Here is an (slightly edited) 'brain dump' I just wrote on the topic of Authorisation and SDL.
Let me know what are your views on the ideas presented below:
---------------------------------------------------------------------
Let me know what are your views on the ideas presented below:
---------------------------------------------------------------------
The need for a strong Auth strategy
Knowing 'who is talking to whom' is a key pillar of security. Since there is going to be a number of parties and players involved, it will not be possible to have a one-size-fits-all Authentication technology/workflow (specially when dealing with the partner's systems and existing SSO technology).