On Friday, February 8, 2013 at 9:36 PM, Anil Saldhana wrote:
Hi All,
our release ninja, Pedro has released PicketBox 5.0.0.Final whose
notes is at
We delayed the release mainly to accommodate PicketLink v3.0 IDM that
was under development. PicketBox5 uses the most recent version of IDM.
Congratulation guys.
** What is PicketBox5? **
PicketBox5 is a project that provides the various tools for Java Security.
** Are there quickstarts? **
Looks like the quickstarts are referencing to the Pedro's repository, not PicketBox
** Where is PicketBox5 useful? **
Java Applications wherever the following are needed:
* Authentication.
* Authorization
* Audit
* Session Management (non-http based)
* Entitlements Management
It does have general purpose HTTP authentication (basic/form/digest)
support that is not EE container security
** How is this different from PicketLink v3? **
Here comes the tricky part to understand, at least for me. If I recall correctly
PicketLink v3 is our
opportunity to build something new from the experience of Seam Security, PicketBox,
GateIn, Resteasy….
Are we filling the gaps with PicketBox instead of provide the final solution? For example,
picketlink provides something like this for me:
package org.picketlink.internal;
public class DefaultIdentity implements Identity….
On picketlink-extensions I have:
package org.picketlink.extensions.core.pbox;
public class DefaultPicketBoxIdentity extends DefaultIdentity implements
It makes me confuse. Are we filling the gaps on PicketLink or creating workarounds inside
something new?
PicketLink v3 is our umbrella project for enabling security for
applications (EE6+). PicketLinkv3 contains core security, IDM, SAML,
OAuth and Social (facebook/twitter/openid) components that are useful
for JavaEE applications. There is PicketLink Extensions project that
does use PicketBox5 underneath to fill in some of the gaps missing in
PicketLink v3, as we are transitioning features into PL3 based on user
Feedback welcome.
Now onto making PicketLink v3 Final release a reality. :)
security-dev mailing list
security-dev(a)lists.jboss.org (mailto:security-dev@lists.jboss.org)