Dale Bingham
1 min readSep 17, 2019

--

Thank you. As for analyzing the security issues our groups logged into the interface to view them, see notes, see test coverage, etc. We did not uses any framework for that. We talked on using the API interface for automating more things. I am not there so I am not sure where that went.

I did this very thing in the article for a platform we were building for a very large organization. We used Keycloak for SAML based authentication and the roles in the Keycloak realm we designated for authorization into only specific projects people could use. We had a naming standard for the groups matched to projects.

--

--

Dale Bingham
Dale Bingham

Written by Dale Bingham

CEO of Soteria Software. Developer on OpenRMF. Software Geek by trade. Father of three daughters. Husband. Love new tech where it fits. Follow at @soteriasoft

No responses yet