><category>apis</category></item><item><title>Identity Protocols, Hosted Login UIs, and Custom Login UIs</title><link>https://iyasec.io/blog/identity-protocols-hosted-login-uis-and-custom-login-uis/</link><guid isPermaLink="true">https://iyasec.io/blog/identity-protocols-hosted-login-uis-and-custom-login-uis/</guid><description>There are many ways to implement user authentication in a modern application (mobile, desktop, tablet, web, etc). I have previously explored Authentication, Federation, and SSO; that post introduces several key concepts that are assumed here. At the intersection of user experience, authentication,…</description><pubDate>Mon, 13 Jul 2020 03:01:03 GMT</pubDate><category>authentication</category><category>federation</category><category>sso</category><category>identity</category></item><item><title>More Single Page Application (SPA) and OAuth2 Thoughts</title><link>https://iyasec.io/blog/more-single-page-application-spa-and-oauth2-thoughts/</link><guid isPermaLink="true">https://iyasec.io/blog/more-single-page-application-spa-and-oauth2-thoughts/</guid><description>This post continues where “SECURELY USING THE OIDC AUTHORIZATION CODE FLOW AND A PUBLIC CLIENT WITH SINGLE PAGE APPLICATIONS” left off on the topic of securing Single Page Applications (SPAs). That post describes an architecture where the SPA running in the browser (User Agent)is acting as the…</description><pubDate>Sun, 01 Sep 2019 00:39:16 GMT</pubDate><category>authorization</category><category>oauth2</category><category>openid-connect</category><category>web-application-security</category></item><item><title>OAuth2 Access Tokens and Multiple Resources Series</title><link>https://iyasec.io/blog/oauth2-access-tokens-and-multiple-resources-series/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth2-access-tokens-and-multiple-resources-series/</guid><description>This article is a place my other blog posts can point at when referencing this series.</description><pubDate>Sat, 31 Aug 2019 23:35:44 GMT</pubDate><category>access-tokens</category><category>oauth2</category><category>series</category></item><item><title>Authorization Series</title><link>https://iyasec.io/blog/authorization-series/</link><guid isPermaLink="true">https://iyasec.io/blog/authorization-series/</guid><description>This post contains links to all the articles about authorization that I have written.</description><pubDate>Sat, 31 Aug 2019 23:21:50 GMT</pubDate><category>authorization</category><category>series</category></item><item><title>OAUTH2 ACCESS TOKEN USAGE STRATEGIES FOR MULTIPLE RESOURCES (APIS): PART 3</title><link>https://iyasec.io/blog/oauth2-access-token-usage-strategies-for-multiple-resources-apis-part-3/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth2-access-token-usage-strategies-for-multiple-resources-apis-part-3/</guid><description>This post was originally published as “OAUTH2 ACCESS TOKEN USAGE STRATEGIES FOR MULTIPLE RESOURCES (APIS): PART 3” on the Ping Identity Blog.</description><pubDate>Sat, 31 Aug 2019 23:16:51 GMT</pubDate><category>access-tokens</category><category>oauth2</category><category>apis</category><category>identity</category></item><item><title>OAuth2 Access Token Usage Strategies for Multiple Resources (APIs) Part 2</title><link>https://iyasec.io/blog/oauth2-access-token-usage-strategies-for-multiple-resources-apis-part-2/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth2-access-token-usage-strategies-for-multiple-resources-apis-part-2/</guid><description>This post was originally published as “OAUTH 2 ACCESS TOKEN USAGE STRATEGIES FOR MULTIPLE RESOURCES (APIS): PART 2” on the Ping Identity Blog.</description><pubDate>Sat, 22 Jun 2019 07:22:16 GMT</pubDate><category>access-tokens</category><category>oauth2</category><category>apis</category><category>identity</category></item><item><title>OAUTH 2 ACCESS TOKEN USAGE STRATEGIES FOR MULTIPLE RESOURCES (APIS): PART 1</title><link>https://iyasec.io/blog/oauth-2-access-token-usage-strategies-for-multiple-resources-apis-part-1/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth-2-access-token-usage-strategies-for-multiple-resources-apis-part-1/</guid><description>This post was originally published as “OAUTH 2 ACCESS TOKEN USAGE STRATEGIES FOR MULTIPLE RESOURCES (APIS): PART 1” on the Ping Identity Blog.</description><pubDate>Mon, 27 May 2019 06:33:13 GMT</pubDate><category>access-tokens</category><category>oauth2</category><category>apis</category><category>identity</category></item><item><title>API GOVERNANCE: A VITAL BUILDING BLOCK FOR API SECURITY</title><link>https://iyasec.io/blog/api-governance-a-vital-building-block-for-api-security/</link><guid isPermaLink="true">https://iyasec.io/blog/api-governance-a-vital-building-block-for-api-security/</guid><description>This post was originally published as “API GOVERNANCE: A VITAL BUILDING BLOCK FOR API SECURITY” on the Ping Identity blog.</description><pubDate>Sat, 20 Apr 2019 07:45:05 GMT</pubDate><category>api-management</category><category>api-security</category><category>governance</category><category>apis</category><category>identity</category><category>security</category></item><item><title>SECURELY USING THE OIDC AUTHORIZATION CODE FLOW AND A PUBLIC CLIENT WITH SINGLE PAGE APPLICATIONS</title><link>https://iyasec.io/blog/securely-using-the-oidc-authorization-code-flow-and-a-public-client-with/</link><guid isPermaLink="true">https://iyasec.io/blog/securely-using-the-oidc-authorization-code-flow-and-a-public-client-with/</guid><description>This blog post was originally published as “SECURELY USING THE OIDC AUTHORIZATION CODE FLOW AND A PUBLIC CLIENT WITH SINGLE PAGE APPLICATIONS” on the Ping Identity blog.</description><pubDate>Wed, 07 Nov 2018 18:02:48 GMT</pubDate><category>authorization</category><category>openid-connect</category><category>identity</category></item><item><title>OpenID Connect Authorization Code Flow with AWS Cognito</title><link>https://iyasec.io/blog/openid-connect-authorization-code-flow-with-aws-cognito/</link><guid isPermaLink="true">https://iyasec.io/blog/openid-connect-authorization-code-flow-with-aws-cognito/</guid><description>Earlier this year, I was working on a project that was using AWS Cognito (as the identity stack) and the AWS API Gateway (as the front-door to all of the API calls). AWS Cognito is a relatively new player in the identity space. It doesn’t support the full OAuth2 or OpenID Connect specs, but, does…</description><pubDate>Sat, 27 Oct 2018 06:06:32 GMT</pubDate><category>api-gateway</category><category>authorization</category><category>aws</category><category>oauth2</category><category>openid-connect</category><category>cloud</category></item><item><title>Kerberos and Windows Security: Kerberos on Windows</title><link>https://iyasec.io/blog/kerberos-and-windows-security-kerberos-on-windows/</link><guid isPermaLink="true">https://iyasec.io/blog/kerberos-and-windows-security-kerberos-on-windows/</guid><description>In this next post in my Kerberos and Windows Security Series, we are going to look at the use of Kerberos in Microsoft Windows (Microsoft Kerberos). At the end of the day, Kerberos with Windows is more-or-less the same as Kerberos anywhere else; though, there are several proprietary extensions that…</description><pubDate>Thu, 25 Oct 2018 02:40:01 GMT</pubDate><category>kerberos</category><category>security</category></item><item><title>Authorization Decision Input Parameters</title><link>https://iyasec.io/blog/authorization-decision-input-parameters/</link><guid isPermaLink="true">https://iyasec.io/blog/authorization-decision-input-parameters/</guid><description>I was working with a developer not so long ago and it was explained to me that a caching layer had been added to a services layer (API Provider) to make the authorization (Fine Grained Authorization, FGA) decision more efficient for subsequent API calls. In particular, the cache contains data…</description><pubDate>Wed, 24 Oct 2018 03:07:37 GMT</pubDate><category>authorization</category><category>apis</category></item><item><title>Active Directory Federation Services (ADFS) and Kerberos</title><link>https://iyasec.io/blog/active-directory-federation-services-adfs-and-kerberos/</link><guid isPermaLink="true">https://iyasec.io/blog/active-directory-federation-services-adfs-and-kerberos/</guid><description>While researching an upcoming blog post about Kerberos and Mobile, I needed to understand how Identity Providers (like ADFS or Ping Federate) use Kerberos (and possibly Kerberos Delegation) to perform authentication via username and password. This blog post captures what I found for ADFS.</description><pubDate>Wed, 24 Oct 2018 02:42:52 GMT</pubDate><category>active-directory</category><category>authentication</category><category>delegation</category><category>federation</category><category>identity-provider</category><category>kerberos</category></item><item><title>The Benefits of JWTs as OAuth2 Access Tokens</title><link>https://iyasec.io/blog/the-benefits-of-jwts-as-oauth2-access-tokens/</link><guid isPermaLink="true">https://iyasec.io/blog/the-benefits-of-jwts-as-oauth2-access-tokens/</guid><description>Update (01/31/2021) — Since I originally wrote this article, a proposal has been created that officially describes using JSON Web Tokens (JWTs) as OAuth2 Access Tokens. As of this date, it has not yet been adopted as an official RFC.</description><pubDate>Sat, 13 Oct 2018 23:17:51 GMT</pubDate><category>access-tokens</category><category>jwt</category><category>oauth2</category></item><item><title>OpenID Connect (OIDC) and OAuth2 Authentication Libraries</title><link>https://iyasec.io/blog/openid-connect-oidc-and-oauth2-authentication-libraries/</link><guid isPermaLink="true">https://iyasec.io/blog/openid-connect-oidc-and-oauth2-authentication-libraries/</guid><description>It’s 2018. At this point, application developers should not be writing code that directly implements HTTPS calls to OAuth2 or OpenID Connect endpoints, token caching, token refreshes, token validation, or other such activities. An authentication library should be used that implements these…</description><pubDate>Sat, 13 Oct 2018 06:44:13 GMT</pubDate><category>authentication</category><category>oauth2</category><category>openid-connect</category><category>http</category></item><item><title>IDENTIVERSE REFLECTIONS: NEWS, TRENDS AND A GLIMPSE INTO THE FUTURE</title><link>https://iyasec.io/blog/identiverse-reflections-news-trends-and-a-glimpse-into-the-future/</link><guid isPermaLink="true">https://iyasec.io/blog/identiverse-reflections-news-trends-and-a-glimpse-into-the-future/</guid><description>This blog post was originally published as “IDENTIVERSE REFLECTIONS: NEWS, TRENDS AND A GLIMPSE INTO THE FUTURE” on the Ping Identity blog.</description><pubDate>Fri, 05 Oct 2018 03:03:44 GMT</pubDate><category>speaking</category><category>identity</category></item><item><title>Identity + API Management Component Relationships</title><link>https://iyasec.io/blog/identity-api-management-component-relationships/</link><guid isPermaLink="true">https://iyasec.io/blog/identity-api-management-component-relationships/</guid><description>This diagram captures the relationships between concepts I’ve been writing about for a couple of years now.</description><pubDate>Thu, 04 Oct 2018 21:33:45 GMT</pubDate><category>api-management</category><category>apis</category><category>identity</category></item><item><title>The Many Ways of Approaching Identity Architecture</title><link>https://iyasec.io/blog/the-many-ways-of-approaching-identity-architecture/</link><guid isPermaLink="true">https://iyasec.io/blog/the-many-ways-of-approaching-identity-architecture/</guid><description>At some point in the finite past, I had the good fortune to become involved in a project that was essentially completely greenfield. An unnamed company, in an unnamed industry decided to try something new. In a page right out of “The Innovator’s dilemma”, they spun up a new, separate organization,…</description><pubDate>Fri, 01 Jun 2018 22:55:11 GMT</pubDate><category>api-gateway</category><category>application-security</category><category>authentication</category><category>authorization</category><category>aws</category><category>identity</category></item><item><title>A Brief Summary of All Things Apigee and API Management that I Have Written</title><link>https://iyasec.io/blog/a-brief-summary-of-all-things-apigee-and-api-management-that-i/</link><guid isPermaLink="true">https://iyasec.io/blog/a-brief-summary-of-all-things-apigee-and-api-management-that-i/</guid><description>Not so long ago, someone asked me for a list of all the Apigee and API Management related material I have written. The following was my response. The recipient suggested that I post this; so, here we go.</description><pubDate>Wed, 16 May 2018 22:56:13 GMT</pubDate><category>api-management</category><category>apigee</category><category>apis</category></item><item><title>Kerberos and Windows Security Series</title><link>https://iyasec.io/blog/kerberos-and-windows-security-series/</link><guid isPermaLink="true">https://iyasec.io/blog/kerberos-and-windows-security-series/</guid><description>The following are the Kerberos and Windows Security posts that I have written.</description><pubDate>Wed, 16 May 2018 21:44:06 GMT</pubDate><category>kerberos</category><category>series</category><category>security</category></item><item><title>Kerberos Wireshark Captures: A Windows Login Example</title><link>https://iyasec.io/blog/kerberos-wireshark-captures-a-windows-login-example/</link><guid isPermaLink="true">https://iyasec.io/blog/kerberos-wireshark-captures-a-windows-login-example/</guid><description>This blog post is the next in my Kerberos and Windows Security series. It describes the Kerberos network traffic captured during the sign on of a domain user to a domain-joined Windows Server 2016 instance. This post will help solidify our understanding of the Kerberos v5 protocol with a real world…</description><pubDate>Wed, 16 May 2018 21:43:04 GMT</pubDate><category>kerberos</category><category>networking</category><category>security</category></item><item><title>Kerberos v5 Related Specs and RFCs</title><link>https://iyasec.io/blog/kerberos-v5-related-specs-and-rfcs/</link><guid isPermaLink="true">https://iyasec.io/blog/kerberos-v5-related-specs-and-rfcs/</guid><description>This post lists all of the related RFCs and specifications to Kerberos v5 that have been published over the years. It is part of my Kerberos and Windows Security Series. When I was researching this series, finding all of this information together in one place was quite challenging. As noted in my…</description><pubDate>Wed, 16 May 2018 21:42:30 GMT</pubDate><category>kerberos</category><category>standards</category><category>security</category></item><item><title>The Common Identity Protocols</title><link>https://iyasec.io/blog/the-common-identity-protocols/</link><guid isPermaLink="true">https://iyasec.io/blog/the-common-identity-protocols/</guid><description>I’ve written blog posts on the following identity protocols. I’m creating this post to have a central place to refer to “identity protocols”. I will periodically update this list as I publish new posts with related material.</description><pubDate>Wed, 16 May 2018 21:41:30 GMT</pubDate><category>federation</category><category>kerberos</category><category>oauth2</category><category>openid-connect</category><category>saml</category><category>identity</category></item><item><title>Kerberos Wireshark Captures: A SPNEGO Example</title><link>https://iyasec.io/blog/kerberos-wireshark-captures-a-spnego-example/</link><guid isPermaLink="true">https://iyasec.io/blog/kerberos-wireshark-captures-a-spnego-example/</guid><description>This is the second post that presents a real world example of the use of Kerberos. The first post captured the Kerberos protocol details of a Windows domain user login. Both of these posts are part of a series I created about Kerberos and Windows Security. In this post, we will look at the use of…</description><pubDate>Wed, 16 May 2018 21:39:55 GMT</pubDate><category>kerberos</category><category>networking</category><category>security</category></item><item><title>Kerberos and Windows Security: History</title><link>https://iyasec.io/blog/kerberos-and-windows-security-history/</link><guid isPermaLink="true">https://iyasec.io/blog/kerberos-and-windows-security-history/</guid><description>In previous posts, we explored various identity protocols including OAuth2, OpenID Connect, SAML2 profiles, WS-Trust, and WS-Federation. This post continues our exploration of identity protocols by looking at the Kerberos v5 authentication protocol and its use in Microsoft Windows authentication. I…</description><pubDate>Wed, 16 May 2018 21:37:03 GMT</pubDate><category>authentication</category><category>federation</category><category>kerberos</category><category>oauth2</category><category>openid-connect</category><category>security</category></item><item><title>Kerberos and Windows Security: Kerberos v5 Protocol</title><link>https://iyasec.io/blog/kerberos-and-windows-security-kerberos-v5-protocol/</link><guid isPermaLink="true">https://iyasec.io/blog/kerberos-and-windows-security-kerberos-v5-protocol/</guid><description>In our last post, we looked at the history of Kerberos and its use in Windows Security. This post continues our Kerberos and Windows Security discussion. Here we will look at the Kerberos v5 protocol independent of its use in Microsoft Windows.</description><pubDate>Wed, 16 May 2018 21:34:25 GMT</pubDate><category>kerberos</category><category>security</category></item><item><title>Demo: Apigee Edge OAuth2 Debugging</title><link>https://iyasec.io/blog/demo-apigee-edge-oauth2-debugging/</link><guid isPermaLink="true">https://iyasec.io/blog/demo-apigee-edge-oauth2-debugging/</guid><description>This post was originally published as “Demo: Apigee Edge OAuth2 Debugging” on the Apigee Blog.</description><pubDate>Mon, 30 Apr 2018 23:22:40 GMT</pubDate><category>api-management</category><category>apigee</category><category>debugging</category><category>oauth2</category></item><item><title>Apigee Edge and Third-Party Identity Provider Integration — Detailed View</title><link>https://iyasec.io/blog/apigee-edge-and-third-party-identity-provider-integration-detailed-view/</link><guid isPermaLink="true">https://iyasec.io/blog/apigee-edge-and-third-party-identity-provider-integration-detailed-view/</guid><description>This post provides a detailed view of what happens when my example API Proxy that integrates Apigee Edge and a Third-Party Identity Provider for OAuth2 use cases. The setup instructions are available here.</description><pubDate>Thu, 29 Mar 2018 04:30:16 GMT</pubDate><category>api-management</category><category>apigee</category><category>identity-provider</category><category>oauth2</category><category>integration</category><category>identity</category></item><item><title>Identity Broker: An SSO Protocol Transition From OpenID Connect To WS-Federation</title><link>https://iyasec.io/blog/identity-broker-an-sso-protocol-transition-from-openid-connect-to-ws-federation/</link><guid isPermaLink="true">https://iyasec.io/blog/identity-broker-an-sso-protocol-transition-from-openid-connect-to-ws-federation/</guid><description>I’ve been building up to more complex federation use cases over the past year. In previous posts, we explored the details of OpenID Connect(OIDC) and WS-Federation (WS-Fed). In those posts, we covered basic scenarios of how to use each protocol to integrate one Relying Party (Service Provider,…</description><pubDate>Wed, 28 Feb 2018 03:08:56 GMT</pubDate><category>federation</category><category>identity-provider</category><category>openid-connect</category><category>sso</category><category>ws-federation</category><category>identity</category></item><item><title>The Future of API Security</title><link>https://iyasec.io/blog/the-future-of-api-security/</link><guid isPermaLink="true">https://iyasec.io/blog/the-future-of-api-security/</guid><description>On February 15, 2018, Bernard Harguindeguy of Elastic Beam and I filmed a webcast on The Future of API Security. The webcast can be viewed here.</description><pubDate>Thu, 22 Feb 2018 10:10:59 GMT</pubDate><category>api-security</category><category>apis</category><category>security</category></item><item><title>The Tale of Thomas, Richard, and Karen — A Software Architecture Parable</title><link>https://iyasec.io/blog/the-tale-of-thomas-richard-and-karen-a-software-architecture-parable/</link><guid isPermaLink="true">https://iyasec.io/blog/the-tale-of-thomas-richard-and-karen-a-software-architecture-parable/</guid><description>It so happened that one day, in a corporate IT department not unlike the one you are familiar with, three IT resources were preparing to design a software system. It doesn’t much matter what the system is or what it is supposed to do, for the results would be more-or-less the same. The assembled…</description><pubDate>Wed, 21 Feb 2018 05:28:14 GMT</pubDate><category>war-stories</category><category>integration</category></item><item><title>Apigee Edge OAuth2 and Third-Party Identity Providers</title><link>https://iyasec.io/blog/apigee-edge-oauth2-and-third-party-identity-providers/</link><guid isPermaLink="true">https://iyasec.io/blog/apigee-edge-oauth2-and-third-party-identity-providers/</guid><description>This blog post summarizes the details of how to deploy and configure the the Apigee Edge OAuth2 example that I put together. This example will use the OAuth2 Authorization Code Grant and Refresh Token Grant to demonstrate how OAuth2 can be used with Apigee Edge in a real-world application.</description><pubDate>Sun, 04 Feb 2018 20:37:35 GMT</pubDate><category>access-tokens</category><category>api-management</category><category>apigee</category><category>identity-provider</category><category>oauth2</category><category>identity</category></item><item><title>Refresh Token Support in OAuth2 + OIDC Debugger</title><link>https://iyasec.io/blog/refresh-token-support-in-oauth2-oidc-debugger/</link><guid isPermaLink="true">https://iyasec.io/blog/refresh-token-support-in-oauth2-oidc-debugger/</guid><description>This post describes the Refresh Token support that was added to the OAuth2 + OIDC Debugger in late 2017. The OAuth2 + OIDC Debugger is a general-purpose testing tool for the OAuth2 and OpenID Connect protocols. It has been tested with many of the leading Identity Providers in the industry.</description><pubDate>Sun, 04 Feb 2018 19:43:02 GMT</pubDate><category>access-tokens</category><category>debugging</category><category>identity-provider</category><category>oauth2</category><category>openid-connect</category><category>tools</category></item><item><title>Differences Between Azure Active Directory and Red Hat SSO v7.1</title><link>https://iyasec.io/blog/differences-between-azure-active-directory-and-red-hat-sso-v7-1/</link><guid isPermaLink="true">https://iyasec.io/blog/differences-between-azure-active-directory-and-red-hat-sso-v7-1/</guid><description>I recently finished implementing OAuth2 and OIDC support for Azure Active Directory in my OAuth2 + OIDC Debugger. Previously, we implemented support for Red Hat SSO v7.1 and 3Scale. This post compares the two product’s implementations of these protocols (OAuth2 and OIDC). In particular, it looks at…</description><pubDate>Sat, 30 Dec 2017 09:50:31 GMT</pubDate><category>3scale</category><category>active-directory</category><category>api-management</category><category>azure</category><category>keycloak</category><category>sso</category></item><item><title>OAuth2 Resource Owner Password Credential Grant with 3Scale and Red Hat SSO</title><link>https://iyasec.io/blog/oauth2-resource-owner-password-credential-grant-with-3scale-and-red-hat-sso/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth2-resource-owner-password-credential-grant-with-3scale-and-red-hat-sso/</guid><description>This blog post continues demonstrating (and documenting) the use of the OAuth2 + OIDC Debugger with 3Scale API Management and Red Hat SSO. Now, we are going to look at the OAuth2 Resource Owner Password Credential Grant with 3Scale and Red Hat SSO.</description><pubDate>Fri, 08 Dec 2017 09:09:20 GMT</pubDate><category>3scale</category><category>api-management</category><category>debugging</category><category>keycloak</category><category>oauth2</category><category>sso</category></item><item><title>OAuth2 Implicit Grant with 3Scale and Red Hat SSO</title><link>https://iyasec.io/blog/oauth2-implicit-grant-with-3scale-and-red-hat-sso/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth2-implicit-grant-with-3scale-and-red-hat-sso/</guid><description>This post demonstrates the OAuth2 Implicit Grant with 3Scale SaaS, APICast Gateway, and Red Hat SSO v7.1. In the last post, we introduced these components and demonstrated a functioning OAuth2 Authorization Code Grant (and OpenID Connect Authorization Code Flow). This is all part of my 3Scale API…</description><pubDate>Mon, 27 Nov 2017 21:17:23 GMT</pubDate><category>3scale</category><category>api-management</category><category>authorization</category><category>keycloak</category><category>oauth2</category><category>sso</category></item><item><title>OAuth2 Configuration in 3Scale API Management (and APICast) with Red Hat SSO</title><link>https://iyasec.io/blog/oauth2-configuration-in-3scale-api-management-and-apicast-with-red-hat-sso/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth2-configuration-in-3scale-api-management-and-apicast-with-red-hat-sso/</guid><description>This tutorial builds on the capabilities we explored in the “Red Hat SSO + 3Scale API Management” series and in particular in the first tutorial. In this post, we will:</description><pubDate>Wed, 22 Nov 2017 23:23:56 GMT</pubDate><category>3scale</category><category>api-management</category><category>keycloak</category><category>oauth2</category><category>sso</category><category>apis</category></item><item><title>Red Hat SSO v7.1 OAuth2 Client Credentials Grant</title><link>https://iyasec.io/blog/red-hat-sso-v7-1-oauth2-client-credentials-grant/</link><guid isPermaLink="true">https://iyasec.io/blog/red-hat-sso-v7-1-oauth2-client-credentials-grant/</guid><description>This post continues our exploration of OAuth2 Authorization Grants with Red Hat SSO v7.1. In previous posts, we looked at:</description><pubDate>Thu, 16 Nov 2017 14:34:02 GMT</pubDate><category>authorization</category><category>keycloak</category><category>oauth2</category><category>sso</category></item><item><title>Red Hat SSO v7.1 OAuth2 Resource Owner Password Credential Grant Support</title><link>https://iyasec.io/blog/red-hat-sso-v7-1-oauth2-resource-owner-password-credential-grant-support/</link><guid isPermaLink="true">https://iyasec.io/blog/red-hat-sso-v7-1-oauth2-resource-owner-password-credential-grant-support/</guid><description>In this post, we will look at an example of the OAuth2 Resource Owner Password Credential Grant using Red Hat SSO v7.1. In previous posts, I described the Red Hat SSO setup for OpenID Connect authentication and OAuth2. We have also looked at examples of:</description><pubDate>Mon, 13 Nov 2017 16:37:40 GMT</pubDate><category>authentication</category><category>keycloak</category><category>oauth2</category><category>openid-connect</category><category>sso</category></item><item><title>Red Hat SSO and 3Scale API Management Series</title><link>https://iyasec.io/blog/red-hat-sso-and-3scale-api-management-series/</link><guid isPermaLink="true">https://iyasec.io/blog/red-hat-sso-and-3scale-api-management-series/</guid><description>This post contains a collection of links to blog posts I’ve written about the use of OAuth2 and OpenID Connect with Red Hat SSO and 3Scale API Management.</description><pubDate>Sun, 12 Nov 2017 15:29:55 GMT</pubDate><category>3scale</category><category>api-management</category><category>keycloak</category><category>sso</category><category>series</category><category>apis</category></item><item><title>OAuth2 Implicit Grant with Red Hat SSO v7.1</title><link>https://iyasec.io/blog/oauth2-implicit-grant-with-red-hat-sso-v7-1/</link><guid isPermaLink="true">https://iyasec.io/blog/oauth2-implicit-grant-with-red-hat-sso-v7-1/</guid><description>In my last post, we looked at how to configure Red Hat SSO v7.1 for OpenID Connect. That post also introduced a web-based OAuth2 + OIDC debugger and the OIDC Authorization Code Authentication Flow. The Red Hat SSO configuration that was created in that post also allows the OAuth2 Implicit Grant to…</description><pubDate>Sun, 12 Nov 2017 15:29:15 GMT</pubDate><category>authentication</category><category>authorization</category><category>debugging</category><category>keycloak</category><category>oauth2</category><category>sso</category></item><item><title>Red Hat SSO v7.1 Spec Support</title><link>https://iyasec.io/blog/red-hat-sso-v7-1-spec-support/</link><guid isPermaLink="true">https://iyasec.io/blog/red-hat-sso-v7-1-spec-support/</guid><description>Red Hat SSO v7.1 provides support for OAuth2, OpenID Connect, and SAML2. There are numerous other identity protocols, but these are quite common and can handle a wide variety of use cases.</description><pubDate>Sun, 12 Nov 2017 15:25:05 GMT</pubDate><category>keycloak</category><category>oauth2</category><category>openid-connect</category><category>saml</category><category>sso</category><category>standards</category></item><item><title>What is Authorization?</title><link>https://iyasec.io/blog/what-is-authorization/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-authorization/</guid><description>In a previous post, I gave a definition of Authentication. In this post, we’re going to explore authorization, which is typically the next step in the processing pipeline after authentication. The concepts described here can apply equally to traditional web applications, SPA apps, mobile apps,…</description><pubDate>Sun, 12 Nov 2017 15:00:13 GMT</pubDate><category>authentication</category><category>authorization</category><category>ci-cd</category><category>supply-chain-security</category></item><item><title>OpenID Connect (Authorization Code Flow) with Red Hat SSO</title><link>https://iyasec.io/blog/openid-connect-authorization-code-flow-with-red-hat-sso/</link><guid isPermaLink="true">https://iyasec.io/blog/openid-connect-authorization-code-flow-with-red-hat-sso/</guid><description>This post was originally published as “White Paper: OpenID Connect (Authorization Code Flow) with Red Hat SSO” on the Levvel Blog.</description><pubDate>Sat, 11 Nov 2017 03:27:55 GMT</pubDate><category>authorization</category><category>keycloak</category><category>openid-connect</category><category>sso</category></item><item><title>Application Security Models</title><link>https://iyasec.io/blog/application-security-models/</link><guid isPermaLink="true">https://iyasec.io/blog/application-security-models/</guid><description>I like to start system design (at the application level) with the security model that will be used to protect the system. Application security models have several attributes that need to be addressed at each layer of the application.</description><pubDate>Sun, 05 Nov 2017 14:00:35 GMT</pubDate><category>application-security</category><category>security-architecture</category><category>security</category></item><item><title>Digital Signature Series</title><link>https://iyasec.io/blog/digital-signature-series/</link><guid isPermaLink="true">https://iyasec.io/blog/digital-signature-series/</guid><description>The following blog posts are part of a series I wrote on digital signatures.</description><pubDate>Sun, 05 Nov 2017 13:42:13 GMT</pubDate><category>digital-signatures</category><category>series</category><category>cryptography</category></item><item><title>Performance Tuning Methodology</title><link>https://iyasec.io/blog/performance-tuning-methodology/</link><guid isPermaLink="true">https://iyasec.io/blog/performance-tuning-methodology/</guid><description>I’m taking a brief excursion from my usual identity and API-centric posts to answer a question about performance tuning that someone asked me earlier this year. In a previous incarnation of my career, I was focused on performance tuning and diagnostics — particularly involving Java systems.…</description><pubDate>Sun, 05 Nov 2017 12:06:46 GMT</pubDate><category>performance</category><category>troubleshooting</category><category>java</category><category>apis</category><category>identity</category></item><item><title>Understanding WS-Federation — Passive Requestor Profile</title><link>https://iyasec.io/blog/understanding-ws-federation-passive-requestor-profile/</link><guid isPermaLink="true">https://iyasec.io/blog/understanding-ws-federation-passive-requestor-profile/</guid><description>There are several identity protocols that are commonly supported by Identity Providers today — OAuth2, OAuth2 Token Exchange, OIDC, SAML2 Browser Profile, WS-Trust, WS-Federation, etc. The OAuth2 and OIDC protocols are relative newcomers. The other protocols have been around longer — and, tend to…</description><pubDate>Wed, 18 Oct 2017 16:20:40 GMT</pubDate><category>federation</category><category>identity-provider</category><category>oauth2</category><category>openid-connect</category><category>saml</category><category>ws-federation</category></item><item><title>Summary of Azure Active Directory OAuth2 Authorization Grant and OIDC Authentication Flow Uses</title><link>https://iyasec.io/blog/summary-of-azure-active-directory-oauth2-authorization-grant-and-oidc-authentication-flow/</link><guid isPermaLink="true">https://iyasec.io/blog/summary-of-azure-active-directory-oauth2-authorization-grant-and-oidc-authentication-flow/</guid><description>A while back I needed a summary of which protocols were supported/recommended in different situations by Azure Active Directory while I was researching the “When To Use Which (OAuth2) Grants and (OIDC) Flows” post. So, I am summarizing it here.</description><pubDate>Sun, 24 Sep 2017 12:03:53 GMT</pubDate><category>active-directory</category><category>authentication</category><category>authorization</category><category>azure</category><category>oauth2</category><category>openid-connect</category></item><item><title>Authentication vs. Federation vs. SSO</title><link>https://iyasec.io/blog/authentication-vs-federation-vs-sso/</link><guid isPermaLink="true">https://iyasec.io/blog/authentication-vs-federation-vs-sso/</guid><description>Authentication. Federation. Single Sign On (SSO). I’ve mentioned these concepts many times. I haven’t actually formally defined what each of these terms mean even though I’ve used these many times throughout my writing — these concepts are closely related.</description><pubDate>Sun, 24 Sep 2017 10:53:49 GMT</pubDate><category>authentication</category><category>federation</category><category>sso</category></item><item><title>How To Submit Your Security Tokens to an API Provider, Pt. 2</title><link>https://iyasec.io/blog/how-to-submit-your-security-tokens-to-an-api-provider-pt-2/</link><guid isPermaLink="true">https://iyasec.io/blog/how-to-submit-your-security-tokens-to-an-api-provider-pt-2/</guid><description>This post was originally published as “How to Submit Tokens to an API Provider, Pt 2” on the Apigee Blog.</description><pubDate>Sun, 17 Sep 2017 05:31:23 GMT</pubDate><category>api-management</category><category>apigee</category><category>apis</category><category>security</category></item><item><title>How To Submit Your Security Tokens to an API Provider Pt. 1</title><link>https://iyasec.io/blog/how-to-submit-your-security-tokens-to-an-api-provider-pt-1/</link><guid isPermaLink="true">https://iyasec.io/blog/how-to-submit-your-security-tokens-to-an-api-provider-pt-1/</guid><description>This post was originally published as “How to Submit Tokens to an API Provider, Pt 1” on the Apigee Blog.</description><pubDate>Sun, 17 Sep 2017 05:19:29 GMT</pubDate><category>api-management</category><category>apigee</category><category>apis</category><category>security</category></item><item><title>SAML2 vs JWT: A Comparison</title><link>https://iyasec.io/blog/saml2-vs-jwt-a-comparison/</link><guid isPermaLink="true">https://iyasec.io/blog/saml2-vs-jwt-a-comparison/</guid><description>This post concludes our discussion of SAML2 and JWT. Here we look at a comparison of the features and use cases of the two technologies. It’s difficult to make a direct comparison of JWT and SAML2. As we’ve seen through this series, one must take into account the specifications that work in…</description><pubDate>Wed, 19 Jul 2017 16:45:07 GMT</pubDate><category>jwt</category><category>saml</category></item><item><title>JWT Use Cases</title><link>https://iyasec.io/blog/jwt-use-cases/</link><guid isPermaLink="true">https://iyasec.io/blog/jwt-use-cases/</guid><description>This post explores the equivalent JWT use cases corresponding to the five SAML2 use cases that were explored earlier in this series. We had to build up our tool set to get to this point — including exploring JWT, OAuth2, OpenID Connect, and the supporting specs. To be ready for this moment, we’ve…</description><pubDate>Thu, 13 Jul 2017 12:34:04 GMT</pubDate><category>jwt</category><category>oauth2</category><category>openid-connect</category><category>saml</category></item><item><title>OpenID Connect Logout</title><link>https://iyasec.io/blog/openid-connect-logout/</link><guid isPermaLink="true">https://iyasec.io/blog/openid-connect-logout/</guid><description>The OpenID Connect (OIDC) family of specs supports logout (from a single application) and global (or single) logout (from all applications that the user has logged into through the OpenID Provider, OP), but these features are optional or in draft status (as of Q2, 2017). So, these spec features may…</description><pubDate>Wed, 12 Jul 2017 16:28:12 GMT</pubDate><category>api-gateway</category><category>application-security</category><category>authentication</category><category>c</category><category>compilers</category><category>openid-connect</category></item><item><title>SAML2 Use Cases</title><link>https://iyasec.io/blog/saml2-use-cases/</link><guid isPermaLink="true">https://iyasec.io/blog/saml2-use-cases/</guid><description>The following blog posts discuss SAML2 use cases that have been explored in this series:</description><pubDate>Sun, 09 Jul 2017 06:24:44 GMT</pubDate><category>jwt</category><category>rest</category><category>saml</category><category>soap</category><category>sso</category><category>web-services</category></item><item><title>Identity Propagation in an API Gateway Architecture</title><link>https://iyasec.io/blog/identity-propagation-in-an-api-gateway-architecture/</link><guid isPermaLink="true">https://iyasec.io/blog/identity-propagation-in-an-api-gateway-architecture/</guid><description>The power of end-to-end user security context with APIs</description><pubDate>Sat, 17 Jun 2017 13:54:05 GMT</pubDate><category>api-gateway</category><category>apis</category><category>identity</category><category>security</category></item><item><title>When To Use Which (OAuth2) Grants and (OIDC) Flows</title><link>https://iyasec.io/blog/when-to-use-which-oauth2-grants-and-oidc-flows/</link><guid isPermaLink="true">https://iyasec.io/blog/when-to-use-which-oauth2-grants-and-oidc-flows/</guid><description>Update(07/01/2019): This is by far my most popular post. I’ve continued to update this article based on feedback and things that I have noticed. I’m trying to keep it relevant.Please leave feedback in the comments section.</description><pubDate>Sun, 21 May 2017 10:33:24 GMT</pubDate><category>oauth2</category><category>openid-connect</category></item><item><title>An Alternative to Delegated Access in the Enterprise</title><link>https://iyasec.io/blog/an-alternative-to-delegated-access-in-the-enterprise/</link><guid isPermaLink="true">https://iyasec.io/blog/an-alternative-to-delegated-access-in-the-enterprise/</guid><description>Extending OAuth2 and OpenID Connect as the enterprise standard for API security</description><pubDate>Mon, 24 Apr 2017 12:31:53 GMT</pubDate><category>api-security</category><category>delegation</category><category>oauth2</category><category>openid-connect</category><category>apis</category><category>security</category></item><item><title>Understanding OpenID Connect Series</title><link>https://iyasec.io/blog/understanding-openid-connect-series/</link><guid isPermaLink="true">https://iyasec.io/blog/understanding-openid-connect-series/</guid><description>The following blog posts make up my series on OpenID Connect. This is part of the SAML2 vs JWT series.</description><pubDate>Wed, 29 Mar 2017 14:09:19 GMT</pubDate><category>jwt</category><category>openid-connect</category><category>saml</category><category>series</category></item><item><title>SAML2 vs JWT: Understanding OpenID Connect Part 3</title><link>https://iyasec.io/blog/saml2-vs-jwt-understanding-openid-connect-part-3/</link><guid isPermaLink="true">https://iyasec.io/blog/saml2-vs-jwt-understanding-openid-connect-part-3/</guid><description>In part 1 and part 2 of Understanding OpenID Connect, core concepts and the first Authentication Flow (Authorization Code Grant Flow) were introduced. In part 3, we look at the remaining Authentication Flows (Implicit Flow and Hybrid Flow) and some other features of the OIDC specification.</description><pubDate>Sat, 25 Mar 2017 08:42:08 GMT</pubDate><category>authentication</category><category>authorization</category><category>jwt</category><category>openid-connect</category><category>saml</category></item><item><title>SAML2 vs JWT: Understanding OpenID Connect Part 2</title><link>https://iyasec.io/blog/saml2-vs-jwt-understanding-openid-connect-part-2/</link><guid isPermaLink="true">https://iyasec.io/blog/saml2-vs-jwt-understanding-openid-connect-part-2/</guid><description>This post continues our discussion of OpenID Connect (OIDC). We look at one of the three Authentication Flows defined by the OIDC spec — the Authorization Code Grant Flow.</description><pubDate>Sat, 25 Mar 2017 08:40:09 GMT</pubDate><category>authentication</category><category>authorization</category><category>jwt</category><category>openid-connect</category><category>saml</category></item><item><title>SAML2 vs JWT: Understanding OpenID Connect Part 1</title><link>https://iyasec.io/blog/saml2-vs-jwt-understanding-openid-connect-part-1/</link><guid isPermaLink="true">https://iyasec.io/blog/saml2-vs-jwt-understanding-openid-connect-part-1/</guid><description>This post builds upon what we learned about OAuth2 and JWT in previous posts. OpenID Connect will give us the final building block for the JWT-related use cases that this series will explore. The goal of this blog post is to provide a deep understanding of the OpenID Connect spec without having to…</description><pubDate>Sat, 25 Mar 2017 08:38:58 GMT</pubDate><category>jwt</category><category>oauth2</category><category>openid-connect</category><category>saml</category></item><item><title>Design Principles for Seamless User Authentication</title><link>https://iyasec.io/blog/design-principles-for-seamless-user-authentication/</link><guid isPermaLink="true">https://iyasec.io/blog/design-principles-for-seamless-user-authentication/</guid><description>This post was originally published as “Design Principles for Seamless User Authentication” on the Apigee Blog.</description><pubDate>Tue, 07 Mar 2017 13:31:37 GMT</pubDate><category>api-management</category><category>apigee</category><category>authentication</category></item><item><title>Keeping Your APIs Secure for Multiple User Types</title><link>https://iyasec.io/blog/keeping-your-apis-secure-for-multiple-user-types/</link><guid isPermaLink="true">https://iyasec.io/blog/keeping-your-apis-secure-for-multiple-user-types/</guid><description>This post was originally published as “Keeping Your APIs Secure for Multiple User Types” on the Apigee Blog.</description><pubDate>Tue, 14 Feb 2017 23:29:45 GMT</pubDate><category>api-management</category><category>apigee</category><category>apis</category><category>security</category></item><item><title>The Tools of API Management — The Full Stack</title><link>https://iyasec.io/blog/the-tools-of-api-management-the-full-stack/</link><guid isPermaLink="true">https://iyasec.io/blog/the-tools-of-api-management-the-full-stack/</guid><description>In the first three API Management posts I wrote, we discussed “What are APIs?(The Technical Perspective)”, “What is API Management?”, and “The Anatomy of an API Management Solution”. Continuing with this theme, we will explore the API Management Stack. So, what do I mean by API Management Stack?</description><pubDate>Mon, 06 Feb 2017 10:19:38 GMT</pubDate><category>api-management</category><category>apis</category></item><item><title>SAML2 vs JWT: Understanding OAuth2</title><link>https://iyasec.io/blog/saml2-vs-jwt-understanding-oauth2/</link><guid isPermaLink="true">https://iyasec.io/blog/saml2-vs-jwt-understanding-oauth2/</guid><description>This blog post continues the SAML2 vs JWT series. In the last post, we discussed JSON Web Tokens. Now, we are going to move on to OAuth2 and OpenID Connect, which provides some structure and protocol around the use of JWT. These protocols are used, along with JWT, to build the JWT use cases this…</description><pubDate>Mon, 23 Jan 2017 06:31:11 GMT</pubDate><category>jwt</category><category>oauth2</category><category>openid-connect</category><category>saml</category></item><item><title>Azure Active Directory Setup for API Actors</title><link>https://iyasec.io/blog/azure-active-directory-setup-for-api-actors/</link><guid isPermaLink="true">https://iyasec.io/blog/azure-active-directory-setup-for-api-actors/</guid><description>This post outlines how to setup an Azure Active Directory tenant with a Pay-As-You-Go or Free subscription (which only lasts for 30 days). This post is an ancillary post that gives the AAD configuration details needed for the Apigee and Azure Active Directory Integration — A JWT Story post to…</description><pubDate>Mon, 16 Jan 2017 07:37:35 GMT</pubDate><category>active-directory</category><category>api-management</category><category>apigee</category><category>azure</category><category>infrastructure</category><category>apis</category></item><item><title>SAML2 vs JWT: Apigee &amp; Azure Active Directory Integration — A JWT Story</title><link>https://iyasec.io/blog/saml2-vs-jwt-apigee-azure-active-directory-integration-a-jwt-story/</link><guid isPermaLink="true">https://iyasec.io/blog/saml2-vs-jwt-apigee-azure-active-directory-integration-a-jwt-story/</guid><description>In our next SAML2 vs JWT post, we are going to use a JWT with a very simple API that is proxied through Apigee Edge Public Cloud. The JWT token will be an OAuth2 access token generated by Azure Active Directory. In the last post in this series, we explored what JSON Web Tokens (JWTs) are and the…</description><pubDate>Sun, 15 Jan 2017 04:55:38 GMT</pubDate><category>active-directory</category><category>api-management</category><category>apigee</category><category>azure</category><category>jwt</category><category>saml</category></item><item><title>SAML2 vs JWT: Understanding JSON Web Token (JWT)</title><link>https://iyasec.io/blog/saml2-vs-jwt-understanding-json-web-token-jwt/</link><guid isPermaLink="true">https://iyasec.io/blog/saml2-vs-jwt-understanding-json-web-token-jwt/</guid><description>In this post, we begin our exploration of the JSON Web Token (JWT) specification as part of the SAML v2.0 vs JWT Series. To understand JWT use cases, we must also look at OpenID Connect v1.0, OAuth v2.0, and and a few related specifications — the JWT spec by itself is not very interesting or…</description><pubDate>Wed, 11 Jan 2017 03:48:06 GMT</pubDate><category>jwt</category><category>openid-connect</category><category>saml</category></item><item><title>SAML v2.0 vs. JWT: SAML2 Single Logout</title><link>https://iyasec.io/blog/saml-v2-0-vs-jwt-saml2-single-logout/</link><guid isPermaLink="true">https://iyasec.io/blog/saml-v2-0-vs-jwt-saml2-single-logout/</guid><description>This post wraps our look at SAML v2.0 Use Cases. The first four use cases are described in “SAML v2.0 vs JWT: SAML2 Web Application SSO Use Cases” and “SAML v2.0 vs. JWT: SAML2 with SOAP Web Services and REST APIs”. The full list of SAML2 vs JWT-related blog posts can be found here.</description><pubDate>Sun, 25 Dec 2016 18:07:47 GMT</pubDate><category>jwt</category><category>rest</category><category>saml</category><category>soap</category><category>sso</category><category>web-services</category></item><item><title>SAML v2.0 vs. JWT: SAML2 with SOAP Web Services and REST APIs</title><link>https://iyasec.io/blog/saml-v2-0-vs-jwt-saml2-with-soap-web-services-and-rest/</link><guid isPermaLink="true">https://iyasec.io/blog/saml-v2-0-vs-jwt-saml2-with-soap-web-services-and-rest/</guid><description>This post continues our look at SAML v2.0 Use Cases. The first two use cases are described in “SAML v2.0 vs JWT: SAML2 Web Application SSO Use Cases”. The full list of SAML2 vs JWT-related blog posts can be found here.</description><pubDate>Sun, 25 Dec 2016 07:10:40 GMT</pubDate><category>jwt</category><category>rest</category><category>saml</category><category>soap</category><category>web-services</category><category>apis</category></item><item><title>SAML v2.0 vs. JWT Series</title><link>https://iyasec.io/blog/saml-v2-0-vs-jwt-series/</link><guid isPermaLink="true">https://iyasec.io/blog/saml-v2-0-vs-jwt-series/</guid><description>This is a list of all the SAML2 vs JWT related posts I have written. This series explores SAML2 use cases, JWT use cases, the relevant specifications, and explores how the two technologies differ. The reader will see how identity federation technology has evolved over the past fifteen years.</description><pubDate>Sat, 24 Dec 2016 23:01:21 GMT</pubDate><category>federation</category><category>jwt</category><category>saml</category><category>series</category><category>identity</category></item><item><title>SAML v2.0 vs JWT: SAML2 Web Application SSO Use Cases</title><link>https://iyasec.io/blog/saml-v2-0-vs-jwt-saml2-web-application-sso-use-cases/</link><guid isPermaLink="true">https://iyasec.io/blog/saml-v2-0-vs-jwt-saml2-web-application-sso-use-cases/</guid><description>This post continues our look at SAML v2.0 and how it compares to JSON Web Tokens (JWT). In the last post, we looked at the history, specs, and basics of SAML v2.0. In this post, we begin exploring SAML v2.0 use cases in detail.</description><pubDate>Thu, 22 Dec 2016 02:43:54 GMT</pubDate><category>jwt</category><category>saml</category><category>sso</category></item><item><title>API GOVERNANCE IN THE ENTERPRISE</title><link>https://iyasec.io/blog/api-governance-in-the-enterprise/</link><guid isPermaLink="true">https://iyasec.io/blog/api-governance-in-the-enterprise/</guid><description>This post was originally published as “API Governance in the Enterprise” on the Levvel Blog.</description><pubDate>Fri, 28 Oct 2016 22:58:47 GMT</pubDate><category>api-management</category><category>governance</category><category>apis</category></item><item><title>SAML 2.0 VS. JWT: UNDERSTANDING FEDERATED IDENTITY AND SAML</title><link>https://iyasec.io/blog/saml-2-0-vs-jwt-understanding-federated-identity-and-saml/</link><guid isPermaLink="true">https://iyasec.io/blog/saml-2-0-vs-jwt-understanding-federated-identity-and-saml/</guid><description>This post was originally published as “SAML 2.0 VS. JWT: UNDERSTANDING FEDERATED IDENTITY AND SAML” on the Levvel Blog.</description><pubDate>Thu, 20 Oct 2016 05:12:16 GMT</pubDate><category>federation</category><category>jwt</category><category>saml</category><category>identity</category></item><item><title>API MANAGEMENT AND PERIMETER SECURITY FOR COTS APPLICATIONS</title><link>https://iyasec.io/blog/api-management-and-perimeter-security-for-cots-applications/</link><guid isPermaLink="true">https://iyasec.io/blog/api-management-and-perimeter-security-for-cots-applications/</guid><description>This post was originally published as “API Management and Perimeter Security for COTS Applications” on the Levvel Blog.</description><pubDate>Wed, 17 Aug 2016 16:34:18 GMT</pubDate><category>api-management</category><category>apis</category><category>security</category></item><item><title>API Security vs. Web Application Security: Part 2</title><link>https://iyasec.io/blog/api-security-vs-web-application-security-part-2/</link><guid isPermaLink="true">https://iyasec.io/blog/api-security-vs-web-application-security-part-2/</guid><description>This post was originally published as “API Security vs. Web Application Security: Part 2” on the Levvel Blog.</description><pubDate>Tue, 17 May 2016 05:12:35 GMT</pubDate><category>api-security</category><category>application-security</category><category>apis</category><category>security</category></item><item><title>API Security vs. Web Application Security Part 1: A Brief History of Web Application Architecture</title><link>https://iyasec.io/blog/api-security-vs-web-application-security-part-1-a-brief-history-of/</link><guid isPermaLink="true">https://iyasec.io/blog/api-security-vs-web-application-security-part-1-a-brief-history-of/</guid><description>This post was originally published as “API Security vs. Web Application Security Part 1: A Brief History of Web Application Architecture” on the Levvel Blog.</description><pubDate>Tue, 17 May 2016 04:42:35 GMT</pubDate><category>api-security</category><category>application-security</category><category>apis</category><category>security</category></item><item><title>DSig Part 3: XML DSig vs. JSON Web Signature</title><link>https://iyasec.io/blog/dsig-part-3-xml-dsig-vs-json-web-signature/</link><guid isPermaLink="true">https://iyasec.io/blog/dsig-part-3-xml-dsig-vs-json-web-signature/</guid><description>This post was originally published as “DSig Part 3: XML DSig vs. JSON Web Signtaure” on the Levvel Blog.</description><pubDate>Sun, 10 Apr 2016 06:45:35 GMT</pubDate><category>digital-signatures</category><category>jwt</category><category>xml</category><category>cryptography</category></item><item><title>DSig Part 2: JSON Web Signature (JWS)</title><link>https://iyasec.io/blog/dsig-part-2-json-web-signature-jws/</link><guid isPermaLink="true">https://iyasec.io/blog/dsig-part-2-json-web-signature-jws/</guid><description>This post was originally published as “DSig Part 2: JSON Web Signature (JWS)” on the Levvel Blog.</description><pubDate>Fri, 01 Apr 2016 18:30:03 GMT</pubDate><category>digital-signatures</category><category>jwt</category><category>cryptography</category></item><item><title>DSig Part 1: XML Digital Signature and WS-Security Integrity</title><link>https://iyasec.io/blog/dsig-part-1-xml-digital-signature-and-ws-security-integrity/</link><guid isPermaLink="true">https://iyasec.io/blog/dsig-part-1-xml-digital-signature-and-ws-security-integrity/</guid><description>This post was originally published as “DSig Part 1: XML Digital Signature and WS-Security Integrity” on the Levvel Blog.</description><pubDate>Thu, 31 Mar 2016 05:34:18 GMT</pubDate><category>digital-signatures</category><category>ws-security</category><category>xml</category><category>cryptography</category><category>security</category></item><item><title>Nissan LEAF, API Security, Who Owns API Security, and How Much Security Is Enough?</title><link>https://iyasec.io/blog/nissan-leaf-api-security-who-owns-api-security-and-how-much-security/</link><guid isPermaLink="true">https://iyasec.io/blog/nissan-leaf-api-security-who-owns-api-security-and-how-much-security/</guid><description>This post was originally published as “Nissan LEAF, API Security, Who Owns API Security, and How Much Security Is Enough?” on the Levvel Blog.</description><pubDate>Mon, 14 Mar 2016 04:26:17 GMT</pubDate><category>api-security</category><category>career</category><category>apis</category><category>security</category></item><item><title>The Anatomy of an API Management Solution</title><link>https://iyasec.io/blog/the-anatomy-of-an-api-management-solution/</link><guid isPermaLink="true">https://iyasec.io/blog/the-anatomy-of-an-api-management-solution/</guid><description>This post was originally published as “The Anatomy of an API Management Solution” on the Levvel Blog.</description><pubDate>Tue, 08 Mar 2016 06:45:04 GMT</pubDate><category>api-management</category><category>apis</category></item><item><title>What is API Management?</title><link>https://iyasec.io/blog/what-is-api-management/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-api-management/</guid><description>This post was originally published as “What is API Management?” on the Levvel Blog.</description><pubDate>Sat, 27 Feb 2016 01:59:48 GMT</pubDate><category>api-management</category><category>apis</category></item><item><title>What are APIs? (The Technology Perspective)</title><link>https://iyasec.io/blog/what-are-apis-the-technology-perspective/</link><guid isPermaLink="true">https://iyasec.io/blog/what-are-apis-the-technology-perspective/</guid><description>This post was originally published as “What are APIs? (The Technology Perspective)” on the Levvel Blog.</description><pubDate>Tue, 16 Feb 2016 06:24:48 GMT</pubDate><category>environments</category><category>memory-management</category><category>performance</category><category>rest</category><category>soap</category><category>apis</category></item><item><title>Modernizing SOA with APIs</title><link>https://iyasec.io/blog/modernizing-soa-with-apis/</link><guid isPermaLink="true">https://iyasec.io/blog/modernizing-soa-with-apis/</guid><description>This post was originally published as “Modernizing SOA with APIs” on the Levvel Blog.</description><pubDate>Tue, 16 Feb 2016 05:57:42 GMT</pubDate><category>soa</category><category>apis</category></item><item><title>Protecting Server Resources Hosting Unauthenticated APIs</title><link>https://iyasec.io/blog/protecting-server-resources-hosting-unauthenticated-apis/</link><guid isPermaLink="true">https://iyasec.io/blog/protecting-server-resources-hosting-unauthenticated-apis/</guid><description>This post was originally published as “Protecting Server Resources Hosting Unauthenticated APIs” on the Levvel Blog.</description><pubDate>Tue, 16 Feb 2016 05:30:15 GMT</pubDate><category>authentication</category><category>apis</category></item><item><title>Convert an X509v3 Binary Security Token to PEM Format</title><link>https://iyasec.io/blog/convert-an-x509v3-binary-security-token-to-pem-format/</link><guid isPermaLink="true">https://iyasec.io/blog/convert-an-x509v3-binary-security-token-to-pem-format/</guid><description>This tutorial describes how to convert a Binary Security Token extracted from a SOAP message into a valid PEM format that can be read by openssl or similar tool. If you are ever troubleshooting the use of X509v3 certificates used with WS-Security, this can come in very handy.</description><pubDate>Sun, 30 Dec 2012 21:58:00 GMT</pubDate><category>pki</category><category>troubleshooting</category><category>ws-security</category><category>xml</category><category>cryptography</category><category>security</category></item><item><title>WS-Security Integrity (XML Digital Signature)</title><link>https://iyasec.io/blog/ws-security-integrity-xml-digital-signature/</link><guid isPermaLink="true">https://iyasec.io/blog/ws-security-integrity-xml-digital-signature/</guid><description>This post continues exploring the use of XML Digital Signature; this time we look at WS-Security Integrity (use of XML Digital Signatures with WS-Security). Our examples show a digital signature and a timestamp in a WS-Security &lt;Security&gt; SOAP Header.</description><pubDate>Sun, 11 Nov 2012 22:00:00 GMT</pubDate><category>digital-signatures</category><category>soap</category><category>ws-security</category><category>xml</category><category>cryptography</category><category>security</category></item><item><title>XML Digital Signature (an Example)</title><link>https://iyasec.io/blog/xml-digital-signature-an-example/</link><guid isPermaLink="true">https://iyasec.io/blog/xml-digital-signature-an-example/</guid><description>In the last post, we looked at the steps involved in generating a digital signature using the XML Digital Signature spec. The algorithm to produce a signature and validate it were explored but no examples were given. In this post, we’ll look at an example that is given in the XML Digital Signature…</description><pubDate>Mon, 05 Nov 2012 00:04:00 GMT</pubDate><category>digital-signatures</category><category>security-architecture</category><category>xml</category><category>cryptography</category><category>security</category></item><item><title>XML Digital Signatures</title><link>https://iyasec.io/blog/xml-digital-signatures/</link><guid isPermaLink="true">https://iyasec.io/blog/xml-digital-signatures/</guid><description>The XML DSig specification is used to provide digital signature functionality to XML Documents. It is is used by numerous other specs such as WS-Security and SAML2. This blog entry will describe how digital signatures work with an X509 private/public key pair.</description><pubDate>Mon, 29 Oct 2012 01:30:00 GMT</pubDate><category>authentication</category><category>digital-signatures</category><category>pki</category><category>xml</category><category>cryptography</category><category>security</category></item><item><title>XML Editor…</title><link>https://iyasec.io/blog/xml-editor/</link><guid isPermaLink="true">https://iyasec.io/blog/xml-editor/</guid><description>I was asked recently what XML, XSD and XSLT editor I use. Given that I am an independent/small consulting firm owner, spending $1000s of dollars on development tooling that will come out of my own pocket is not my first choice.</description><pubDate>Sun, 21 Oct 2012 23:35:00 GMT</pubDate><category>debugging</category><category>tools</category><category>xslt</category><category>career</category><category>xml</category></item><item><title>What is Authentication?</title><link>https://iyasec.io/blog/what-is-authentication/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-authentication/</guid><description>I’ve talked about authentication many times on ThinkMiddleware.com. It recently occurred to me that I have never devoted a blog post to defining authentication. I’ve had a section on the subject in a couple of different places, but I wanted to have an article to reference from other posts. So, here…</description><pubDate>Sun, 14 Oct 2012 23:32:00 GMT</pubDate><category>authentication</category><category>j2ee</category><category>web-services</category><category>integration</category><category>security</category></item><item><title>Datapower SOMA Calls</title><link>https://iyasec.io/blog/datapower-soma-calls/</link><guid isPermaLink="true">https://iyasec.io/blog/datapower-soma-calls/</guid><description>The primary administration automation mechanism on IBM WebSphere DataPower appliances is the XML Management Interface. The XMI interface allows one to make SOMA (SOAP Configuration Management, assuming SOMA = SOap MAnagement) calls to perform various administration tasks. How to perform these…</description><pubDate>Wed, 10 Oct 2012 23:51:00 GMT</pubDate><category>datapower</category><category>soap</category><category>websphere</category><category>career</category><category>infrastructure</category><category>xml</category></item><item><title>ShrewSoft VPN Client Has Problem After Windows 7 Laptop Sleeps with VPN Active</title><link>https://iyasec.io/blog/shrewsoft-vpn-client-has-problem-after-windows-7-laptop-sleeps-with-vpn/</link><guid isPermaLink="true">https://iyasec.io/blog/shrewsoft-vpn-client-has-problem-after-windows-7-laptop-sleeps-with-vpn/</guid><description>A few months ago I switched from using Cisco’s QuickVPN software to the ShrewSoft VPN Client for Windows. I’m not going to get into the issues that I had with QuickVPN-it wasn’t very reliable. I’ve had ShrewSoft VPN for Windows v2.1.7 connecting to a Cisco RV082 VPN router. ShrewSoft provides…</description><pubDate>Mon, 01 Oct 2012 23:49:00 GMT</pubDate><category>networking</category><category>security</category></item><item><title>SOA Specs Visualized</title><link>https://iyasec.io/blog/soa-specs-visualized/</link><guid isPermaLink="true">https://iyasec.io/blog/soa-specs-visualized/</guid><description>In a previous blog post, I listed a number of SOA Specs and Security Specs that I thought were important to be familiar with when working with DataPower and other SOA technologies. In this post, I made a quick (and dirty) Visio diagram that I tend to draw up on a whiteboard when I’m at a new client…</description><pubDate>Sun, 23 Sep 2012 18:21:00 GMT</pubDate><category>soa</category><category>soap</category><category>tls</category><category>http</category><category>standards</category><category>networking</category></item><item><title>Active  Directory Return Codes</title><link>https://iyasec.io/blog/active-directory-return-codes/</link><guid isPermaLink="true">https://iyasec.io/blog/active-directory-return-codes/</guid><description>While working with DataPower and Active Directory (acting as the User Repository) I have often run into situation where AD returns an LDAP error code 49 plus a sub-code in the error string that is unique to AD. The sub-code can be very useful to troubleshooting, if you know what it means.</description><pubDate>Sun, 02 Sep 2012 21:26:00 GMT</pubDate><category>active-directory</category><category>datapower</category><category>ldap</category><category>troubleshooting</category><category>security</category></item><item><title>Some Simple Updates To A DataPower XSLT stylesheet.</title><link>https://iyasec.io/blog/some-simple-updates-to-a-datapower-xslt-stylesheet/</link><guid isPermaLink="true">https://iyasec.io/blog/some-simple-updates-to-a-datapower-xslt-stylesheet/</guid><description>In the last post, we saw how an XML Firewall in loopback mode could be used to return a valid SOAP response to a service message. The stylesheet used simply returned a static SOAP response that was independent of the input parameters. The stylesheet returns a response containing the sum of two…</description><pubDate>Fri, 27 Jul 2012 22:20:00 GMT</pubDate><category>datapower</category><category>soap</category><category>web-services</category><category>xslt</category><category>xml</category></item><item><title>SOAP Web Service Mockup tutorial on DataPower</title><link>https://iyasec.io/blog/soap-web-service-mockup-tutorial-on-datapower/</link><guid isPermaLink="true">https://iyasec.io/blog/soap-web-service-mockup-tutorial-on-datapower/</guid><description>It is often the case that a DataPower developer will have work to do, but does not yet have a backend Service Provider to point the DataPower service at. In general, anything beyond trivial examples will need to point at something that returns a valid response. In order to satisfy this requirement,…</description><pubDate>Fri, 27 Jul 2012 18:14:00 GMT</pubDate><category>datapower</category><category>soap</category><category>tools</category><category>web-services</category><category>networking</category></item><item><title>JBoss/PicketLink WS-Trust Client and Third-Party Security Token Services</title><link>https://iyasec.io/blog/jboss-picketlink-ws-trust-client-and-third-party-security-token-services/</link><guid isPermaLink="true">https://iyasec.io/blog/jboss-picketlink-ws-trust-client-and-third-party-security-token-services/</guid><description>Another use-case that I touched on during my JBoss World 2012 presentation was using the PicketLink WS-Trust Client implementation to communicate with third-party Security Token Services. In particular, we discussed how the PicketLink SAML2STSIssuingLoginModule can communicate with the IBM Tivoli…</description><pubDate>Wed, 04 Jul 2012 04:39:00 GMT</pubDate><category>jboss</category><category>soa</category><category>speaking</category><category>ws-trust</category><category>java</category><category>security</category></item><item><title>JBoss and LTPAv2 support</title><link>https://iyasec.io/blog/jboss-and-ltpav2-support/</link><guid isPermaLink="true">https://iyasec.io/blog/jboss-and-ltpav2-support/</guid><description>I’ve been at a couple of different client sites where there was a heavy IBM product presence, the use of IBM’s proprietary token format-LTPA2, and the need for a non-IBM technology such as JBoss EAP. Given the nature of the LTPA2 technology (IBM proprietary protocol), there isn’t any direct support…</description><pubDate>Tue, 03 Jul 2012 07:19:00 GMT</pubDate><category>jboss</category><category>speaking</category><category>integration</category><category>java</category><category>security</category></item><item><title>DataPower Access Rental—Maybe DataPower in the Cloud?</title><link>https://iyasec.io/blog/datapower-access-rental-maybe-datapower-in-the-cloud/</link><guid isPermaLink="true">https://iyasec.io/blog/datapower-access-rental-maybe-datapower-in-the-cloud/</guid><description>Ever since I was first started working with IBM WebSphere DataPower I was looking around for someone that was offering access to a IBM WebSphere Datapower, I was looking around for someone that was offering access to an Internet-facing appliance that I could use for experimenting and learning. I…</description><pubDate>Mon, 02 Jul 2012 05:25:00 GMT</pubDate><category>datapower</category><category>websphere</category><category>cloud</category><category>java</category></item><item><title>JBoss World 2012 Session–Trusted Security with JBoss Enterprise Application Platform</title><link>https://iyasec.io/blog/jboss-world-2012-session-trusted-security-with-jboss-enterprise-application-platform/</link><guid isPermaLink="true">https://iyasec.io/blog/jboss-world-2012-session-trusted-security-with-jboss-enterprise-application-platform/</guid><description>It’s been a few weeks since I have posted any updates. I started a new project at the beginning of June; it always takes a few weeks to get up to speed on an extended project. Integrating the IBM Tivoli Security stack and JBoss EAP was the subject of my JBoss World 2012 presentation.</description><pubDate>Mon, 02 Jul 2012 05:11:00 GMT</pubDate><category>jaas</category><category>jboss</category><category>speaking</category><category>cryptography</category><category>integration</category><category>security</category></item><item><title>Fine Grained Authorization versus Coarse Grained Authorization</title><link>https://iyasec.io/blog/fine-grained-authorization-versus-coarse-grained-authorization/</link><guid isPermaLink="true">https://iyasec.io/blog/fine-grained-authorization-versus-coarse-grained-authorization/</guid><description>I was recently involved in a conversation where someone asked the question what is FGA (Fine Grained Authorization) versus Coarse Grained Authorization(CGA)? From their perspective, there was just authorization. Further distinction was not needed.</description><pubDate>Wed, 06 Jun 2012 05:48:57 GMT</pubDate><category>authorization</category><category>security</category></item><item><title>RBM–Administrative Access &amp; Security for DataPower</title><link>https://iyasec.io/blog/rbm-administrative-access-security-for-datapower/</link><guid isPermaLink="true">https://iyasec.io/blog/rbm-administrative-access-security-for-datapower/</guid><description>I generally recommend to clients that DataPower RBM (Role-Based Management) be configured to perform authentication and authorization of DataPower administrators and developers with LDAP. In particular, whatever respository serves as the central repository of user information should be used (of…</description><pubDate>Tue, 05 Jun 2012 05:52:00 GMT</pubDate><category>authentication</category><category>authorization</category><category>datapower</category><category>ldap</category><category>infrastructure</category><category>security</category></item><item><title>DataPower Appliances &amp; HSMs</title><link>https://iyasec.io/blog/datapower-appliances-hsms/</link><guid isPermaLink="true">https://iyasec.io/blog/datapower-appliances-hsms/</guid><description>I’ve been in a couple of shops that have used the HSM module option of DataPower for FIPS 140-2 v2 or v3 compliance. An HSM is a Hardware Security Module. My understanding is that there is a short list of IBM customers that are using this technology. I thought collecting all the information and…</description><pubDate>Fri, 01 Jun 2012 00:48:09 GMT</pubDate><category>datapower</category><category>hsm</category><category>key-management</category><category>cryptography</category><category>security</category></item><item><title>JBoss World 2012 Session…</title><link>https://iyasec.io/blog/jboss-world-2012-session/</link><guid isPermaLink="true">https://iyasec.io/blog/jboss-world-2012-session/</guid><description>I will be presenting at JBoss World 2012 in Boston the last week of June. I’ll be presenting with Anil Saldana on JBoss Security, PicketLink, and Identity Management, JBoss Security Architect. A link to the description can be found here. The original abstract:</description><pubDate>Wed, 30 May 2012 00:56:00 GMT</pubDate><category>jboss</category><category>speaking</category><category>java</category><category>identity</category><category>security</category></item><item><title>DataPower Exports and XML Files Referenced by Stylesheets</title><link>https://iyasec.io/blog/datapower-exports-and-xml-files-referenced-by-stylesheets/</link><guid isPermaLink="true">https://iyasec.io/blog/datapower-exports-and-xml-files-referenced-by-stylesheets/</guid><description>I was recently presented with an opportunity to be clever while promoting DataPower objects from a development environment to a testing environment. The WS-Proxy object’s policy rules had a Transform Action that ran a custom stylesheet. The stylesheet referenced a configuration file that was kept…</description><pubDate>Tue, 29 May 2012 01:58:00 GMT</pubDate><category>datapower</category><category>xslt</category><category>xml</category></item><item><title>How To Rename a WS-Proxy or Multi-Protocol Gateway Object on a DataPower Appliance</title><link>https://iyasec.io/blog/how-to-rename-a-ws-proxy-or-multi-protocol-gateway-object-on/</link><guid isPermaLink="true">https://iyasec.io/blog/how-to-rename-a-ws-proxy-or-multi-protocol-gateway-object-on/</guid><description>Anyone who has worked with DataPower for a while has gotten into a situation where they need to rename a service object (XML Firewall, WS-Proxy, Multi-Protocol Gateway, etc). There isn’t a rename button that I have ever found. This tutorial will describe two ways of renaming such objects.</description><pubDate>Tue, 22 May 2012 01:37:00 GMT</pubDate><category>datapower</category><category>jboss</category><category>career</category><category>xml</category></item><item><title>Thomas Erl’s SOA Book Series</title><link>https://iyasec.io/blog/thomas-erls-soa-book-series/</link><guid isPermaLink="true">https://iyasec.io/blog/thomas-erls-soa-book-series/</guid><description>I listed several of Thomas Erl’s books in my SOA Recommended reading list. A full list of Thomas Erl’s series of SOA books can be found here. Anyone working in the SOA space, regardless of vendor or technology stack, should read these books.</description><pubDate>Wed, 16 May 2012 01:41:00 GMT</pubDate><category>reading-list</category><category>soa</category><category>series</category></item><item><title>Who Owns DataPower Within An Organization?</title><link>https://iyasec.io/blog/who-owns-datapower-within-an-organization/</link><guid isPermaLink="true">https://iyasec.io/blog/who-owns-datapower-within-an-organization/</guid><description>The definition of the word ownership has varying meanings across organizations, but there is always a group that retains control of the technology. It’s typically the group that sponsored the adoption of the technology and owns day-to-day support of it. But, sometimes, the technology initiative…</description><pubDate>Tue, 08 May 2012 00:36:00 GMT</pubDate><category>datapower</category><category>career</category><category>infrastructure</category><category>networking</category><category>security</category></item><item><title>DataPower and Terminal Servers…</title><link>https://iyasec.io/blog/datapower-and-terminal-servers/</link><guid isPermaLink="true">https://iyasec.io/blog/datapower-and-terminal-servers/</guid><description>DataPower has a serial port console that is used during initial bootstrap of the appliance, recovering from problems, and certain configuration changes. Having access to the serial console is the only feasible approach to resolving certain issues that arise with any appliance (or piece of network…</description><pubDate>Sun, 06 May 2012 00:27:00 GMT</pubDate><category>datapower</category><category>infrastructure</category><category>networking</category></item><item><title>WebSphere DataPower Roles and Responsibilities…</title><link>https://iyasec.io/blog/websphere-datapower-roles-and-responsibilities/</link><guid isPermaLink="true">https://iyasec.io/blog/websphere-datapower-roles-and-responsibilities/</guid><description>DataPower is a weird (but, wonderful) beast. It has a tendency to break some of the traditional IT silos that develop within infrastructure groups. That can lead to a lot of friction and amusing arguments in which everyone is simply talking past one another. In this post, I want to describe the…</description><pubDate>Fri, 04 May 2012 03:56:00 GMT</pubDate><category>datapower</category><category>websphere</category><category>career</category><category>infrastructure</category><category>java</category></item><item><title>Three Internal Architectures—Designs for DataPower Deployments</title><link>https://iyasec.io/blog/three-internal-architectures-designs-for-datapower-deployments/</link><guid isPermaLink="true">https://iyasec.io/blog/three-internal-architectures-designs-for-datapower-deployments/</guid><description>I have been in several different shops that are either deploying DataPower or are a few years after deploying DataPower. I’ve also had opportunities to talk to numerous different DataPower technical resources about how they have utilized DataPower. In the post, I want to describe what I’ve seen as…</description><pubDate>Thu, 03 May 2012 03:03:00 GMT</pubDate><category>datapower</category><category>security-architecture</category><category>soa</category></item><item><title>OSI 7-Layer Network Model</title><link>https://iyasec.io/blog/osi-7-layer-network-model/</link><guid isPermaLink="true">https://iyasec.io/blog/osi-7-layer-network-model/</guid><description>I’ve been playing with Cisco switches and routers recently at home to get a handle on VLANs-more about VLANs later. Some people I know who have gotten involved in DataPower started out in system administration or networking and worked their way up the technology stack to SOA Appliances (WebSphere…</description><pubDate>Tue, 01 May 2012 02:37:00 GMT</pubDate><category>datapower</category><category>protocols</category><category>soa</category><category>websphere</category><category>java</category><category>networking</category></item><item><title>Symmetric Keys—Addendum</title><link>https://iyasec.io/blog/symmetric-keys-addendum/</link><guid isPermaLink="true">https://iyasec.io/blog/symmetric-keys-addendum/</guid><description>A couple of weeks ago I wrote a brief post about how to generate symmetric keys that can be used with DataPower. It demonstrates how to generate shared keys of various lengths using the Unix dd command. Today, someone asked how a shared key (or symmetric key) can be generated using the openssl…</description><pubDate>Tue, 24 Apr 2012 22:50:00 GMT</pubDate><category>aes</category><category>datapower</category><category>key-management</category><category>tls</category><category>cryptography</category><category>security</category></item><item><title>SSL Handshake—The Visual</title><link>https://iyasec.io/blog/ssl-handshake-the-visual/</link><guid isPermaLink="true">https://iyasec.io/blog/ssl-handshake-the-visual/</guid><description>This is an old picture that I made for a 2010 JBoss World security presentation. It came in handy not so long ago when I was explaining the SSL Handshake to someone.</description><pubDate>Mon, 23 Apr 2012 23:23:00 GMT</pubDate><category>jboss</category><category>pki</category><category>tls</category><category>cryptography</category><category>java</category><category>security</category></item><item><title>IBM Impact 2012 Client Panel: Experiences with IBM SOA Stack Rollout</title><link>https://iyasec.io/blog/ibm-impact-2012-client-panel-experiences-with-ibm-soa-stack-rollout/</link><guid isPermaLink="true">https://iyasec.io/blog/ibm-impact-2012-client-panel-experiences-with-ibm-soa-stack-rollout/</guid><description>I will be leading a discussion panel at IBM Impact 2012 in Las Vegas on Monday, April 30th, 3:45-4pm. More information can be found here. It will be an open ended discussion and Q&amp;A session detailing experiences rolling out IBM technology for an ESB. I’ve done this at a couple of different…</description><pubDate>Sun, 22 Apr 2012 21:02:00 GMT</pubDate><category>datapower</category><category>esb</category><category>soa</category><category>speaking</category><category>integration</category></item><item><title>DataPower Extension Functions and Elements</title><link>https://iyasec.io/blog/datapower-extension-functions-and-elements/</link><guid isPermaLink="true">https://iyasec.io/blog/datapower-extension-functions-and-elements/</guid><description>Anyone who has spent time working with DataPower has had to write an XSLT stylesheet at some point. DataPower provides a library of functions and elements that provide access to various DataPower functionality.</description><pubDate>Thu, 19 Apr 2012 02:34:00 GMT</pubDate><category>datapower</category><category>xslt</category><category>xml</category></item><item><title>XSLT &amp; XPath</title><link>https://iyasec.io/blog/xslt-xpath/</link><guid isPermaLink="true">https://iyasec.io/blog/xslt-xpath/</guid><description>XSLT is the only scripting language supported by WebSphere DataPower appliances. It is the only way to customize DataPower functionality and behavior. So, anyone that works with DataPower for a while will sooner be writing XSLT stylesheets.</description><pubDate>Wed, 18 Apr 2012 02:32:00 GMT</pubDate><category>datapower</category><category>quantum-computing</category><category>websphere</category><category>xslt</category><category>xml</category><category>java</category></item><item><title>Sample Stylesheet—Starting Point</title><link>https://iyasec.io/blog/sample-stylesheet-starting-point/</link><guid isPermaLink="true">https://iyasec.io/blog/sample-stylesheet-starting-point/</guid><description>I often have to go back and look up these details; so, I decided to post a standard starting point for a new stylesheet.</description><pubDate>Tue, 17 Apr 2012 02:33:00 GMT</pubDate><category>datapower</category><category>xslt</category><category>xml</category></item><item><title>Protocol Transformations</title><link>https://iyasec.io/blog/protocol-transformations/</link><guid isPermaLink="true">https://iyasec.io/blog/protocol-transformations/</guid><description>Previously, I wrote a Wire Protocols post that outlined the common protocols that I’ve encountered when working with ESBs and SOA technology-especially DataPower. A primary function of an ESB is to provide the ability to convert service requests between these different protocols in a mostly…</description><pubDate>Fri, 13 Apr 2012 01:44:00 GMT</pubDate><category>datapower</category><category>protocols</category><category>soa</category><category>tls</category><category>http</category><category>integration</category></item><item><title>Privacy Policy</title><link>https://iyasec.io/blog/privacy-policy/</link><guid isPermaLink="true">https://iyasec.io/blog/privacy-policy/</guid><description>I just added a Privacy Policy to ThinkMiddleware.com.</description><pubDate>Thu, 12 Apr 2012 01:45:17 GMT</pubDate><category>site-news</category><category>privacy</category><category>integration</category></item><item><title>What is a Web Service? What is a Service?</title><link>https://iyasec.io/blog/what-is-a-web-service-what-is-a-service/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-a-web-service-what-is-a-service/</guid><description>I have watched this debate unfold at every client site I have visited in the past few years. There are several angles to this question. From a technical stand point, a service is a program that takes some type of input, performs a task, and return some type of output. This is vague. It can describe…</description><pubDate>Wed, 04 Apr 2012 03:33:00 GMT</pubDate><category>rest</category><category>soa</category><category>soap</category><category>web-services</category></item><item><title>Generating and Uploading a Shared Key (Symmetric Key) to DataPower Appliances</title><link>https://iyasec.io/blog/generating-and-uploading-a-shared-key-symmetric-key-to-datapower-appliances/</link><guid isPermaLink="true">https://iyasec.io/blog/generating-and-uploading-a-shared-key-symmetric-key-to-datapower-appliances/</guid><description>DataPower does not seem to provide a tool to generate a Shared Key that can be used with 3DES or AES algorithms. DataPower does provide a tool for generating X509 private keys, certificate requests, and self-signed certificates-in the Crypto Tools section-but we are concerned with Shared Keys…</description><pubDate>Sun, 18 Mar 2012 01:16:00 GMT</pubDate><category>aes</category><category>datapower</category><category>key-management</category><category>pki</category><category>tls</category><category>cryptography</category></item><item><title>Service Mediation vs. Service Orchestration</title><link>https://iyasec.io/blog/service-mediation-vs-service-orchestration/</link><guid isPermaLink="true">https://iyasec.io/blog/service-mediation-vs-service-orchestration/</guid><description>I’ve wanted to define this term for a while, but, someone beat me to it several years ago. I generally agree with what these guys have to say. These terms are still in use today at client sites where DataPower and the IBM SOA stack is being deployed. Service Mediation logic is the application of…</description><pubDate>Sun, 11 Mar 2012 01:24:00 GMT</pubDate><category>datapower</category><category>soa</category><category>web-services</category><category>integration</category></item><item><title>Data Transformations</title><link>https://iyasec.io/blog/data-transformations/</link><guid isPermaLink="true">https://iyasec.io/blog/data-transformations/</guid><description>In a previous post, I described the different types of Data Formats that are commonly used with ESBs, XML Gateways, and SOA. Converting from one format to another is a common task performed by an ESB or XML Gateway. One can make arguments either way about whether this functionality should exist in…</description><pubDate>Sun, 04 Mar 2012 01:38:00 GMT</pubDate><category>datapower</category><category>esb</category><category>protocols</category><category>soa</category><category>xml</category><category>integration</category></item><item><title>Data Formats</title><link>https://iyasec.io/blog/data-formats/</link><guid isPermaLink="true">https://iyasec.io/blog/data-formats/</guid><description>To follow up on the Wire Protocol post, the next logical step in our SOA exploration is Data Formats. A web service message’s Data Format describes how the data is organized in the message.</description><pubDate>Sun, 26 Feb 2012 02:10:00 GMT</pubDate><category>datapower</category><category>protocols</category><category>soa</category><category>web-services</category><category>integration</category></item><item><title>Wire Protocols</title><link>https://iyasec.io/blog/wire-protocols/</link><guid isPermaLink="true">https://iyasec.io/blog/wire-protocols/</guid><description>Like so much of our computer industry, the ecosystem around SOA has many acronyms, buzzwords, and phrases that are supposed to mean something. Likewise, this jargon may be poorly defined or ambiguous. The posts that I have made over the past few months are slowly building up a common vocabulary…</description><pubDate>Sat, 18 Feb 2012 23:15:00 GMT</pubDate><category>esb</category><category>protocols</category><category>soa</category><category>web-services</category><category>http</category></item><item><title>Recommended Reading Material for SOA</title><link>https://iyasec.io/blog/recommended-reading-material-for-soa/</link><guid isPermaLink="true">https://iyasec.io/blog/recommended-reading-material-for-soa/</guid><description>Following up on the recommended reading lists I’ve posted recently, this post contains a list of the books and specifications that I direct people to about SOA.</description><pubDate>Sun, 12 Feb 2012 01:59:00 GMT</pubDate><category>datapower</category><category>reading-list</category><category>security-architecture</category><category>soa</category><category>web-services</category></item><item><title>SOA Security Reading Material</title><link>https://iyasec.io/blog/soa-security-reading-material/</link><guid isPermaLink="true">https://iyasec.io/blog/soa-security-reading-material/</guid><description>At nearly every client site, I’m asked to put together a recommended reading list on a variety of subjects. Web Services security is generally among them. SO, I’m putting together a list of the links that usually make it on that list.</description><pubDate>Sun, 05 Feb 2012 01:34:00 GMT</pubDate><category>aes</category><category>reading-list</category><category>soa</category><category>web-services</category><category>cryptography</category><category>security</category></item><item><title>SOA Actors</title><link>https://iyasec.io/blog/soa-actors/</link><guid isPermaLink="true">https://iyasec.io/blog/soa-actors/</guid><description>When I am describing complex SOA or Web Service architectures, environments, and scenarios to clients, I often use the term “SOA Actors” to generically refer to components of such environments in the abstract. I will often do the same on Thinkmiddleware.com posts. Here, I define what I mean by this…</description><pubDate>Sun, 29 Jan 2012 04:18:00 GMT</pubDate><category>environments</category><category>esb</category><category>soa</category><category>web-services</category><category>integration</category></item><item><title>What is a Service Consumer?</title><link>https://iyasec.io/blog/what-is-a-service-consumer/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-a-service-consumer/</guid><description>A Service Consumer is any tier of an organization’s systems that calls web services. These services could be implemented by SOAP, REST, XML over HTTP, EJBs, JMS or MQ applications, RMI, RPC, invocation of COBOL programs on a mainframe with 3270 screen-scraping, communication over a custom TCP…</description><pubDate>Sun, 22 Jan 2012 04:17:00 GMT</pubDate><category>rest</category><category>soa</category><category>soap</category><category>web-services</category><category>http</category><category>standards</category></item><item><title>What is a Service Provider?</title><link>https://iyasec.io/blog/what-is-a-service-provider/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-a-service-provider/</guid><description>A Service Provider is any tier or system in an organization’s environment that hosts web services (or services of any kind).</description><pubDate>Sun, 15 Jan 2012 04:16:00 GMT</pubDate><category>soa</category><category>web-services</category></item><item><title>What is an ESB?</title><link>https://iyasec.io/blog/what-is-an-esb/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-an-esb/</guid><description>In the past year, I have stood in a conference room at more than one client fielding a question along the lines of exactly what is an ESB? I’ve found that there is a wide variety of impressions about what exactly makes something an ESB. I’m hardly the first person to post something on the Internet…</description><pubDate>Sun, 08 Jan 2012 04:16:00 GMT</pubDate><category>esb</category><category>security-architecture</category><category>web-services</category></item><item><title>What Is A SOAP Web Service?</title><link>https://iyasec.io/blog/what-is-a-soap-web-service/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-a-soap-web-service/</guid><description>A SOAP Web Service is any web service that is compliant with the SOAP 1.1 or SOAP 1.2 specs. When referring to a SOAP Web Service we will use the capitalized Web Service. This convention is followed by most publications within the industry.</description><pubDate>Thu, 05 Jan 2012 01:32:00 GMT</pubDate><category>soa</category><category>soap</category><category>web-services</category></item><item><title>What is a Web Service? What is a web service?</title><link>https://iyasec.io/blog/what-is-a-web-service-what-is-a-web-service/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-a-web-service-what-is-a-web-service/</guid><description>This one has probably been addressed many times. But, I needed a place to link to whenever it comes up in other posts. For our purposes, a Web Service is SOAP Web Service and a web service is anything acting as a web service in the generic sense.</description><pubDate>Thu, 05 Jan 2012 01:32:00 GMT</pubDate><category>soa</category><category>soap</category><category>web-services</category><category>standards</category></item><item><title>What Is A REST Web Service?</title><link>https://iyasec.io/blog/what-is-a-rest-web-service/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-a-rest-web-service/</guid><description>REST web services are not nearly as formalized as their SOAP equivalent. A REST web service adheres to the principals laid out in Roy Fielding’s PhD Thesis. REST stands for Representational State Transition.</description><pubDate>Thu, 05 Jan 2012 01:31:00 GMT</pubDate><category>rest</category><category>soap</category><category>web-services</category><category>standards</category></item><item><title>What is an XML Gateway?</title><link>https://iyasec.io/blog/what-is-an-xml-gateway/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-an-xml-gateway/</guid><description>An XML Gateway is an externally-facing DMZ tier of a web services platform. Generally, this DMZ tier will be facing the Internet, but it may simply be between business units or facing a leased line connecting one entity to another. It can be implemented using a software solution (such as web…</description><pubDate>Sun, 01 Jan 2012 04:15:00 GMT</pubDate><category>datapower</category><category>network-security</category><category>soa</category><category>web-services</category><category>xml</category><category>security</category></item><item><title>What is an Appliance? What is a SOA Appliance?</title><link>https://iyasec.io/blog/what-is-an-appliance-what-is-a-soa-appliance/</link><guid isPermaLink="true">https://iyasec.io/blog/what-is-an-appliance-what-is-a-soa-appliance/</guid><description>I suppose I’m switching gears a bit here back towards something almost philosophical rather than my usual concrete technical info So be it. In the last six months, I’ve been at several clients sites that are using SOA appliances to build XML Gateway and ESB patterns. I answer quite a few client…</description><pubDate>Sun, 25 Dec 2011 02:31:00 GMT</pubDate><category>assembly</category><category>datapower</category><category>esb</category><category>soa</category><category>xml</category><category>networking</category></item><item><title>JVM Heap &amp; GC Tuning…</title><link>https://iyasec.io/blog/jvm-heap-gc-tuning/</link><guid isPermaLink="true">https://iyasec.io/blog/jvm-heap-gc-tuning/</guid><description>So, obviously, I haven’t posted anything here in a while🙂. Life has been busy. Starting several months ago, I left my job of four years and began independent consulting. Among other things, this means that the variety of topics discussed on thinkmiddleware.com should be more varied. I’m also going…</description><pubDate>Mon, 10 Oct 2011 02:53:08 GMT</pubDate><category>garbage-collection</category><category>jvm</category><category>memory-management</category><category>integration</category><category>java</category></item><item><title>IBM Announced the New XG45 DataPower appliance</title><link>https://iyasec.io/blog/ibm-announced-the-new-xg45-datapower-appliance/</link><guid isPermaLink="true">https://iyasec.io/blog/ibm-announced-the-new-xg45-datapower-appliance/</guid><description>This is the first post on thinkmiddleware.com where we discuss DataPower. Guess what I’ve been doing with my career lately🙂.</description><pubDate>Thu, 06 Oct 2011 03:18:00 GMT</pubDate><category>datapower</category><category>soa</category><category>integration</category><category>security</category></item><item><title>JBoss 4.x and DataSource Configuration</title><link>https://iyasec.io/blog/jboss-4-x-and-datasource-configuration/</link><guid isPermaLink="true">https://iyasec.io/blog/jboss-4-x-and-datasource-configuration/</guid><description>On JBoss 4.x, a MySQL datasource looks something like:</description><pubDate>Sun, 12 Jun 2011 01:14:40 GMT</pubDate><category>data-security</category><category>j2ee</category><category>jboss</category><category>java</category></item><item><title>Secure Identity Propagation using WS-Trust, WS-Security, and SAML2 — IBM Impact, 2011 Session</title><link>https://iyasec.io/blog/secure-identity-propagation-using-ws-trust-ws-security-and-saml2-ibm-impact/</link><guid isPermaLink="true">https://iyasec.io/blog/secure-identity-propagation-using-ws-trust-ws-security-and-saml2-ibm-impact/</guid><description>On April 13th, 2011, Ryan Triplett and I spoke at IBM Impact in Las Vegas. The topic was “Secure Identity Propagation using WS-Trust, WS-Security, and SAML2“. The PowerPoint presentation can be found here. The original abstract:</description><pubDate>Sat, 16 Apr 2011 06:07:05 GMT</pubDate><category>saml</category><category>speaking</category><category>ws-security</category><category>ws-trust</category><category>identity</category><category>security</category></item><item><title>Secure Identity Propagation using WS-Trust, WS-Security, and SAML2</title><link>https://iyasec.io/blog/secure-identity-propagation-using-ws-trust-ws-security-and-saml2/</link><guid isPermaLink="true">https://iyasec.io/blog/secure-identity-propagation-using-ws-trust-ws-security-and-saml2/</guid><description>I gave the following presentation at IBM Impact in April, 2011.</description><pubDate>Sat, 16 Apr 2011 00:01:00 GMT</pubDate><category>saml</category><category>soa</category><category>speaking</category><category>web-services</category><category>ws-security</category><category>security</category></item><item><title>HTTP Client – Form-Based Authentication</title><link>https://iyasec.io/blog/http-client-form-based-authentication/</link><guid isPermaLink="true">https://iyasec.io/blog/http-client-form-based-authentication/</guid><description>This article continues the discussion started in the Servlet Authentication article. Here we discuss Form-Based authentication; another common form of authentication when Servlet technology is used.</description><pubDate>Sat, 11 Sep 2010 23:48:09 GMT</pubDate><category>authentication</category><category>j2ee</category><category>http</category><category>java</category><category>security</category></item><item><title>Servlet Container Authentication</title><link>https://iyasec.io/blog/servlet-container-authentication/</link><guid isPermaLink="true">https://iyasec.io/blog/servlet-container-authentication/</guid><description>There are three required authentication mechanisms supported by a compliant Servlet Container: HTTP Basic Authentication, Form-based Authentication, and CLIENT_CERT authentication. There is a fourth authentication method, DIGEST, that isn’t used very often in my experience. This final…</description><pubDate>Sat, 11 Sep 2010 23:20:40 GMT</pubDate><category>authentication</category><category>j2ee</category><category>http</category><category>java</category><category>security</category></item><item><title>Summary of J2EE Specs</title><link>https://iyasec.io/blog/summary-of-j2ee-specs/</link><guid isPermaLink="true">https://iyasec.io/blog/summary-of-j2ee-specs/</guid><description>If you were ever looking for a summary of each version of the J2EE Spec, it can take a few minutes to find it. So, here is a summary. The J2EE Specification is actually collection of numerous different Java-based technology specifications.</description><pubDate>Sat, 11 Sep 2010 22:58:22 GMT</pubDate><category>j2ee</category><category>standards</category><category>java</category></item><item><title>JBossWorld 2010 Session — Securing JBoss Services</title><link>https://iyasec.io/blog/jbossworld-2010-session-securing-jboss-services/</link><guid isPermaLink="true">https://iyasec.io/blog/jbossworld-2010-session-securing-jboss-services/</guid><description>On June 24, 2010, I gave a presentation at JBoss World in Boston. This was my second time at JBoss World. The presentation covered Securing JBoss Services. It explored the use of JaasSecurityDomain MBeans to configure SSL in JBoss 4.3 (also relevent for newer versions of JBoss) for various…</description><pubDate>Thu, 01 Jul 2010 21:18:00 GMT</pubDate><category>jboss</category><category>pki</category><category>speaking</category><category>tls</category><category>java</category><category>security</category></item><item><title>JAX-WS Example With JBossWS – Server-Side</title><link>https://iyasec.io/blog/jax-ws-example-with-jbossws-server-side/</link><guid isPermaLink="true">https://iyasec.io/blog/jax-ws-example-with-jbossws-server-side/</guid><description>In previous article, a very simple Web Application was presented. In any complex environment, there will often be multiple tiers within an application or environments hosting code/services for different teams. A common way of communicating within such environments is through SOAP-based Web Services…</description><pubDate>Tue, 06 Oct 2009 02:40:46 GMT</pubDate><category>environments</category><category>soap</category><category>web-services</category><category>java</category></item><item><title>Running JBoss on an OpenJDK6 build</title><link>https://iyasec.io/blog/running-jboss-on-an-openjdk6-build/</link><guid isPermaLink="true">https://iyasec.io/blog/running-jboss-on-an-openjdk6-build/</guid><description>Recently, I had some free time and set out to bring up JBoss on OpenJDK6. In particular, I wanted to Run JBoss on an OpenJDK build that I personally compiled.</description><pubDate>Mon, 31 Aug 2009 03:58:07 GMT</pubDate><category>jboss</category><category>jvm</category><category>java</category></item><item><title>J2EE Security Series</title><link>https://iyasec.io/blog/j2ee-security-series/</link><guid isPermaLink="true">https://iyasec.io/blog/j2ee-security-series/</guid><description>An Openldap Directory Server JBoss 4.3.x Setup Adding Groups To OpenLdap Using OpenLdap as a User Repository with JBoss 4.3.x</description><pubDate>Wed, 26 Aug 2009 17:27:58 GMT</pubDate><category>j2ee</category><category>jboss</category><category>ldap</category><category>series</category><category>java</category><category>security</category></item><item><title>Securing The JBoss JAAS Subject Reader Application with J2EE Security</title><link>https://iyasec.io/blog/securing-the-jboss-jaas-subject-reader-application-with-j2ee-security/</link><guid isPermaLink="true">https://iyasec.io/blog/securing-the-jboss-jaas-subject-reader-application-with-j2ee-security/</guid><description>This article continues the J2EE Security Series from the past few months. Here we expand the Simple J2EE Web Application that was introduced in this article to use J2EE Security.</description><pubDate>Tue, 25 Aug 2009 20:03:54 GMT</pubDate><category>j2ee</category><category>jaas</category><category>jboss</category><category>java</category><category>security</category></item><item><title>HTTP(S) URLs &amp; Context Roots</title><link>https://iyasec.io/blog/http-s-urls-context-roots/</link><guid isPermaLink="true">https://iyasec.io/blog/http-s-urls-context-roots/</guid><description>What is a URL? What is a context root? It’s helpful to understand these things when writing or working with web applications.</description><pubDate>Tue, 25 Aug 2009 18:39:56 GMT</pubDate><category>http</category><category>networking</category></item><item><title>A Simple Web Application</title><link>https://iyasec.io/blog/a-simple-web-application/</link><guid isPermaLink="true">https://iyasec.io/blog/a-simple-web-application/</guid><description>In order to test J2EE Security with the Security Realm and Openldap User Repository we created in the last article in this series, we need an application to protect. The focus of this article is to create a very simple web application that can be protected by J2EE Security.</description><pubDate>Tue, 25 Aug 2009 17:08:31 GMT</pubDate><category>j2ee</category><category>ldap</category><category>java</category><category>security</category></item><item><title>J2EE Security</title><link>https://iyasec.io/blog/j2ee-security/</link><guid isPermaLink="true">https://iyasec.io/blog/j2ee-security/</guid><description>The article continues the series discussing J2EE Security and its related concepts. The following brings together the numerous concepts discussed in the past articles.</description><pubDate>Mon, 15 Jun 2009 02:03:09 GMT</pubDate><category>j2ee</category><category>java</category><category>security</category></item><item><title>Role Mapping &amp; J2EE Security</title><link>https://iyasec.io/blog/role-mapping-j2ee-security/</link><guid isPermaLink="true">https://iyasec.io/blog/role-mapping-j2ee-security/</guid><description>The discussion of J2EE Security on the JBoss Application Server continues as Role Mapping is introduced.</description><pubDate>Mon, 15 Jun 2009 01:47:35 GMT</pubDate><category>j2ee</category><category>jboss</category><category>java</category><category>security</category></item><item><title>Using OpenLdap as a User Repository with JBoss 4.3.x</title><link>https://iyasec.io/blog/using-openldap-as-a-user-repository-with-jboss-4-3-x/</link><guid isPermaLink="true">https://iyasec.io/blog/using-openldap-as-a-user-repository-with-jboss-4-3-x/</guid><description>This article continues our discussion of setting up J2EE Security in a JBoss 4.3.x container. In the last article, we completed the setup of an OpenLdap database that can be used as a User Repository.</description><pubDate>Mon, 15 Jun 2009 01:42:14 GMT</pubDate><category>j2ee</category><category>jboss</category><category>ldap</category><category>java</category><category>security</category></item><item><title>Adding Groups To OpenLdap</title><link>https://iyasec.io/blog/adding-groups-to-openldap/</link><guid isPermaLink="true">https://iyasec.io/blog/adding-groups-to-openldap/</guid><description>This article describes how to setup an OpenLdap server and add inetperson user objects. However, the article didn’t describe how to add groups to OpenLdap and add users to the groups.</description><pubDate>Mon, 15 Jun 2009 00:46:36 GMT</pubDate><category>j2ee</category><category>ldap</category><category>infrastructure</category><category>security</category></item><item><title>URL &amp; HTML Character Representation</title><link>https://iyasec.io/blog/url-html-character-representation/</link><guid isPermaLink="true">https://iyasec.io/blog/url-html-character-representation/</guid><description>I’ve had to look up the HTML codes for special characters like space many times. In fact, while writing blog entries for Thinkmiddleware.com, I’ve had to stop and look up the HTML code for less-than sign and greater-than sign one to many times. I just haven’t bothered memorizing them.</description><pubDate>Wed, 13 May 2009 14:08:27 GMT</pubDate><category>jvm</category><category>web-application-security</category><category>http</category><category>integration</category></item><item><title>JBoss 4.3.X Setup</title><link>https://iyasec.io/blog/jboss-4-3-x-setup/</link><guid isPermaLink="true">https://iyasec.io/blog/jboss-4-3-x-setup/</guid><description>This article explains how to install and start the JBoss “default” server.</description><pubDate>Sun, 26 Apr 2009 11:37:39 GMT</pubDate><category>jboss</category><category>infrastructure</category><category>java</category></item><item><title>Capturing Network Communication Between Two Processes On the Same Machine…</title><link>https://iyasec.io/blog/capturing-network-communication-between-two-processes-on-the-same-machine/</link><guid isPermaLink="true">https://iyasec.io/blog/capturing-network-communication-between-two-processes-on-the-same-machine/</guid><description>Have you ever run snoop on Solaris or tcpdump on Linux or AIX and discovered that these tools cannot capture IP-based communication that occurs between two processes on the same machine? Or, Wireshark (formerly, Ethereal) on Windows? Only to discover the same limitation?</description><pubDate>Tue, 07 Apr 2009 18:14:57 GMT</pubDate><category>linux</category><category>troubleshooting</category><category>operating-systems</category><category>java</category><category>networking</category></item><item><title>Capturing JVM TCP Traffic</title><link>https://iyasec.io/blog/capturing-jvm-tcp-traffic/</link><guid isPermaLink="true">https://iyasec.io/blog/capturing-jvm-tcp-traffic/</guid><description>Any time you have a distributed application, there is network communication involved. Capturing this network traffic can be instrumental in diagnosing and solving problems. Generally, to capturing network traffic, superuser privledges, timing, and a bit of luck is needed. Often, the appropriate…</description><pubDate>Fri, 03 Apr 2009 23:38:19 GMT</pubDate><category>debugging</category><category>jvm</category><category>troubleshooting</category><category>java</category><category>networking</category></item><item><title>Websphere v6.x Classloaders</title><link>https://iyasec.io/blog/websphere-v6-x-classloaders/</link><guid isPermaLink="true">https://iyasec.io/blog/websphere-v6-x-classloaders/</guid><description>Building on the ideas introduced in the last article, a J2EE Application servers classloaders are explored in this installment. In particular, Websphere Application Server v.6.x Classloaders are introduced. The J2EE Spec provides some guidance regarding J2EE Application Servers, but as with so many…</description><pubDate>Sat, 21 Feb 2009 23:47:07 GMT</pubDate><category>classloaders</category><category>j2ee</category><category>jvm</category><category>troubleshooting</category><category>websphere</category><category>java</category></item><item><title>JEE 6 Draft Proposal Is Available For Public Review</title><link>https://iyasec.io/blog/jee-6-draft-proposal-is-available-for-public-review/</link><guid isPermaLink="true">https://iyasec.io/blog/jee-6-draft-proposal-is-available-for-public-review/</guid><description>Check out JSR 316 and this article. There is also a Slashdot.org thread on the subject.</description><pubDate>Sun, 01 Feb 2009 03:36:37 GMT</pubDate><category>concurrency</category><category>j2ee</category><category>standards</category><category>java</category></item><item><title>Java Virtual Machine Classloaders</title><link>https://iyasec.io/blog/java-virtual-machine-classloaders/</link><guid isPermaLink="true">https://iyasec.io/blog/java-virtual-machine-classloaders/</guid><description>Classloaders are responsible for finding and loading classes that are requested in Java code executed inside a Java Virtual Machine. Classloader-related issues are among the most difficult to troubleshoot in the Java/J2EE technology stack.</description><pubDate>Mon, 19 Jan 2009 04:50:57 GMT</pubDate><category>classloaders</category><category>j2ee</category><category>jvm</category><category>security-architecture</category><category>troubleshooting</category><category>java</category></item><item><title>Site Maintenance — Clean Up</title><link>https://iyasec.io/blog/site-maintenance-clean-up/</link><guid isPermaLink="true">https://iyasec.io/blog/site-maintenance-clean-up/</guid><description>The older articles predating the use of WordPress are slowly being copied over to the WordPress format. This provides a common look &amp; feel and allows WordPress seach functionality, RSS feeds, and other goodies to work properly with the older content.</description><pubDate>Sun, 11 Jan 2009 01:40:55 GMT</pubDate><category>site-news</category></item><item><title>Computer Measurement Prefixes and Number Naming Conventions</title><link>https://iyasec.io/blog/computer-measurement-prefixes-and-number-naming-conventions/</link><guid isPermaLink="true">https://iyasec.io/blog/computer-measurement-prefixes-and-number-naming-conventions/</guid><description>I always forget the quantity prefixes above “tera”. Even more interestingly, one rarely thinks about the numbers’ names. For example, consider the number</description><pubDate>Sat, 10 Jan 2009 12:02:54 GMT</pubDate><category>jvm</category><category>infrastructure</category></item><item><title>JVM process Virtual Memory Usage (Resident Set Size) On A Linux 2.6.25 Kernel</title><link>https://iyasec.io/blog/jvm-process-virtual-memory-usage-resident-set-size-on-a-linux-2/</link><guid isPermaLink="true">https://iyasec.io/blog/jvm-process-virtual-memory-usage-resident-set-size-on-a-linux-2/</guid><description>This article expands on the previous Virtual Memory post by exploring Resident Set Size growth while running a Java program that will consume all available Java Heap memory. Four different JVM implementations are used to compare results of these experiments. These JVMs come from two different…</description><pubDate>Thu, 01 Jan 2009 21:41:04 GMT</pubDate><category>jvm</category><category>linux</category><category>memory-management</category><category>operating-systems</category><category>java</category></item><item><title>Google Browser Security Handbook</title><link>https://iyasec.io/blog/google-browser-security-handbook/</link><guid isPermaLink="true">https://iyasec.io/blog/google-browser-security-handbook/</guid><description>Google has released a Browser Security Handbook online. It can be found here.</description><pubDate>Thu, 01 Jan 2009 18:38:22 GMT</pubDate><category>reading-list</category><category>web-application-security</category><category>security</category></item><item><title>Virtual Memory — Linux</title><link>https://iyasec.io/blog/virtual-memory-linux/</link><guid isPermaLink="true">https://iyasec.io/blog/virtual-memory-linux/</guid><description>It has been a couple of weeks since the last article was published. Recently, I had to dig into Virtual Memory on AIX to work through some issues. I realized there were several details I needed to explore further to understand Virtual Memory implementations. In particular, the implementation…</description><pubDate>Sun, 28 Dec 2008 19:41:55 GMT</pubDate><category>linux</category><category>memory-management</category><category>troubleshooting</category><category>operating-systems</category></item><item><title>Dumping the contents of a JAAS Subject</title><link>https://iyasec.io/blog/dumping-the-contents-of-a-jaas-subject/</link><guid isPermaLink="true">https://iyasec.io/blog/dumping-the-contents-of-a-jaas-subject/</guid><description>In the last article, JAAS was introduced. An authenticated calling-entity (perhaps a user), has a JAAS Subject. This JAAS Subject contains some combination of Principals, Public Credentials, and Private Credentials. It can be very helpful to dump the contents of this JAAS Subject for debugging…</description><pubDate>Sun, 07 Dec 2008 08:07:26 GMT</pubDate><category>authentication</category><category>debugging</category><category>jaas</category><category>java</category><category>security</category></item><item><title>JAAS Authentication — An Introduction</title><link>https://iyasec.io/blog/jaas-authentication-an-introduction/</link><guid isPermaLink="true">https://iyasec.io/blog/jaas-authentication-an-introduction/</guid><description>This article introduces JAAS authentication via a relatively simple example. The example presented here is based upon the Sun tutorial of the same subject. The thinkmiddleware.com example extends the tutorial to use LDAP to authenticate users.</description><pubDate>Sun, 30 Nov 2008 08:31:19 GMT</pubDate><category>authentication</category><category>j2ee</category><category>jaas</category><category>ldap</category><category>java</category><category>security</category></item><item><title>An Openldap Directory Server</title><link>https://iyasec.io/blog/an-openldap-directory-server/</link><guid isPermaLink="true">https://iyasec.io/blog/an-openldap-directory-server/</guid><description>The recent JNDI article and an upcoming JAAS article require an LDAP server. This tutorial will walk through the basic details of reproducing the Openldap Server used in these two articles.</description><pubDate>Sat, 29 Nov 2008 10:02:33 GMT</pubDate><category>j2ee</category><category>jaas</category><category>ldap</category><category>java</category><category>security</category></item><item><title>JNDI — Java Naming &amp; Directory Interface</title><link>https://iyasec.io/blog/jndi-java-naming-directory-interface/</link><guid isPermaLink="true">https://iyasec.io/blog/jndi-java-naming-directory-interface/</guid><description>While researching an upcoming JAAS article, the decision was made to use JNDI to interact with the Openldap server that was stored user information. JNDI is used extensively in the J2EE landscape; so, exploring JNDI separately from JAAS seemed in order.</description><pubDate>Wed, 26 Nov 2008 23:34:15 GMT</pubDate><category>j2ee</category><category>jaas</category><category>ldap</category><category>java</category><category>security</category></item><item><title>Ant — Build Control</title><link>https://iyasec.io/blog/ant-build-control/</link><guid isPermaLink="true">https://iyasec.io/blog/ant-build-control/</guid><description>I’ve mentioned that for larger projects/examples on thinkmiddleware.com, Ant would be used. The Java Security Manager article was the first time it was used. Although, the full details of the source code were not included, Ant was used.</description><pubDate>Sat, 22 Nov 2008 19:57:26 GMT</pubDate><category>integration</category><category>java</category><category>security</category></item><item><title>The Java Security Manager</title><link>https://iyasec.io/blog/the-java-security-manager/</link><guid isPermaLink="true">https://iyasec.io/blog/the-java-security-manager/</guid><description>In the last post, the Java Standard Edition and Java Enterprise Edition security features were introduced. This is the second in a series of articles that introduces each Java security feature in depth. This article introduces the Java Security Manager and the sandbox it creates for a Java…</description><pubDate>Sat, 15 Nov 2008 13:16:06 GMT</pubDate><category>jvm</category><category>java</category><category>security</category></item><item><title>Java Security — The Low-Level details To J2EE Security–And, Beyond</title><link>https://iyasec.io/blog/java-security-the-low-level-details-to-j2ee-security-and-beyond/</link><guid isPermaLink="true">https://iyasec.io/blog/java-security-the-low-level-details-to-j2ee-security-and-beyond/</guid><description>While researching details for a Java Security Manager article, it became obvious that I didn’t understand the mappings of all the different Java, security-related specifications to the technologies and acronyms I knew. Thus, was the beginning of this article. Below each security-related feature in…</description><pubDate>Sat, 08 Nov 2008 23:12:26 GMT</pubDate><category>j2ee</category><category>jvm</category><category>java</category><category>security</category></item><item><title>Java Networking API vs. The C library networking API</title><link>https://iyasec.io/blog/java-networking-api-vs-the-c-library-networking-api/</link><guid isPermaLink="true">https://iyasec.io/blog/java-networking-api-vs-the-c-library-networking-api/</guid><description>The original article is located here. In this article, I described what was involved in writing a server program in the C language. The details are not important, but I wanted to compare the details that are exposed in this relatively simple C network programming example with the equivalent Java…</description><pubDate>Sun, 02 Nov 2008 11:15:12 GMT</pubDate><category>c</category><category>career</category><category>java</category><category>networking</category><category>apis</category></item><item><title>Concurrency And Server-Side Networking APIs — Part 4</title><link>https://iyasec.io/blog/concurrency-and-server-side-networking-apis-part-4/</link><guid isPermaLink="true">https://iyasec.io/blog/concurrency-and-server-side-networking-apis-part-4/</guid><description>The original article can be found here. Introduction</description><pubDate>Sat, 01 Nov 2008 00:14:09 GMT</pubDate><category>concurrency</category><category>jvm</category><category>performance</category><category>troubleshooting</category><category>http</category><category>java</category></item><item><title>Concurrency And Server-Side Networking APIs — Part 3</title><link>https://iyasec.io/blog/concurrency-and-server-side-networking-apis-part-3/</link><guid isPermaLink="true">https://iyasec.io/blog/concurrency-and-server-side-networking-apis-part-3/</guid><description>This is part three of an exploration of how concurrency in networking APIs works in Unix-like operating systems and Java technology. This article now looks at the Java equivalents of several C-based server implementations that have been presented. If you haven’t read this series from the beginning,…</description><pubDate>Thu, 30 Oct 2008 18:10:24 GMT</pubDate><category>concurrency</category><category>jvm</category><category>performance</category><category>troubleshooting</category><category>http</category><category>java</category></item><item><title>Concurrency And Server-Side Networking APIs — Part 2</title><link>https://iyasec.io/blog/concurrency-and-server-side-networking-apis-part-2/</link><guid isPermaLink="true">https://iyasec.io/blog/concurrency-and-server-side-networking-apis-part-2/</guid><description>In the second part of this series we continue to explore how Unix-like operating systems implement the networking API and threading API. In particular, we are supremely interested in how the kernel allows server programs accept incoming connections. Part two explores implementing concurrency in…</description><pubDate>Tue, 28 Oct 2008 01:00:45 GMT</pubDate><category>concurrency</category><category>jboss</category><category>jvm</category><category>http</category><category>java</category><category>networking</category></item><item><title>Concurrency And Server-Side Networking APIs — Part 1</title><link>https://iyasec.io/blog/concurrency-and-server-side-networking-apis-part-1/</link><guid isPermaLink="true">https://iyasec.io/blog/concurrency-and-server-side-networking-apis-part-1/</guid><description>This article explores how a Sun Hotspot JVM behaves when accepting incoming TCP/IP socket connections. The behavior of native server programs–written in C–are also explored to better understand how concurrency can be achieved. Then, a comparison of how these runtime environments implement…</description><pubDate>Sun, 26 Oct 2008 23:22:13 GMT</pubDate><category>concurrency</category><category>jvm</category><category>performance</category><category>http</category><category>java</category><category>networking</category></item><item><title>Threads, Threads Everywhere.  And, Not a Needle In Sight</title><link>https://iyasec.io/blog/threads-threads-everywhere-and-not-a-needle-in-sight/</link><guid isPermaLink="true">https://iyasec.io/blog/threads-threads-everywhere-and-not-a-needle-in-sight/</guid><description>Several terms have been used liberally throughout articles on thinkmiddleware.com. A moment should be taken to formally define them. I am going to attempt to present these concepts in as generic a sense as possible, but the truth of the matter is, every OS has its own threading model and…</description><pubDate>Sun, 19 Oct 2008 23:18:46 GMT</pubDate><category>concurrency</category><category>jvm</category><category>performance</category><category>troubleshooting</category><category>integration</category><category>java</category></item><item><title>Mapping An LWP Using Excessive CPU Time To a Java Thread</title><link>https://iyasec.io/blog/mapping-an-lwp-using-excessive-cpu-time-to-a-java-thread/</link><guid isPermaLink="true">https://iyasec.io/blog/mapping-an-lwp-using-excessive-cpu-time-to-a-java-thread/</guid><description>It happens. End users are complaining about a slow system or a request that never returned. You log into a production middleware server and notice that a java process is consuming an entire CPU or worst every available CPU on the box. It has happened again–a thread(s) has gone into an infinite loop…</description><pubDate>Sun, 19 Oct 2008 21:16:50 GMT</pubDate><category>concurrency</category><category>jvm</category><category>troubleshooting</category><category>integration</category><category>java</category></item><item><title>Configure Your JVM For Use With a Remote Debugger</title><link>https://iyasec.io/blog/configure-your-jvm-for-use-with-a-remote-debugger/</link><guid isPermaLink="true">https://iyasec.io/blog/configure-your-jvm-for-use-with-a-remote-debugger/</guid><description>As I’ve pointed out in several previous articles, I like the jdb command line debugger that is available with the Sun JDK. This debugger can actually be used with any spec-compliant JVM. The JPDA specification defines the interfaces and services that are used by remote debuggers and profiles. The…</description><pubDate>Sat, 18 Oct 2008 21:06:11 GMT</pubDate><category>debugging</category><category>jvm</category><category>tools</category><category>infrastructure</category><category>java</category></item><item><title>Generating Thread Dumps</title><link>https://iyasec.io/blog/generating-thread-dumps/</link><guid isPermaLink="true">https://iyasec.io/blog/generating-thread-dumps/</guid><description>Thread dumps are the basic diagnostic tool for JVMs. Thread dumps present a partial state of each Java thread in a running JVM. I say partial because it doesn’t present all information that captures the state of a Java thread. The state of a running Java thread is stored in a series of data…</description><pubDate>Sat, 18 Oct 2008 20:57:13 GMT</pubDate><category>concurrency</category><category>jboss</category><category>jvm</category><category>performance</category><category>troubleshooting</category><category>java</category></item><item><title>My JVM ran out of memory!  What objects are consuming all of the memory?</title><link>https://iyasec.io/blog/my-jvm-ran-out-of-memory-what-objects-are-consuming-all-of/</link><guid isPermaLink="true">https://iyasec.io/blog/my-jvm-ran-out-of-memory-what-objects-are-consuming-all-of/</guid><description>This article isn&apos;t a comprehensive JVM Java heap sizing and garbage collection tuning document; its goal is simply to outline options for identifying which type of Object(s) are consuming the majority of memory in a running JVM--troubleshooting memory leaks in the Java heap. As usual, I focus on…</description><pubDate>Thu, 16 Oct 2008 20:48:56 GMT</pubDate><category>garbage-collection</category><category>jboss</category><category>jvm</category><category>memory-management</category><category>troubleshooting</category><category>java</category></item><item><title>Troubleshooting Deadlock Conditions With Monitor Locks In Java Virtual Machines</title><link>https://iyasec.io/blog/troubleshooting-deadlock-conditions-with-monitor-locks-in-java-virtual-machines/</link><guid isPermaLink="true">https://iyasec.io/blog/troubleshooting-deadlock-conditions-with-monitor-locks-in-java-virtual-machines/</guid><description>In this article, I wanted to present a brief tutorial regarding troubleshooting deadlock conditions in JVMs. Before one can troubleshoot a deadlock condition, one needs to understand what it is; to this end, I have written a simple Java program called DeadLock.java, which is guaranteed to very…</description><pubDate>Tue, 14 Oct 2008 20:48:29 GMT</pubDate><category>concurrency</category><category>jvm</category><category>performance</category><category>troubleshooting</category><category>java</category></item><item><title>The Definition of Reverse Engineering, JVMs, and the Java programming language</title><link>https://iyasec.io/blog/the-definition-of-reverse-engineering-jvms-and-the-java-programming-language/</link><guid isPermaLink="true">https://iyasec.io/blog/the-definition-of-reverse-engineering-jvms-and-the-java-programming-language/</guid><description>I recently had a conversation with a colleague that reminded me of a another discussion with my Masters Project advisor a couple of years ago when I was exploring research topics. The topic under discussion was Reverse Engineering --in particular, Software Reverse Engineering. It sounds really…</description><pubDate>Sun, 12 Oct 2008 20:11:20 GMT</pubDate><category>reverse-engineering</category><category>java</category></item><item><title>EJB vs. Web Services</title><link>https://iyasec.io/blog/ejb-vs-web-services/</link><guid isPermaLink="true">https://iyasec.io/blog/ejb-vs-web-services/</guid><description>This article is by no means an exhaustive discussion on the subject of Web Services and EJBs. But, I have often found many of the points I bring up here missing from meaningful debate. Researching this article also gave me an opportunity to go over material I&apos;ve been wanting to read for a while now.</description><pubDate>Mon, 06 Oct 2008 20:07:51 GMT</pubDate><category>j2ee</category><category>jboss</category><category>performance</category><category>web-services</category><category>websphere</category><category>security</category></item><item><title>The Java Instruction Set, Assemblers, and Disassemblers</title><link>https://iyasec.io/blog/the-java-instruction-set-assemblers-and-disassemblers/</link><guid isPermaLink="true">https://iyasec.io/blog/the-java-instruction-set-assemblers-and-disassemblers/</guid><description>Note: this is another article that I wrote a while ago using a Java Disassembler that no longer seems to be available--d-Java. There are numerous Java Disassemblers on the Internet. Two more that could be used are mentioned in the reference section: Jasper &amp; Kimera. They can produce the Jasmin…</description><pubDate>Sun, 05 Oct 2008 20:03:19 GMT</pubDate><category>assembly</category><category>jvm</category><category>java</category></item><item><title>Generating Thread Dumps from a Sun or IBM JVM Running As A Windows Service</title><link>https://iyasec.io/blog/generating-thread-dumps-from-a-sun-or-ibm-jvm-running-as-a/</link><guid isPermaLink="true">https://iyasec.io/blog/generating-thread-dumps-from-a-sun-or-ibm-jvm-running-as-a/</guid><description>I was recently asked if there was a way to generate a Thread Dump from a JVM running as a Windows Service. It occured to me that I had a similar issue during my Masters Project when I was trying to generate a thread dump from a Cygwin xterm; Googling at the time turned up no good way of accomplishing the task. But, I knew that you could use the Java Debugger that ships with the Sun JDK, jdb, to generate a thread dump of all non-System Threads in a JVM. I posed this as a solution to generating Thread Dumps from a JVM running as a Windows Service.</description><pubDate>Mon, 29 Sep 2008 19:28:10 GMT</pubDate><category>debugging</category><category>jvm</category><category>linux</category><category>troubleshooting</category><category>operating-systems</category><category>java</category></item><item><title>Performance Tuning In Industry</title><link>https://iyasec.io/blog/performance-tuning-in-industry/</link><guid isPermaLink="true">https://iyasec.io/blog/performance-tuning-in-industry/</guid><description>IT Professionals face an up hill battle in the realm of performance tuning. First, management must be convinced that time needs to be set aside for it. Next, the skill sets to successfully move through the performance tuning life cycle must be present. Then, the tools to effectively identify issues…</description><pubDate>Mon, 29 Sep 2008 19:16:15 GMT</pubDate><category>j2ee</category><category>performance</category><category>operating-systems</category><category>java</category></item><item><title>Part 2: Custom Client-Server Java Application That CommunicatesOver A Mutually Authenticated SSL (MASSL) Connection</title><link>https://iyasec.io/blog/part-2-custom-client-server-java-application-that-communicatesover-a-mutually-authenticated/</link><guid isPermaLink="true">https://iyasec.io/blog/part-2-custom-client-server-java-application-that-communicatesover-a-mutually-authenticated/</guid><description>This is the second of a two-part series discussing Java and Mutually Authenticated SSL. This will gave you a taste of how a J2EE container is communicating (over SSL or MASSL) behind the scenes.</description><pubDate>Thu, 11 Sep 2008 19:02:01 GMT</pubDate><category>authentication</category><category>j2ee</category><category>pki</category><category>tls</category><category>java</category><category>security</category></item><item><title>Part 1: Creating your own SSL certificates for a custom Java client-server application</title><link>https://iyasec.io/blog/part-1-creating-your-own-ssl-certificates-for-a-custom-java-client/</link><guid isPermaLink="true">https://iyasec.io/blog/part-1-creating-your-own-ssl-certificates-for-a-custom-java-client/</guid><description>If you replace the steps for creating your own CA private key &amp; certificate and signing your own certificate (with the CA) with having certificates signed by a legitimate Certificate Authority, you&apos;ve got the basic idea behind creating/ordering certs for most situations.</description><pubDate>Wed, 27 Aug 2008 18:09:41 GMT</pubDate><category>key-management</category><category>pki</category><category>tls</category><category>java</category><category>security</category></item><item><title>Achieving highly available HTTP database session persistence spanning multiple cells with Websphere v6.1</title><link>https://iyasec.io/blog/achieving-highly-available-http-database-session-persistence-spanning-multiple-cells-with-websphere/</link><guid isPermaLink="true">https://iyasec.io/blog/achieving-highly-available-http-database-session-persistence-spanning-multiple-cells-with-websphere/</guid><description>Websphere can provide HTTP Session data replication across multiple clusters and cells by using database session persistence.</description><pubDate>Sun, 24 Aug 2008 18:03:48 GMT</pubDate><category>j2ee</category><category>speaking</category><category>websphere</category><category>infrastructure</category><category>java</category><category>apis</category></item><item><title>References I Cited in My Masters Project</title><link>https://iyasec.io/blog/references-i-cited-in-my-masters-project/</link><guid isPermaLink="true">https://iyasec.io/blog/references-i-cited-in-my-masters-project/</guid><description>This week (er, quarter), I wanted to share the references I used while researching my Masters Project. It’s a collection of about fifty web links and books that I found helpful. Reading this stuff and staring at long sequences of numbers represents about eighteen months of my life. More information…</description><pubDate>Fri, 21 Mar 2008 03:13:00 GMT</pubDate><category>reading-list</category><category>speaking</category></item><item><title>These are the references I cited in my Masters Project Defense</title><link>https://iyasec.io/blog/these-are-the-references-i-cited-in-my-masters-project-defense/</link><guid isPermaLink="true">https://iyasec.io/blog/these-are-the-references-i-cited-in-my-masters-project-defense/</guid><description>So, obviously, I haven’t been adding to this site nearly as often as I had hoped. This week (er, quarter), I wanted to share the references I used while researching my Masters Project. It’s a collection of about fifty web links and books that I found helpful. Reading this stuff and staring at long…</description><pubDate>Thu, 20 Mar 2008 06:05:16 GMT</pubDate><category>reading-list</category><category>speaking</category></item><item><title>Masters Project Defense</title><link>https://iyasec.io/blog/masters-project-defense/</link><guid isPermaLink="true">https://iyasec.io/blog/masters-project-defense/</guid><description>On November 29, 2007, I gave my Masters Project Defense before Dr. Chris Gill, Dr. Cindy Grimm, and Dr. Roger Chamberlain. This is the presentation. I’m posting it here because it involved analyzing low-level details of a Sun JVM running JBoss 3.x.</description><pubDate>Sun, 02 Dec 2007 03:11:00 GMT</pubDate><category>j2ee</category><category>jboss</category><category>performance</category><category>speaking</category><category>java</category><category>security</category></item><item><title>Masters Project</title><link>https://iyasec.io/blog/masters-project/</link><guid isPermaLink="true">https://iyasec.io/blog/masters-project/</guid><description>On November 29, 2007, I gave my Masters Project Defense before Dr. Chris Gill, Dr. Cindy Grimm, and Dr. Roger Chamberlain. This is the presentation.</description><pubDate>Sat, 01 Dec 2007 06:03:27 GMT</pubDate><category>speaking</category></item><item><title>Presentation I gave to the CS450 Video Game Programming Class at Wash U on October 12, 2007</title><link>https://iyasec.io/blog/presentation-i-gave-to-the-cs450-video-game-programming-class-at-wash/</link><guid isPermaLink="true">https://iyasec.io/blog/presentation-i-gave-to-the-cs450-video-game-programming-class-at-wash/</guid><description>Here is the presentation.</description><pubDate>Mon, 15 Oct 2007 06:02:22 GMT</pubDate><category>personal</category><category>speaking</category></item><item><title>Flying Over Mars</title><link>https://iyasec.io/blog/flying-over-mars/</link><guid isPermaLink="true">https://iyasec.io/blog/flying-over-mars/</guid><description>I’ve had this one sitting on the shelf for a while. The last semester of my undergraduate program at Wash U., I created a flight simulator program that could be used to view Martian terrtain data. We created this by grabbing a series of still shots while the flight simulator was running.</description><pubDate>Fri, 09 Feb 2007 06:01:36 GMT</pubDate><category>personal</category></item><item><title>The First 1500 Hamming Numbers</title><link>https://iyasec.io/blog/the-first-1500-hamming-numbers/</link><guid isPermaLink="true">https://iyasec.io/blog/the-first-1500-hamming-numbers/</guid><description>I haven’t had a chance to post anything here since the beginning of last semester. I’m in a class at the moment where all of the programming assignments involves annoying little math algorithms. The most recent required us to generate the first N hamming numbers using an efficient algorithm that…</description><pubDate>Tue, 30 Jan 2007 05:59:51 GMT</pubDate><category>jvm</category><category>mathematics</category><category>memory-management</category><category>java</category></item><item><title>JCup &amp; JFlex With Ant</title><link>https://iyasec.io/blog/jcup-jflex-with-ant/</link><guid isPermaLink="true">https://iyasec.io/blog/jcup-jflex-with-ant/</guid><description>I’ve been bogged down in work and school lately. So, it has been a while since I’ve written anything. This semester I’m taking an Instruction Set Architecture course at Wash U–basically, the final project is to design a processor with VHDL in ModelSim. I think I’m going to stick to software.…</description><pubDate>Sat, 18 Nov 2006 03:31:00 GMT</pubDate><category>assembly</category><category>c</category><category>compilers</category><category>personal</category></item><item><title>Using JCup &amp; JFlex with Ant</title><link>https://iyasec.io/blog/using-jcup-jflex-with-ant/</link><guid isPermaLink="true">https://iyasec.io/blog/using-jcup-jflex-with-ant/</guid><description>I’ve been bogged down in work and school lately. So, it has been a while since I’ve written anything. This semester I’m taking an Instruction Set Architecture course at Wash U–basically, the final project is to design a processor with VHDL in ModelSim. I think I’m going to stick to software.…</description><pubDate>Fri, 17 Nov 2006 05:56:33 GMT</pubDate><category>assembly</category><category>c</category><category>compilers</category><category>personal</category></item><item><title>Linux Kernel Modules</title><link>https://iyasec.io/blog/linux-kernel-modules/</link><guid isPermaLink="true">https://iyasec.io/blog/linux-kernel-modules/</guid><description>I’m reading the book Linux Device Drivers to get up to speed on writing Linux modules; I’ll be using this for an upcoming project, if all goes according to plan. This isn’t much, but if you need to get the most basic of kernel modules built, this is what you need to do.</description><pubDate>Sun, 17 Sep 2006 05:58:39 GMT</pubDate><category>linux</category><category>operating-systems</category></item><item><title>Examining the Call Stack with GDB</title><link>https://iyasec.io/blog/examining-the-call-stack-with-gdb/</link><guid isPermaLink="true">https://iyasec.io/blog/examining-the-call-stack-with-gdb/</guid><description>This will be the second Blog entry I’ve made. I need to come up with a fancier welcome and introduction to each of these things. I started the forth semester of CS Masters program at Wash U. last week. I’ve got a lot of reading to do.</description><pubDate>Sun, 03 Sep 2006 05:54:35 GMT</pubDate><category>c</category><category>debugging</category><category>personal</category></item><item><title>Flex &amp; Bison Example using Microsoft Visual C++ 7.0</title><link>https://iyasec.io/blog/flex-bison-example-using-microsoft-visual-c-7-0/</link><guid isPermaLink="true">https://iyasec.io/blog/flex-bison-example-using-microsoft-visual-c-7-0/</guid><description>Well, I guess this is my first Blog entry. I’m at the tail end of the four weeks I’ve had between the end of summer school and the beginning of the Fall semester. I’m working on a CS Masters degree at Washington University in St. Louis.</description><pubDate>Mon, 28 Aug 2006 05:51:57 GMT</pubDate><category>c</category><category>compilers</category></item><item><title>Universal Exterminator</title><link>https://iyasec.io/blog/universal-exterminator/</link><guid isPermaLink="true">https://iyasec.io/blog/universal-exterminator/</guid><description>I took CS450–Game Programming– at Wash U in Fall, 2005. This was the result. This was the end result. My group called themselves “Die Sphere, Die!”–you may notice our logo pop up occasionally.</description><pubDate>Mon, 21 Aug 2006 05:48:09 GMT</pubDate><category>personal</category><category>ai</category><category>networking</category></item></channel></rss>