InfoQ

Interview

ASP.NET Authentication Practices with Josh Holmes

Interview with Josh Holmes on Mar 06, 2007 05:00 AM

Community
.NET
Topics
Security
Tags
ASP.NET
Summary
ASP.NET authentication and authorization is essentially a solved problem in ASP.NET 2.0 according to .NET guru Josh Holmes. While the built in authorization providers offer 90% coverage, Josh also discusses when you should utilize a custom provider. Join Josh for ASP.NET tips and tricks in this interview done by David Totzke at VSLive Toronto.

Bio
Josh Holmes is a principal of SRT Solutions as well as a Microsoft MVP and INETA Speaker Bureau member. He helps his clients-ranging from the Fortune 500 to small firms-to understand and implement an array of software technology, including .NET.
I'm here at VS Live with Josh Holmes. Josh could you please introduce yourself, tell us who you are and what you do?
One of your focuses is on security especially in the ASP.NET world, and you mentioned that authentication is basically a solved problem.
Once the user is authenticated, the next problem that is not so well defined at this point is authorization. What should be the guidance?
What do you do in the ASP.NET space to wire up for authorization seamlessly?
You mentioned that there's the built in authorization providers, you also mentioned that we can create a custom provider. Have you got an example of that?
How do we get authorization and authentication integrated for FTP or Telnet?
Great. Thank you very much for sharing your time with us and good luck with the rest of the conference.
show all  show all

1 comment

Reply

infoq interviews by Arne Garvander Posted Mar 18, 2007 7:20 PM
  1. Back to top

    infoq interviews

    Mar 18, 2007 7:20 PM by Arne Garvander

    flash player doesn't seem to work in ie/vista. Am I wrong?

Exclusive Content

10 Ways to Screw Up with Scrum and XP

Henrik Kniberg talks about 10 possible reasons to fail while doing Scrum and XP. Maybe the team does not have a definition of what Done means to them, or they don't know what their velocity is.

Tips from a Top Sports Team Coach

This article outlines 9 principles Marc Lammers discovered while building the world’s best field hockey team, mapping them to software development practices.

SOA Governance: An Enterprise View

Michael Poulin explains the necessity for SOA governance to ensure an Enterprise SOA's success, relying on concepts from the OASIS SOA Reference Model and Reference Architecture.

Developing Portlets using JSF, Ajax, and Seam (Part 2 of 3)

This article covers setting up a RichFaces portlet using JBoss Portlet Container and JBoss Portlet Bridge, deploying a RichFaces portlet, and RichFaces capabilities.

Scalability Worst Practices

This article discusses scalability worst pratices including The Golden Hammer, Resource Abuse, Big Ball of Mud, Dependency Management, Timeouts, Hero Pattern, Not Automating, and Monitoring.

Do the Hustle

Obie Fernandez shares his experience selling consulting services for both Thoughtworks and Hashrocket and give tips how Ruby developers can work with clients.

Natural Laws of Software Development - Deriving Agile Practices

Jeffries and Hendrickson derive Agile practices from the natural laws of software development. They don't just say "Be Agile!", but they explain why Agile practices make perfect sense.

Jinesh Varia About Amazon Alexa Web Service's Architecture

Jinesh Varia talks about the architecture of one of Amazon's web services called Alexa. Jinesh explains how Amazon has reached scalability, performance and reduced costs for the Alexa service.