Home > SOA News > OASIS ratifies long-awaited SAML 2.0
SOA News:
EMAIL THIS

OASIS ratifies long-awaited SAML 2.0

By Nitin Bharti, News Editor
15 Mar 2005 | SearchWebServices.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

OASIS on Monday ratified the long-anticipated Security Assertion Markup Language (SAML) Version 2.0, formalizing a key standard for federated security.

Version 2.0 adds key functions to create and manage federated networks that share preexisting repositories of identity information. It unifies the protocols defined in SAML 1.0, such as single sign-on, with work the Liberty Alliance Project did through its identity federation framework.

SAML, which enables the secure exchange of authentication, attribute and authorization information across security boundaries, leverages core Web services standards, including XML, SOAP, Transport Layer Security, XML Signature and XML Encryption.

"Prior to SAML, there was no XML-based standard that enabled the exchange of security information between a security system and an application," said John Pescatore, analyst at Stamford, Conn.-based Gartner Inc. "SAML also specifies a Web services-based request/reply protocol for exchanging these statements."

Last month, the Liberty Alliance released the public draft of its Identity Web Services Framework 2.0 specification, which was extended to support the SAML 2.0 specification. Now developers can use SAML assertions to communicate identity information, such as authentication status, user attributes and authorization decisions, between identity-based Web service transactions.

For more information

Learn how XACML and SAML are synergistic

 

See how the Liberty Alliance is supporting SAML 2.0

"SAML is fast becoming the dominant Web services standard for federating 'identity as a service,'" said Eugene Kuznetsov, chief technology officer and chairman of Cambridge, Mass.-based DataPower Technology. "The 2.0 version of SAML and the very successful 12-vendor OASIS SAML Interoperability Lab at the RSA conference are further proof of SAML's maturity."

In February, at least 12 vendors teamed up with the U.S. General Service Administration E-Gov E-Authentication Initiative to demonstrate the interoperability of SAML 2.0 using a combination of Web single sign-on and single logout scenarios.

In separate statements, BEA Systems Inc., IBM, Oracle Corp., SAP AG and Sun Microsystems Inc. said they support the latest iteration of the standard.

SAML 2.0's approval comes on the heels of the ratification of the Extensible Access Control Markup Language (XACML) 2.0, which defines an XML schema for representing authorization and entitlement policies. SAML and XACML share a common domain model and complement one another.

While SAML enables the secure exchange of identity information across security boundaries, XACML leverages this information to determine access to resources using a policy enforcement point and a policy decision point.

"SAML 2.0 is the underpinning of identity-based integration," said Miko Matsumura, vice president of marketing at Cupertino, Calif.-based Infravio Inc. "As Web services applications integrate with business processes (through standards like BPEL), securely managed identities become endpoints for orchestration and workflow."



Tags: SAMLOASIS SOA and Web services standardsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
SAML
UML-based SoaML attacks SOA services modeling issues
IBM, HP qualify on SAML 2.0
SOA governance, security concerns drive XACML interop
Microsoft, Liberty join for Web services identity interop
OASIS begins work on WS-Federation
Web 2.0 lacks the business impact of SOA, Burton warns
Eclipse and Novell join in Web service security effort
Liberty reaches out to open source
SAML declares victory, closes in on a billion IDs
WS-Security 1.1 approved
SAML Research

OASIS SOA and Web services standards
BPEL4People and WS-HumanTask get reference implementation
BPEL4People seen uniting SOA/BPM
Mindreef updates SOA testing tools
The Content Assembly Mechanism and SOA data service layers
OASIS okays ebXML messaging standard
The standards behind Web services
SOA simplicity by committee?
Apache releases Java SCA
Why does SOA need BPEL?
JCP offers portlet spec

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



SOA Web Services: Application Server, Portals, Java, Microsoft .NET
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2001 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts