Abstract:
A VPN gateway is described that provides single sign-on (SSO) functionality with respect to remote users who have established tunneling sessions with the VPN gateway and who attempt to access a protected resource. The VPN gateway may receive, from a client device, a security assertion request that includes a request for a security assertion to be made by the VPN gateway with respect to a user of a private network associated with the VPN gateway, determine whether the security assertion request was received via a tunneling session established for the user between the client device and the VPN gateway, and issue a security assertion for the user in response to determining that the security assertion request was received via the tunneling session. In this way, a VPN gateway may act as an SSO identity provider for users that have an established tunneling session with the gateway.
Abstract:
In general, the invention is directed to techniques for enabling single sign-on (SSO) for a client seeking access to multiple resources protected by a certificate-based authentication scheme. For example, as described herein, a secure gateway comprises a certificate repository to store a digital certificate as well as a policy that includes one or more policy rules. A network interface of the secure gateway receives a message from a client device, wherein the message comprises a request to access a protected resource and an identifier for the requesting agent. The secure gateway also comprises a resource authentication module to map the identifier and the protected resource to the digital certificate based on the policy. The resource authentication module retrieves the digital certificate from the certificate repository and sends the digital certificate to the protected resource to authenticate the secure gateway to the protected resource.
Abstract:
In general, techniques are described for dynamic resource allocation in virtual environments. A network device comprising physical resources, a first virtual machine (VM), a second VM and a hypervisor may implement these techniques. The first VM executes within a first partition of the physical resources to process a first portion of received network traffic, while the second MV executes within a second partition of the physical resources to process a second portion of the received network traffic. The first VM determines whether physical resources in addition to those allocated by way of the first partition are required to process the incoming network traffic and issues a request requesting additional physical resources based on the determination. Either the second VM or the hypervisor, in response to the request, dynamically reallocates at least a portion of the physical resources allocated to the second partition to the first partition.
Abstract:
Method and system for managing a storage environment having a cluster based storage system and a non-cluster based storage system is provided. A management application collects information regarding components of both the cluster based storage system and the non-cluster based storage system. A layout having a plurality of data structures is generated and maintained by the management application. The data structures include information regarding the components and their relationships with each other, if any. The layout is used for responding to user requests and presenting an integrated view of the storage environment on a display device with selectable options for selecting the cluster based storage system components and the non-cluster based storage system components.
Abstract:
A storage management application is provided to manage and monitor virtual storage servers in a hosting storage server. In addition, in order to facilitate virtual storage server management and monitoring, a virtual storage server administrator role is provided. The role is allowed to access details of the virtual storage server assigned to the role, but not the details of the hosting server and other virtual servers.
Abstract:
A storage management application is provided to manage and monitor virtual storage servers in a hosting storage server. In addition, in order to facilitate virtual storage server management and monitoring, a virtual storage server administrator role is provided. The role is allowed to access details of the virtual storage server assigned to the role, but not the details of the hosting server and other virtual servers.
Abstract:
Method and system for managing a storage environment having a cluster based storage system and a non-cluster based storage system is provided. A management application collects information regarding components of both the cluster based storage system and the non-cluster based storage system. A layout having a plurality of data structures is generated and maintained by the management application. The data structures include information regarding the components and their relationships with each other, if any. The layout is used for responding to user requests and presenting an integrated view of the storage environment on a display device with selectable options for selecting the cluster based storage system components and the non-cluster based storage system components.
Abstract:
A system and method administers virtual servers executing on one or more physical storage systems. One or more virtual servers are created and associated with a management group. An administrator is then granted permissions to the group. Upon logging into management software, only information relating to the virtual servers associated with the group are displayed to the administrator, thereby limiting access to information related to other virtual servers and/or physical storage systems.
Abstract:
An embodiment of a network manager permits a resource group administrator (with resource group level permissions but without global permissions) to add a global object to his/her resource group as a managed object, without requiring the administrator to have a global permission, as discussed further below. An embodiment of the network manager permits a resource group administrator to also edit the configuration settings that are attached to his/her resource group without requiring the administrator to have a global permission.
Abstract:
A device is provided to clean an object by positioning the surface of the object to be cleaned in contact with a cleaning medium comprising one or more liquids having a dielectric constant of from 1 to 200 and placed in an electric field in the range of from 103 V/m to 107 V/m wherein said device is capable of generating said electric field using an alternating voltage/current source, said device comprising at least two electrodes where one of the electrodes is at a higher potential than the other and said electrodes are spatially separated by a distance of 1 micron to 2 cm by an insulating material having a dielectric breakdown strength greater than the applied electric field.
Abstract translation:提供一种装置,用于通过将被清洁物体的表面定位为与包含一种或多种介电常数为1至200的液体的清洁介质接触并将其放置在103范围内的电场中来清洁物体 V / m至107V / m,其中所述器件能够使用交流电压/电流源产生所述电场,所述器件包括至少两个电极,其中一个电极处于比另一个更高的电位,并且所述电极为 通过具有大于所施加的电场的介电击穿强度的绝缘材料在空间上分隔1微米至2厘米的距离。