<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/1.5.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
	<title>IdentityMeme.org</title>
	<link>http://identitymeme.org</link>
	<description>=JeffH's musings on identity, security, protocols, SDOs, and tussles thereof...</description>
	<pubDate>Mon, 10 Mar 2008 12:07:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=1.5.2</generator>
	<language>en</language>

		<item>
		<title>Stats – A Cool Last.fm Group</title>
		<link>http://identitymeme.org/archives/2008/03/10/stats-%e2%80%93-a-cool-lastfm-group/</link>
		<comments>http://identitymeme.org/archives/2008/03/10/stats-%e2%80%93-a-cool-lastfm-group/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 11:58:28 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>Identity</dc:subject>
	<dc:subject>Web Services</dc:subject>
	<dc:subject>Markup</dc:subject>
	<dc:subject>Social Networking</dc:subject>
	<dc:subject>Tools</dc:subject>
	<dc:subject>Data Mining</dc:subject>
	<dc:subject>Visualization</dc:subject>
		<guid>http://identitymeme.org/archives/2008/03/10/stats-%e2%80%93-a-cool-lastfm-group/</guid>
		<description><![CDATA[	I just ran across this group at Last.fm..
	
Stats

	..it&#8217;s denizens post articles about and pointers to cool little gizmos/widgets/whathaveyous that one can use to leverage Last.fm data. 
	I ran across it via this person&#8217;s profile..
	
Anthony Liekens

	..he has a personal website where he offers..
	
Data mining musical profiles
Anthony Liekens, March, 28-April, 2 2007

	..that article, and a web interface [...]]]></description>
			<content:encoded><![CDATA[	<p>I just ran across this group at Last.fm..</p>
	<blockquote><p>
<a href="http://www.last.fm/group/Stats/?welcome=1">Stats</a>
</p></blockquote>
	<p>..it&#8217;s denizens post articles about and pointers to cool little gizmos/widgets/whathaveyous that one can use to leverage Last.fm data. </p>
	<p>I ran across it via this person&#8217;s profile..</p>
	<blockquote><p>
<a href="http://www.last.fm/user/aliekens">Anthony Liekens</a>
</p></blockquote>
	<p>..he has a personal website where he offers..</p>
	<blockquote><p>
<a href="http://anthony.liekens.net/index.php/Computers/DataMining">Data mining musical profiles<br />
Anthony Liekens, March, 28-April, 2 2007</a>
</p></blockquote>
	<p>..that article, and <a href="http://anthony.liekens.net/pub/scripts/last.fm/">a web interface to his various tools</a>.<br />
. </p>
	<p>=JeffH sez check it out <img src='http://identitymeme.org/wp-images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
No Tags]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2008/03/10/stats-%e2%80%93-a-cool-lastfm-group/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>I Done Left Los Windows…</title>
		<link>http://identitymeme.org/archives/2008/01/30/i-done-left-los-windows%e2%80%a6/</link>
		<comments>http://identitymeme.org/archives/2008/01/30/i-done-left-los-windows%e2%80%a6/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 01:11:44 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>Software</dc:subject>
	<dc:subject>Open Source</dc:subject><dc:subject>debian</dc:subject><dc:subject>gnu</dc:subject><dc:subject>kubuntu</dc:subject><dc:subject>linux</dc:subject><dc:subject>Microsoft</dc:subject><dc:subject>opensource</dc:subject><dc:subject>ubuntu</dc:subject><dc:subject>windows</dc:subject>
		<guid>http://identitymeme.org/archives/2008/01/30/i-done-left-los-windows%e2%80%a6/</guid>
		<description><![CDATA[	I&#8217;m blogging about my personal computing environment over on my &#8220;personal&#8221; blog, and just posted a note about my recent migration from MS Windows XP to (K)ubuntu GNU/Linux. Here&#8217;s a pointer to it..
	
I Done Left Los Windows…
http://kingsmountain.com/blog/archives/2008/01/30/i-done-left-los-windows/

	=JeffH
Technorati Tags: debian, gnu, kubuntu, linux, Microsoft, opensource, ubuntu, windows]]></description>
			<content:encoded><![CDATA[	<p>I&#8217;m blogging about my personal <a href="http://en.wikipedia.org/wiki/Computing">computing</a> environment over on my &#8220;<a href="http://en.wikipedia.org/wiki/Personal_identity">personal</a>&#8221; blog, and just posted <a href="http://kingsmountain.com/blog/archives/2008/01/30/i-done-left-los-windows/">a note about my recent migration</a> from <a href="http://en.wikipedia.org/wiki/Windows_xp">MS Windows XP</a> to <a href="http://www.ubuntu.com/">(K)ubuntu</a> <a href="http://en.wikipedia.org/wiki/Linux">GNU/Linux</a>. Here&#8217;s a pointer to it..</p>
	<blockquote><p>
I Done Left Los Windows…<br />
<a href="http://kingsmountain.com/blog/archives/2008/01/30/i-done-left-los-windows/">http://kingsmountain.com/blog/archives/2008/01/30/i-done-left-los-windows/</a>
</p></blockquote>
	<p><a href="http://xri.net/=JeffH">=JeffH</a></p>
Technorati Tags: <a href="http://www.technorati.com/tag/debian" rel="tag">debian</a>, <a href="http://www.technorati.com/tag/gnu" rel="tag">gnu</a>, <a href="http://www.technorati.com/tag/kubuntu" rel="tag">kubuntu</a>, <a href="http://www.technorati.com/tag/linux" rel="tag">linux</a>, <a href="http://www.technorati.com/tag/Microsoft" rel="tag">Microsoft</a>, <a href="http://www.technorati.com/tag/opensource" rel="tag">opensource</a>, <a href="http://www.technorati.com/tag/ubuntu" rel="tag">ubuntu</a>, <a href="http://www.technorati.com/tag/windows" rel="tag">windows</a>]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2008/01/30/i-done-left-los-windows%e2%80%a6/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Will &#8220;open internet&#8221; IDM Migrate Towards &#8220;trust circles&#8221; ?</title>
		<link>http://identitymeme.org/archives/2008/01/21/will-open-internet-idm-migrate-towards-trust-circles/</link>
		<comments>http://identitymeme.org/archives/2008/01/21/will-open-internet-idm-migrate-towards-trust-circles/#comments</comments>
		<pubDate>Tue, 22 Jan 2008 02:28:32 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>Identity</dc:subject>
	<dc:subject>Security</dc:subject>
	<dc:subject>SAML</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>Trust</dc:subject>
	<dc:subject>Deployment</dc:subject><dc:subject>deployment</dc:subject><dc:subject>openid</dc:subject><dc:subject>saml</dc:subject><dc:subject>Security</dc:subject><dc:subject>trust</dc:subject>
		<guid>http://identitymeme.org/archives/2008/01/21/will-open-internet-idm-migrate-towards-trust-circles/</guid>
		<description><![CDATA[	Eve (aka xmlgrrl) posted the following bit of musing today..
	
Circles of trust: disaster? or really bad idea?
http://www.xmlgrrl.com/blog/archives/2008/01/21/circles-of-trust-disaster-or-really-bad-idea/

	..which I tend to think hits the proverbial nail pretty squarely on the head wrt &#8220;open internet&#8221;, &#8220;trust all comers&#8221;, and &#8220;trust circles&#8221;. 
	One very small, detail-level comment I have on her post is that where she writes..
	
(where users [...]]]></description>
			<content:encoded><![CDATA[	<p><a href="http://www.xmlgrrl.com/blog/">Eve</a> (aka <a href="http://www.xmlgrrl.com/blog/">xmlgrrl</a>) posted the following bit of musing today..</p>
	<blockquote><p>
<a href="http://www.xmlgrrl.com/blog/archives/2008/01/21/circles-of-trust-disaster-or-really-bad-idea/">Circles of trust: disaster? or really bad idea?</a><br />
<a href="http://www.xmlgrrl.com/blog/archives/2008/01/21/circles-of-trust-disaster-or-really-bad-idea/">http://www.xmlgrrl.com/blog/archives/2008/01/21/circles-of-trust-disaster-or-really-bad-idea/</a>
</p></blockquote>
	<p>..which I tend to think hits the proverbial nail pretty squarely on the head wrt &#8220;open internet&#8221;, &#8220;trust all comers&#8221;, and &#8220;trust circles&#8221;. </p>
	<p>One very small, detail-level comment I have on her post is that where she writes..</p>
	<blockquote><p>
(where users are okay with this sort of back-channel communication)
</p></blockquote>
	<p>..I would instead make it explicitly clear that &#8220;users&#8221; sometimes don&#8217;t have any direct say with respect to the machinations of the IT department on their behalf. Hence I would write it as..</p>
	<blockquote><p>
(where users are okay with this sort of back-channel communication, or where they don&#8217;t have any say (e.g. in an enterprise deployment))
</p></blockquote>
	<p>Note I don&#8217;t feel that the latter is necessarily a good thing, but it&#8217;s reality in corporate, governmental, and education worlds (at least), and no amount of attesting that &#8220;I want to <em>own</em> my identity data!&#8221; is going to change it any time soon (admittedly unfortunately). Besides one&#8217;s identity, outside of one&#8217;s own thoughts, &#8220;..is a <em>story</em>&#8220;, <a href="http://notabob.blogspot.com/2005/08/identity-is-story.html">as Bob Blakley noted a while back</a>, but has been understood for quite a while by social scientists and philosophers (see, for example, <a href="http://en.wikipedia.org/wiki/Erving_Goffman">Erving Goffman</a>). </p>
	<p>But I digress&#8230;  <img src='http://identitymeme.org/wp-images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
Technorati Tags: <a href="http://www.technorati.com/tag/deployment" rel="tag">deployment</a>, <a href="http://www.technorati.com/tag/openid" rel="tag">openid</a>, <a href="http://www.technorati.com/tag/saml" rel="tag">saml</a>, <a href="http://www.technorati.com/tag/Security" rel="tag">Security</a>, <a href="http://www.technorati.com/tag/trust" rel="tag">trust</a>]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2008/01/21/will-open-internet-idm-migrate-towards-trust-circles/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>New version of OpenID SAML comparison document</title>
		<link>http://identitymeme.org/archives/2008/01/21/new-version-of-openid-saml-comparison-document/</link>
		<comments>http://identitymeme.org/archives/2008/01/21/new-version-of-openid-saml-comparison-document/#comments</comments>
		<pubDate>Mon, 21 Jan 2008 20:54:23 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>Identity</dc:subject>
	<dc:subject>Security</dc:subject>
	<dc:subject>Public Policy</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>Protocols</dc:subject><dc:subject>authentication</dc:subject><dc:subject>Open Standards</dc:subject><dc:subject>openid</dc:subject><dc:subject>saml</dc:subject><dc:subject>Security</dc:subject><dc:subject>simplified sign on</dc:subject><dc:subject>single sign on</dc:subject>
		<guid>http://identitymeme.org/archives/2008/01/21/new-version-of-openid-saml-comparison-document/</guid>
		<description><![CDATA[	I&#8217;ve done a modest editorial and copy editing update to the OpenID SAML technical comparison document announced earlier. Going forward, the latest rev will be available via this URL:
	
http://identitymeme.org/doc/draft-hodges-saml-openid-compare.html

Technorati Tags: authentication, Open Standards, openid, saml, Security, simplified sign on, single sign on]]></description>
			<content:encoded><![CDATA[	<p>I&#8217;ve done a modest editorial and copy editing update to the OpenID SAML technical comparison document <a href="http://identitymeme.org/archives/2007/12/17/draft-technical-comparison-openid-and-saml/">announced earlier</a>. Going forward, the latest rev will be available via this URL:</p>
	<blockquote><p>
<a href="http://identitymeme.org/doc/draft-hodges-saml-openid-compare.html">http://identitymeme.org/doc/draft-hodges-saml-openid-compare.html</a>
</p></blockquote>
Technorati Tags: <a href="http://www.technorati.com/tag/authentication" rel="tag">authentication</a>, <a href="http://www.technorati.com/tag/Open+Standards" rel="tag">Open Standards</a>, <a href="http://www.technorati.com/tag/openid" rel="tag">openid</a>, <a href="http://www.technorati.com/tag/saml" rel="tag">saml</a>, <a href="http://www.technorati.com/tag/Security" rel="tag">Security</a>, <a href="http://www.technorati.com/tag/simplified+sign+on" rel="tag">simplified sign on</a>, <a href="http://www.technorati.com/tag/single+sign+on" rel="tag">single sign on</a>]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2008/01/21/new-version-of-openid-saml-comparison-document/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>SAML Wiki is open for business</title>
		<link>http://identitymeme.org/archives/2007/12/18/open-saml-wiki-is-open-for-business/</link>
		<comments>http://identitymeme.org/archives/2007/12/18/open-saml-wiki-is-open-for-business/#comments</comments>
		<pubDate>Tue, 18 Dec 2007 23:31:59 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>Uncategorized</dc:subject>
	<dc:subject>SAML</dc:subject>
	<dc:subject>Community</dc:subject><dc:subject>saml</dc:subject>
		<guid>http://identitymeme.org/archives/2007/12/18/open-saml-wiki-is-open-for-business/</guid>
		<description><![CDATA[	It looks like this new SAML wiki..
	SAML.XML.org
	..opened for business on or about the middle of October 2007. Looks like it&#8217;ll be a good resource for the wide SAML community. 
	There&#8217;s also another wiki that&#8217;s apparently for the members of the OASIS Security Services Technical Committee (SSTC - the group creating and shepherding the SAML specs)..
	SSTC [...]]]></description>
			<content:encoded><![CDATA[	<p>It looks like this new SAML wiki..</p>
	<blockquote><p><a href="http://saml.xml.org/">SAML.XML.org</a></p></blockquote>
	<p>..opened for business on or about the middle of October 2007. Looks like it&#8217;ll be a good resource for the wide SAML community. </p>
	<p>There&#8217;s also another wiki that&#8217;s apparently for the members of the OASIS Security Services Technical Committee (SSTC - the group creating and shepherding the SAML specs)..</p>
	<blockquote><p><a href="http://wiki.oasis-open.org/security/FrontPage">SSTC Wiki</a></p></blockquote>
	<p>..so it looks like we&#8217;ll have to be careful to figure out what sort of content goes where. </p>
Technorati Tags: <a href="http://www.technorati.com/tag/saml" rel="tag">saml</a>]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2007/12/18/open-saml-wiki-is-open-for-business/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>SAML Open Source Implementations Page</title>
		<link>http://identitymeme.org/archives/2007/12/18/saml-open-source-implementations-page/</link>
		<comments>http://identitymeme.org/archives/2007/12/18/saml-open-source-implementations-page/#comments</comments>
		<pubDate>Tue, 18 Dec 2007 23:22:57 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>SAML</dc:subject>
	<dc:subject>Software</dc:subject>
	<dc:subject>Open Source</dc:subject><dc:subject>Open Standards</dc:subject><dc:subject>saml</dc:subject><dc:subject>Security</dc:subject><dc:subject>simplified sign on</dc:subject><dc:subject>single sign on</dc:subject>
		<guid>http://identitymeme.org/archives/2007/12/18/saml-open-source-implementations-page/</guid>
		<description><![CDATA[	This page..
	SAML Open Source Implemenations

	..lists eight (at this time) open source SAML implementations of one flavor or another.  If you have one and it isn&#8217;t listed there as yet, create an account and edit the wiki page appropriately  
Technorati Tags: Open Standards, saml, Security, simplified sign on, single sign on]]></description>
			<content:encoded><![CDATA[	<p>This page..</p>
	<blockquote><p><a href="http://saml.xml.org/saml-open-source-implementations">SAML Open Source Implemenations</a>
</p></blockquote>
	<p>..lists eight (at this time) open source SAML implementations of one flavor or another.  If you have one and it isn&#8217;t listed there as yet, create an account and edit the wiki page appropriately <img src='http://identitymeme.org/wp-images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
Technorati Tags: <a href="http://www.technorati.com/tag/Open+Standards" rel="tag">Open Standards</a>, <a href="http://www.technorati.com/tag/saml" rel="tag">saml</a>, <a href="http://www.technorati.com/tag/Security" rel="tag">Security</a>, <a href="http://www.technorati.com/tag/simplified+sign+on" rel="tag">simplified sign on</a>, <a href="http://www.technorati.com/tag/single+sign+on" rel="tag">single sign on</a>]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2007/12/18/saml-open-source-implementations-page/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>(Draft) Technical Comparison: OpenID and SAML</title>
		<link>http://identitymeme.org/archives/2007/12/17/draft-technical-comparison-openid-and-saml/</link>
		<comments>http://identitymeme.org/archives/2007/12/17/draft-technical-comparison-openid-and-saml/#comments</comments>
		<pubDate>Mon, 17 Dec 2007 21:38:51 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>Identity</dc:subject>
	<dc:subject>Security</dc:subject>
	<dc:subject>Public Policy</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>Protocols</dc:subject><dc:subject>authentication</dc:subject><dc:subject>Open Standards</dc:subject><dc:subject>openid</dc:subject><dc:subject>saml</dc:subject><dc:subject>Security</dc:subject><dc:subject>simplified sign on</dc:subject><dc:subject>single sign on</dc:subject>
		<guid>http://identitymeme.org/archives/2007/12/17/draft-technical-comparison-openid-and-saml/</guid>
		<description><![CDATA[	Over the past couple of years quite a few folks have asked me, and I&#8217;m sure others, &#8220;what&#8217;s the salient differences between OpenID and SAML?&#8221;  So earlier this year I began hacking together a technical comparison of the two. It&#8217;s an interesting exercise comparing two Web SSO protocols, even one as ostensibly simple, and [...]]]></description>
			<content:encoded><![CDATA[	<p>Over the past couple of years quite a few folks have asked me, and I&#8217;m sure others, &#8220;what&#8217;s the salient differences between <a href="http://openid.net/">OpenID</a> and <a href="http://wiki.oasis-open.org/security/">SAML</a>?&#8221;  So earlier this year I began hacking together a technical comparison of the two. It&#8217;s an interesting exercise comparing two Web SSO protocols, even one as ostensibly simple, and straightforwardly specified, as OpenID. It turns out to be a fairly complex task given all the different facets inherent in authentication protocols in general, and in web-, i.e. HTTP-based, protocols (and profiles thereof) in particular. And also given the various audiences affected by such protocols: implementors, deployers, end users, and protocol designers. </p>
	<p>The resultant comparison paper, &#8220;Technical Comparison: OpenID and SAML - Draft 05&#8243; seems to me to be at a stage where it can be shared widely (i.e. on the <a href="http://en.wikipedia.org/wiki/World_Wide_Web">web</a> <img src='http://identitymeme.org/wp-images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ), here it is..</p>
	<blockquote><p>
<a href="http://identitymeme.org/doc/draft-hodges-saml-openid-compare-05.html">http://identitymeme.org/doc/draft-hodges-saml-openid-compare-05.html</a>
</p></blockquote>
	<p>..For many readers,<a href="http://identitymeme.org/doc/draft-hodges-saml-openid-compare-05.html#intro"> sections 1</a>, <a href="http://identitymeme.org/doc/draft-hodges-saml-openid-compare-05.html#scnt-exec-summary">2</a>, and perhaps <a href="http://identitymeme.org/doc/draft-hodges-saml-openid-compare-05.html#sctn-term">3</a> ought to cover things. For those necessarily interested in gory, really geeky details, parts or all of <a href="http://identitymeme.org/doc/draft-hodges-saml-openid-compare-05.html#sctn-comparison"> section 4</a> will be of interest. Note that this is still a &#8220;<a href="http://en.wiktionary.org/wiki/Draft">draft</a>&#8220;&#8211;there are various items, especially in <a href="http://identitymeme.org/doc/draft-hodges-saml-openid-compare-05.html#sctn-comparison">section 4</a>, that are not as yet evaluated as thoroughly as I&#8217;d like, or at all (as yet). </p>
	<p>I&#8217;ve tried as much as possible to provide an objective comparison. It&#8217;s admittedly difficult given I&#8217;ve been intimately involved in SAML&#8217;s gestation since essentially the very beginning. It&#8217;s also a technically difficult comparison because of the differing design centers of OpenID and SAML, as well as differing specification styles, and thus the difficulty in presenting the comparison to the reader, not to mention attempting to be &#8220;<a href="http://en.wiktionary.org/wiki/balance">balanced</a>&#8220;. </p>
	<p>So, I hope this paper will prove at least somewhat enlightening and useful to the multifaceted &#8220;<a href="http://en.wikipedia.org/wiki/Identity">identity</a>&#8221; community out there, and to those shepherding <a href="http://en.wikipedia.org/wiki/Website">websites</a> who are wondering what these two oft-mentioned beasts are, how&#8217;re they&#8217;re different/similar/alike, and also nominally how they work. </p>
	<p><a href="http://xri.net/=JeffH">=JeffH</a> sez check it out.</p>
Technorati Tags: <a href="http://www.technorati.com/tag/authentication" rel="tag">authentication</a>, <a href="http://www.technorati.com/tag/Open+Standards" rel="tag">Open Standards</a>, <a href="http://www.technorati.com/tag/openid" rel="tag">openid</a>, <a href="http://www.technorati.com/tag/saml" rel="tag">saml</a>, <a href="http://www.technorati.com/tag/Security" rel="tag">Security</a>, <a href="http://www.technorati.com/tag/simplified+sign+on" rel="tag">simplified sign on</a>, <a href="http://www.technorati.com/tag/single+sign+on" rel="tag">single sign on</a>]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2007/12/17/draft-technical-comparison-openid-and-saml/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Latest revisions of SAML-lSSO and SAML OpenID Profile</title>
		<link>http://identitymeme.org/archives/2007/09/21/latest-revisions-of-saml-lsso-and-saml-openid-profile/</link>
		<comments>http://identitymeme.org/archives/2007/09/21/latest-revisions-of-saml-lsso-and-saml-openid-profile/#comments</comments>
		<pubDate>Fri, 21 Sep 2007 21:32:35 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>Identity</dc:subject>
	<dc:subject>SAML</dc:subject>
	<dc:subject>Draft Specs</dc:subject><dc:subject>Open Standards</dc:subject><dc:subject>openid</dc:subject><dc:subject>saml</dc:subject><dc:subject>Security</dc:subject><dc:subject>simplified sign on</dc:subject><dc:subject>single sign on</dc:subject>
		<guid>http://identitymeme.org/archives/2007/09/21/latest-revisions-of-saml-lsso-and-saml-openid-profile/</guid>
		<description><![CDATA[	I&#8217;ve updated the SAML-lSSO and SAML OpenID Profile specs just to bring them up-to-date with the latest revisions of various SAML and OpenID specs and to fix minor editorial issues. The SAML-lSSO spec is presently not a current IETF Internet-Draft &#8212; it&#8217;s prior version expired a few months ago. We&#8217;re thinking about whether we want [...]]]></description>
			<content:encoded><![CDATA[	<p>I&#8217;ve updated the SAML-lSSO and SAML OpenID Profile specs just to bring them up-to-date with the latest revisions of various SAML and OpenID specs and to fix minor editorial issues. The SAML-lSSO spec is presently <em>not</em> a current IETF Internet-Draft &#8212; it&#8217;s prior version expired a few months ago. We&#8217;re thinking about whether we want to pursue that spec &#8220;officially&#8221; or not. The issue with it being that in implementing it, one can optionally turn security completely off &#8212; which is a &#8220;feature&#8221; various folks advocating for so-called &#8220;open Internet&#8221; identity management desire. But SDOs such as IETF, OASIS, W3C, Liberty Alliance, etc all would look askance at blessing such a spec. In fact the IETF definitely would not allow it to go forward in that they have an explicit policy against promulgating insecure protocols. </p>
	<p>The SAML OpenID Profile is a simple hack I threw together a year or so ago (in a single afternoon) to prove the point that there&#8217;s nothing OpenID accomplishes protocol- and user-experience-wise that is inherently un-do-able with SAML.  [1]</p>
	<p>Anyway, here&#8217;s the links to said specs&#8230;</p>
	<blockquote><p>
<a href="http://identitymeme.org/doc/draft-hodges-saml-lsso-02.html">SAMLv2 Lightweight Web Browser SSO Profile</a>
</p></blockquote>
	<blockquote><p>
<a href="http://identitymeme.org/doc/draft-hodges-saml-openid-profile-02.html">OpenID-SAML Lightweight Web Browser SSO Profile - Draft 02</a>
</p></blockquote>
	<p><a href="http://xri.net/=JeffH">=JeffH</a> sez check &#8216;em out. </p>
	<p>[1] Note that I&#8217;m not claiming that they are equivalently &#8220;easy&#8221; to implement. By &#8220;implement&#8221; I mean to write code implementing the protocol on both or either the Relying Party or Identity Provider (aka OpenID Provider) side. Also note that I don&#8217;t use the term &#8220;implemneting&#8221; as a synonym for &#8220;deployment&#8221;. Also, I am not claiming that they are equivalently &#8220;easy&#8221; to deploy. Almost all the artifacts of deployment are inherent in how a protocol is implemented. A &#8220;feature&#8221; that&#8217;s often claimed about OpenID as a differentiator is that anyone with a minimally capable hosting environment can field an OpenID relying party. I.e. they don&#8217;t need root access, nor access to their webserver configuration, etc. In fact, the same is true with some (all?) of the &#8220;scripty&#8221; SAML implementations, e.g. <a href="http://zxid.org/">ZXID</a> being a case in point. </p>
Technorati Tags: <a href="http://www.technorati.com/tag/Open+Standards" rel="tag">Open Standards</a>, <a href="http://www.technorati.com/tag/openid" rel="tag">openid</a>, <a href="http://www.technorati.com/tag/saml" rel="tag">saml</a>, <a href="http://www.technorati.com/tag/Security" rel="tag">Security</a>, <a href="http://www.technorati.com/tag/simplified+sign+on" rel="tag">simplified sign on</a>, <a href="http://www.technorati.com/tag/single+sign+on" rel="tag">single sign on</a>]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2007/09/21/latest-revisions-of-saml-lsso-and-saml-openid-profile/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>PHP SAML 2.0 IdP launched!</title>
		<link>http://identitymeme.org/archives/2007/09/07/php-saml-20-idp-launched/</link>
		<comments>http://identitymeme.org/archives/2007/09/07/php-saml-20-idp-launched/#comments</comments>
		<pubDate>Fri, 07 Sep 2007 23:54:30 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>Uncategorized</dc:subject>
	<dc:subject>Security</dc:subject>
	<dc:subject>SAML</dc:subject>
	<dc:subject>Software</dc:subject>
	<dc:subject>Open Source</dc:subject><dc:subject>Identity</dc:subject><dc:subject>Open Standards</dc:subject><dc:subject>opensource</dc:subject><dc:subject>saml</dc:subject>
		<guid>http://identitymeme.org/archives/2007/09/07/php-saml-20-idp-launched/</guid>
		<description><![CDATA[	Andreas Åkre Solberg writes on his Feide blog..
	
simpleSAMLphp 0.3 is launched. Most interesting in this new release is the SAML 2.0 IdP functionality. The documentation is not covering everything in detail yet, but it should be sufficient to get something up running.

	The simpleSAMLphp 0.3 package also features a Shibboleth 1.3-compatible SP written in PHP. 
Technorati [...]]]></description>
			<content:encoded><![CDATA[	<p>Andreas Åkre Solberg writes on his <a href="http://rnd.feide.no/">Feide blog</a>..</p>
	<blockquote><p>
simpleSAMLphp 0.3 is launched. Most interesting in this new release is the SAML 2.0 IdP functionality. The documentation is not covering everything in detail yet, but it should be sufficient to get something up running.
</p></blockquote>
	<p>The simpleSAMLphp 0.3 package also features a Shibboleth 1.3-compatible SP written in PHP. </p>
Technorati Tags: <a href="http://www.technorati.com/tag/Identity" rel="tag">Identity</a>, <a href="http://www.technorati.com/tag/Open+Standards" rel="tag">Open Standards</a>, <a href="http://www.technorati.com/tag/opensource" rel="tag">opensource</a>, <a href="http://www.technorati.com/tag/saml" rel="tag">saml</a>]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2007/09/07/php-saml-20-idp-launched/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>SAML and ColdFusion</title>
		<link>http://identitymeme.org/archives/2007/02/09/saml-and-coldfusion/</link>
		<comments>http://identitymeme.org/archives/2007/02/09/saml-and-coldfusion/#comments</comments>
		<pubDate>Fri, 09 Feb 2007 21:34:06 +0000</pubDate>
		<dc:creator>JeffH</dc:creator>
		
	<dc:subject>SAML</dc:subject>
	<dc:subject>Adoption</dc:subject><dc:subject>saml</dc:subject><dc:subject>simplified sign on</dc:subject><dc:subject>single sign on</dc:subject>
		<guid>http://identitymeme.org/archives/2007/02/09/saml-and-coldfusion/</guid>
		<description><![CDATA[	Here&#8217;s someone &#8212; Phil Duba &#8212; out in the wide web-developer world who&#8217;s picked up the SAML specs, largely figured them out, and is working on integrating it (SAML-based SSO) into sites built with Cold Fusion&#8230;
	
SAML and ColdFusion - Part 1
http://www.philduba.com/index.cfm/2006/12/29/SAML-and-ColdFusion&#8211;Part-1
	SAML and ColdFusion - Part 2
http://www.philduba.com/index.cfm/2007/2/9/SAML-and-ColdFusion&#8211;Part-2

	Cool Stuff. 
Technorati Tags: saml, simplified sign on, single sign [...]]]></description>
			<content:encoded><![CDATA[	<p>Here&#8217;s someone &#8212; <a href="http://www.philduba.com/">Phil Duba</a> &#8212; out in the wide web-developer world who&#8217;s picked up the <a href="http://www.oasis-open.org/specs/index.php#samlv2.0">SAML specs</a>, largely figured them out, and is working on integrating it (SAML-based SSO) into sites built with <a href="http://www.adobe.com/products/coldfusion/">Cold Fusion</a>&#8230;</p>
	<blockquote><p>
SAML and ColdFusion - Part 1<br />
<a href="http://www.philduba.com/index.cfm/2006/12/29/SAML-and-ColdFusion--Part-1">http://www.philduba.com/index.cfm/2006/12/29/SAML-and-ColdFusion&#8211;Part-1</a></p>
	<p>SAML and ColdFusion - Part 2<br />
<a href="http://www.philduba.com/index.cfm/2007/2/9/SAML-and-ColdFusion--Part-2">http://www.philduba.com/index.cfm/2007/2/9/SAML-and-ColdFusion&#8211;Part-2</a>
</p></blockquote>
	<p>Cool Stuff. </p>
Technorati Tags: <a href="http://www.technorati.com/tag/saml" rel="tag">saml</a>, <a href="http://www.technorati.com/tag/simplified+sign+on" rel="tag">simplified sign on</a>, <a href="http://www.technorati.com/tag/single+sign+on" rel="tag">single sign on</a>]]></content:encoded>
			<wfw:commentRSS>http://identitymeme.org/archives/2007/02/09/saml-and-coldfusion/feed/</wfw:commentRSS>
	</item>
	</channel>
</rss>
