??xml version="1.0" encoding="utf-8" standalone="yes"?> Acegi Security 你可以选择怎么样在你的webFilterToBeanProxyFilterChainProxyFilterToBeanProxyweb.xml<filter> <filter-name>Acegi HTTP Request Security Filter</filter-name> <filter-class>org.acegisecurity.util.FilterToBeanProxy</filter-class> <init-param> <param-name>targetClass</param-name> <param-value>org.acegisecurity.ClassThatImplementsFilter</param-value> </init-param> </filter>
qo(h)?/strong>
]]>
]]>
]]>
]]>
]]>
q次译是因为我在学?fn)这个,随手翻译记录下来?jin)Q看到哪d哪了(jin)。多有些地Ҏ(gu)握不好语义,而且0.1版本肯定q没有校验的Q经不v考验的?br />
在翻译过E中遇到颇多的术语,鉴于本h知识面比较狭H,语文表达能力比较薄弱。有些地方就译?jin),多数地方q是用的原文?br />
我希望我能够译一大安能理解,q且没有歧义的东西出来。能够不出现偏差的结果就是我的梦想了(jin)。所以就?x)出C些英文,那些是我一时还没有扑ֈ合适的语言来表辄。还有一些可能是一时犯懒就没翻译的Q?br />
犯懒部分的内容一般会(x)是很Ҏ(gu)理解的;q有一U情况可能没有翻译的是英文表达的太完美?jin),我不忍?j)破坏。我会(x)在以后的日子里慢慢的完善Acegi Security 参考文档的译。诚然也?x)写我工作中的用,l对入门。因为我现在q是freshman?br />
一些术语:(x)
AuthenticationQ?w䆾验证Q确认用P有时候也能表辄陆,Zw䆾的验证,证明pȝ存在q个principal
AuthorizationQ?nbsp; 授权验证Q?font style="background-color: #d4d0c8">认已经登陆用户的权?/font>认已经登陆用户的权限,证明是否有够的权限
Application Context 应用E序上下文,ApplicationContext可以讉K
术语部分会(x)逐步d?br />
所有原文请参考:(x)http://www.acegisecurity.org/guide/springsecurity.html
]]>
在底层,你需要处理诸如transport security 和系ln份验?system identification)Q这栯够减?mitigate)man-in-the-middle attacks(怀疑就是减应用程序受到攻?.下一步,一般来说你需要一个防火墙Q也许是用VPNs或者IP安全措施来保证只有通过授权的系l能够连接。在公司的环境下Q你也许需要布|一个DMZ把公共服务期和后台数据库、应用服务器隔离。你的操作体l同h一个非帔R要的部分
addressing issues such as running processes as
non-privileged users and maximising file system security. An operating system will usually also be
configured with its own firewall. Hopefully somewhere along the way you'll be trying to prevent
denial of service and brute force attacks against the system. An intrusion detection system will also be
especially useful for monitoring and responding to attacks, with such systems able to take protective
action such as blocking offending TCP/IP addresses in real-time. Moving to the higher layers, your
Java Virtual Machine will hopefully be configured to minimize the permissions granted to different
Java types, and then your application will add its own problem domain-specific security configuration.
Acegi Security makes this latter area - application security - much easier.
Of course, you will need to properly address all security layers mentioned above, together with
managerial factors that encompass every layer. A non-exhaustive list of such managerial factors
would include security bulletin monitoring, patching, personnel vetting, audits, change control,
engineering management systems, data backup, disaster recovery, performance benchmarking, load
monitoring, centralised logging, incident response procedures etc.
With Acegi Security being focused on helping you with the enterprise application security layer, you
will find that there are as many different requirements as there are business problem domains. A
banking application has different needs from an ecommerce application. An ecommerce application
has different needs from a corporate sales force automation tool. These custom requirements make
application security interesting, challenging and rewarding.
该参考文档已lؓ(f)Acegi Security1.0.0版本重新设计改写。请阅读W一部分Q全面的设计架构Q其他部分就是按照传l的参考文写的,有需要的时候可以参考?br /> 我们希望你能从参考文档中得到帮助Q同h们也Ƣ迎你的和意见?br /> E后Q欢q来到Acegi Security C?br />
“Rose 2003 ?nbsp; Xp Home不能安装”
问题描述Q?br />
Rose 2003在Xp Home下安装会(x)出现“安装的操作系l不被支?#8221;提示Qƈl止安装?nbsp;
Rational官方|站UXp Home?Unsupported OS"
解决Ҏ(gu)Q?nbsp;
l过安装E序Ҏ(gu)作系l版本的(g)?nbsp;
注意Q该Ҏ(gu)只能保证安装E序得以q行Q不涉及(qing)Rose在Xp Home的实际运行效果?br />
目前为止Rose在笔者的Xp Homepȝ上表现良好?nbsp;
使用工具QMicrosoft Orca
下蝲Ҏ(gu)Q?nbsp;
http://support.microsoft.com/default.aspx?scid=kb;EN-US;255905#XSLTH3122121122120121120120
~者按Q在下蝲的地方,我找C(jin)PSDK-amd64.exe、PSDK-ia64.exe、PSDK-x86.exe?br />
没搞懂区别,不过我找?jin)个认识的x86下蝲?jin),看来中?jin)?/em>
使用Ҏ(gu)Q清先备份相应文Ӟ(j)Q?nbsp;
用Orca打开Setup/rose.msi,查找"xph",?x)定位到该行Q?nbsp;
(VersionNT AND (NOT RSWINXPHOME))OR (DISABLE_PLATFORM_BLOCKS = 1)|You are attempting to install on an...
用Table/drop row删除该行,保存该文Ӟ退?nbsp;
重新q行安装E序
注意Q同L(fng)限制条g出现在setup文g夹其他的msi文g中,但笔者在安装q程中没有遇到问题。如果你在安装某个特性的时候出现问题,可以使用上面的步骤修改相应的msi文g?nbsp;
~者:(x)
下蝲后安装吓?jin)我一跻I一看标题居然是微Y的plateform SDK。以Z错东西了(jin)呢,仔细看了(jin)下说明知道了(jin)大概。看来玩软gQreadmeq是必须要搞定先的了(jin)?br />
没事q译出来了(jin)Q如?br />
安装和运行Oraca
安装和运行Orca~辑器,参考下面步骤:(x)
1、从下面地址下蝲Windows Installer SDK例子、工具和文档
http://www.microsoft.com/downloads/details.aspx?FamilyId=A55B6B43-E24F-4EA3-A93E-40C0EC4F68E5&displaylang=en (http://www.microsoft.com/downloads/details.aspx?FamilyId=A55B6B43-E24F-4EA3-A93E-40C0EC4F68E5&displaylang=en)
2、在 \Microsoft SDK\bin目录下双击Orca.msi 安装Orca~辑?br />
3、开?-〉程?-〉敲 Orca
4、文件目录,点OpenQ找C惌收拾?msi文g
5、你惛_折腾折腑
不过话说回来Q微软出来也不是一天两天了(jin)Q在U个指导之前它说?jin)这么句?br />
警告Q?/strong>~辑MSI文g会(x)可能D严重的问题,严重的程度就是搞得你的系l不E_。微软不保证q些问题是由于修改MSI文g引v的,也不?x)保证这些问题能够解冟뀂修改这些文件呢在厂家指g?br />
当然׃国的玩家也不是闹的,Z(jin)问题q是自己搞定吧,彩头好了(jin)可以换个专业版xp?jin),不用考虑q个Oraca?jin)?br />
最后说句,我还在安装,不知后果如何~
====
可用Q不q过E就慢慢M?x)?..