Thursday, August 19, 2010

Security Auditing in WebLogic

Weblogic provides an extensible mechanism to audit the activities of weblogic security framework. Weblogic security framework is the framework which takes care of all security related features in a weblogic server including authentication and authorization. Auditing is turned off by default.

The security framework comes out of the box with a DefaultAuditProvider which can be installed and configured into the security framework. When installed and configured in, it starts logging audit information into a file named DefaultAuditRecorder.log in the server log directory. If the default audit provider is not sufficient, users can write custom audit providers and have it installed and perform custom activities such as storing in database etc. The security framework is designed in a pluggable fashion and there can be multiple audit providers if desired.

All the components of the security framework such as authentication providers, authorization providers etc. emit audit events. If an audit provider is installed, then it receives these audit events and it can do whatever it wants with it. Obviously, the DefaultAuditProvider simply logs these events.

A generic audit event has the following information – (1) event type (2) severity level (information, warning, error, success and failure). The severity levels also have ranks associated with them, with “information” having the least rank and “failure” the maximum and (3) optional “context info” about the event (things like ejb method name and parameters in an authorization audit event).

The DefaultAuditProvider has configuration to choose the severity and context information to be filtered or propagated. This configuration is of course specific to the DefaultAuditProvider. A custom audit provider can have any other configuration as desired. Once the audit provider is installed, its settings can be changed at runtime without having to bounce WLS instance. All the settings and configurations are done through WLS console.

The security framework components also add extra data to the event by inheriting from the generic audit event. For example, events generated by the authentication provider have sub type which specifies the action being performed – such as authentication, identity assertion, user being locked etc. An authorization provider adds information regarding the resource being accessed and the subject accessing the resource. The interfaces for the sub events are well defined and a custom auditor can be more intelligent when dealing with the events. The DefaultAuditProvider does not bother much and just logs it using the “toString” semantics.


28 Comments:

Anonymous Anonymous said...

Hi to every , since I am genuinely eager of reading this webpage's post to be updated regularly. It carries good information.

my web-site: Moms Work From Home Jobs

6:36 PM  
Anonymous Anonymous said...

Hi there Dear, are you actually visiting this site on a regular basis, if so afterward you will definitely obtain good experience.


my web page ... tarifvergleich private krankenversicherung

8:35 PM  
Anonymous Anonymous said...

Wow, this paragraph is fastidious, my younger sister is analyzing these
things, therefore I am going to tell her.

Feel free to surf to my site :: Kredite Aus Der Schweiz

10:10 PM  
Anonymous Anonymous said...

Amazing! This blog looks just like my old one!
It's on a completely different topic but it has pretty much the same layout and design. Wonderful choice of colors!

my page :: website optimization companies

5:23 PM  
Anonymous Anonymous said...

Do you have a spam issue on this website; I also am a blogger, and
I was curious about your situation; many of us have developed some nice practices and we
are looking to trade methods with other folks, why not shoot me an
email if interested.

Feel free to surf to my web site ... secured loans

8:24 PM  
Anonymous Anonymous said...

Howdy! I simply wish to offer you a big thumbs up for your excellent info you have got right here on
this post. I will be coming back to your website for more soon.


Check out my blog - Mortgage With Bad Credit

8:32 PM  
Anonymous Anonymous said...

I could not refrain from commenting. Perfectly written!



Feel free to visit my homepage :: Vergleich Der Krankenkassen

10:27 PM  
Anonymous Anonymous said...

Its like you read my thoughts! You seem to know so much about this,
like you wrote the book in it or something.
I believe that you just could do with a few % to pressure the message house a little bit, however instead of that, that is magnificent blog. A great read. I will certainly be back.

Feel free to visit my site - wechsel von privat in gesetzliche krankenkasse

1:13 PM  
Anonymous Anonymous said...

Touche. Sound arguments. Keep up the great effort.

Check out my page; how to take out a home equity loan

2:22 PM  
Anonymous Anonymous said...

That is very interesting, You are a very professional blogger.
I've joined your rss feed and sit up for in quest of extra of your great post. Additionally, I've shared your website in my
social networks

Here is my blog beiträge zur privaten krankenversicherung

2:43 PM  
Anonymous Anonymous said...

Wow, amazing blog layout! How long have you been blogging for?
you made blogging look easy. The overall look of your site is wonderful, let alone
the content!

Feel free to surf to my web-site :: best business ideas 2011

7:49 PM  
Anonymous Anonymous said...

It's going to be end of mine day, however before finish I am reading this wonderful article to improve my experience.

Here is my blog google adsence

4:45 AM  
Anonymous Anonymous said...

Now I am going to do my breakfast, once having my breakfast coming over again to read more
news.

Here is my web site; to get a loan with bad credit

8:22 PM  
Anonymous Anonymous said...

When I initially commented I clicked the "Notify me when new comments are added" checkbox and now each time a comment
is added I get four e-mails with the same comment.
Is there any way you can remove me from that service?
Many thanks!

Here is my site: cheap best hosting

5:58 AM  
Anonymous Anonymous said...

Greetings! Very useful advice in this particular article!
It is the little changes that produce the most important changes.
Thanks for sharing!

Feel free to visit my web-site multiple website hosting

2:13 AM  
Anonymous Anonymous said...

Can I simply say what a relief to uncover somebody who truly knows what
they are discussing on the internet. You actually
know how to bring an issue to light and make it important.
A lot more people should look at this and understand this side of your story.
It's surprising you are not more popular because you most certainly possess the gift.

Feel free to visit my homepage; best home jobs Online

6:40 AM  
Anonymous Anonymous said...

Pretty nice post. I simply stumbled upon your blog and wanted to say that I've truly enjoyed surfing around your weblog posts. After all I'll be subscribing in your feed
and I hope you write again soon!

Feel free to visit my blog ... hilton head island vacation

4:29 AM  
Anonymous Anonymous said...

Hi, I do not realize that if you own your own
website in RSS reader. Are you able to enable me please:)

my blog: billigen urlaub

11:47 PM  
Blogger Unknown said...

ugg outlet
ugg boots
moncler outlet
canada goose jackets
belstaff jackets
woolrich outlet
barbour coats
parajumpers coats
wellensteyn jackets
canada goose jackets
nobis outlet
barbour coats
moncler jackets
black friday deals
black friday 2015
cyber monday deals
cyber monday 2015
winter coats
winter jackets
snow boots
ugg boots
ugg outlet
ugg outlet
ugg sale
ugg australia
discount ugg boots
cheap ugg boots
michael kors factory outlet
canada goose outlet
canada goose jackets
canada goose jackets
canada goose outlet
ray ban sunglasses
cheap ray ban sunglasses
coach outlet store
swarovski outlet
achang1212

2:25 PM  
Blogger John said...

coach outlet store online
canada goose jackets
pandora jewelry
michael kors outlet online
cheap oakley sunglasses
michael kors outlet
michael kors outlet online
uggs outlet
toms outlet
christian louboutin outlet
louis vuitton
nike roshe run
canada goose outlet
ugg boots outlet
abercrombie outlet
louis vuitton outlet online
coach outlet
coach factory outlet
nike air huarache
cheap ugg boots
replica watches for sale
retro jordans
hollister kids
ugg outlet store
michael kors outlet online
hollister
ed hardy clothing
gucci shoes
toms
ugg boots
oakley sunglasses
20151226yuanyuan

11:07 AM  
Blogger Unknown said...

http://demenageur-paris-devis.fr/devismontemeuble.php
http://demenageur-paris-devis.fr/devisgardemeuble.php
http://demenageur-paris-devis.fr/devistransfertentreprise.php
http://devis-demenagement-pascher.fr/devis-monte-meuble.php
http://devis-demenagement-pascher.fr/devis-garde-meuble.php
http://devis-demenagement-pascher.fr/devis-transfert-entreprise.php

5:21 PM  
Blogger oakleyses said...

christian louboutin uk, louis vuitton outlet, christian louboutin shoes, michael kors pas cher, louis vuitton outlet, sac longchamp pas cher, prada handbags, gucci handbags, tiffany and co, polo ralph lauren outlet online, christian louboutin outlet, cheap oakley sunglasses, longchamp outlet, uggs on sale, polo outlet, louis vuitton, nike air max, oakley sunglasses, longchamp outlet, nike free, nike outlet, longchamp outlet, longchamp pas cher, chanel handbags, nike air max, oakley sunglasses, nike free run, tiffany jewelry, oakley sunglasses wholesale, louboutin pas cher, ray ban sunglasses, ugg boots, replica watches, air max, louis vuitton outlet, oakley sunglasses, nike roshe, louis vuitton, tory burch outlet, ray ban sunglasses, jordan shoes, christian louboutin, prada outlet, polo ralph lauren, burberry pas cher, ugg boots, jordan pas cher, kate spade outlet, ray ban sunglasses

8:49 AM  
Blogger oakleyses said...

nike blazer pas cher, mulberry uk, burberry handbags, michael kors, timberland pas cher, oakley pas cher, ray ban uk, vans pas cher, coach purses, north face, nike free uk, new balance, ray ban pas cher, sac hermes, michael kors, nike air force, ralph lauren uk, nike air max, kate spade, nike roshe run uk, true religion jeans, north face uk, hogan outlet, michael kors outlet online, nike air max uk, uggs outlet, nike tn, burberry outlet, hollister uk, coach outlet store online, replica handbags, lululemon canada, michael kors outlet online, michael kors outlet online, michael kors outlet, michael kors outlet online, converse pas cher, michael kors outlet, true religion outlet, true religion outlet, polo lacoste, hollister pas cher, coach outlet, guess pas cher, true religion outlet, abercrombie and fitch uk, nike air max uk, sac vanessa bruno, michael kors outlet

8:50 AM  
Anonymous Débouchage canalisation Torcy said...

Excellent blog je vous invite à visité mon site web :
Débouchage évier Pontault Combault
Sosdebouchage

12:28 AM  
Anonymous canalisation bouchée vitry sur seine said...

good luck

9:00 PM  
Blogger yanmaneee said...

nike basketball shoes
air max 97
kobe shoes
curry 6 shoes
cheap mlb jerseys
michael kors outlet online
christian louboutin outlet
nike kd 11
ferragamo belts
nike air max

3:44 PM  
Anonymous chamilia wholesale chile said...

All the components of the security framework such as authentication providers, authorization providers etc. emit audit events. If an audit provider is installed, then it receives these audit events and it can do whatever it wants with it. Obviously, the DefaultAuditProvider simply logs these events. locket necklace chile , locket necklace germany ,

7:38 PM  
Anonymous Anonymous said...

hermes birkin bag
supreme clothing
fear of god essentials
giannis antetokounmpo shoes
kyrie irving shoes
fear of god
hermes
air jordan 1
golden goose outlet
golden goose sale

6:23 PM  

Post a Comment

<< Home