Questions about Access Manager tutorials available in netbeans site

Hi
Thank you for reading my post
I have some questions about two tutoral which i find in :
http://www.netbeans.org/kb/55/amsecurity.html and
http://www.netbeans.org/kb/55/amsecurity-liberty.html
here is my problem :
we have some web services, now we want to have authentication applied for consumer who try to access our web services.
we need to have most possible flexibility because we may deploy the server for a customer with an already established Identity database ( Database Table with user details)
Also we need to have Transport level security using SSL.
I read and studied both of them and now i have some questions :
-I think Securing Web Services Using the SAML or UserNameToken is what we need for authentication and autorization of web service consumers?
is that right?
-Does Sun Java System Access Manager provide flexibility to authenticate user/password with a database table content?
-How we can apply roles in Sun Java System Access Manager when we authenticate users ?
Thanks

Imagine that we want to have an end to end security for our web services
we thought that we could use message level encryption to protect the soap message and also we should protect our web services from un-authenticated acess,
we will use userName token for this.
Our customer has large database which contains many user/password and role of those users.
some of web services should be available to higher role (manager) and not for all users.
so we should check a user role before we allows him/her to access a web service.
my question is whether Sun Access manager can help us with this? or there are other configuration or packages that we should apply to have this feature.
to explain more :
our client side is a swing application, users enter username/password to login into system. after they loged in, we send user/pass every time user want to request some data from some services. (is it good to send user/pass every time?)
We want Sun Access Manager to handle users authentication .
We also need to handle role related authorization, can Sun access manager handle this?
Thanks

Similar Messages

  • Two questions about Risk Management 2.0

    hi experts,
    Please find below two questions about Risk Management:
    -In SPRO, Risk Management>Create top node: after completing information and executing I have this error:
    Error in the ABAP Application Program
    The current ABAP program "/ORM/ORM_CREATE_TOP_NODES" had to be terminated
    because it has
    come across a statement that unfortunately cannot be executed.
    The following syntax error occurred in program "/ORM/SAPLORM_API_SERVICES " in
    include "/ORM/LORM_API_SERVICESU10 " in
    line 97:
    "Bei PERFORM bzw. CALL FUNCTION "GET_ORGUNIT_THRESHOLDS" ist der Aktual"
    "parameter "I_ORGUNIT_ID" zum Formalparameter "IV_ORGUNIT_ID" inkompati"
    "bel."
    The include has been created and last changed by:
    Created by: "SAP "
    Last changed by: "SAP "
    Error in the ABAP Application Program
    The current ABAP program "/ORM/ORM_CREATE_TOP_NODES" had to be terminated
    because it has
    come across a statement that unfortunately cannot be executed.
    Do you know where it could come from?
    -On the Portal>Risk Management
    when I click in a link under the risk management menu(activities and risks, risk report, document risk,...) i alway have an internal server error:
    While processing the current request, an exception occured which could not be handled by the application or the framework.
    If the information contained on this page doesn't help you to find and correct the cause of the problem, please contact your system administrator. To facilitate analysis of the problem, keep a copy of this error page. Hint: Most browsers allow to select all content, copy it and then paste it into an empty document (e.g. email or simple text file).
    Do we have to set up some customizing points before accessing these links?
    Thank you !
    Regards,
    Julien

    Hi Julien ,
    I have the same error what u described as :-
    -On the Portal>Risk Management
    when I click in a link under the risk management menu(activities and risks, risk report, document risk,...) i alway have an internal server error:
    While processing the current request, an exception occured which could not be handled by the application or the framework.
    If the information contained on this page doesn't help you to find and correct the cause of the problem, please contact your system administrator. To facilitate analysis of the problem, keep a copy of this error page. Hint: Most browsers allow to select all content, copy it and then paste it into an empty document (e.g. email or simple text file).
    Do we have to set up some customizing points before accessing these links?    "
    Are you able to solve this. Please let me know how to resolve this???
    Thanks
    Regards,
    Atul

  • Question: about accessing Nik collection through Lightroom

    I have recently purchased and installed Nik collection. I have no problem reaching the plug-ins in Photoshopbut can't in Lightroom (except for HDR)

    Thanks!  Technology senses my fear and always makes it difficult for me! Ha! I can use the Nik programs so if I have to, I'll work on them there.
    Date: Sat, 13 Apr 2013 16:27:45 -0700
    From: [email protected]
    To: [email protected]
    Subject: question: about accessing Nik collection through Lightroom
        Re: question: about accessing Nik collection through Lightroom
        created by trihelm2 in Photoshop Lightroom - View the full discussion
    I suspect there are potential issues on some systems with the Google "combined" version, when I installed it I had recieved a copy of the Google complete version free because of my purchase history. I was advised that I could install over the Individual Plugins I had. I never got as far as trying it with Lightroom, only in Elements. The plugins appeared but the load times were abysmal and I mean realy bad , far longer than the Nik individual Installs, so I dumped it and reverted to the originals. Pity cos I wanted the Sharpen Plugin that I have'nt got. After reverting all was back to normal The Nik individual Plugins load very quickly. It was this that convinced me there is a difference in the Google setup.There are people on here with far more knowledge than me, hopefully one of them can help you, alternatively you might try asking Google for help with this.
         Please note that the Adobe Forums do not accept email attachments. If you want to embed a screen image in your message please visit the thread in the forum to embed the image at http://forums.adobe.com/message/5232723#5232723
         Replies to this message go to everyone subscribed to this thread, not directly to the person who posted the message. To post a reply, either reply to this email or visit the message page: http://forums.adobe.com/message/5232723#5232723
         To unsubscribe from this thread, please visit the message page at http://forums.adobe.com/message/5232723#5232723. In the Actions box on the right, click the Stop Email Notifications link.
         Start a new discussion in Photoshop Lightroom by email or at Adobe Community
      For more information about maintaining your forum email notifications please go to http://forums.adobe.com/message/2936746#2936746.

  • Sorry, we couldn't open your file using this feature. Visio Web Access is not available on this site.

    Recently installed Service Pack 1 in SharePoint Server 2013 Farm, post upgrade we are experiencing issue when opening visio documents:
    I am trying to open .vsdx (visio 2013) file but encounter following issue:
    Sorry, we couldn't open your file using this feature. Visio Web Access is not available on this site.
    Under Document library-->Library settings-->Advanced Settings
    Still I cant open file in browser as we always used to. Unfortunately we don't have Visio services in Farm.
    can you share your experiences regarding this issue post Sp1 SharePoint Server 2013.
    Thank You

    Hi Octopus,
    Based on the error message, it seems that the Visio Graphics Service is not started or the Enterprise feature is not enabled.
    I recommend to check the things below:
    Go to Central Administration > System Settings > Manage service on server > check if the Visio Graphics Service is started > then click Application Management > Manage service applications > check if the Visio Graphics Service application
    is created.
    Go to the root site settings page of the site where you got this error, click Site collection features to check if the SharePoint Server Enterprise Site Collection Features is enabled.
    Go to the site settings page of the site where you got this error, click Manage site feature to check if the SharePoint Server Enterprise Site Features is enabled.
    More information about the Visio Graphics Service:
    http://tutorial.programming4.us/windows_server/microsoft-sharepoint-2013---looking-at-visio-services-(part-3)---visio-graphics-service-service-application.aspx
    Best regards.
    Thanks
    Victoria Xia
    TechNet Community Support

  • Some Question about solution manager

    Question about Trusted/Trusting system solution manager
    1. What is the different between:- thease RFC SAP created automatically ? can we create ?
    SAPNET_RFC
    SAPNET_RTCC
    SAPOSS
    SM_NSMCLINT100_BACK
    SM_NSMCLINT100_TRUSTED
    TRUSTING_SYSTEM@NSM
    2. How EarlyWatch Report works, Is that Job run first in R/3 system or solution manager, and what job would be?
    3. In Tr: SDCCN "ToDo" where this data comes from ? what posible resons to check if data is not there in R3 system
    4. SM_CLNT100_BACK & SM_CLNT100_TRUSTED has login user: solman do we need to put password for that ?
    5. In R3 NQA system SMT1 there is no Trusted systems show: when create: messages "No authorization to logon as trusted system"
    Thanks in Advanced

    ok

  • Question about Photo Management

    Hello -
    I am an amateur photographer with a few thousand photos and just bought Aperture 2 to replace iPhoto. One of the things that always irked me about iPhoto was the file structure, and I longed to be able to organize my photos into my own folders within the finder. Somehow, in my mind, this always made them more tangible and accessible.
    My question is... Is this opinion founded, or is it just as viable to store them in the Aperture library and be done with it? I'd love to hear how the "pros" do it.
    Thanks.

    There is not such thing as a "pro way" of working with Aperture. It all depends on your own unique workflow.
    If all your adjustment and manipulation need can be fullfilled by the functionality in Aperture then the easy and simple solution will be to store all your images in the Aperture library. This will allow you to take advantage of features like complete backing up to vaults.
    If you for some process reason (for example panorama stitching) want other software applications to have access to your master files then there are two options. Yu can store all your masters as referenced files or your could just export those specific masters from the Aperture library when you need them. The new plug-in feature may in the future provide "round-tripping" capability to support your specific needs.
    I think that you should decide if you want and need to use the limited features in the Finder to locate specific images. Aperture is a image management application that offers almost any thinkable way of structuring, searching, sorting and filtering your images. It do not make any difference if your images are stored in the Aperture library or if they are referenced from locations outside your Aperture library. You will in any case need to import your images into Aperture in order to take advantage of the image management functionality.
    I am not a pro photog but I hope this answers some of your questions.
    Karsten

  • Question about accessing CIFS with LUM user (permissions)

    Hi there,
    I have a question related to accessing a CIFS mount throught a user in a linux box.
    First of all, its a system based in OES11 sp2 & SLES 11 SP3. I have a cifs mount
    in /media/nss, with novell cifs, coming from a NSS Filesystem. This mount is mounted
    with a username/password with password policy, etc. I have four users LUM-enabled,
    in the Linux box, which should access the CIFS mount, but I have a permission denied.
    I have set trustees for the primary group for the 4 lum-enabled users and also I have
    addedd permissions for a group in the NSS volume, and add this group to the membership
    of the users, but doesnt works.
    I guess Im missing something or Im doing something wrong. Could anybody give me a pointer?
    Thanks!

    Antoniogutierrez,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://forums.novell.com/

  • Some questions about Skype Manager and Skype Conne...

    Hallo,
    I found one of your post:
    That, if I have some questions I may contact with  Contact our solutions team
    Sadly that link wont work...
    I have few questions and also I contacted with Microsoft support, but sadly they wasn’t able to help me. Only what they suggests, that I may contact with Skype Team trough to Forum, or Facebook...
    So, I choose first one and maybe you can help me, or redirect my question !?
    About my questions:
    As I understand Skype for business is just name what contain two free software, like Skype manager and Skype connect. Also those are free, without charge ?
    Also I read that there are two different accounts, like Premium and regular one. Premium contains some benefit. So, If I use that Skype for business manager system to I may or can add some premium accounts for some my staff and leave others with regular account ? I don’t have that manager systems installed jet, but what I read, I understand that I maybe just split credit - or is there way how I may also share regular and premium conots ?
    Also, Right now my customers have 25 workers, but what - if soon my another customer also want to use Skype Service, and he have 50 - 100 workers ? Will be there special price for different amount of users on one firm ?
    And at last, firm who I represent right now are using Elion VoiP (Elion, is Estonian ISP) service, trough to xLite program. 
    Sadly that one wont work properly, it will hack, or you cant hear other people and so on. With, Skype everything works fine. So, if he will starting to use Skype manger and will make account for every workers (sips) can he bound those sips with same VoiP numbers what he will use right now with Elion ? Or if not, is there some way how to redirect those numbers (to lose those numbers, is sadly out of question) ?
    I hope, you can help me guy´s.
    Best regards
    Rainer

    Tere Rainer,
    indeed we don't have the solutions team offer any longer. Let me try to answer some of your questions here.
    Skype Manager and Skype Connect itself are free of charge. But obviously you can purchase and distribute paid products via Skype Manager.
    Yes, you can freely distribute Premium subscription to Manager group members and leave others without. You can do the same with all kind of Skype products, e.g. Skype numbers, calling subscriptions etc.
    There are no discounts with Skype Manager purchases. It's a tool to simplify administration.
    Unfortunately you cannot transfer numbers to Skype connect. For more details on which features are supported and how they work please have a look here: https://support.skype.com/en/faq/FA10549/what-is-s​kype-connect-and-how-does-it-work
    I hope my answers could help a bit already.
    Tervitustega Mustamäelt.
    Follow the latest Skype Community News
    ↓ Did my reply answer your question? Accept it as a solution to help others, Thanks. ↓

  • Basic question about accessing card reader from browser

    Hi,
    I am very new to card technology. I have a very basic and general question not directly related to java cards.
    I need to write a web application that allows the user to read a card with a card reader.
    For that I maybe need to write an applet that has to access a native DLL and call methods
    to get the card ID. I already have that DLL (written in Delphi) that reads multi-technology cards.
    Then pass that ID to the application server to retrieve complete information
    about the card holder and display them on the user browser.
    Please could someone guide me on useful resources for that kind of development, for example
    already existing developments, personal experience, design solutions ?
    Thanks.
    Adriano

    Hi Joseph,
    One thing I forgot to tell is that I work with contactless cards and readers.
    Contactless cards use radio frequency. Despite this fact, the problem stays the same. I already have a Delphi DLL that reads contactless cards.
    What I need is a way to retrieve card holder information from a client browser. The card contains a unique ID. My idea is to use an applet that reads that ID on the client-side and then calls a servlet on the server-side to retrieve holder information associated with that ID, i.e. first and last names, and finally displays them on the client browser.
    So the card contains only the unique ID, a database on the server-side contains all other related data.
    Technically the applet has to call the DLL via JNI.
    Do you think that using an applet that way is a good solution, do you see simpler solutions, is there security issues ?
    Thanks.

  • Question about accessing Runtime MBean server

    I would like to access the Runtime MBean server, and I've read this link: http://e-docs.bea.com/wls/docs91/jmx/accessWLS.html#1119237
    I want to access this from within my EJB application. My WLS 9.1 setup is simple (it's a Single Server Domain), and the class which is attempting to get to the runtime MBean server is from a stateful session bean. The Bean class is in a Jar which is deployed within an Ear as part of an ELB module.
    After reading "If the classes for the JMX client are located in a J2EE module, such as an EJB or Web application, then the JNDI name for the Runtime MBeanServer is", I expected to use the JNI name java:comp/jmx/runtime. But this failed.
    What worked was the other address specified (java:comp/env/jmx/runtime).
    So, apparently this means that "If the classes for the JMX client are located at the top level of an enterprise application (that is, if they are deployed from the application's APP-INF directory)"
    So, I'm not sure what this means? Can someone clarify when each address is available and when it's not? The existing explaination in the doco doesn't make sense to me. My application is defined as part of an EJB module, yet I can't use the JNI name for an EJB module?
    Thanks for any help,
    Ed

    It's called DNS registration.
    You need to talk with your network engineers or someone who manages your public website.
    We did our DNS registration of our Portal site through the telecom company who provides our office with Internet access.
    Our portal URL from the Internet is:
    https://portal.opnext.com/pls/portal
    If you can access it and want to log in using our "demo" ID, please send me an e-mail requesting the password.
    Eric
    [email protected]

  • Question About "Manually Manage Music and Videos"

    Hi!
    I have a podcast stuck on my iPod. It is not deleted from a Playlist upon syncing, even though I've deleted it from the Playlist in iTunes. It still shows up in the "On My Device" representation of the Playlist, and of course, on the iPod itself. So I thought to manually delete it, but of course it's name is obfuscated in the iPod's directory. So I thought that maybe I could do it by selecting "manually manage music and videos" in iTunes. Presumably files would become human readable then, yes?
    Here's my question: What will happen to all the content already on my iPod via syncing if I check that box? Will it all (all 140 GB) disappear and have to be re-synced? Or can I check that box, go in and delete the one podcast, then uncheck the box, all without affecting the rest of the content already on the device?
    TIA for your help!

    If you post from a a question from the bottom of an article's page then you should get its reference, e.g. HT1535 in your case, on the post's title. The ability to edit you post only lasts for 15 minutes and allows you to correct/add extra info.
    I get the 'manually manage music and videos' tockbox as described on that article. If you only 'videos' then are you using iTunes Match on your iPad ? I don't use it but I've seen posts that say having it enabled on a device can affect the syncing of music.

  • Question about project manager on Flash CS4

    1 It seems that CS4 can not open flp, so how can I use CS4 to manager a project builded by CS3?
    2 if you choose a folder to found a new project in CS4, when you want to publish the whole project, you need to choose all the fla of that project...that will cost a lot of time if the project includes hundreds of files. But I didn't find out any quicker solution except check every fla by manpower. Is there any solution to publish a project faster?
    I am beginner of both CS3 and CS4, and thank you for anyone who can answer my questions.

    I'm planning on burning 1 master to a Taiyo Yuden White Inkjet Hub Printable 16X DVD-R disc.
    Make a disk image instead. It will be faster than a disc to disc copy.
    I have burnt tons of discs with the setting on "As fast as possible" with a 16x drive and discs. Never a problem. Some say that burning at a lower speed will increase reliability and decrease the chance of turning out a dud. Can't say that I have seen a difference.
    does it matter if I burn first and then print or should I print first and then burn?
    I would burn, check the disc and then print. If you do happen to get a bad batch, that's a lot of wasted time and ink if the discs don't work.

  • Questions about accessing Oracle9i Database Release 2

    Hi
    I'm new to this whole process. My question is how do I access the Application Development portion(SQL+). Do I have to subscribe to the OTN network in order to receive a username, password and host string, in order to log into the SQL Plus application. Is there any documentation that explains how I am able to access the Oracle 9i Database and all of its functions. What do I have to do in order to access The OTN network

    This is fairly basic but it should get you to where you need: http://download-west.oracle.com/docs/cd/B10501_01/server.920/a90842/ch1.htm
    OTN

  • Question about online Illustrator tutorials

    Hey guys,
    I wanted to ask - has anyone ever paid for online Illustrator tutorials when learning Illustrator?
    If you have, how did you find it, would you recommend it for beginners?  If you've never bought an online tutorial, would you ever consider doing so and why/why not?

    If you've never bought an online tutorial, would you ever consider doing so and why/why not?
    No. Because anyone with the necessary interest (stick-to-it-iveness), a brain, and grade-school literacy should be able to learn to work mainstream graphics programs like Illustrator from the provided documentation. This stuff is not rocket science.
    All you really need is the self-discipline to thoroughly read the provided documentation start-to-finish and work through  what it describes as you go. Actually performing the operations as you read helps you retain, and also combats the inherent boredom, because you will find yourself inclined to take little "experimental side-trips" as the understanding bells go off. Do that as you go, but always return to where you left off and don't skip parts.
    Supplement that with just a few carefully selected books. You can waste a small fortune on mediocre aftermarket books that largely or even mostly just rehash the provided documentation in an attempt to broaden their audience.
    Supplement that  with whatever real-world exposure/experience you can access, pertaining to your delivery media. If you're illustrating/designing for print, that means where-ink-hits-paper experience. If you think you can escape print as  a career illustrator/designer, you probably need a reality check.
    Online tutorials are 90% crap, because the vast majority of their authors are beginners themselves--intermediate users at best--who are just enamoured with the program, think they are more expert than they really are, and are seeking notoriety. The tutorials are incomplete, seldom use proper terminology, and seldom reflect best-practice. And the beginner, of course, does not yet possess the discernment to judge.
    The provided documentation is basic, as it should be; not whiz-bang, gee-whiz instant gratification. It's therefore boring, but it does what it needs to do: lay a general foundationof understanding of the program's fundamental capabilities and "logic"--without alot of needless unproductive anecdotal drivel--which you then begin to use to your own creative advantage.
    Video, unless very well produced, is arguably the least efficient method to learn anything the least bit technical, because it is not information dense. You can call digital video "random access" if you want; but even if you jump around in it, you still have to watch it linearly, suffering through every word, "clever" annecdote, etc., etc. everytime you just need to pause and think a bit on a particular phrase, or "re-read" a sentence. Written prose is carefully written and edited for thoroughness, accuracy, and efficiency; not sloppily narrated.
    It's common-sense that you can see in anything. Seriously consider how many hours-worth (weeks-worth, months-worth) of linear video you would have to watch in order to gain the same level of understanding of, say, your car, as compared to reading a single proper service manual, and keeping it handy while you are under the hood.
    Like several here, I've been doing this stuff everyday, all day since its beginning in the mid 80s. I have yet to meet a single college or tech school instructor that I would consider an above intermediate level user. Most, I'd call rank beginners, if even that. They just teach out of the Adobe-sanctioned "Classroom In A Book" manuals.
    Be honest with yourself: Why are you seeking alternative learning methods before you've even read and worked through the provided documentation? I'm convinced the true answer is practically always simple laziness. Too many beginners think they can get some kind of magic shortcut toward proficiency. It just isn't that way.
    JET

  • Few questions about Profile Manager

    As i know, profile manager will install the following profile on the enrolled iPad.
    - Trust Profile > Code Signing Certificate
    - Remote Management > Device Managment Identiity Certificate
    But the validation of above certificates just 1 year by defaults.
    My questions are:
    1.  Is there any way can regenerate the certificate for 10 years? Due to i don't want to re-enroll the iPad every year.
    2.  The vaild period of Device Managment Identiity Certificate is "The date of enrollment" to "The date of enrollment + 1 year". (e.g: 1/6/2012 - 1/6/2013) I would like to know if this certifcate expired, what will happen?

    Well, I know this is an old thread but did you ever find out? Mine expired and everything stopped working. Couldn't push any settings or update device info. I got a button dialog on the profile in Settings saying "This profile has expired. Update this profile for a newver version. [Update Profile]" - which didn't work. I ultimately re-enrolled, but I could imagine it being a nightmare to re-enroll a large number of devices.

Maybe you are looking for