﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>BlogJava-David.Turing's blog-最新评论</title><link>http://www.blogjava.net/security/CommentsRSS.aspx</link><description /><language>zh-cn</language><pubDate>Sat, 24 Aug 2013 00:12:47 GMT</pubDate><lastBuildDate>Sat, 24 Aug 2013 00:12:47 GMT</lastBuildDate><generator>cnblogs</generator><item><title>re: 0Day发布Confluence 2.1.4 破解，所见即所得的编辑界面终于亮相</title><link>http://www.blogjava.net/security/archive/2013/06/20/41538.html#400775</link><dc:creator>beichen</dc:creator><author>beichen</author><pubDate>Thu, 20 Jun 2013 05:57:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2013/06/20/41538.html#400775</guid><description><![CDATA[师兄，求密码，谢谢你百忙之中抽空来回复我！祝你工作顺利！<br>beichen2210@126.com<img src ="http://www.blogjava.net/security/aggbug/400775.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">beichen</a> 2013-06-20 13:57 <a href="http://www.blogjava.net/security/archive/2013/06/20/41538.html#400775#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 0Day发布Confluence 2.1.4 破解，所见即所得的编辑界面终于亮相</title><link>http://www.blogjava.net/security/archive/2013/04/02/41538.html#397313</link><dc:creator>游客</dc:creator><author>游客</author><pubDate>Tue, 02 Apr 2013 13:17:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2013/04/02/41538.html#397313</guid><description><![CDATA[clancy_js@163.com<br>兄台求密码<img src ="http://www.blogjava.net/security/aggbug/397313.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">游客</a> 2013-04-02 21:17 <a href="http://www.blogjava.net/security/archive/2013/04/02/41538.html#397313#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 解释CAS Logout问题</title><link>http://www.blogjava.net/security/archive/2013/01/04/68383.html#393763</link><dc:creator>liveandevil</dc:creator><author>liveandevil</author><pubDate>Fri, 04 Jan 2013 09:31:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2013/01/04/68383.html#393763</guid><description><![CDATA[<a href="https://login.cqu.edu.cn:8443/cas-server-webapp-3.2.1/logout" target="_new" rel="nofollow">https://login.cqu.edu.cn:8443/cas-server-webapp-3.2.1/logout</a>  但是logout还是能访问webapp1（就是当前webapp），这是为什么？我删除回话cookie后就不能访问了。（登录、验证都是可以的）<br>&lt;filter&gt;<br>		&lt;filter-name&gt;CASFilter&lt;/filter-name&gt;<br>		&lt;filter-class&gt;edu.yale.its.tp.cas.client.filter.CASFilter<br>		&lt;/filter-class&gt;<br>		&lt;init-param&gt;<br>			&lt;param-name&gt;edu.yale.its.tp.cas.client.filter.loginUrl&lt;/param-name&gt;<br>			&lt;param-value&gt;<a href="https://huxiapp.cqu.edu.cn:8443/cas-server-webapp-3.5.1/login&lt;/param-value&gt;" target="_new" rel="nofollow">https://huxiapp.cqu.edu.cn:8443/cas-server-webapp-3.5.1/login&lt;/param-value&gt;</a><br>		&lt;/init-param&gt;<br>		&lt;init-param&gt;<br>			&lt;param-name&gt;edu.yale.its.tp.cas.client.filter.validateUrl<br>			&lt;/param-name&gt;<br>			&lt;param-value&gt;<a href="https://huxiapp.cqu.edu.cn:8443/cas-server-webapp-3.5.1/proxyValidate&lt;/param-value&gt;" target="_new" rel="nofollow">https://huxiapp.cqu.edu.cn:8443/cas-server-webapp-3.5.1/proxyValidate&lt;/param-value&gt;</a><br>		&lt;/init-param&gt;<br>		&lt;init-param&gt;<br>			&lt;param-name&gt;edu.yale.its.tp.cas.client.filter.serverName&lt;/param-name&gt;<br>			&lt;param-value&gt;localhost:8888&lt;/param-value&gt;<br>		&lt;/init-param&gt;<br>	&lt;/filter&gt;<br>	&lt;filter-mapping&gt;<br>		&lt;filter-name&gt;CASFilter&lt;/filter-name&gt;<br>		&lt;url-pattern&gt;/*&lt;/url-pattern&gt;<br>	&lt;/filter-mapping&gt;<img src ="http://www.blogjava.net/security/aggbug/393763.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">liveandevil</a> 2013-01-04 17:31 <a href="http://www.blogjava.net/security/archive/2013/01/04/68383.html#393763#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 已经申请了Google Hosted Mail[未登录]</title><link>http://www.blogjava.net/security/archive/2012/11/26/102536.html#391966</link><dc:creator>SK</dc:creator><author>SK</author><pubDate>Mon, 26 Nov 2012 04:18:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2012/11/26/102536.html#391966</guid><description><![CDATA[给我一个邀请 谢谢了 magicbaby810@gmail.com<br><br><img src ="http://www.blogjava.net/security/aggbug/391966.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">SK</a> 2012-11-26 12:18 <a href="http://www.blogjava.net/security/archive/2012/11/26/102536.html#391966#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 0Day FTP服务器帐号密码</title><link>http://www.blogjava.net/security/archive/2012/11/23/50367.html#391832</link><dc:creator>刷刷刷</dc:creator><author>刷刷刷</author><pubDate>Fri, 23 Nov 2012 04:47:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2012/11/23/50367.html#391832</guid><description><![CDATA[看得懂的就是够资格了，看不懂就不要强求了。信息是经过加密的，对加密有所了解的都能轻易解开。<br><br>就是不知道2年前的信息，现在改了没有<img src ="http://www.blogjava.net/security/aggbug/391832.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">刷刷刷</a> 2012-11-23 12:47 <a href="http://www.blogjava.net/security/archive/2012/11/23/50367.html#391832#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Yale CAS异常问题总结(1)Unable to validate ProxyTicketValidator之HTTPS hostname wrong:  should be.....[未登录]</title><link>http://www.blogjava.net/security/archive/2012/10/24/67865.html#390176</link><dc:creator>cx</dc:creator><author>cx</author><pubDate>Wed, 24 Oct 2012 08:55:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2012/10/24/67865.html#390176</guid><description><![CDATA[edu.yale.its.tp.cas.client.CASAuthenticationException: Unable to validate ProxyTicketValidator [[edu.yale.its.tp.cas.client.ProxyTicketValidator proxyList=[null] [edu.yale.its.tp.cas.client.ServiceTicketValidator casValidateUrl=[<a href="https://cx.com:8443/cas/proxyValidate" target="_new" rel="nofollow">https://cx.com:8443/cas/proxyValidate</a>] ticket=[ST-1-BS35zseNBoCQaZwNWjUu-cas] service=[http%3A%2F%2Fcx.com%3A8080%2Fjsp-examples%2F] renew=false]]]<br> 使用域名依旧错误……<img src ="http://www.blogjava.net/security/aggbug/390176.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">cx</a> 2012-10-24 16:55 <a href="http://www.blogjava.net/security/archive/2012/10/24/67865.html#390176#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Programmer援助交际群证书发布</title><link>http://www.blogjava.net/security/archive/2012/09/06/26789.html#387187</link><dc:creator>程斌</dc:creator><author>程斌</author><pubDate>Thu, 06 Sep 2012 09:49:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2012/09/06/26789.html#387187</guid><description><![CDATA[找个好女人做朋友<img src ="http://www.blogjava.net/security/aggbug/387187.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">程斌</a> 2012-09-06 17:49 <a href="http://www.blogjava.net/security/archive/2012/09/06/26789.html#387187#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Apache License更适合中国人</title><link>http://www.blogjava.net/security/archive/2012/09/04/31787.html#386956</link><dc:creator>一只程序猿</dc:creator><author>一只程序猿</author><pubDate>Tue, 04 Sep 2012 06:16:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2012/09/04/31787.html#386956</guid><description><![CDATA[实在不能理解为何您使用原作者的代码还强硬的想要违背原作者的意愿和GPL，然后还说出宣战这种话，好似取得巨大胜利一般，无法理解！不管是对作者，对法律，对协议，连起码的尊重都没有！<img src ="http://www.blogjava.net/security/aggbug/386956.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">一只程序猿</a> 2012-09-04 14:16 <a href="http://www.blogjava.net/security/archive/2012/09/04/31787.html#386956#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Apache License更适合中国人</title><link>http://www.blogjava.net/security/archive/2012/05/19/31787.html#378553</link><dc:creator>dirtyacc@126.com</dc:creator><author>dirtyacc@126.com</author><pubDate>Sat, 19 May 2012 03:16:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2012/05/19/31787.html#378553</guid><description><![CDATA[@ds<br>同意。这么丢人的事居然还拿出来大书特书，好像自己抗战胜利似得。<br><br>还说“他已经对开源没兴趣。。。”，明明是自己不遵守开源协议，这人也有意思，居然还耐着性子回了那么多邮件<img src ="http://www.blogjava.net/security/aggbug/378553.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">dirtyacc@126.com</a> 2012-05-19 11:16 <a href="http://www.blogjava.net/security/archive/2012/05/19/31787.html#378553#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Certificate chain received from 客户端- 192.168.10.10 was not trusted causing SSL handshake failure</title><link>http://www.blogjava.net/security/archive/2011/10/09/58032.html#360248</link><dc:creator>11</dc:creator><author>11</author><pubDate>Sun, 09 Oct 2011 02:02:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/10/09/58032.html#360248</guid><description><![CDATA[jjjjj<img src ="http://www.blogjava.net/security/aggbug/360248.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">11</a> 2011-10-09 10:02 <a href="http://www.blogjava.net/security/archive/2011/10/09/58032.html#360248#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Yale CAS异常问题总结(1)Unable to validate ProxyTicketValidator之HTTPS hostname wrong:  should be.....[未登录]</title><link>http://www.blogjava.net/security/archive/2011/08/30/67865.html#357596</link><dc:creator>小猪</dc:creator><author>小猪</author><pubDate>Tue, 30 Aug 2011 10:20:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/08/30/67865.html#357596</guid><description><![CDATA[我的也是啊，用ip生成的cn，也是用ip访问，还是报这个错误啊<img src ="http://www.blogjava.net/security/aggbug/357596.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">小猪</a> 2011-08-30 18:20 <a href="http://www.blogjava.net/security/archive/2011/08/30/67865.html#357596#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 发现GDCA USBKey(电子钥匙)的CSP数字签名实现存在缺陷</title><link>http://www.blogjava.net/security/archive/2011/08/17/72073.html#356743</link><dc:creator>summit</dc:creator><author>summit</author><pubDate>Wed, 17 Aug 2011 13:43:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/08/17/72073.html#356743</guid><description><![CDATA[这个不是缺陷..出于安全考虑设计的<img src ="http://www.blogjava.net/security/aggbug/356743.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">summit</a> 2011-08-17 21:43 <a href="http://www.blogjava.net/security/archive/2011/08/17/72073.html#356743#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创]国内大部分的USBKey通过B/S方式（CAPICOM）产生数字签名的严重安全漏洞</title><link>http://www.blogjava.net/security/archive/2011/08/15/80837.html#356565</link><dc:creator>ca</dc:creator><author>ca</author><pubDate>Mon, 15 Aug 2011 06:48:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/08/15/80837.html#356565</guid><description><![CDATA[这是一个很矛盾的事情，我们曾经做过每次签名都要用户输入私钥保护PIN码，但结果很多用户（主要是像省厅这样的大业主）都嫌太麻烦，即使我们以安全要求强调这个问题。<br>还有更严重的问题，很多应用喜欢让用户在网页输入PIN码，这样后可以在不用户不知不觉前获取PIN码而进行各种私钥操作。<img src ="http://www.blogjava.net/security/aggbug/356565.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">ca</a> 2011-08-15 14:48 <a href="http://www.blogjava.net/security/archive/2011/08/15/80837.html#356565#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 解释CAS Logout问题</title><link>http://www.blogjava.net/security/archive/2011/08/01/68383.html#355516</link><dc:creator>say_hello</dc:creator><author>say_hello</author><pubDate>Mon, 01 Aug 2011 11:37:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/08/01/68383.html#355516</guid><description><![CDATA[@phoenix<br>调用特定方法   我只知道php是  phpCas：：logout（）  <br>而不是像这样直接去server上<a href="https://yale_casserver:8443/cas/lougout企图注销" target="_new" rel="nofollow">https://yale_casserver:8443/cas/lougout企图注销</a><img src ="http://www.blogjava.net/security/aggbug/355516.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">say_hello</a> 2011-08-01 19:37 <a href="http://www.blogjava.net/security/archive/2011/08/01/68383.html#355516#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创]实施WebService Security[WS-Security1.0]的Encrypt和Sign模式(XFire+WSS4J)</title><link>http://www.blogjava.net/security/archive/2011/06/02/62283.html#351630</link><dc:creator>xuezhishou</dc:creator><author>xuezhishou</author><pubDate>Thu, 02 Jun 2011 13:10:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/06/02/62283.html#351630</guid><description><![CDATA[不知楼主现在是否还能回答下问题！本人遇到了和srvrv12的第一个问题一样的问题，即在Sign的模式下一直出現 Could not invoke service.. Nested exception is org.codehaus.xfire.fault.XFireFault: WSS4JInHandler: security processing failed ，不知是否已经有人解决了，可否赐教下<br><img src ="http://www.blogjava.net/security/aggbug/351630.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">xuezhishou</a> 2011-06-02 21:10 <a href="http://www.blogjava.net/security/archive/2011/06/02/62283.html#351630#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创] SSO(Single Sign-on) in Action(上篇)[未登录]</title><link>http://www.blogjava.net/security/archive/2011/04/16/73199.html#348419</link><dc:creator>ddd</dc:creator><author>ddd</author><pubDate>Sat, 16 Apr 2011 13:54:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/04/16/73199.html#348419</guid><description><![CDATA[看不出CAS和SAML的差别<br><br>你画的那个SAML再加一个服务 实际上整个流程就是CAS了<br><br><br>Ticket和断言除了叫法不一样之外 有什么差别?<img src ="http://www.blogjava.net/security/aggbug/348419.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">ddd</a> 2011-04-16 21:54 <a href="http://www.blogjava.net/security/archive/2011/04/16/73199.html#348419#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 微软开始使用Google广告了[未登录]</title><link>http://www.blogjava.net/security/archive/2011/03/29/97600.html#347224</link><dc:creator>me</dc:creator><author>me</author><pubDate>Tue, 29 Mar 2011 09:23:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/03/29/97600.html#347224</guid><description><![CDATA[test<img src ="http://www.blogjava.net/security/aggbug/347224.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">me</a> 2011-03-29 17:23 <a href="http://www.blogjava.net/security/archive/2011/03/29/97600.html#347224#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Apache License更适合中国人[未登录]</title><link>http://www.blogjava.net/security/archive/2011/02/03/31787.html#343881</link><dc:creator>ds</dc:creator><author>ds</author><pubDate>Wed, 02 Feb 2011 22:57:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/02/03/31787.html#343881</guid><description><![CDATA[丢人。<img src ="http://www.blogjava.net/security/aggbug/343881.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">ds</a> 2011-02-03 06:57 <a href="http://www.blogjava.net/security/archive/2011/02/03/31787.html#343881#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Unexpected Signal : EXCEPTION_ACCESS_VIOLATION</title><link>http://www.blogjava.net/security/archive/2011/01/06/56000.html#342427</link><dc:creator>replica watch</dc:creator><author>replica watch</author><pubDate>Thu, 06 Jan 2011 07:00:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2011/01/06/56000.html#342427</guid><description><![CDATA[# An error report file with more information is saved as hs_err_pid1964.log <img src ="http://www.blogjava.net/security/aggbug/342427.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">replica watch</a> 2011-01-06 15:00 <a href="http://www.blogjava.net/security/archive/2011/01/06/56000.html#342427#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Apache License更适合中国人[未登录]</title><link>http://www.blogjava.net/security/archive/2010/12/28/31787.html#341649</link><dc:creator>maple</dc:creator><author>maple</author><pubDate>Tue, 28 Dec 2010 01:36:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/12/28/31787.html#341649</guid><description><![CDATA[坦白地说是不是样板戏看多了，不要选择斗争，没有好处的。<br>你既然是用他的代码就该遵守授权，这是天经地义的。<br><br>我个人不看盗版碟片、不用盗版软件：包括操作系统是自己购买的。<img src ="http://www.blogjava.net/security/aggbug/341649.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">maple</a> 2010-12-28 09:36 <a href="http://www.blogjava.net/security/archive/2010/12/28/31787.html#341649#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创] SSO(Single Sign-on) in Action(上篇)</title><link>http://www.blogjava.net/security/archive/2010/12/13/73199.html#340556</link><dc:creator>Jacklondon Chen</dc:creator><author>Jacklondon Chen</author><pubDate>Mon, 13 Dec 2010 14:38:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/12/13/73199.html#340556</guid><description><![CDATA[有几点不同意：<br>1. 虽然身份管理软件都非常强，但成本同时也很高. ---当然也有便宜的。我们的 sso 就比较便宜。<br><a href="http://zhegui.biz" target="_new" rel="nofollow">http://zhegui.biz</a><br>2. 不看好 SAML ， 不实用。<br>3. 喜欢 SAML 的另一个原因是因为，它跟 SOAP 一样，不考虑传输协议 ----实际上, SOAP 最常用的协议是 HTTP, 其它如 JMS 基本上无人实用。<br>所谓不考虑传输协议，并非什么优点。因为最后实用的，其实只有一种。<img src ="http://www.blogjava.net/security/aggbug/340556.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">Jacklondon Chen</a> 2010-12-13 22:38 <a href="http://www.blogjava.net/security/archive/2010/12/13/73199.html#340556#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 关于JVM的Thin Lock, Fat Lock, SPIN Lock与Tasuki Lock</title><link>http://www.blogjava.net/security/archive/2010/12/02/254880.html#339611</link><dc:creator>游客</dc:creator><author>游客</author><pubDate>Thu, 02 Dec 2010 07:02:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/12/02/254880.html#339611</guid><description><![CDATA[达人呀。研究的很深呀。<br><img src ="http://www.blogjava.net/security/aggbug/339611.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">游客</a> 2010-12-02 15:02 <a href="http://www.blogjava.net/security/archive/2010/12/02/254880.html#339611#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创] SSO(Single Sign-on) in Action(上篇)</title><link>http://www.blogjava.net/security/archive/2010/12/02/73199.html#339591</link><dc:creator>jacklondon chen</dc:creator><author>jacklondon chen</author><pubDate>Thu, 02 Dec 2010 03:54:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/12/02/73199.html#339591</guid><description><![CDATA[有另一种 single sign on 的工作模式，反向代理(reverse proxy)。<br>见这里：<br>ZSSO<br><a href="http://zhegui.biz" target="_new" rel="nofollow">http://zhegui.biz</a><img src ="http://www.blogjava.net/security/aggbug/339591.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">jacklondon chen</a> 2010-12-02 11:54 <a href="http://www.blogjava.net/security/archive/2010/12/02/73199.html#339591#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创] SSO(Single Sign-on) in Action(上篇)</title><link>http://www.blogjava.net/security/archive/2010/12/02/73199.html#339584</link><dc:creator>游客</dc:creator><author>游客</author><pubDate>Thu, 02 Dec 2010 03:14:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/12/02/73199.html#339584</guid><description><![CDATA[确实是一篇对cas原理的好文章。<br>david.turing怎么那么长时间没有更新blog，是否换地方了。<br>期待你的blog继续。<img src ="http://www.blogjava.net/security/aggbug/339584.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">游客</a> 2010-12-02 11:14 <a href="http://www.blogjava.net/security/archive/2010/12/02/73199.html#339584#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 关于Weblogic 10下开发WebService的配置问题</title><link>http://www.blogjava.net/security/archive/2010/11/19/137275.html#338466</link><dc:creator>sdf</dc:creator><author>sdf</author><pubDate>Fri, 19 Nov 2010 04:31:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/11/19/137275.html#338466</guid><description><![CDATA[sdafsd<img src ="http://www.blogjava.net/security/aggbug/338466.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">sdf</a> 2010-11-19 12:31 <a href="http://www.blogjava.net/security/archive/2010/11/19/137275.html#338466#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Apache License更适合中国人</title><link>http://www.blogjava.net/security/archive/2010/09/29/31787.html#333409</link><dc:creator>路人甲</dc:creator><author>路人甲</author><pubDate>Wed, 29 Sep 2010 09:11:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/09/29/31787.html#333409</guid><description><![CDATA[有病。你会不会觉得银行保安系统不顺眼，你就是要去抢银行？<br><img src ="http://www.blogjava.net/security/aggbug/333409.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">路人甲</a> 2010-09-29 17:11 <a href="http://www.blogjava.net/security/archive/2010/09/29/31787.html#333409#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 使用PGP你的文章进行签名</title><link>http://www.blogjava.net/security/archive/2010/09/16/34511.html#332222</link><dc:creator>甲子龙</dc:creator><author>甲子龙</author><pubDate>Thu, 16 Sep 2010 10:00:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/09/16/34511.html#332222</guid><description><![CDATA[如果要PGP签名有效，就要把你的公钥传递到PGP验证服务器上去，中国的和外国的都传才行。<img src ="http://www.blogjava.net/security/aggbug/332222.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">甲子龙</a> 2010-09-16 18:00 <a href="http://www.blogjava.net/security/archive/2010/09/16/34511.html#332222#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 使用PGP你的文章进行签名</title><link>http://www.blogjava.net/security/archive/2010/08/12/34511.html#328618</link><dc:creator>zhaiduo</dc:creator><author>zhaiduo</author><pubDate>Thu, 12 Aug 2010 02:33:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/08/12/34511.html#328618</guid><description><![CDATA[现在不是用PnuPGP吗<img src ="http://www.blogjava.net/security/aggbug/328618.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">zhaiduo</a> 2010-08-12 10:33 <a href="http://www.blogjava.net/security/archive/2010/08/12/34511.html#328618#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 0Day FTP服务器帐号密码</title><link>http://www.blogjava.net/security/archive/2010/08/02/50367.html#327735</link><dc:creator>Clarence</dc:creator><author>Clarence</author><pubDate>Mon, 02 Aug 2010 04:44:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/08/02/50367.html#327735</guid><description><![CDATA[也給我一個.....<br>clarence@clarence.twbbs.org<img src ="http://www.blogjava.net/security/aggbug/327735.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">Clarence</a> 2010-08-02 12:44 <a href="http://www.blogjava.net/security/archive/2010/08/02/50367.html#327735#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Apache License更适合中国人</title><link>http://www.blogjava.net/security/archive/2010/07/05/31787.html#325260</link><dc:creator>xaverine</dc:creator><author>xaverine</author><pubDate>Mon, 05 Jul 2010 01:57:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/07/05/31787.html#325260</guid><description><![CDATA[我去看了一下GPL的內容<br>其實GPL是完全的開放(強制性)<br>也就是只要你使用了GPL的代碼<br>您就必須要開放&quot;所有&quot;的代碼<br>包含您的創作<br>在另一方面Wayne本身也沒有權利將GPL的代碼relicense(就算他是原作者)<br>您只要使用任何一部分Wayne的source也必須是GPL<br>您是無法relicense就跟Wayne一樣<br><img src ="http://www.blogjava.net/security/aggbug/325260.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">xaverine</a> 2010-07-05 09:57 <a href="http://www.blogjava.net/security/archive/2010/07/05/31787.html#325260#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Yale CAS异常问题总结(2)Unable to validate ProxyTicketValidator之unable to find valid certification path to requested target[未登录]</title><link>http://www.blogjava.net/security/archive/2010/06/30/67944.html#324888</link><dc:creator>堕落佛</dc:creator><author>堕落佛</author><pubDate>Wed, 30 Jun 2010 07:22:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/06/30/67944.html#324888</guid><description><![CDATA[@oldman<br><br>你看看你是不是显示声明了 trustStore的位置，如果是的话，看看那个位置对不对<img src ="http://www.blogjava.net/security/aggbug/324888.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">堕落佛</a> 2010-06-30 15:22 <a href="http://www.blogjava.net/security/archive/2010/06/30/67944.html#324888#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Yale CAS异常问题总结(2)Unable to validate ProxyTicketValidator之unable to find valid certification path to requested target</title><link>http://www.blogjava.net/security/archive/2010/06/26/67944.html#324562</link><dc:creator>zhaoyanh</dc:creator><author>zhaoyanh</author><pubDate>Sat, 26 Jun 2010 09:19:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/06/26/67944.html#324562</guid><description><![CDATA[@yongyuan.jiang<br>经验总结，需要将CAS服务器的证书文件，不是CRT文件，而是用KEYTOOL生成的数据文件拷贝到应用服务器上，用keytool  -import 导入到已在应用服务上自己生成的证书文件中（cacerts）,用 -list 命令查看变成了2条，一条是自己的，一条是CAS服务器的，将这个文件拷贝到JVM环境中，就好用了。<img src ="http://www.blogjava.net/security/aggbug/324562.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">zhaoyanh</a> 2010-06-26 17:19 <a href="http://www.blogjava.net/security/archive/2010/06/26/67944.html#324562#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 跟XFire对比, AXIS2是垃圾吗? </title><link>http://www.blogjava.net/security/archive/2010/06/13/65249.html#323531</link><dc:creator>hongweigg</dc:creator><author>hongweigg</author><pubDate>Sun, 13 Jun 2010 09:56:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/06/13/65249.html#323531</guid><description><![CDATA[@bwzhang<br>有理,无端的谩骂和牢骚只能说明没搞懂它<img src ="http://www.blogjava.net/security/aggbug/323531.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">hongweigg</a> 2010-06-13 17:56 <a href="http://www.blogjava.net/security/archive/2010/06/13/65249.html#323531#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 0Day发布Confluence 2.1.4 破解，所见即所得的编辑界面终于亮相</title><link>http://www.blogjava.net/security/archive/2010/05/12/41538.html#320725</link><dc:creator>b</dc:creator><author>b</author><pubDate>Wed, 12 May 2010 09:39:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/05/12/41538.html#320725</guid><description><![CDATA[changbaozc@163.com 解压密码，谢谢！<img src ="http://www.blogjava.net/security/aggbug/320725.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">b</a> 2010-05-12 17:39 <a href="http://www.blogjava.net/security/archive/2010/05/12/41538.html#320725#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Weblogic download url记载</title><link>http://www.blogjava.net/security/archive/2010/04/14/36450.html#318308</link><dc:creator>俞敏洪</dc:creator><author>俞敏洪</author><pubDate>Wed, 14 Apr 2010 10:04:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/04/14/36450.html#318308</guid><description><![CDATA[很好<img src ="http://www.blogjava.net/security/aggbug/318308.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">俞敏洪</a> 2010-04-14 18:04 <a href="http://www.blogjava.net/security/archive/2010/04/14/36450.html#318308#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 使用PGP你的文章进行签名</title><link>http://www.blogjava.net/security/archive/2010/04/08/34511.html#317693</link><dc:creator>Easy PGP</dc:creator><author>Easy PGP</author><pubDate>Thu, 08 Apr 2010 01:51:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/04/08/34511.html#317693</guid><description><![CDATA[Web-based 的 PGP 加密軟體. 使用者只要以瀏灠器就能進行PGP加密運算, 個人電腦上完全不用安裝任何軟體, 使用者可以在任何時間, 任何地點, 不管電腦是Windows, Linux, Mac, 都能很方便的保護機密資料<img src ="http://www.blogjava.net/security/aggbug/317693.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">Easy PGP</a> 2010-04-08 09:51 <a href="http://www.blogjava.net/security/archive/2010/04/08/34511.html#317693#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创] SSO(Single Sign-on) in Action(上篇)[未登录]</title><link>http://www.blogjava.net/security/archive/2010/03/25/73199.html#316522</link><dc:creator>lucifer</dc:creator><author>lucifer</author><pubDate>Thu, 25 Mar 2010 05:17:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/03/25/73199.html#316522</guid><description><![CDATA[@rogershi<br>这个凭证是与某个service有关的，目的是为了让SP去IdP（注意，我看到的文档中没有IDP这玩意儿）那里获得用户信息。如果获得成功，必然在cas client会产生一个标识（可能是seesion），那么下次用户访问的时候client发现这个session有效的话，就不会去cas server了。<br>一旦，这个session过期，那么client还是会重定向会cas server。这时候，由于TGC的存在，cas server端 验证机制发现该用户已经登入，就无需再输入user，pass了。直接产生ST返回给client，发生后续动作。<br>可以看到，TG是一次性的，用于获取用户信息。<br>真正实现SSO的是靠TGC，这个才是标明了用户已经登入。<br>lz没有提到一个的一点是，sso和federation其实是分离的。再saml2.0中把这两种都包含进来了。之所以这么说是因为，我看到siteminder即做sso，又做federation会很贵。由于siteminder可以customize，因此，有些公司买了部分siteminder做sso，通过PingFederate来做federation，这样可以节约很多成本。<br>希望lz可以更新文章，文章写得很不错，但是对于初学可能还是有点难度。不过，这种课题单看一片文章就能够完全懂 确实不太现实。<img src ="http://www.blogjava.net/security/aggbug/316522.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">lucifer</a> 2010-03-25 13:17 <a href="http://www.blogjava.net/security/archive/2010/03/25/73199.html#316522#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创] SSO(Single Sign-on) in Action(上篇)</title><link>http://www.blogjava.net/security/archive/2010/03/08/73199.html#314875</link><dc:creator>rogershi</dc:creator><author>rogershi</author><pubDate>Mon, 08 Mar 2010 12:46:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2010/03/08/73199.html#314875</guid><description><![CDATA[service ticket在服务器端只能被访问一次，无论鉴权成功与否，都要销毁。<br><br>如果是这样的话，客户端又怎么能通过TGC达到SSO呢？实在是难以理解啊<img src ="http://www.blogjava.net/security/aggbug/314875.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">rogershi</a> 2010-03-08 20:46 <a href="http://www.blogjava.net/security/archive/2010/03/08/73199.html#314875#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创] SSO(Single Sign-on) in Action(上篇)</title><link>http://www.blogjava.net/security/archive/2009/12/22/73199.html#306876</link><dc:creator>chy.chan@hotmail.com</dc:creator><author>chy.chan@hotmail.com</author><pubDate>Tue, 22 Dec 2009 02:07:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2009/12/22/73199.html#306876</guid><description><![CDATA[请教版主，cas支持DOMINO吗<img src ="http://www.blogjava.net/security/aggbug/306876.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">chy.chan@hotmail.com</a> 2009-12-22 10:07 <a href="http://www.blogjava.net/security/archive/2009/12/22/73199.html#306876#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: [原创] SSO(Single Sign-on) in Action(上篇)</title><link>http://www.blogjava.net/security/archive/2009/12/02/73199.html#304550</link><dc:creator>qq：553273295</dc:creator><author>qq：553273295</author><pubDate>Wed, 02 Dec 2009 13:06:00 GMT</pubDate><guid>http://www.blogjava.net/security/archive/2009/12/02/73199.html#304550</guid><description><![CDATA[迄今为止读的最好的一篇关于sso的文章。如果作者来长沙讲课的话，本人愿意花钱去听你的讲座。<img src ="http://www.blogjava.net/security/aggbug/304550.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/security/" target="_blank">qq：553273295</a> 2009-12-02 21:06 <a href="http://www.blogjava.net/security/archive/2009/12/02/73199.html#304550#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>