Home > SOA Tips > XML Developer > Security concerns unite archrivals Microsoft, Sun
SOA Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

XML DEVELOPER

Security concerns unite archrivals Microsoft, Sun


Ed Tittel
05.31.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Like the occasional needs of political reality, those for information security can -- and sometimes do -- trump the impulses of competitors to compete rather than collaborate. This phenomenon showed itself in spades on May 13, when Microsoft Corp. and Sun Microsystems held a joint press conference to spread the word about two new, XML-based identity management specifications, along with plans for additional collaboration aimed at supporting product interoperability and enhanced security.

The focus of this unusual partnership is to create Single-Sign On (SSO) identity specifications for use on the Web. This recent work has resulted in two specifications:

  • Web Single-Sign On Metadata Exchange Protocol (Web SSO MEX protocol): this is designed to enable services to "...query an identity provider for metadata that describes the identity-processing protocol suites supported..." to facilitate communications between the service provider and the identity provider.
  • Web Single-Sign On Interoperability Profile (Web SSO Interop profile): this creates an interoperability profile of the Web SSO MEX Protocol designed to permit Liberty Identity Federation or Web Services (WS)-Federation based identity providers to interact with a Web service.

Together, the two specifications are intended to let Web service providers turn to reliable third parties for identity verification and processing, and, in turn, to make it easy for those third parties to deliver identity information and verification back to those same service providers.

The idea, of course, is to put XML to a standard and desirable use -- namely, to reduce or eliminate code dependencies associated with different groups of identity providers (in this case, the Liberty Identity Federation and WS-Federation are singled out for specific mention, but there's no reason why other such associations couldn't also be included in the future). The impetus behind SSO is to make it easy to establish and maintain identity when logging into one type of system, then making it likewise easy (but also transparent) to establish identity on other types of systems in the background as part of handling access requests, rather than requiring additional logins and requiring further proofs of identity.

Although there's still a lot of work left to do before these drafts change from working to recommended status, it's an encouraging sign that companies that are sometimes at odds can collaborate to meet genuine user needs that cross product and platform boundaries. It should be interesting to watch this effort mature and begin to deliver on its promises to enable single sign-on for multiple Web service environments.

The text of the original press release is available, as is a transcript of the press conference held on May 13, 2005. Drafts of the specifications are available at Microsoft and Sun for public comment.

Ed Tittel is a full-time writer and trainer whose interests include XML and development topics, along with IT Certification and information security topics. E-mail Ed with comments, questions, or suggested topics or tools for review.


Rate this Tip
To rate tips, you must be a member of SearchSOA.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Web services security specifications
The case against WS-Security
SOA governance, security concerns drive XACML interop
OASIS begins work on WS-Federation
Web 2.0 lacks the business impact of SOA, Burton warns
New BizTalk Services rolling out
Malicious JavaScript threat seen growing
Will acquisitions stifle SOA innovation?
Web services security standards approved
WS-Policy on SOA fast track, W3C approval this summer
Web services and SOA security standard released

XML and XML schema
What's the future of XML?
SOA pattern of the week (#7): policy centralization
Try XML-based Extensible Business Reporting Language (XBRL) for accounting reports
What's new at the W3C
Ganymede: Modeling tools target SOA, UML
Data services mashups emerge for SOA
Making sense of data services mashups
XML turns 10
SOA helps save 100-year-old business
Oracle maps heterogeneous data services strategy for SOA

XML Developer
Use the soapUI software tool to tame WSDL
WSDL 2.0, new messaging for Web services
Using RELAX NG For data integration
Efficient XML Interchange tackles data verbosity
XML to DDL imports, synchronizes database schemata
The basics of MathML 3.0
Migrating to XSLT 2.0
What's up with XML 2.0?
Say hello to XPath 2.0
Podcasting software covers many bases

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
WS-SecureConversation  (SearchSoftwareQuality.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Software Design & Testing - Project Management
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2001 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts