<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bob&#039;s Identity Management Blog</title>
	<atom:link href="http://www.bobbobel.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bobbobel.com</link>
	<description>&#34;Anyone can hold the helm when the sea is calm.&#34; - Syrus Publilius</description>
	<lastBuildDate>Wed, 16 May 2012 12:45:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Active Directory was compromised, now what?</title>
		<link>http://www.bobbobel.com/active-directory-was-compromised-now-what/</link>
		<comments>http://www.bobbobel.com/active-directory-was-compromised-now-what/#comments</comments>
		<pubDate>Wed, 16 May 2012 12:45:15 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Active Directory Experts]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[Active Directory Tools]]></category>
		<category><![CDATA[AD Auditing]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[Privilege Account Management]]></category>
		<category><![CDATA[Robert Bobel]]></category>
		<category><![CDATA[Windows Credential Editor]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1202</guid>
		<description><![CDATA[Re-constituting Active Directory after a critical compromise or detection of an Advanced Persistent Threat Microsoft&#8217;s Active Directory (AD) provides a secure and stable directory service on which many organizations depend to provide user authentication and authorization.  Because AD represents the preverbal keys to the kingdom it typically receives the appropriate level of care and feeding [...]]]></description>
			<content:encoded><![CDATA[<h2><strong>Re-constituting Active Directory after a critical compromise or detection of an Advanced Persistent Threat</strong></h2>
<p>Microsoft&#8217;s Active Directory (AD) provides a secure and stable directory service on which many organizations depend to provide user authentication and authorization.  Because AD represents the preverbal keys to the kingdom it typically receives the appropriate level of care and feeding required maintaining it. Despite proper upkeep, there is still a chance that an Advanced Persistent Threats (APT) may be successful and compromise your Active Directory. Because of the nature of APTs a wide range of attacks vectors may be tried that may or may not attempt to subjugate AD directly. The result is that a successful compromise may go undetected for some time until the attacker decides to exploit the compromise by stealing data or making critical systems unavailable.</p>
<p>Most administrators are now resigned to the fact that their network will be hacked. It&#8217;s just a matter of time. It&#8217;s no secret that there is a lot of activity around cyber security, and the most serious (damaging?) breach that could happen to any organization is a compromise of their Active Directory (AD) environment. AD is at the heart of many missile critical services, including desktop logins, file &amp; print sharing, email &amp; other communications and collaboration. And once the compromise happens, it can have far reaching effects. Plus, attackers are much more sophisticated, using many (various?) tactics to penetrate and then stay hidden within your environment. At this point, it is an arms race, and the &#8220;bad guys&#8221; only have to win once to get in where you must win everyday.</p>
<h2>Reducing the immediate threat &#8211; Domain Admins role</h2>
<p>A quick way to reduce the threat to Active Directory is to reduce the number of privileged accounts that can make major changes to Active Directory. This is especially important for AD users who have the Domain Administrators privilege. Because of the Active Directory design, many organizations have dozens or many dozens of users who hold this role. There are several management solutions on the market today that will allow administrators to perform day-to-day tasks without requiring the Domain Administrator&#8217;s role. Another critical way to reduce the threat to your production environment is to ensure your directory auditing and monitoring solutions are up to the task.</p>
<h2>Why re-establishing AD after a critical compromise goes beyond normal recovery</h2>
<p>Because a critical compromise may only be uncovered long after it was introduced the validity and security of backup data because changes made via. the compromise may be indistinguishable from day-to-day administrative changes. The sheer volume of changes made from the time of the compromise&#8217;s introduction to the current state of the directory data make it virtually impossible to identify the changes intentional vs. non-intentional. The best option and certainly the fastest option is to remove the compromise and maintain your directory data is to migrate the data to a new sanitized directory on clean servers.</p>
<h2>More on Advanced Persistent Threats</h2>
<p>An Advanced Persistent Threat (APT) typically refers a conspiracy by a group of foreign government attempt or complete some a cyber attack. What makes these threats particularly scary is after the group or foreign government perpetrating these attacks the compromise may not be exploited until such time as maximum damage can be achieved or when the highest value theft can be achieved. For more information on Advanced Persistent Threats see: <a href="http://en.wikipedia.org/wiki/Advanced_persistent_threat">http://en.wikipedia.org/wiki/Advanced_persistent_threat</a></p>
<h2>Windows Credential Editor</h2>
<p>If you don&#8217;t think people can get past your complex AD password, check out <a href="http://www.ampliasecurity.com/research/wcefaq.html">http://www.ampliasecurity.com/research/wcefaq.html</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/active-directory-was-compromised-now-what/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Beyond Trust Buys eEye Digital</title>
		<link>http://www.bobbobel.com/beyond-trust-buys-eeye-digital/</link>
		<comments>http://www.bobbobel.com/beyond-trust-buys-eeye-digital/#comments</comments>
		<pubDate>Thu, 10 May 2012 20:27:49 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Beyondtrust]]></category>
		<category><![CDATA[eEye Digital]]></category>
		<category><![CDATA[Quest Software]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1199</guid>
		<description><![CDATA[http://www.beyondtrust.com/News-and-Events/Press-Releases/2012/BeyondTrust-Acquires-Vulnerability-Management-Pioneer-eEye-Digital-Security/]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.beyondtrust.com/News-and-Events/Press-Releases/2012/BeyondTrust-Acquires-Vulnerability-Management-Pioneer-eEye-Digital-Security/">http://www.beyondtrust.com/News-and-Events/Press-Releases/2012/BeyondTrust-Acquires-Vulnerability-Management-Pioneer-eEye-Digital-Security/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/beyond-trust-buys-eeye-digital/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Overnight sucess often takes more than overnight</title>
		<link>http://www.bobbobel.com/overnight-sucess-often-takes-more-than-overnight/</link>
		<comments>http://www.bobbobel.com/overnight-sucess-often-takes-more-than-overnight/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 17:42:44 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Start-ups]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1195</guid>
		<description><![CDATA[Great article on Fast Company about how start-ups are challenged and almost fail, but can go on to become huge successes. It is pretty clear that the Risk/Reward can be a tough hurdle for many to overcome. http://www.fastcompany.com/1826976/the-dirty-little-secret-of-overnight-successes]]></description>
			<content:encoded><![CDATA[<p>Great article on Fast Company about how start-ups are challenged and almost fail, but can go on to become huge successes. It is pretty clear that the Risk/Reward can be a tough hurdle for many to overcome.</p>
<p><a href="http://www.fastcompany.com/1826976/the-dirty-little-secret-of-overnight-successes">http://www.fastcompany.com/1826976/the-dirty-little-secret-of-overnight-successes</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/overnight-sucess-often-takes-more-than-overnight/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dmitry&#8217;s New Quest</title>
		<link>http://www.bobbobel.com/dmitrys-new-quest/</link>
		<comments>http://www.bobbobel.com/dmitrys-new-quest/#comments</comments>
		<pubDate>Sat, 11 Feb 2012 14:22:19 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[AD Bridge]]></category>
		<category><![CDATA[Dmitry Sotnikov]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Jelastic]]></category>
		<category><![CDATA[PowerGUI]]></category>
		<category><![CDATA[PowerShell AD CMDLETS]]></category>
		<category><![CDATA[Quest Software]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1190</guid>
		<description><![CDATA[Dmitry Sotnikov, my colleague and friend announced on his blog that he has left Quest to join a very-very cool start up called Jelastic. I had the great fortune to work with Dmitry on a number of cool projects at Quest such as our AD Bridge and our my teams AD PowerShell Commandlets. Check out [...]]]></description>
			<content:encoded><![CDATA[<p>Dmitry Sotnikov, my colleague and friend announced on his blog that he has left Quest to join a very-very cool start up called Jelastic. I had the great fortune to work with Dmitry on a number of cool projects at Quest such as our AD Bridge and our my teams AD PowerShell Commandlets. Check out Dmitry&#8217;s Blog entry and watch the video of the new technology he will be working with&#8230; it is really amazing. <a href="http://dmitrysotnikov.wordpress.com/2012/02/10/jump-they-say-off-to-a-start-up/">http://dmitrysotnikov.wordpress.com/2012/02/10/jump-they-say-off-to-a-start-up/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/dmitrys-new-quest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Matt Hitchcock posted some cool comments about Windows 8 AD</title>
		<link>http://www.bobbobel.com/matt-hitchcock-posted-some-cool-comments-about-windows-8-ad/</link>
		<comments>http://www.bobbobel.com/matt-hitchcock-posted-some-cool-comments-about-windows-8-ad/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 21:47:10 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1186</guid>
		<description><![CDATA[http://matthitchcock.com/2012/01/08/active-directory-in-windows-8-first-look/]]></description>
			<content:encoded><![CDATA[<p><a href="http://matthitchcock.com/2012/01/08/active-directory-in-windows-8-first-look/">http://matthitchcock.com/2012/01/08/active-directory-in-windows-8-first-look/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/matt-hitchcock-posted-some-cool-comments-about-windows-8-ad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October was a bad month for computing founders</title>
		<link>http://www.bobbobel.com/october-was-a-bad-month-for-computing-founders/</link>
		<comments>http://www.bobbobel.com/october-was-a-bad-month-for-computing-founders/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 15:51:15 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Founding Fathers of Computing]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1176</guid>
		<description><![CDATA[Apple http://en.wikipedia.org/wiki/Steve_Jobs C http://en.wikipedia.org/wiki/Dennis_Ritchie LISP http://techcrunch.com/2011/10/24/creator-of-lisp-john-mccarthy-dead-at-84/]]></description>
			<content:encoded><![CDATA[<p>Apple <a href="http://en.wikipedia.org/wiki/Steve_Jobs">http://en.wikipedia.org/wiki/Steve_Jobs</a></p>
<p>C <a href="http://en.wikipedia.org/wiki/Dennis_Ritchie">http://en.wikipedia.org/wiki/Dennis_Ritchie</a></p>
<p>LISP <a href="http://techcrunch.com/2011/10/24/creator-of-lisp-john-mccarthy-dead-at-84/">http://techcrunch.com/2011/10/24/creator-of-lisp-john-mccarthy-dead-at-84/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/october-was-a-bad-month-for-computing-founders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Steve Jobs 1955 &#8211; 2011</title>
		<link>http://www.bobbobel.com/steve-jobs-1955-2011/</link>
		<comments>http://www.bobbobel.com/steve-jobs-1955-2011/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 00:06:32 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Steve Jobs Passing]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1173</guid>
		<description><![CDATA[You have to be impressed by this guys life &#8211; http://www.cnn.com/2011/10/05/us/obit-steve-jobs/index.html?iref=BN1&#38;hpt=hp_t1.]]></description>
			<content:encoded><![CDATA[<p>You have to be impressed by this guys life &#8211; <a href="http://www.cnn.com/2011/10/05/us/obit-steve-jobs/index.html?iref=BN1&amp;hpt=hp_t1">http://www.cnn.com/2011/10/05/us/obit-steve-jobs/index.html?iref=BN1&amp;hpt=hp_t1</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/steve-jobs-1955-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ActiveRoles Update 3663 just released!</title>
		<link>http://www.bobbobel.com/activeroles-update-3663-just-released/</link>
		<comments>http://www.bobbobel.com/activeroles-update-3663-just-released/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 16:10:57 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[ActiveRoles Multi-browser]]></category>
		<category><![CDATA[ActiveRoles Server update 3663]]></category>
		<category><![CDATA[Cloud IDM]]></category>
		<category><![CDATA[Self-Service]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1165</guid>
		<description><![CDATA[Last week development released the 6.7.3663 update for ActiveRoles Server.  Included in the update are some generic fixes as you would expect, but there is also a set of updates for a long standing limitation that only Internet Explorer worked properly. This update adds multi-browser support  and allows the ActiveRoles web interface to be accessed from [...]]]></description>
			<content:encoded><![CDATA[<p>Last week development released the 6.7.3663 update for <strong>ActiveRoles Server</strong>.  Included in the update are some generic fixes as you would expect, but there is also a set of updates for a long standing limitation that only Internet Explorer worked properly. This update adds multi-browser support  and allows the <em>ActiveRoles</em> web interface to be accessed from the following browsers:</p>
<ul>
<li>Firefox 5.0 and 6.0</li>
<li>Google Chrome 13</li>
<li>Safari 4 and 5</li>
<li>Windows Internet Explorer 7.0, 8.0 and 9.0</li>
</ul>
<dl id="attachment_1166" class="wp-caption aligncenter" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://www.bobbobel.com/wp-content/uploads/2011/10/ActiveRoles_Grey_On_Chrome.png"><img class="size-medium wp-image-1166" title="ActiveRoles_Grey_On_Chrome" src="http://www.bobbobel.com/wp-content/uploads/2011/10/ActiveRoles_Grey_On_Chrome-300x249.png" alt="" width="300" height="249" /></a></dt>
<dd class="wp-caption-dd">ActiveRoles w/3663 installed running on Google Chrome displayed with altered color scheme.</dd>
</dl>
<p>It is interesting that the release notes don&#8217;t mention IE 6.0, but with information like this (<a href="http://en.wikipedia.org/wiki/Internet_Explorer_6">http://en.wikipedia.org/wiki/Internet_Explorer_6</a>) being prevalent around the Internet it is not surprising.  With the everyday increase in hacking and exploits attacks &#8211; anyone still using IE 6 should be afraid, very afraid and move to a secure and supported browser immediately.  My installation experience was good. Installation went as expected with no surprises and things continued to work including the add-ins for QAS and Defender. Changing the color scheme is a bit tricky since you really are setting a single color that will be used in place of the standard Blue UI color. But for many customers this will be a welcome change from modifying XML files with new color codes.</p>
<p>Customers can download the update from Quest support <a href="https://support.quest.com/Search/SolutionDetail.aspx?id=SOL78214">https://support.quest.com/Search/SolutionDetail.aspx?id=SOL78214</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/activeroles-update-3663-just-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bhold what Microsoft bought</title>
		<link>http://www.bobbobel.com/bhold-what-microsoft-bought/</link>
		<comments>http://www.bobbobel.com/bhold-what-microsoft-bought/#comments</comments>
		<pubDate>Fri, 23 Sep 2011 15:04:57 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[aquisitions]]></category>
		<category><![CDATA[Bhold]]></category>
		<category><![CDATA[IAG]]></category>
		<category><![CDATA[Quest]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1160</guid>
		<description><![CDATA[Micrsosoft announced the aquistion of Bhold to enhance the FIM family of products. http://www.microsoft.com/pathways/bhold/ http://blogs.gartner.com/ian-glazer/2011/09/23/bhold-wins-the-microsoft-iag-lottery/ &#160;]]></description>
			<content:encoded><![CDATA[<p>Micrsosoft announced the aquistion of Bhold to enhance the FIM family of products.</p>
<p><a href="http://www.microsoft.com/pathways/bhold/">http://www.microsoft.com/pathways/bhold/</a></p>
<p><a href="http://blogs.gartner.com/ian-glazer/2011/09/23/bhold-wins-the-microsoft-iag-lottery/">http://blogs.gartner.com/ian-glazer/2011/09/23/bhold-wins-the-microsoft-iag-lottery/</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/bhold-what-microsoft-bought/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defender &amp; ActiveRoles MMC Integration</title>
		<link>http://www.bobbobel.com/defender-activeroles-mmc-integration/</link>
		<comments>http://www.bobbobel.com/defender-activeroles-mmc-integration/#comments</comments>
		<pubDate>Fri, 23 Sep 2011 14:46:27 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[ActiveRoles Integration]]></category>
		<category><![CDATA[Defender]]></category>
		<category><![CDATA[OTP Token Management]]></category>
		<category><![CDATA[Strong Authorization Management]]></category>
		<category><![CDATA[Two Factor Authentication]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1155</guid>
		<description><![CDATA[For ActiveRoles customers using or considering using Quest Defender, integration between the two products is a requirement. Being able to perform OTP token management from the point where user management is performed is one key to efficient management of strong authentication. Token Management from the ActiveRoles Web Console I was working with a customer this [...]]]></description>
			<content:encoded><![CDATA[<p>For <strong>ActiveRoles</strong> customers using or considering using <span style="text-decoration: underline;">Quest Defender</span>, integration between the two products is a requirement. Being able to perform OTP token management from the point where user management is performed is one key to efficient management of strong authentication.</p>
<p style="text-align: center;"><em><strong>Token Management from the ActiveRoles Web Console<br />
</strong></em><img class="aligncenter size-medium wp-image-1156" title="Defender-ARS-Web-Integration" src="http://www.bobbobel.com/wp-content/uploads/2011/09/Defender-ARS-Web-Integration-300x135.png" alt="" width="300" height="135" /></p>
<p>I was working with a customer this week who had a requirement to manage Quest Defender two factor tokens through the <em>ActiveRoles</em> MMC console. While I knew this was under development, I did not realize you can get it today without waiting for the next release of Defender. Integration with the <em>ActiveRoles</em> MMC can be critical for customers who are primarily using the MMC for day-to-day or help desk operations.</p>
<p style="text-align: center;"><em><strong>Token Management from the ActiveRoles MMC<br />
(click to enlarge)</strong></em><a href="http://www.bobbobel.com/wp-content/uploads/2011/09/Defender-ARS-MMC-Integration.png"><img class="aligncenter size-medium wp-image-1157" title="Defender-ARS-MMC-Integration" src="http://www.bobbobel.com/wp-content/uploads/2011/09/Defender-ARS-MMC-Integration-300x262.png" alt="" width="300" height="262" /></a></p>
<p>The <strong>ActiveRoles</strong> integration pack on the Defender 5.6 CD installs property pages and commands into the ActiveRoles Web Interface only. Separately, Defender Software update 5.6.0.2593 adds token management and property tabs into the ActiveRoles MMC on user property pages. This update can be obtained through the Quest support site and you will need to install two components 1) Defender ARS Integration Pack_Update_5.6.0.2593 and 2) Defender Administration Console_Update_5.6.0.2593.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/defender-activeroles-mmc-integration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HTC Incredible to support Near Field Communciation (NFC)</title>
		<link>http://www.bobbobel.com/htc-incredible-to-support-near-field-communciation-nfc/</link>
		<comments>http://www.bobbobel.com/htc-incredible-to-support-near-field-communciation-nfc/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 19:13:55 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Entitlement]]></category>
		<category><![CDATA[Mobile Computing]]></category>
		<category><![CDATA[Cloud Payment]]></category>
		<category><![CDATA[Droid Incredible S]]></category>
		<category><![CDATA[Near Field Communication]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1144</guid>
		<description><![CDATA[A friend of mine is working on NFC and I wondered if my Android device would support it &#8211; well it didn&#8217;t but there is a new version of the phone in development that was just tested by the FCC for NFC compatibility. http://www.nfcrumors.com/08-17-2011/is-the-htc-incredible-s-the-next-google-wallet-enabled-nfc-phone-it-just-passed-through-the-fcc/]]></description>
			<content:encoded><![CDATA[<p>A friend of mine is working on NFC and I wondered if my Android device would support it &#8211; well it didn&#8217;t but there is a new version of the phone in development that was just tested by the FCC for NFC compatibility.</p>
<p><a href="http://www.nfcrumors.com/08-17-2011/is-the-htc-incredible-s-the-next-google-wallet-enabled-nfc-phone-it-just-passed-through-the-fcc/">http://www.nfcrumors.com/08-17-2011/is-the-htc-incredible-s-the-next-google-wallet-enabled-nfc-phone-it-just-passed-through-the-fcc/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/htc-incredible-to-support-near-field-communciation-nfc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Putting a price on governmental security</title>
		<link>http://www.bobbobel.com/putting-a-price-on-governmental-security/</link>
		<comments>http://www.bobbobel.com/putting-a-price-on-governmental-security/#comments</comments>
		<pubDate>Thu, 15 Sep 2011 14:26:30 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1139</guid>
		<description><![CDATA[My colleague Dmitry Kagansky sharing his insites on Security its cost to government.  http://fedscoop.com/tv/quest-federal-cto-dmitry-kagansky-on-security-in-government/]]></description>
			<content:encoded><![CDATA[<p>My colleague Dmitry Kagansky sharing his insites on Security its cost to government.</p>
<p> <a href="http://fedscoop.com/tv/quest-federal-cto-dmitry-kagansky-on-security-in-government/">http://fedscoop.com/tv/quest-federal-cto-dmitry-kagansky-on-security-in-government/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/putting-a-price-on-governmental-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Working with Field Labels in ActiveRoles</title>
		<link>http://www.bobbobel.com/working-with-field-labels-in-activeroles/</link>
		<comments>http://www.bobbobel.com/working-with-field-labels-in-activeroles/#comments</comments>
		<pubDate>Fri, 02 Sep 2011 12:28:28 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[AcitveRoles Server]]></category>
		<category><![CDATA[ActiveRoles XML]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1137</guid>
		<description><![CDATA[In the past it was common to have a requirement that additional details be presented at the top of a web interface form in ActiveRoles &#8211; this would often require modification to the underlying XML making the solution difficult to maintain during upgrades. If the requirement is simple enough there is a workaround that may [...]]]></description>
			<content:encoded><![CDATA[<p>In the past it was common to have a requirement that additional details be presented at the top of a web interface form in ActiveRoles &#8211; this would often require modification to the underlying XML making the solution difficult to maintain during upgrades. If the requirement is simple enough there is a workaround that may provide relief in this situation. If you would like to provide limited additional information at the top of a form in the ActiveRoles Web Interface you can add this information to the label field of the first entry. This information must be limited as it is subject to the constraints of the form sizing and so you probably won&#8217;t be able to make it look exactly like you require, but you may get it close. Some HTML tags may work, but not all are guaranteed to be available. My suggestion is that you keep things simple like using line breaks and list tags.</p>
<ol>
<li>Logon as a DS Admin to the web interface you wish to modify.</li>
<li>Click <em>&#8220;Click here to customize this form&#8221;</em></li>
<li>Locate the top field and click <em>(edit&#8230;)</em> at the far left end of the entry name.</li>
<li>In the <em>Entry name:</em> field enter the text you want to display at the top of the form. Make sure to add any text to the left of the field name already in that entry so that it will continue to display properly.</li>
<li>For example:<br />
Directions&lt;BR&gt;Contacts may not be used for authentication.You have two choices at this point.&lt;BR&gt;&lt;BR&gt;&lt;ol&gt;&lt;li&gt;If the person will need to authenticate against Active Directory, you should create a user account object on their behalf.&lt;/i&gt;&lt;li&gt;Continue creating this Contact object.&lt;/i&gt;&lt;/ol&gt;&lt;BR&gt; First Name</li>
<li>Click <em>Save</em></li>
<li>Click <em>Reload</em></li>
</ol>
<p>Navigate to the form in the UI so that you can validate your work.</p>
<p><em></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/working-with-field-labels-in-activeroles/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Smart card presentation at the AFITC</title>
		<link>http://www.bobbobel.com/smart-card-presentation-at-the-afitc/</link>
		<comments>http://www.bobbobel.com/smart-card-presentation-at-the-afitc/#comments</comments>
		<pubDate>Tue, 30 Aug 2011 16:02:50 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[HSBD-12]]></category>
		<category><![CDATA[Microsoft PKI]]></category>
		<category><![CDATA[PowerShell AD CMDLETS]]></category>
		<category><![CDATA[Safenet]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1123</guid>
		<description><![CDATA[Yesterday I had the opportunity to present at the Air Force Information Technology Conference 2011 on HSPD-12 and its impact on logical access control. While preparing for this session I realized I needed to re-visit Microsoft&#8217;s PKI (Public Key Infrastructure); especially changes in Windows 2008, Vista and Windows 7 strong authentication support. The first thing [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday I had the opportunity to present at the <a href="http://afitc.gunter.af.mil/">Air Force Information Technology Conference </a>2011 on HSPD-12 and its impact on logical access control. While preparing for this session I realized I needed to re-visit Microsoft&#8217;s PKI (Public Key Infrastructure); especially changes in Windows 2008, Vista and Windows 7 strong authentication support.</p>
<p>The first thing that struck me was how many good resources are available for learning Microsoft&#8217;s PKI. Back in 2000 when I first installed a Microsoft CA (Certificate Authority) there didn&#8217;t seem to be enough detailed information and over the past eleven years I have only had infrequent occasions to use the software. At this point I want to recommend Brian Komar&#8217;s book <a href="http://www.amazon.com/Windows-Server%C2%AE-Certificate-Security-ebook/dp/B004OR1Y0A/ref=sr_1_5?ie=UTF8&amp;qid=1314715186&amp;sr=8-5">Windows Server 2008 PKI and Certificate Security</a> (I got the Kindle version for about $39). I also wanted to mention Vadim Podans&#8217; white paper on PKI and using the Quest AD Commandlets to managed. You can download the <a href="http://www.quest.com/documents/landing.aspx?id=12189&amp;amp;technology=&amp;amp;prod=537&amp;amp;prodfamily=&amp;amp;loc=">white paper here </a>and you can get the latest version of the <a href="http://www.quest.com/powershell/activeroles-server.aspx" target="_blank">AD CMDLETS here</a>.</p>
<p style="text-align: center;"><a href="http://www.bobbobel.com/wp-content/uploads/2011/08/Safenet-CertInfo.png"><img class="aligncenter size-medium wp-image-1128" title="SafeNet Token Tools" src="http://www.bobbobel.com/wp-content/uploads/2011/08/Safenet-CertInfo-300x234.png" alt="" width="300" height="234" /></a></p>
<p>I also wanted to give a special thanks to Chen and John from <a href="http://www.safenet-inc.com/" target="_blank">SafeNet </a>for hooking me up with SafeNet middle-ware tools (above) and smart cards that I used for to prep for the session. The software was both intuitive and easy to deploy.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/smart-card-presentation-at-the-afitc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Delegation over mail enabled users and contacts only</title>
		<link>http://www.bobbobel.com/delegation-over-mail-enabled-users-and-groups-only/</link>
		<comments>http://www.bobbobel.com/delegation-over-mail-enabled-users-and-groups-only/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 12:49:21 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Demo]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[Bob Bobel]]></category>
		<category><![CDATA[Delegation over mail enabled objects]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1118</guid>
		<description><![CDATA[The ActiveRoles product comes with Roles (a.k.a. Access Templates) that use the native permission model to provide delegation. To perform delegation you need to identify the Role, the Trustee (in this case an OU Admin) and the scope. The first two are simple as you just select an Access Template and a user or group [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>ActiveRoles</strong> product comes with Roles (a.k.a. Access Templates) that use the native permission model to provide delegation. To perform delegation you need to identify the Role, the Trustee (in this case an OU Admin) and the scope. The first two are simple as you just select an Access Template and a user or group while the third can also be simple if you understand how to define custom scopes using Managed Units.  In this video I will show you how to delegate managing email address over mail enabled users and contacts, but not mailbox enabled users or groups.</p>
<p><iframe src="http://www.youtube.com/embed/IiSD2979uSo?hl=en&amp;fs=1" frameborder="0" width="425" height="349"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/delegation-over-mail-enabled-users-and-groups-only/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

