Forum tags


Top Posters

Last 30 days

  • Antoine (93)
  • talita.pezzi (27)
  • eduardo.lawisch (14)
  • alfons.bataller.diaz (14)
  • sundaravadivel.n (13)
  • ravinderjit.singh (12)
  • hellonico (8)
  • jose.mendoza (8)
  • barry.sperling (7)
  • marcia.martins (7)

All time

  • Antoine (1402)
  • Shivanand (1189)
  • cshekhar (921)
  • psq (795)
  • jag (391)
  • metabyte (370)
  • arnaud (327)
  • jalateras (325)
  • dfrench (263)
  • venkaiah.k (198)

Show last 4 hrs - 12 hrs - 24 hrs

POLL

We are looking for more information to tailor our training to better meet the needs of our customers. Please indicate all options that apply.

I would like to attend specialized training from Intalio on BPM as it relates to my application area:


I would like to attend specialized training from Intalio on BPM as it relates to my job function:


I would like to attend specialized training from Intalio on BPM as it relates to my industry:

Login

MAIN arrow FORUMS
Re:Security Architecture (0 viewing) 
Go to bottom Post Reply Favoured: 0
TOPIC: Re:Security Architecture
#14829
dfrench (User)
Gold Boarder
User Offline Click here to see the profile of this user
Security Architecture 4 Months, 2 Weeks ago Karma: 8  
Has anyone developed a security architecture around Intalio that allows for integration with external services and user interface components?
Out of the box, the Intalio suite does very basic user logon into the TEMPO workflow application. Some guidance on fitting Intalio into enterprise or multi-enterprise operations would be of interest.
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
#14833
Antoine (Admin)
Admin
User Offline Click here to see the profile of this user
Re:Security Architecture 4 Months, 2 Weeks ago Karma: 25  
We have good integration with LDAP if that's what you are after.
 
Report to moderator   Logged Logged  
 
Intalio, the Open Source BPMS company
www.intalio.com
  The administrator has disabled public write access.
#14834
dfrench (User)
Gold Boarder
User Offline Click here to see the profile of this user
Re:Security Architecture 4 Months, 2 Weeks ago Karma: 8  
Yes I understand that and obviously for a single enterprise LDAP is sufficient as a database of roles, rights and the like. However, it is more complicated when the Intalio product is used to integrate between organisations or independent systems or in any case where the end points of ODE and TEMPO components are exposed .

Consider for example the simple case where the business process receives inbound SOAP messages from a 'black box' external entity. If you take an Intalio-centric view you could
1. Require the external entity to authenticate itself
2. Pass a token representing that authentication in every inbound message to Intalio BPMS
3. Validate that token in each BPMS process before doing anything else

This strikes me as being open to error and difficult to scale in a large development.

Alternatively you could move the problem up to the WS security layer. Has any work been done in this area?
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
Go to top Post Reply
get the latest posts directly to your desktop