Hi all,  I have to write a Master Thesis for my study "Applied IT  
Security" at the university of Bochum, Germany.

I convinced my mentors to have a topic about security of geodata  
infrastructures. The title will be something like

"Building a secure GDI using Geoserver,Spring Security,SAML and GeoXACML"

The thesis has 3 main parts.

1) Integration of Spring Security 3.0 into geoserver. This gives us  
the possibility to offer a lot of authentication mechanisms including  
customized plugins.
http://static.springsource.org/spring-security/site/docs/3.0.x/reference/introduction.html#what-is-acegi-security
There are also nice possibilities for access control like a new  
expression syntax.

2) Examine how to integrate the geoxacml community module as spring  
access plugin into geoserver.

3) Take a deeper look into SAML ( "Single Sign On" would be a nice thing).


The first part has top priority. The existing file based access  
control system should be refactored to fit into Spring 3.0. No user  
action should be necessary. I do not want to break existing security  
deployments.

It is also possible to write the thesis in English. The idea is to  
have about 60 pages as documentation, the rest of the work is  
coding/integrating. Since I am not a native English speaker, is there  
anybody who can read my thesis and correct my mistakes ?

Opinions, Votes ?

Cheers
Christian




----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.



------------------------------------------------------------------------------
Virtualization is moving to the mainstream and overtaking non-virtualized
environment for deploying applications. Does it make network security 
easier or more difficult to achieve? Read this whitepaper to separate the 
two and get a better understanding.
http://p.sf.net/sfu/hp-phase2-d2d
_______________________________________________
Geoserver-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Reply via email to