Archive for the ‘Identity’ Category

Wednesday, April 19th, 2006

The SAMLv1 effort began in earnest in Jan-2001. The Liberty Alliance was kicked off by Sun Microsystems in late Summer 2001 and got rolling by Dec-2001. Official, “OASIS Standard” SAMLv1 specs were published in Nov-2002, and the initial Liberty ID-FFv1 (Identity Federation Framework) specs were published in summer 2001 (based on SAMLv1 drafts), with v1.1 in Jan 2003 (based on OASIS-Standard SAMLv1.0). Subsequently, ID-FFv1.x and SAMLv1.x were formally converged to become SAMLv2.0 — which was issued as an OASIS-Standard spec in March 2005.

It’s now April 2006. The above specs are implemented in various commercial and open-source products (e.g. SAMLv2.0 conformance-tested products). What’s up with deployment? Various people have claimed that “those specs are too complicated and aren’t user-centric, and there isn’t any wide deployment of them” (to sort of paraphrase, but nearly quote).

Well, the Liberty Alliance has done some navel-gazing about this, beginning in earnest last year, and we’ve now published both a “Market Adoption” page (to be periodically updated), and have launched a quarterly “Executive Newsletter” — this first issue of which focuses on adoption.

It looks like deployments are occuring and momentum is building (the term “billions” is used), and we’re proving the above quote wrong. Check it out.

Average Rating: 4.8 out of 5 based on 183 user reviews.

Saturday, March 11th, 2006

I recently co-authored a major rewrite of the so-called “SIP SAML” I-D, crafting it into an actual SAMLv2 profile and binding, now (rather plainly) entitled “SIP SAML Profile and Binding”. Here’s the publication announcement: I-D ACTION:draft-tschofenig-sip-saml-05.txt.

Here is the abstract:

This document specifies a Session Initiation Protocol (SIP) profile of Security Assertion Markup Language (SAML) as well as a SAML SIP binding. The defined SIP SAML Profile composes with the mechanisms defined in the SIP Identity specification and satisfy requirements presented in “Trait-based Authorization Requirements for the Session Initiation Protocol (SIP)”.

Average Rating: 4.7 out of 5 based on 183 user reviews.

Saturday, March 11th, 2006

The “SIP Identity” Internet-Draft, whose lead author is my colleague Jon Peterson, was recently blessed by the IESG and is to be issued as a “Proposed Standard” RFC. Here’s the announcement: Protocol Action: ‘Enhancements for Authenticated Identity Management in the Session Initiation Protocol (SIP)’ to Proposed Standard.

Average Rating: 4.7 out of 5 based on 151 user reviews.

Saturday, March 11th, 2006

My colleague John Kemp has blogged a quick, accurate (although partial) tutorial on the Liberty Authentication Service, of which I was the original designer (see my bibliography). I hope he gets the time to post part 2 of his write-up!

Average Rating: 4.6 out of 5 based on 208 user reviews.