Members of the OASIS Web Services Federation (WSFED) Technical Committee have released an approved draft of WS-Federation version 1.2 for public review. The specification defines mechanisms to allow different security realms to federate, such that authorized access to resources managed in one realm can be provided to security principals whose identities are managed in other realms.This includes mechanisms for brokering of identity, attribute, authentication and authorization assertions between realms, and privacy of federated claims. The public review ends 12 Feb 2009.
News
WS-Federation 1.2 public review begins
New Year’s Resolution: Let’s Talk More about SPML
Jackson Shaw and James McGovern have been blogging recently about one of my favorite topics: Service Provisioning Markup Language (SPML). I’d like to contribute to the discussion.
Blogger: Mark Diodati - Burton Group
Single Sign-On and Social Networks
authentication -- letting users sign on to the Internet once and securely
access network resources anywhere has been one of the industry's enduring
quests. While numerous standards efforts have steadily pursued this
capability, most have been back-end technologies of which users are
mostly unaware. Periodically, however, something brings these efforts
to the foreground. Recent developments surrounding the open source OpenID
SC World Congress: Commission on cybersecurity releases recommendations
Cybersecurity control should be taken away from the U.S. Department of Homeland Security placed under the White House's purview, a panel of government and industry leaders are urging President-elect Barack Obama.
The Commission on Cybersecurity for the 44th Presidency, which released its recommendations on Monday in a 63-page report, said an executive White House office should be charged with cybercrime coordination.
Researchers Hack Internet Security Infrastructure-International Team Discovers Way to Mimic Digital Identity
An international team of computer security researchers demonstrated today a key weakness in the Internet infrastructure that could let hackers launch virtually undetectable attacks aimed at intercepting secured online communications when consumers visit bank and e-commerce Web sites.
By Brian Krebs washingtonpost.com Staff Writer
