- Porównanie EJB i przyszłość rozwoju - http://www.theserverside.com/tt/articles/article.tss?track=NL-461&ad=666661&l=NewFeaturesinEJB31-Part5&asrc=EM_NLN_4711771&uid=267959
- Czy EJB zawsze musi się kojarzyć z BEA czy IBM? Niekoniecznie - są kontenery nie wymagające Java EE np.:
- OpenEJB (EJB 3 container for Apache Geronimo and WebSphere Community Edition)
- EasyBeans (extracted from the JOnAS application server)
- Embedded JBoss
- nawet GlassFish
- OpenEJB (EJB 3 container for Apache Geronimo and WebSphere Community Edition)
- Zalecane praktyki AJAX - http://developer.yahoo.com/performance/rules.html
- DNJ - jest za darmo po wcześniejszej rejestracji - http://dnjonline.com/article.aspx?ID=dotNET2_webapps
- Sprawdzanie podpisu XML w .NET - file:///C:/Users/marekw/AppData/Roaming/Mozilla/Firefox/Profiles/epc3mo09.default/ScrapBook/data/20080826161002/index.html
- Inne posty:
- http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=2867604&SiteID=1
- http://msdn.microsoft.com/en-us/magazine/cc163454.aspx
- http://blogs.msdn.com/shawnfa/archive/2004/03/31/105137.aspx
- http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=2155375&SiteId=1
- http://social.msdn.microsoft.com/forums/en-US/netfxbcl/thread/fd3df8d5-1e20-4a64-b75d-f3efbbabaeb6/
- http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=2867604&SiteID=1
- http://blogs.msdn.com/shawnfa/archive/2006/02/27/539990.aspx
- http://blogs.msdn.com/shawnfa/archive/2008/07/10/clr-security-team-codeplex-site.aspx
- http://www.softwaremaker.net/blog/xadesinteropwithxmldsigasimplementedbythenetframework.aspx
- http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=2867604&SiteID=1
- Odwleczone wiązanie danych - http://www.codeproject.com/KB/cs/dyninvok.aspx
- Wstęp do MS Mesh - https://www.mesh.com/Welcome/Welcome.aspx
- MS Mesh na slideshae - http://www.slideshare.net/jeffblankenburg/amazing-things-you-need-to-see/
- Wprowadzenie AJAX do istniejących formularzy - http://www.ibm.com/developerworks/web/library/wa-aj-overhaul4/index.html?S_TACT=105AGX01&S_CMP=HP
- VFP:
- Ustalanie w VFP szerokości czcionki - http://doughennig.blogspot.com/2006/04/forget-txtwidth-use-gdipmeasurestring.html
- Prezentacja GRID - http://www.garfieldhudson.com/freevideos/online/lvfp_app_pt3/lvfp_app_pt3.html
- VFP lightbox - http://weblogs.foxite.com/bernardbout/archive/2008/09/13/6768.aspx
- http://www.west-wind.com/presentations/dotnetwebservices/DotNetWebServices.asp
- Ustalanie w VFP szerokości czcionki - http://doughennig.blogspot.com/2006/04/forget-txtwidth-use-gdipmeasurestring.html
- Podpis:
- http://java.sun.com/j2se/1.5.0/docs/guide/security/p11guide.html
- http://forums.sun.com/forum.jspa?forumID=9&start=0
- http://java.sun.com/j2se/1.5.0/docs/guide/security/p11guide.html
- Zabezpieczenie cookie - http://rollercoasters-bunker.blogspot.com/2008/07/secureencrypted-cookies-in-aspnet-with.html
- Jak tworzyć servlety (best practices) - http://java.sun.com/developer/technicalArticles/javaserverpages/servlets_jsp/
- Ataki typu DLL - http://blogs.msdn.com/david_leblanc/archive/2008/02/20/dll-preloading-attacks.aspx
- Bezpieczeństwo MS:
- http://www.asp.net/learn/security-videos/
- http://www.asp.net/learn/security-videos/video-376.aspx
- http://whitepapers.techrepublic.com.com/thankyou.aspx?&promo=SINGLE&tag=nl.rSINGLE&docid=379457&view=379457&load=1&load=1
- http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032370631&EventCategory=5&culture=en-US&CountryCode=US
- Co oni dają za darmo - http://www.nthpenguin.com/content/WebWidgetry.aspx
- http://www.asp.net/learn/security-videos/
- Przepisy o podpisie:
- http://ipsec.pl/ministerstwa-odpowiadaja-w-sprawie-podpisu-elektronicznego.html:
- http://ipsec.pl/podpis-elektroniczny/2008/czy-mozna-zbudowac-tania-e-fakture-w-oparciu-o-edi.html
- http://www.ecr.pl/grupa_edi/index.php?ac=efaktura
- http://ipsec.pl/podpis-elektroniczny/2008/czy-mozna-zbudowac-tania-e-fakture-w-oparciu-o-edi.html
- http://ipsec.pl/podpis-elektroniczny/dokument-elektroniczny/faktura-elektroniczna-(e-faktura)/.html
- http://ipsec.pl/problemy-legalno%C5%9Bci-faktury-elektronicznej.html
- http://ipsec.pl/ministerstwa-odpowiadaja-w-sprawie-podpisu-elektronicznego.html:
- Wprowadzając e-Fakturę musimy podpisać umowę:
- O co narzuca dyrektywa to konieczność podpisania przez dwie strony transakcji umowy (udostępnione wzory nazywa się "umowami modelowymi"). Umowa EDI reguluje następujące kwestie:
- wzajemną uznawalność dokumentów elektronicznych,
- terminy doręczeń i rozliczeń dokumentów elektronicznych,
- zakres dokumentów, które mogą być przesyłane elektronicznie i które są dla stron wiążące,
- obsługę sytuacji spornych np. opóźnienia w dostarczeniu dokumentu,
- format i zabezpieczenia przesyłanych dokumentów.
- Ostatni punkt jest zwykle delegowany do "aneksu technicznego", również udostępnianego z różnymi "umowami modelowymi". Przykładem konkretnej implementacji "aneksu technicznego" opartego o standardy EANCOM jest umowa modelowa opublikowana przez ECR.
- Wprowadzenie do jQuery - http://www.west-wind.com/presentations/jQuery/default.aspx
- Specjalne odwołania do Java:
- Wicket i trwałość stanu - http://www.javaworld.com/javaworld/jw-09-2008/jw-09-wicket3.html?nhtje=rn_100908&nladname=100908javaworld'senterprisejavaal
- Rozmowa z Bloch na temat konstruowania - http://www.javaworld.com/javaworld/jw-01-2002/jw-0104-bloch.html?nhtje=rn_100908&nladname=100908
- Wstęp do Web4J - http://www.javaworld.com/javaworld/jw-10-2008/jw-10-web4j.html?nhtje=rn_100908&nladname=100908
- Poszerzenia Java - http://www.ajaxonomy.com/2008/java/jumping-in-java
- Abstract Factory Pattern -http://www.informit.com/guides/content.aspx?g=java&seqNum=442
- Przewodnik po Java - http://www.informit.com/guides/guide.aspx?g=java
- Spring MVC - http://www.informit.com/guides/content.aspx?g=java&seqNum=448
- GofF - http://www.informit.com/guides/content.aspx?g=java&seqNum=441
- Spring i Hibernate - http://www.informit.com/guides/content.aspx?g=java&seqNum=449
- WS - http://www.informit.com/articles/article.aspx?p=27645
- WS :
- Blog sun-a - http://java.sun.com/javaee/community/blogs/?feed=JSC
- Kursy programowania - http://www.idevelopment.info/data/Programming/java/PROGRAMMING_Java_Programming.shtml
piątek, października 10, 2008
środa, października 08, 2008
- SUN - wzorzec DOA - http://java.sun.com/blueprints/corej2eepatterns/Patterns/DataAccessObject.html
- SUN - nauka JAVA - http://java.sun.com/docs/books/tutorial/java/IandI/override.html
- Kursy w zakresie Java - http://www.idevelopment.info/data/Programming/java/PROGRAMMING_Java_Programming.shtml
- Odbicia w Java - http://www.onjava.com/pub/a/onjava/2007/03/15/reflections-on-java-reflection.html?page=1
- Nauka Java w portalu NetBeans - http://www.netbeans.org/features/web/web-app.html
- Nauka Java od samego SUN-a - http://java.sun.com/javaee/community/blogs/?feed=JSC
- Serwis z dużą iloscią informacji o .NET - http://www.windowshosting.pl/
- Strona MS o bezpieczeństwie dla deweloperów - http://msdn.microsoft.com/pl-pl/security/default(en-us).aspx
- Udostępnienie CLR wewnątrz VFP - http://www.west-wind.com/wconnect/weblog/ShowEntry.blog?id=631
- Technologia ActiveRecord (z RUBY onR) w .NET -http://www.castleproject.org/activerecord/index.html
- Czytanie plików z UTF-8 w VFP i konsekwencje tego (wraz z programem File2Var) - http://www.west-wind.com/wconnect/weblog/ShowEntry.blog?id=594
- Strona do wyszukiwania fragmentów kodu - http://www.koders.com/
- To zawsze mnie frapowało - SunCAPICOM - http://java.sun.com/developer/technicalArticles/J2SE/security/
- Laskowski o tym jak samodzielnie zbudować JPA w Eclipse i Netbeans - http://www.jaceklaskowski.pl/blog/2007/02/27/aplikacja-jpa-w-glassfish-v2-z-firebird-v2-i-eclipse-ide-33/
- Inny standard JPA - http://openjpa.apache.org/documentation.html
- Java Reference Guide - http://www.informit.com/guides/guide.aspx?g=java
- Dokumentacja do DALI (takie JPA) - http://www.eclipse.org/webtools/dali/docs/dali_user_guide.pdf
- Wiedza - http://www.code-magazine.com/
- Ciekawe odnosniki do zasobów o .NET - http://portal.artemis-solutions.com/glugnet/go/iris/3373/en-US/DesktopDefault.aspx
- Portal o .NET - http://www.codeguru.com/ oraz c-sharp corner
- Jak kontrolka z .NET może sobie zamieszkać w VFP - http://www.sweetpotatosoftware.com/SPSBlog/PermaLink,guid,3dd24f92-a52c-4bb0-8121-c2e6e2cc4f93.aspx
- Jakiś pogański sposób na wywoływanie DLL z Java (posługuje się kompilatorem JVC z MS) - http://www.codeguru.com/java/tij/tij0193.shtml
- Przykład jak JVM ładuje DLL i ją wykonuje - http://www.inonit.com/cygwin/jni/helloWorld/load.html
- Podobny problem rozwiązany przez Borlanda - http://dn.codegear.com/article/20679
- Javalobby - http://www.javalobby.org/java/forums/t88774.html - ich zdanie o DLL -http://www.codeproject.com/java/jnibasics1.asp, http://java.sun.com/docs/books/jni/html/jniTOC.html, http://www-128.ibm.com/developerworks/edu/j-dw-javajni-i.html
- Nowoczesna komunikacja .NET - Java w obie strony - http://www.ikvm.net/userguide/tutorial.html
- Jak skonwertować aplikację w java do .exe - http://www.codeguru.com/forum/archive/index.php/t-258554.html
- Rgagnon - http://www.rgagnon.com/howto.html
- Klasyka podpisu - http://www.developer.com/security/article.php/3587361
- Kodowanie znaków w .NET - http://www.codeguru.com/csharp/.net/net_general/tipstricks/article.php/c15547/
- NoScript dla FireFoxa - skuteczna ochrona przed zwabieniem (przyciągnięciem) nieświadomego użytkownika do kliknięcia na nieznany lub niewidoczny link
Znana osobistosć w JS - Douglas Crockford, Yahoo! JavaScript Architect and all-round guru.
When I was learning JavaScript, I read all of Douglas' stuff. If you're keen to see him speak, I recommend his videos on the YUI Theatre site:
- WS wytłumaczony - http://www.west-wind.com/presentations/dotnetwebservices/DotNetWebServices.asp
- WSDL specyficzne narzędzia z Apache CFX (implementacja http://cwiki.apache.org/CXF20DOC/index.html) może "rozmawiać" w różnych technologiach "Apache CXF is an open source services framework. CXF helps you build and develop services using frontend programming APIs, like JAX-WS. These services can speak a variety of protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a variety of transports such as HTTP, JMS or JBI":
- wsdl2java - wygeneruje proxy - http://cwiki.apache.org/CXF20DOC/wsdl-to-java.html
- odwrotna sytuacja - http://cwiki.apache.org/CXF20DOC/java-to-ws.html
- generuj proxy dla js - http://cwiki.apache.org/CXF20DOC/wsdl-to-javascript.html
- Ajaxonomy dwa artykuły na temat REST/SOAP:
- xhttp://www.ajaxonomy.com/2008/xml/web-services-part-1-soap-vs-rest
- http://www.ajaxonomy.com/2008/xml/web-services-part-2-wsdl-and-wadl
- Dwie teorie na temat zarządzania ludźmi wynikające z charkteru jednostek X i Y: http://www.economist.com/business/management/displayStory.cfm?source=hptextfeature&story_id=12370445 (Theory X and Theory Y wymyslone przez Douglas McGregor )
- Świetny artykuł o bezpieczeństwie w JEE - http://www.javaworld.com/javaworld/jw-03-2007/jw-03-security.html?page=3 - "From Java EE security to ACEGI"
- Tamże: Spring oferuje WAR zawierający w sobie całą konfigurację, dzięki temu unikamy 'miliona' plików konfiguracyjnych na zewnątrz - Unlike Java EE, Spring and Acegi are concrete implementations of their own APIs. Spring de facto promotes the WAR-level portability of Web applications, such that the war files may deploy and run out-of-box immediately without any external configurations required. In another words, all the configurations are defined inside the application war files.
- Inny artykuł na temat bezipeczeństwa od strony klineta - http://www.javaworld.com/javaworld/jw-11-2007/jw-11-webserviceclient.html?page=7 - "Client side WSDL processing ..." - oczywicie po HTTPS. Jest tam literatura i przykłady.
- Z innej beczki, to samo ale w .NET - http://www.west-wind.com/presentations/dotnetwebservices/DotNetWebServices.asp
- Tamże pożyteczne łącza:
- • http://news.google.com/
• Derby a JavaDB czym się różnią?
• Pomost między COM a Java w wykonaniu IBM - http://www.ibm.com/developerworks/library/j-intbridge/ " Integrate COM and Java components"
• IBM alphaworks - obsługa certyfikatów
• Książka z wieloma przykładami ".Net Framework Security" - Brian A. LaMacchia, Sebastian Lange, Matthew Lyons, Rudi Martin, Kevin T. Price Published Apr 24, 2002 by Addison-Wesley Professional. Wklejono z <http://www.informit.com/store/product.aspx?isbn=067232184X>
• Jak wyglądać świetnie - http://lifehacker.com/5058823/top-10-easy-ways-to-look-sharp
• Polski codeguru - http://www.codeguru.pl/newslist.aspx
• Rozszerzenie GUI dla ASP - http://www.visualwebgui.com/Developers/tabid/360/Default.aspx
• WSO2 nowy gracz w usługach WS - http://www.sdtimes.com/WSO2_RELEASES_PHP_LIBRARY_FOR_SOA_DEVELOPMENT/About_PHP_and_SECURITY_and_SOASAAS_and_WSO2/32836
• IBM-u DERBY oraz SUN-a JavaDB to jedno i to samo - http://developers.sun.com/javadb/
• Coś dla dzieci - ogórd pełen atrakcji architektonicznych z całego świata - http://content.techrepublic.com.com/2346-22_11-165853-11.html - Podczas testowania HTTPS można nawet "Particularly during testing, you may decide to just say "OK" to all self-signed SSL certificates. Therefore, when using HTTPS, you could need a specific SSL Socket Factory that allows for accepting all certificates in test mode"
- Cos dla dzieci - biblioteka graficzna - http://www.sitepoint.com/blogs/2008/10/01/dmitry-baranovskiy-talks-about-raphael/ podpbne możliwosci oferuje http://dojotoolkit.org/projects/dojox lub excanvas (http://excanvas.sourceforge.net/)
- Dojo ma dokumentację - http://dojotoolkit.org/docs oraz łatwe wprowadzenie tzw. quick start - http://sitepen.com/labs/guides/?guide=DojoQuickStart
- W odpowiedzi na zapytanie Miguel de Icaza z firmy Novell pracującego nad Mono, firma MS zmieniła licencjonowanie bibliotek wystawionych na portalu CopePlex. Zamiana dotyczy MEF (Managed Extensibility Framework) z MS-LPL (Limited Public License) na MS-PL (Public License). Widać tu elastyczność firmy. Ale takich projektów z MS-LPL jest na CodePlex wiele.
- Otwarcie MS na Open-Source: Podobno MS ma stosować rusztowanie jQuery w ASP.NET (podobnie zresztą jak Nokia). Ogłosił to Scott Guthrie w swym blogu i chwali jQuery na możliwość łańcuchowania kwerend i poleceń a także na łatwość wyboru i dostępu do elementów HTML. Kod nadal będzie utrzymywał John Resig (twórca biblioteki) i będzie również wprowadzał poprawki zgłoszone przez MS. MS z kolei będzie świadczył wsparcie dla incydentów związanych z tą biblioteką.
- Sprawa sterowników na bazie open-source do kart inteligentnych na stronie http://csp11.labs.libre-entreprise.org/. Ładnie ale to jest kolejna DLL. Takich w Windows już mam na kopy nie muszę brać tego co ktos ponownie wymyslił po to by ominąć DLL firmy MS. Powyższy adres wywodzi się z http://www.opensc-project.org/scb/ projektu udostepniającego możliwosci kart inteligentnych (dziwne - chcą zrobić to samo co MS, jeszcze raz, ;ale po swojemu, czy na tym polega tworzenie oprogramowania open source?). Na stronie http://www.opensc-project.org/scb/wiki/QuickStart pokazano jak wykorzystać polecenie 'openssl' z opcją 'engine' do obsługi SC. Do ciągnięcia oprogramowanie jest ut: http://www.opensc-project.org/files/scb/
- Strona głowna projektu SC (smartcard) - http://www.opensc-project.org/. Są tam różne projekty.
- O SC z pozycji Java - http://www.javaworld.com/jw-12-1997/jw-12-javadev.html?page=1
- Rodzaje SC:
- PC/SC
Microsoft and several other companies introduced PC/SC, a smart card application interface for communicating with smart cards from Win32-based platforms for personal computers. PC/SC does not currently support non-Win32-based systems and may never do so. We will discuss this in greater detail later on. - OpenCard Framework
OpenCard is an open standard that provides inter-operability of smart card applications across NCs, POS, desktops, laptops, set tops, and so on. OpenCard promises to provide 100% pure Java smart card applications. Smart card applications often are not pure because they communicate with an external device and/or use libraries on the client. (As a side note, 100% pure applications could exist without OpenCard, but without it, developers would be using home-grown interfaces to smart cards.) OpenCard also provides developers with an interface to PC/SC for use of existing devices on Win32 platfroms. - JavaCard
JavaCard was introduced by Schlumberger and submitted as a standard by JavaSoft recently. Schlumberger has the only Java card on the market currently, and the company is the first JavaCard licensee. A smart card with the potential to set the overall smart card standard, JavaCard is comprised of standard classes and APIs that let Java applets run directly on a standard ISO 7816 compliant card. JavaCards enable secure and chip-independent execution of different applications
- PC/SC
- Standardy je opisujące:
- ISO 7816 - describes the lowest-level interface to a smart card. It is at this level that data bytes are transferred between card reader and card.
- PC/SC - the standard for communicating with smart cards connected to Win3.1/Win95/NT machines.
- OCF - an all-Java interface for communicating with smart cards from a Java environment. (Soon OCF will allow developers to write to OCF and perform the translation, so there'll be no need to write to PC/SC.)
- JavaCard - describes the JavaCard and what it supports.
- ISO 7816 - describes the lowest-level interface to a smart card. It is at this level that data bytes are transferred between card reader and card.
- Openssl to potężne narzędzie do badania certyfikatów.
- Testy wymienialnosci certyfikatów miedzy Windows i Linux:
- Export z Windows kodowanie DER:
- Polecenie: openssl x509 -in $1 -inform DER:
- thawte_1_DER.cer, comodo_1_DER.cer, centrum_1_DER.cer - OK
- sigillumkwalif_1_DER.cer - błąd kodowania (w nazwie odbiorcy certyfikatu jest literka 'ń')
- thawte_1_DER.cer, comodo_1_DER.cer, centrum_1_DER.cer - OK
- Polecenie: openssl x509 -in $1 -inform PEM:
- Tak samo!!!
- Wydruk tekstowy certyfikatów, poleceniem: openssl x509 -in $1 inform DER -noout -text.
- Wydruk numeru seryjnego certyfikatów, poleceniem: openssl x509 -in $1 inform DER -noout -serial.
- Export z Windows kodowanie DER:
- Certyfikat Sigillum - twardy orzech do zgryzienia - pod Linuxem można się do niego dostać jedynia poprzez opcję asn1parse polecenia openssl :
- openssl asn1parse -in $plikpodpisany -i
- Wynik analizy - plik podpisany przy pomocy CAPICOM (csignData.vbs) jest o strukturze ASN1 zakodowany jako PEM (czyli Binary64) a nie bnarnie czyli DER. Dlatego nie trzeba domyslnie podawać opcji -inform PEM w zleceniu openssl.
- Powyższe polecenie analizuje podpisany dokument z którego można wiele wyłuskać np. numer seryjny certyfikatu, urzędy podpisujące. Przykładowy fragment wydruk:
0:d=0 hl=4 l=5021 cons: SEQUENCE
4:d=1 hl=2 l= 9 prim: OBJECT :pkcs7-signedData taki przechowuje format (chyba udaje)
43:d=4 hl=2 l= 9 prim: OBJECT :pkcs7-data
4844:d=9 hl=2 l= 3 prim: OBJECT :serialNumber
4849:d=9 hl=2 l= 11 prim: PRINTABLESTRING :Nr wpisu: 3
4862:d=6 hl=2 l= 4 prim: INTEGER :4411AFB8 Uwaga tu jest certyfikat mój
czwartek, października 02, 2008
- http://it.toolbox.com/blogs/programming-life/chromes-v8-javascript-engine-is-fast-and-furious-26985
- Productive Java EE 6 - http://www.techjava.de/topics/2008/09/productive-java-ee-6/
- http://blog.thinkrelevance.com/2008/9/10/java-next-4-immutability
- Use an XML database in PHP apps - http://www.ibm.com/developerworks/edu/x-dw-x-xmldbjavaphp.html?&S_TACT=105AGY67&S_CMP=ITTOOLBOX
- Fluently Groove - http://www.ibm.com/developerworks/edu/j-dw-java-jgroovy-i.html?&S_TACT=105AGY67&S_CMP=ITTOOLBOX
- .NET - http://dotnetwitter.wordpress.com/2008/09/10/links-for-2008-09-10/:
- http://weblogs.mozillazine.org/roadmap/archives/2008/08/tracemonkey_javascript_lightsp.html
- http://msdn.microsoft.com/en-us/library/ms819963.aspx
- http://www.codeproject.com/KB/cpp/X509Certificate.aspx
- Sign SOAP using ... - http://msdn.microsoft.com/en-us/library/ms819963.aspx
- X.509 certificates in .NET - http://www.codeproject.com/KB/cpp/X509Certificate.aspx
- http://towardsnext.wordpress.com/2008/09/10/des-encryption-in-c-using-systemsecuritycryptography-part-1/
- http://forums.microsoft.com/msdn/ShowPost.aspx?PostID=3821762&SiteID=1
- Dr.Dobbs - XML Digital Signature - http://www.ddj.com/windows/184416926
- http://blogs.msdn.com/charlie/
- http://community.bartdesmet.net/blogs/bart/default.aspx
- Szybkosć - http://weblogs.mozillazine.org/roadmap/archives/2008/08/tracemonkey_javascript_lightsp.html
- jORA - http://jora.luenasoft.de/index_en.html do Eclipse
- Blog z linkiem do książki o kryptografii - http://bradrhoads.blogspot.com/2008/09/handbook-of-applied-cryptography.html
- Stosowanie MD5 - http://usefulscripts.wordpress.com/2008/09/08/using-md5-encryption-with-c-and-microsoft-sql-server/
- O java - :
- http://java.about.com/
- http://java.sun.com/javaone/sf/
- http://www.javaworld.com/javaworld/javaqa/1999-08/01-qa-static2.html
- http://www.jroller.com/aalmiray/entry/java_groovy_scala_side_to1
- Jak zaszyfrować plik konfiguracyjny - http://dotnetfaqs-edu.blogspot.com/2008/09/encrypt-configuration-sections-in.html
- http://zenhabits.net/2008/09/21-easy-hacks-to-simplify-your-life/
- JS - http://www.webdesignerwall.com/general/javascript-in-modern-web-design/
REST:
http://www.informit.com/articles/article.aspx?p=27645
http://www.ajaxonomy.com/2008/xml/web-services-part-1-soap-vs-rest
Mainsoft oferuje intergrację między .NET a Webshpere :
Klient <---> Logika prezentacyjna - poprzez HTTP do klienta zawiera Portlet container (Struts, JSF/JSP portlets oraz ASP.NET JSR 168 Portlets)) <---> Warstwa logiki biznesowej (EJB, COM). Obie warstwy serwerowe korzystają z Serwisów (Security, Messaging, JNDI, Logging i Mail)
Już nikt nie kwestionuje istnienia dwóch ekosystemów Java i .NET. Dlatego powstaje wiele rozwiązań pomostowych (aplikacje heterogeniczne):
- Boulder, Colo.-based JNBridge's new JNBridgePro 4.0
- Thought - rozwiązanie - dynamic object-to-relational mapping (ORM) - CocoBase 5. Mają mieć produkt JPA dla .NET. Technologia JPA została wprowadzona do EJB 3.0 (składa się z API i JPQL)
- Boulder, Colo.-based JNBridge's new JNBridgePro 4.0
- Co jeszcze mamy:
- Bridge Solutions The code infrastructure in most enterprises today is a heterogeneous mix of Microsoft and Java platforms. Many companies have turned to Web services to get these two environments to interoperate, but that need has also spawned a category of "bridge" solutions, including those from JNBridge LLC and the CocoBase JPA solution from Thought Inc. A short list of similar offerings dev shops might want to consider includes:
- JuggerNET A development tool designed to generate .NET bindings for arbitrary Java classes. It can be used to publish .NET versions of Java APIs and COM bindings for Java APIs, and to integrate .NET clients into JMS or EJB applications. Vendor: Codemesh Inc. Developer license: JuggerNET pricing starts at $1,995 for a Starter Kit, which includes one developer license, first year maintenance and support, and up to five client or server CPU deployments.
- J-Integra for COM Bridges Java and Microsoft COM apps using a Java implementation of Microsoft's DCOM wire protocol, with optional native "JNI" mode. Vendor: Intrinsyc Software International Inc. Developer license $399; Server license (1 CPU) $3,999; Server license (multi-CPU) $7,999; Client license (5 pack) $745. Free trial available.
- EZ JCom Enterprise Provides a bridge between Java-based programs and COM/ActiveX objects. Can be used to interface to standard COM objects that don't include a UI, such as COM objects that provide a service. Can also be used from non-Windows platforms-such as Unix, Linux, Mac or handhelds-by using the included Remote Access Service. Vendor: EZ JCom Enterprise license: $1,495; includes royalty-free redistribution license and a license to use as a server component. The professional version, EZ JCom Pro, is available for $895. Evaluation downloads available.
- JACOB A Java-to-COM bridge designed to allow users to call COM Automation components from Java. It uses JNI to make native calls into the COM and Win32 libraries. Vendor: Open source project hosted on SourceForge License: GNU Library or Lesser General Public License (LGPL). The latest milestone release was announced in December 2007.
Wklejono z <http://adtmag.com/news/article.aspx?editorialsid=9923>
Inne ciekawe linki:- Jak nie zasnąć - http://www.wikihow.com/Stay-Awake-at-Work
- Jak się podładować - http://lifehacker.com/5054947/top-10-ways-to-stay-energized
- Forum na temat JACOB - http://sourceforge.net/forum/forum.php?thread_id=2204884&forum_id=375946
- Inny pakiet do łączenia Java z COM (komercyjny niestety) - http://www.teamdev.com/comfyj/purchase.jsf
- Skróty w MS:
- Dublin - application server - rozszerzenie do W2K8 i zintegrowany z BizTalk wykorzystuje .NET Framework 4.0 i służy do budowy aplikacji kompozytowych. Do tej pory WCF (Communication) i WWF (Workflow Foundation) bazowały na .NET 3.5 i wspierały SOAP zamiast REST, który teraz zaczyna królować w aplikacjach webowych. W nowym produkcie ADO.NET Data Services ("ASTORIA") znajdującym się w SP1 do 3.5 można znaleźć zapowiedzi REST. Natomiast w 4.0 zapowiada się jego pełne wsparcie: REST, ATOM, POX wraz z pełnym wsparciem warstwy WS-*. Można znaleźć na CodePlex - tzw. Starte Kit dla WCF (WCF REST Starter Kit on CodePlex). http://adtmag.com/news/article.aspx?editorialsid=10257
- Oslo - platforma do modelowania aplikacji
- Dublin - application server - rozszerzenie do W2K8 i zintegrowany z BizTalk wykorzystuje .NET Framework 4.0 i służy do budowy aplikacji kompozytowych. Do tej pory WCF (Communication) i WWF (Workflow Foundation) bazowały na .NET 3.5 i wspierały SOAP zamiast REST, który teraz zaczyna królować w aplikacjach webowych. W nowym produkcie ADO.NET Data Services ("ASTORIA") znajdującym się w SP1 do 3.5 można znaleźć zapowiedzi REST. Natomiast w 4.0 zapowiada się jego pełne wsparcie: REST, ATOM, POX wraz z pełnym wsparciem warstwy WS-*. Można znaleźć na CodePlex - tzw. Starte Kit dla WCF (WCF REST Starter Kit on CodePlex). http://adtmag.com/news/article.aspx?editorialsid=10257
- Oficjalne zapowiedzi VS 2010 oraz .Net Framewok 4.0 - najwyższy poziom tego pakietu to Team Suite. Ogromna zmiana - MS lansował model tworzenia aplikacji w oparciu w DSL (fizyczny poziom projektowania), teraz będzie wspierał UML (logiczny poziom projektowania) co się ma odbić w nowej wersji narzędzi "OSLO". O swej determinacji do przejścia na UML świadczy fakt wstąpienia MS do Object Management Group (OMG) - http://adtmag.com/news/article.aspx?editorialsid=10246
- Ciekawy protokoł GSS istnieje jego implementacja w Java - http://www.ietf.org/rfc/rfc2853.txt - ma dwie implemetacje:
- The Simple Public-Key GSS-API Mechanism [SPKM]
- The Kerberos Version 5 GSS-API Mechanism [KERBV5]
- The Simple Public-Key GSS-API Mechanism [SPKM]
- REST czy SOAP?
It was surprising enough when four years ago, Microsoft made an historic decision to ditch its own Web services architecture attempts and go with the flow. Today, it announced its next version of Windows will go with a different flow.
For the last four years, one of the most prominent signs of Microsoft's change of thinking with regard to the division of labor in programming, has been its embrace of Simple Object Access Protocol (now just called SOAP, after too much deliberation over the acronym) in Windows Communication Foundation (WCF). It was Web standards organizations, not Microsoft, that initially drove the widespread adoption of so-called WS-* services that use SOAP, but Windows' embrace of SOAP later cemented the standard as a fixture of Web development.
Initially, WS-* support was to be the hallmark of Microsoft's next-generation operating system back when it was still code-named "Longhorn," but later it was retrofitted to later editions of Windows XP, as well as to the .NET Framework.
But now that the tide of developer sentiment has recently shifted toward a new Web services model, that trades SOAP's platform independence for a more simplistic transaction structure called Representational State Transfer (REST), Microsoft is saying that it will be building what it's calling a "unified XAML model" into the next editions of both WCF and .NET. Those components will premiere in Windows 7, and beta testing will begin later this month.
As .NET Framework product manager Steven Martin described on his blog this afternoon, "As developers are broadly adopting the use of web services to build applications (using a spectrum of both advanced WS-* services as well as lighter weight RESTful services), they are reusing services that can live disparately across their enterprises, or on the Web. The best part of composite applications is that they can improve productivity and efficiency on the dev side and give more power to end users for accessing and managing data that's most critical to the business. As a result of the growing popularity of composite apps, developers require new levels of sophistication for building distributed, long-running, and workflow-centric applications."
That's the crux of Microsoft's marketing message explaining the move toward the REST model. But a white paper also released by Microsoft today takes that language somewhat deeper, going so far as to call into question the viability of the very aspects the company had cited as recently as months earlier as its reasons for embracing SOAP in the first place.
"Composite apps present new challenges around scalability, performance and reliability," reads Microsoft's latest "Overview" white paper on its new "RESTful" technology, code-named "Dublin" (DOCX available here). "The tried and true strategies for optimizing traditional applications do not satisfy in the more complex environment of composite applications. To address these requirements, composite applications must adopt more sophisticated application architectures -- including managing of highly asynchronous transactions, automation of long-running durable workflows, coordination of processes across very heterogeneous environments and seamless interoperability across platforms using standards. Increasingly, customers are turning to workflow-centric and 'declarative' approaches of defining application logic to help manage this complexity."
On the day that Microsoft first announced its WS-* technology adoption publicly, its product managers cited as its reasons for doing so what they called the "four pillars:" scalability, performance, availability, and reliability. (Marketers since that time have merged the final two items into one.) This February 2007 study by WCF program manager Saurabh Gupta graphically demonstrated the superior performance, scalability, and availability of WS-* Web services over the technologies that Microsoft had previously employed prior to embracing WS-* and SOAP, including ASP.NET Web Services (ASMX) and the Web Services Enhancements (WSE) add-on to Visual Studio 2005.
"To summarize the results, WCF is 25%-50% faster than ASP.NET Web Services, and approximately 25% faster than .NET Remoting," reads Gupta's conclusions. "Comparison with .NET Enterprise Service is load dependant, as in one case WCF is nearly 100% faster but in another scenario it is nearly 25% slower. For WSE 2.0/3.0 implementations, migrating them to WCF will obviously provide the most significant performance gains of almost 4x." Earlier in the study, Gupta warned that the chief limiting factor in any SOA system is the implementation of that service, rather than the underlying technology.
Whether a REST implementation will be significantly more scalable or perform better than a similar SOAP implementation may yet be proven by similar tests. Perhaps we'll see some of those tests during Microsoft's PDC in Los Angeles at the end of the month.
What's the difference between REST and SOAP, really? The two implementations of Web services architecture are actually completely different; they may accomplish much the same results, but they go about their jobs in entirely separate ways.
With SOAP, each Web service has its own URL, and a request made of that URL is submitted as a message in an XML enclosure. Each request uses an instruction that's part of the namespace of the service, which is itself explained through an XML scheme called Web Services Description Language (WSDL). So a Web client passes a message to the service, using the lexicon outlined by WSDL and enclosed in a SOAP envelope. The service then responds with results that are enclosed in a very symmetrical fashion, so that the queried element and the response tend to match up.
The key benefits of SOAP are that it is transport-agnostic (just because it uses HTTP now doesn't mean it has to in ten or fifteen years' time), and that it's easy to associate a Web service with an appropriate URL. That makes directories of Web services easier to assemble.
REST is actually a bit simpler to explain, especially to someone who hasn't grown too accustomed to SOAP. Unlike SOAP, REST relies entirely on HTTP. But because of that, its request language is already known; there are only four "verbs" in REST which translate directly to the GET, POST, PUT, and DELETE. So the need for WSDL on the request side is completely thwarted.
With REST, the item of data the client requests -- not the Web service itself -- is the target of the URL. For example, the field where a customer's surname would appear in a database may be the URL, whereas in SOAP, the URL refers to the service to which a request for that surname would be placed in an envelope. The server responds with a message in an XML envelope that pairs both the item that was requested and its response, which makes it easier for an auditing application to account for data transactions.
Is REST necessarily an easier way to go? It is if you're developing applications using a new concept called the model view controller scheme. These are the "composite" applications to which Microsoft's marketing literature refers; they involve three separate components which may be programmed in completely different languages, and may be running on separate processors. The model component sets up the data that's the subject of an application, whereas the view component prepares a meaningful relationship of that data for a human reader. This tends to translate well to systems where JavaScript or dynamic language code can do the modeling, and HTML can set up the view. The controller may be a server application that maintains the active state and integrity of the database.
It's an extremely sensible way to think of a network application, and it may be much easier to develop such a system because the three aspects of maintaining it can be delegated to separate development teams. But it almost mandates that the "what" of the application -- the part which the model component is setting up, and the view is preparing to lay out -- have a discrete name, without relying upon some Web service to give it a name later on during the transaction process. That's where the REST model may be a better fit.
Last November, Microsoft unveiled something called the ASP.NET Model View Controller Framework at a developer's conference in Las Vegas. There, one of the company's non-employee MVPs, author Dino Esposito, noted what he perceived to be the new framework's key benefit.
Summing up that benefit for his blog, Esposito wrote, "It uses a REST-like approach to ASP.NET Web development. It implements each request to the Web server as an HTTP call to something that can be logically described as a 'remote service endpoint.' The target URL contains all that is needed to identify the controller that will process the request up to generating the response -- whatever response format you need. I see more REST than MVC in this model. And, more importantly, REST is a more appropriate pattern to describe what pages created with the MVC framework actually do."
That's a sentiment Microsoft evidently took to heart. As Corporate Vice President Scott Guthrie wrote in describing his team's MVC implementation, "It includes a very powerful URL mapping component that enables you to build applications with clean URLs. URLs do not need to have extensions within them, and are designed to easily support SEO and REST-friendly naming patterns. For example, I could easily map the /products/edit/4 URL to the 'Edit' action of the ProductsController class in my project...or map the /Blogs/scottgu/10-10-2007/SomeTopic/ URL to a 'DisplayPost' action of a BlogEngineController class."
PDC in Los Angeles is a little over four weeks away, and BetaNews will be there to see how the first public betas of .NET 4.0 with REST perform in comparison to their predecessors.
Wklejono z <http://www.betanews.com/article/NET_Framework_40_to_become_less_SOAPcentric_embrace_REST/1222895836/2>
- Bridge Solutions The code infrastructure in most enterprises today is a heterogeneous mix of Microsoft and Java platforms. Many companies have turned to Web services to get these two environments to interoperate, but that need has also spawned a category of "bridge" solutions, including those from JNBridge LLC and the CocoBase JPA solution from Thought Inc. A short list of similar offerings dev shops might want to consider includes:
piątek, września 19, 2008
- http://c2.com/doc/oopsla89/paper.html
- http://javatipsandtricks.blogspot.com/2006/10/cryptography-and-security-on-java-se-6.html
- http://www.frankcornelis.be/dcontract/source-repository.html
- http://www.javaworld.com/javaworld/jw-01-2001/jw-0112-howto.html
- http://www.javaworld.com/javaworld/jw-07-2001/jw-0706-webstart.html
- http://www.javaworld.com/javaworld/jw-03-2003/jw-0321-wssecurity.html
- http://www.javaworld.com/javaworld/jw-06-2005/jw-0627-plugin.html
- http://www.javaworld.com/javaworld/jw-10-2002/jw-1011-securexml.html?
- http://java.sun.com/javase/6/docs/technotes/guides/security/xmldsig/XMLDigitalSignature.html
- http://java.sun.com/j2se/1.4.2/docs/guide/security/CryptoSpec.html#Provider
- http://java.sun.com/webservices/docs/1.5/tutorial/doc/index.html
- http://www.javaworld.com/javaworld/jw-05-2002/jw-0524-j2ee.html?page=2
- http://java.sun.com/j2se/1.5.0/docs/guide/security/p11guide.html
- http://java.sun.com/j2se/1.5.0/docs/guide/security/index.html
środa, września 17, 2008
Zebrane wiadomsci z Chrome:
- Porównanie kodowania znaków w .NET: http://www.billdawson.com/Articles/dotnetstreams.html
- O certyfikatach. Oprogramowanie:
- Oprogramowanie do SSL:
- OpenSSL i XCA - bezpłatne
- Oprogramowanie darmowe do zastosowań profesjonalnych, jak zbudowane na bazie OpenSSL i Perla pakiety OpenCA i OpenXPKI (www.openxpki.org
/ oraz oparty o Javę i serwer JBoss pakiet EJBCA, oprogramowanie komercyjne średniej klasy, takie jak Microsoft Certificate Services) - Oprogramowanie komercyjne z wyższej półki, takie jak RSA Certificate Manager (KEON), Entrust Authority czy Cybertrust Unicert (dawniej Baltimore)
- OpenSSL i XCA - bezpłatne
- Podpis elektroniczny w aplikacjach biurowych (securitystandard.pl) - http://www.securitystandard.pl/news/165699_1.html - wg. zaimplementowany jako XML-DSig w formacie OpenXML (ISO 29500, ECMA 376) rozpoznawalnym przez rozszerzenie DOCX.
- Materiały na temat JS - http://www.webdesignerwall.com/general/javascript-in-modern-web-design/ - widać, że najpopularniejszymi rusztowaniami są MooTools i jQuery. Tutaj są zebrane najpopularniejsze widgety. Bardzo przyjemny wygląd zewnętrzny.
- Cos dla dzieci: http://abrick.sourceforge.net/
- Ciekawe skrypty w różnych j. programowania - http://usefulscripts.wordpress.com/2008/09/08/using-md5-encryption-with-c-and-microsoft-sql-server/ - tutaj pokazene jest jak przechowywać w bazie hasła kodowane MD5.
- Zasoby Pythonowe - http://dawson.webfactional.com/blog/
- Formatowanie liczb w JS - http://usefulscripts.wordpress.com/2008/08/17/javascript-decimals/ na podstawie biblioteki z http://www.javascriptkit.com/javatutors/formatnumber.shtml
- Bardzo fajna strona o JS - http://www.javascriptkit.com/javatutors/formatnumber.shtml
- CodeProject - CertyfikatyX.509 w .NET - http://www.codeproject.com/KB/cpp/X509Certificate.aspx
- C-Sharp - Strumienie w pamięci - http://www.c-sharpcorner.com/UploadFile/Ashish1/memorystream10272005214644PM/memorystream.aspx?ArticleID=90a33ad2-49df-441b-91fc-94ed620f6010
- Dr.Dobbs - XML Sign - http://www.ddj.com/windows/184416926 cz.1
- Najlepsze blogi techniczne - http://itmanagement.earthweb.com/cnews/article.php/3770056/Top+200+Tech+Blogs:+the+Datamation+List.htm a tam sugerują:
piątek, września 05, 2008
Znana witryna - http://today.java.net/pub/a/today/2006/11/21/xml-signature-with-jsr-105.html?page=1 - "XML Signature with JSR-105 in Java SE 5" Standard ten jest już przyjęty tutaj jest dokumentacja - http://jcp.org/aboutJava/communityprocess/final/jsr105/index.html
Celem podpisu cyfrowego jest zapewnienie integralności danych zgodnie z RFC 2828, dodatkowo chodzi o mocniejszy dowód - autentykację (message authentication).
<Signature ID?>
<SignedInfo>
<CanonicalizationMethod/>
<SignatureMethod/>
(<Reference URI? >
(<Transforms>)?
<DigestMethod>
<DigestValue>
</Reference>)+
</SignedInfo>
<SignatureValue>
(<KeyInfo>)?
(<Object ID?>)*
</Signature>
Znaczenie Reference - łącznik między danymi do podpisania a samym podpisem. Wewnątrz dla danych jest liczony skrót wiadomości (hash, digest, footprint, odcisk) w elemencie DigestValue algorytmami (tzw. one way hash) SHA-1, SHA -256, SHA-512. Elementem, który jest podpisywany jest SignedInfo wg algorytmów DSA-SHA1, RSA_SHA1.
Podpisywanie składa się z dwóch etapów:
- Obliczenie wartości hash i wpisanie jej do Digest Value dla każdej wiadomości
- Wygenerowanie podpisu cyfrowego (digital signature) dla całego elementu SignedInfo i wstawienie go do pola SignatureValue. Inaczej mówiąc zaszyfrowanie całego bloku SignedInfo. Do podpisu stosuje się klucz prywatny wysyłającego (podpisującego)
Walidacja podstawowa składa się również z 2 etapów: (http://java.sun.com/developer/technicalArticles/xml/dig_signatures/fig8.gif):
- Reference validation - czy każdy element Reference jest poprawny tzn. oblicza się hash otrzymanego wiadomości i sprawdza z DigestValue
- Signature validation - polega na sprawdzeniu przy pomocy klucz publicznego podpisującego (?) - odszyfrowanie bloku SignedInfo posługując się kluczem publicznym i porównanie tej wartości z wartością hash elementu SignedInfo otrzymanej wiadomości
- Potwierdzenie tego jest na stronach Sun-a - http://java.sun.com/developer/technicalArticles/xml/dig_signatures/
- Inne potwierdzenie "Performing a digital signature involves two steps. In the first step, the data is run through a hashing algorithm. A typical hashing algorithm scans through the data and generates a number of some size -- this is typically called a "digest." If the same data is run through the hashing algorithm again, the same digest should be generated. Good hashing algorithms vary the digest unpredictably if the slightest change is made in the data. This makes it impossible to reverse engineer the original data, given the digest.
The second step in producing a digital signature is to encrypt the digest using the private key of the author. If you're not familiar with the terms public key or private key, then you've probably never heard of public key cryptography. The basic concepts of public key cryptography are simple: anything that is encrypted using an individual's private key, can only be decrypted using the same individual's public key. The reverse is also true: anything encrypted using an individual's public key, can only be decrypted using the same individual's private key. The two keys are mathematically linked. After encrypting the digest with the user's private key, the resulting scrambled data is then appended to the original document data.
Because public keys can be shared with anyone, and private keys should be known only to the signing author, verifying a digital signature is simple. The steps are:
- Rehash the document data that was received.
- Decrypt the encrypted digest with the author's public key that is typically appended to the document.
- Compare the two digests. If they are equal, the signature is valid.
If the two digests are not equal, then either the document has been altered, or the author of the document is not the same as the individual that signed it. However this information does not indicate which of those two faults (or both) have occurred. Wklejono z <http://www.java-tips.org/java-ee-tips/xml-digital-signature-api/using-the-java-xml-digital-signatur-2.html>"
Znaczenie Object -rekomenduje się aby tam umieścić dane które będą podpisywane (w przypadku wersji podpisu enveloping). KeyInfo z kolei może zawierać informacje o kluczu publicznym potrzebnym przy weryfikacji.
Pomocne narzędzia w Javie to keytool - http://java.sun.com/j2se/1.4.2/docs/tooldocs/windows/keytool.html
Lista dyskusyjna:
- http://markmail.org/message/mdeplwlczpa6xub5#query:org.apache.xml.security%20signing+page:1+mid:x537wesoqhhimbmq+state:resultsMetro
- to technologia SUN-a do łączenia się z WS w .NET - https://metro.dev.java.net/getting-started/
- SUN - http://forums.java.net/jive/thread.jspa?messageID=247428 , http://forums.java.net/jive/thread.jspa?messageID=255470
- Derkeiler - http://coding.derkeiler.com/Archive/Java/comp.lang.java/2004-03/0527.html
- Koders - http://www.koders.com/java/fidCEFECC0B536138DCFE919C5324844F8D1A0AC068.aspx
- http://osdir.com/ml/encryption.bouncy-castle.devel/2004-09/msg00046.html
Podpis cyfrowy w Java przy pomocy biblioteki Apache XML Security (DigiSig) - http://www.linux.com/feature/39427
Bardzo ciekawy artykuł "JAVA XML Digital Signature" pokazuje architekturę JCA (Java Cryptographic Architecture) jako rozszerzalną platformę:
Niezbędne biblioteki:
- javax.xml.crypto
- javax.xml.crypto.dsig
- javax.xml.crypto.dsig.keyinfo
- javax.xml.crypto.dsig.spec
- javax.xml.crypto.dom
- javax.xml.crypto.dsig.dom
W celu przyśpieszenia operacji kryptograficznych (zajmują one do 30% CPU) proponuje SUN wykorzystanie rozszerzenia PKCS#11 (Crypto.Token Interface Standard) w celu przeniesienia ciężąru obliczeń na akceleratory sprzętowe lub karty inteligentne.
Na powyższym rysunku Sun PKCS#11 Provider stanowi pomost między warstwami wyższymi a konkretną implementacją obliczeń kryptograficznych. Statycznie określenie rodzaju dostawcy polega na edycji pliku konfiguracyjnego sunpkcs11 umieszczonego w ../jre/lib/scurity/java.security Oto fragment mojego pliku:
#
# List of providers and their preference orders (see above):
#
security.provider.1=sun.security.provider.Sun
security.provider.2=sun.security.rsa.SunRsaSign
security.provider.3=com.sun.net.ssl.internal.ssl.Provider
security.provider.4=com.sun.crypto.provider.SunJCE
security.provider.5=sun.security.jgss.SunProvider
security.provider.6=com.sun.security.sasl.Provider
security.provider.7=org.jcp.xml.dsig.internal.dom.XMLDSigRI
security.provider.8=sun.security.smartcardio.SunPCSC
security.provider.9=sun.security.mscapi.SunMSCAPI
Jak widać jest nawet obsługa MS CAPI (poprzez wpis 9).
Fundamentalne łącza:
- http://java.sun.com/j2se/1.5.0/docs/guide/security/CryptoSpec.html
- Odpowiedzią APACHE na JSR-105 jest http://santuario.apache.org/
- http://java.sun.com/j2se/1.5.0/docs/guide/security/index.html
- http://java.sun.com/javase/6/docs/technotes/guides/security/xmldsig/XMLDigitalSignature.html
- Totalny przykład jak podpisać i sprawdzić: http://www.java-tips.org/java-ee-tips/xml-digital-signature-api/using-the-java-xml-digital-signatur-2.html
- Tutorial do WS też zawiera przykłady - http://java.sun.com/webservices/docs/1.5/tutorial/doc/index.html, rozdział 4 - http://java.sun.com/webservices/docs/1.5/tutorial/doc/XMLDigitalSignatureAPI.html#wp268799
- Generalnie są pomocne wskazówki z http://www.java-tips.org
- Sign and verify XML documents using Apache WSS4J and Websphere DataPower SOA - http://www.ibm.com/developerworks/library/ws-soa-verifyxml/index.html
- WS w IBM - https://www6.software.ibm.com/developerworks/education/ws-understand-web-services4/index.html
- Świetny servis typu cover - http://xml.coverpages.org/xmlSig.html#URLs
- Pełny przykład aplikacji do podpisu i weryfikacji - http://www.javaworld.com/javaworld/jw-12-2002/jw-1220-xmlsecurity.html?page=2
- Secure Web Services - http://www.javaworld.com/javaworld/jw-03-2003/jw-0321-wssecurity.html
- Plug-in - http://www.javaworld.com/javaworld/jw-06-2005/jw-0627-plugin.html
- Yes you can secure WS - http://www.javaworld.com/javaworld/jw-10-2002/jw-1011-securexml.html?
- Java i XML - http://www.javaworld.com/channel_content/jw-xml-index.shtml
- Construct Secure network application - http://www.javaworld.com/javaworld/jw-01-2001/jw-0112-howto.html
- Web Start to rescue - http://www.javaworld.com/javaworld/jw-07-2001/jw-0706-webstart.html
- Stosowanie SUNCAPI - http://javatipsandtricks.blogspot.com/2006/10/cryptography-and-security-on-java-se-6.html
- Bouncy castle -http://www.bouncycastle.org/index.html
- Tworzenie Rich Client - http://www.ibm.com/developerworks/edu/os-dw-os-eclipse-ganymede-pt1.html?S_TACT=105AGX54&S_CMP=B0904&ca=dnw-935
- Ajax i PHP - http://www.ibm.com/vrm/newsletter_10731_3899_85549_email_DYN_6IN/mcu35457530
- Applets with servlets i XML -http://www.javaworld.com/javaworld/jw-05-2002/jw-0524-j2ee.html?page=2
- Projekty Open-Source:
- OpenXAdES - http://www.openxades.org/
- DigiDOc COM - http://www.openxades.org/download.html
- X509 - http://nixbit.com/search/x509-/
- Dcontract - http://nixbit.com/cat/programming/libraries/dcontract/
- Crypt.509 - http://nixbit.com/cat/programming/libraries/crypt::x509/
- Xca - http://nixbit.com/cat/system/networking/xca/
- DigiDoc - http://sourceforge.net/projects/gdigidoc/
- Closed-Source:
- XML Encryption and Digital Signature - http://msdn.microsoft.com/en-us/library/ms229749.aspx
- How to: - http://msdn.microsoft.com/en-us/library/ms229745.aspx
- Wskazówki:
- Dostęp do EJB z poziomu klienta Javy lub poprzez JWS - http://www.java-tips.org/java-ee-tips/enterprise-java-beans/accessing-a-secure-enterprise-bean-from-a-java-client-or-through-java-web-start-techn.html
- Dostęp do EJB z poziomu appletu - http://www.java-tips.org/java-ee-tips/enterprise-java-beans/accessing-an-ejb-from-an-applet-2.html
- Dostęp do EJB z poziomu servleta - http://www.java-tips.org/java-ee-tips/enterprise-java-beans/accessing-ejb-from-a-servlet-within-the-same-cont-2.html
- Dostęp do EJB z poziomu JSP - http://www.java-tips.org/java-ee-tips/javaserver-pages/accessing-bean-components-from-jsp.html
- http://www.java2s.com/Code/Jar/wsit/xmldsig.jar.htm
- http://www.java2s.com/Tutorial/Java/0140__Collections/0021__Collections.htm
- Można ściągnąć i jest opis klas - http://www.java2s.com/Code/Jar/wsit/Downloadxmldsigjar.htm
Przykład diagramu: