<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Prismod Systems</title>
	<atom:link href="http://www.prismod.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.prismod.com</link>
	<description>software solutions for today and tomorrow</description>
	<lastBuildDate>Sun, 05 Sep 2010 22:43:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>AWS is AIMing to please</title>
		<link>http://www.prismod.com/2010/09/aws-is-aiming-to-please/</link>
		<comments>http://www.prismod.com/2010/09/aws-is-aiming-to-please/#comments</comments>
		<pubDate>Sun, 05 Sep 2010 22:43:01 +0000</pubDate>
		<dc:creator>gabe</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.prismod.com/?p=49</guid>
		<description><![CDATA[Amazon Web Services (AWS) is previewing a significant new feature called Identity and Access Management (AIM) as described in this post on Alestic.com and on the Ylastic blog. What I&#8217;m waiting for and don&#8217;t yet see is the ability to &#8230; <a href="http://www.prismod.com/2010/09/aws-is-aiming-to-please/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Amazon Web Services (AWS) is previewing a significant new feature called <a href="http://aws.amazon.com/iam/">Identity and Access Management (AIM)</a> as described in <a href="http://alestic.com/2010/09/aws-iam">this post on Alestic.com</a> and on <a href="http://blog.ylastic.com/using-the-aws-identity-and-access-management">the Ylastic blog</a>.</p>
<p>What I&#8217;m waiting for and don&#8217;t yet see is the ability to delegate to and constrain the access of 3rd party service providers to your AWS account(s). Right now, you have to hand over complete control of your account to even the most trivial AWS service provider which is not a very comfortable model from either a security or traceability perspective. It looks like AIM is getting pretty close to enabling this but is not there yet. Some gaps include:</p>
<ul>
<li>that an AIM user does not have an obvious mapping to an EC2 user (<a href="http://aws.amazon.com/iam/faqs/#Can_users_have_individual_EC2_SSH_keys">or per-user ssh keys</a>).</li>
<li>the lack of <a href="http://aws.amazon.com/iam/faqs/#Will_Identity_and_Access_Management_administrative_actions_be_logged_to_an_audit_trail">AIM user auditing and logging</a>. This is tagged as being addressed in an upcoming release.</li>
</ul>
<p>All in all, a very promising start to addressing a critical chink in the AWS eco-system for 3rd party services.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prismod.com/2010/09/aws-is-aiming-to-please/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Welcome to the Prismod Systems Blog!</title>
		<link>http://www.prismod.com/2010/08/hello-world/</link>
		<comments>http://www.prismod.com/2010/08/hello-world/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 02:19:39 +0000</pubDate>
		<dc:creator>prismod</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://ec2-204-236-145-219.us-west-1.compute.amazonaws.com/wp.prismod.com/?p=1</guid>
		<description><![CDATA[Welcome to the Prismod Systems Blog. We hope you find the posts to be interesting and useful.]]></description>
			<content:encoded><![CDATA[<p>Welcome to the Prismod Systems Blog. We hope you find the posts to be interesting and useful.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prismod.com/2010/08/hello-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
